fw ctl

Description

Controls the Firewall kernel module.

Important - In a Cluster, you must configure all the Cluster Members in the same way.

Syntax

fw [-d] ctl

      arp <options>

      bench <options>

      block <options>

      chain

      conn

      conntab <options>

      cpasstat <options>

      debug <options>

      get <options>

      iflist

      install

      kdebug <options>

      pstat <options>

      set <options>

      tcpstrstat <options>

      uninstall

Parameters

Parameter

Description

-d

Runs the command in debug mode.

Use only if you troubleshoot the command itself.

Best Practice - If you use this parameter, then redirect the output to a file, or use the script command to save the entire CLI session.

arp <options>

Shows the configured Proxy ARP entries based on the $FWDIR/conf/local.arp file on the Security Gateway.

See fw ctl arp.

bench <options>

Runs the CPU benchmark tests that collect these statistics:

  • FireWall Lock Statistics

  • Outbound Packets Statistics

  • Inbound Packets Statistics

See fw ctl bench.

block <options>

Blocks all connections to, from, and through the Security Gateway.

See fw ctl block.

chain

Shows the list of Firewall Chain Modules.

See fw ctl chain.

conn

Shows the list of Firewall Connection Modules.

See fw ctl conn.

conntab <options>

Shows formatted list of current connections from the Connections kernel table (ID 8158).

See fw ctl conntab.

cpasstat <options>

Generates statistics report about Check Point Active Streaming (CPAS).

See fw ctl cpasstat.

debug <options>

Generates kernel debug messages from Check Point Firewall kernel to a debug buffer.

See 'fw ctl debug' and 'fw ctl kdebug'.

dlpkstat <options>

Generates statistics report about Data Loss Prevention kernel module.

See fw ctl dlpkstat.

get <options>

Shows the value of the specified kernel parameter.

See fw ctl get.

iflist

Shows the list with this information:

  • The name of interfaces, to which the Check Point Firewall kernel attached.

  • The internal numbers of the interfaces in the Check Point Firewall kernel.

See fw ctl iflist.

install

Tells the operating system to start passing packets to Firewall.

See fw ctl install.

kdebug <options>

Generates kernel debug messages from Check Point Firewall kernel to a debug buffer.

See 'fw ctl debug' and 'fw ctl kdebug'.

leak <options>

Generates leak detection report.

See fw ctl leak.

pstat <options>

Shows Security Gateway various internal statistics.

See fw ctl pstat.

set <options>

Configures the specified value for the specified kernel parameter.

See fw ctl set.

tcpstrstat <options>

Generates statistics report about TCP Streaming.

See fw ctl tcpstrstat.

uninstall

Tells the operating system to stop passing packets to Firewall, and unloads the current Security Policy.

See fw ctl uninstall.