fwaccel templates
Description
The fwaccel templates and fwaccel6 templates commands show the contents of the SecureXL Check Point product on a Security Gateway that accelerates IPv4 and IPv6 traffic that passes through a Security Gateway. templates tables:
-
Accept Templates
-
Drop Templates
Important - By default, the Drop Templates are disabled.
To enable the Drop Templates:
-
In SmartConsole Check Point GUI application used to manage a Check Point environment - configure Security Policies, configure devices, monitor products and events, install updates, and so on., open the Security Gateway Dedicated Check Point server that runs Check Point software to inspect traffic and enforce Security Policies for connected network resources. / Cluster Two or more Security Gateways that work together in a redundant configuration - High Availability, or Load Sharing. object.
-
In the left tree, click the Optimizations pane.
-
Select Enable drop optimization.
-
Click OK.
-
Install the Access Control policy.
-
|
Important - Based on the number of current templates, these commands can consume memory at very high level. |
Syntax for IPv4
|
Syntax for IPv6
|
Parameters
Parameter |
Description |
---|---|
No Parameters |
Shows the contents of the SecureXL Accept Templates table (Table Name - |
|
Shows the applicable built-in usage. |
|
Shows the contents of the SecureXL Drop Templates table. |
|
Specifies how many rows to show from the templates table. Note - The command counts from the top of the table. Default : 1000 |
|
Shows the summary of SecureXL Connections Templates (number of templates) |
|
Shows statistics for the SecureXL Connections Templates. |
Accept Templates flags
One or more of these flags appears in the output:
Flag |
Description |
---|---|
A |
Connection is accounted (SecureXL counts the number of packets and bytes). |
B |
Connection is created for a rule Set of traffic parameters and other conditions in a Rule Base (Security Policy) that cause specified actions to be taken for a communication session. that contains an Identity Awareness Check Point Software Blade on a Security Gateway that enforces network access and audits data based on network location, the identity of the user, and the identity of the computer. Acronym: IDA. object, or for a rule below that rule. |
E |
Connection is created for a NAT rule that contains an Identity Awareness object. |
I |
Identity Awareness (NAC) is enabled for this connection. |
M |
Connection is created for a rule that contains a Domain object, or for a rule below that rule. |
N |
Connection undergoes NAT. |
O |
Connection is created for a rule that contains a Dynamic object, or for a rule below that rule. |
Q |
QoS Check Point Software Blade on a Security Gateway that provides policy-based traffic bandwidth management to prioritize business-critical traffic and guarantee bandwidth and control latency. is enabled for this connection. |
R |
Connection is created for a rule that contains a Traceroute object, or for a rule below that rule. |
S |
|
T |
Connection is created for a rule that contains a Time object, or for a rule below that rule. |
U |
Connection is unidirectional. |
X |
Connection is created for a NAT rule that contains a translated Dynamic object. |
Z |
Connection is created for a rule that contains a Security Zone object, or for a rule below that rule. |
Drop Templates flags
One or more of these flags appears in the output:
Flag |
Description |
---|---|
D |
Drop template exists for this connection. |
L |
Log and Drop action for this connection. |
Examples
[Expert@MyGW:0]# fwaccel templates -d
The SecureXL drop templates table is empty
[Expert@MyGW:0]#
|
[Expert@MyGW:0]# fwaccel templates -s Total number of templates: 1 [Expert@MyGW:0]# |