Checkpoint commands generally come under, | |
cp - general | |
fw - firewall | |
fwm - management | |
CP, FW & FWM Commands | |
cphaprob stat | List cluster status |
cphaprob -a if | List status of interfaces |
cphaprob syncstat | shows the sync status |
cphaprob list | Shows a status in list form |
cphastart/stop | Stops clustering on the specfic node |
cp_conf sic | SIC stuff |
cpconfig | config util |
cplic print | prints the license |
cprestart | Restarts all Checkpoint Services |
cpstart | Starts all Checkpoint Services |
cpstop | Stops all Checkpoint Services |
cpstop -fwflag -proc | Stops all checkpoint Services but keeps policy active in kernel |
cpwd_admin list | List checkpoint processes |
cplic print | Print all the licensing information. |
cpstat -f all polsrv | Show VPN Policy Server Stats |
cpstat | Shows the status of the firewall |
fw tab -t sam_blocked_ips | Block IPS via SmartTracker |
fw tab -t connections -s | Show connection stats |
fw tab -t connections -f | Show connections with IP instead of HEX |
fw tab -t fwx_alloc -f | Show fwx_alloc with IP instead of HEX |
fw tab -t peers_count -s | Shows VPN stats |
fw tab -t userc_users -s | Shows VPN stats |
fw checklic | Check license details |
fw ctl get int [global kernel parameter] | Shows the current value of a global kernel parameter |
fw ctl set int [global kernel parameter] [value] | Sets the current value of a global keneral parameter. Only Temp ; Cleared after reboot. |
fw ctl arp | Shows arp table |
fw ctl install | Install hosts internal interfaces |
fw ctl ip_forwarding | Control IP forwarding |
fw ctl pstat | System Resource stats |
fw ctl uninstall | Uninstall hosts internal interfaces |
fw exportlog .o | Export current log file to ascii file |
fw fetch | Fetch security policy and install |
fw fetch localhost | Installs (on gateway) the last installed policy. |
fw hastat | Shows Cluster statistics |
fw lichosts | Display protected hosts |
fw log -f | Tail the current log file |
fw log -s -e | Retrieve logs between times |
fw logswitch | Rotate current log file |
fw lslogs | Display remote machine log-file list |
fw monitor | Packet sniffer |
fw printlic -p | Print current Firewall modules |
fw printlic | Print current license details |
fw putkey | Install authenication key onto host |
fw stat -l | Long stat list, shows which policies are installed |
fw stat -s | Short stat list, shows which policies are installed |
fw unloadlocal | Unload policy |
fw ver -k | Returns version, patch info and Kernal info |
fwstart | Starts the firewall |
fwstop | Stop the firewall |
fwm lock_admin -v | View locked admin accounts |
fwm dbexport -f user.txt | used to export users , can also use dbimport |
fwm_start | starts the management processes |
fwm -p | Print a list of Admin users |
fwm -a | Adds an Admin |
fwm -r | Delete an administrator |
Provider 1 | |
mdsenv [cma name] | Sets the mds environment |
mcd | Changes your directory to that of the environment. |
mds_setup | To setup MDS Servers |
mdsconfig | Alternative to cpconfig for MDS servers |
mdsstat | To see the processes status |
mdsstart_customer [cma name] | To start cma |
mdsstop_customer [cma name] | To stop cma |
cma_migrate | To migrate an Smart center server to CMA |
cmamigrate_assist | If you dont want to go through the pain of tar/zip/ftp and if you wish to enable FTP on Smart center server |
VPN | |
vpn tu | VPN utility, allows you to rekey vpn |
vpn ipafile_check ipassignment.conf detail | Verifies the ipassignment.conf file |
dtps lic | show desktop policy license status |
cpstat -f all polsrv | show status of the dtps |
vpn shell /tunnels/delete/IKE/peer/[peer ip] | delete IKE SA |
vpn shell /tunnels/delete/IPsec/peer/[peer ip] | delete Phase 2 SA |
vpn shell /show/tunnels/ike/peer/[peer ip] | show IKE SA |
vpn shell /show/tunnels/ipsec/peer/[peer ip] | show Phase 2 SA |
vpn shell show interface detailed [VTI name] | show VTI detail |
Debugging | |
fw ctl zdebug drop | shows dropped packets in realtime / gives reason for drop |
SPLAT Only | |
router | Enters router mode for use on Secure Platform Pro for advanced routing options |
patch add cd | Allows you to mount an iso and upgrade your checkpoint software (SPLAT Only) |
backup | Allows you to preform a system operating system backup |
restore | Allows you to restore your backup |
snapshot | Performs a system backup which includes all Checkpoint binaries. Note : This issues a cpstop. |
VSX | |
vsx get [vsys name/id] | get the current context |
vsx set [vsys name/id] | set your context |
fw -vs [vsys id] getifs | show the interfaces for a virtual device |
fw vsx stat -l | shows a list of the virtual devices and installed policies |
fw vsx stat -v | shows a list of the virtual devices and installed policies (verbose) |
reset_gw | resets the gateway, clearing all previous virtual devices and settings. |
Labels
- Cheat Sheets (7)
- Checkpoint (159)
- Cisco (24)
- Commands (5)
- Fortigate (2)
- Frame-Relay (9)
- Linux (3)
- Netscaler (29)
- Netscreen (2)
- Nokia (7)
- UNIX (2)
Live Traffic
Checkpoint - Commands
5/18/2010 07:14:00 AM
Posted by MK | Filed Under Commands | 0 Comments
Comments
Search This Blog
Blog Archive
-
▼
2010
(146)
-
▼
May
(90)
- Checkpoint - Ports
- UNIX - The Ultimate Linux Command Reference Guide
- Checkpoint - Useful Files
- Checkpoint Commands
- Alw@ys Knw Wh@ts Happening inside your KERNEL - “A...
- Nokia - Cluster Mac Address - "Grep" Strikes Again...
- Traceroute from Unix
- Checkpoint Logging Issue
- Change Date in Linux
- Finding Smartcenter Server - from Gateway
- SPLAT - Forgot Standard Password
- Checkpoint : fw ctl pstat ???
- GRE is like Girls!!! - GRE Tunnel in IPSEC - there...
- Checkpoint : How to Find the the Management Interface
- Checkpoint Troubleshooting - Debugging
- SSH session timeout in Checkpoint NG/NGX
- Manage VPN tunnels smartly: forget vpn tu,enter th...
- Clear ARP table in Checkpoint
- Mail alert on ssh login or any other rule hit in C...
- What ports are used for communication and how to p...
- fw monitor add-on
- awk weekly – how to see Checkpoint logs on command...
- awk weekly – rule hits statistics . Checkpoint again
- Install native telnet client on Checkpoint firewall
- Telnet from inside Checkpoint firewall
- fw ctl or checkpoint tables by any other name
- Authenticating ssh access on the Checkpoint using ...
- How to add routing script on Secureplatform?
- Checkpoint concurrent sessions and memory calculat...
- Capazity Optimization
- My favorite troubleshooting command
- Neighbour table overflow
- SecurePlatform and NTP
- Delete old log files on SPLAT machines
- Delete all ARP entries on SPLAT
- Download backup from SmartCenter using SCP
- Change password on non-admin user in SPLAT
- How to run web visualization tool in check point??
- How to configure SmartView Monitor Mail Alert in C...
- fw monitor command reference
- NetScaler Password Recovery Procedure
- Installing and Configuring VSX
- Citrix Access Gateway Enterprise - Redirect incomi...
- Enabling LDAP Authentication on the NetScaler
- Citrix Netscaler NS7000 : how to create a content ...
- Citrix Netscaler NS7000 : how to create a content ...
- Cisco VPN Troubleshooting Guide
- Usefull Checkpoint Commands
- Checkpoint FW Monitor
- Causes for a failover when using VRRP
- Usefull Nokia IPSO Commands
- Checkpoint Tables and the FW Tab Command
- Common CLISH Commands
- Installing and Configuring VSX
- So what are QDROPS anyway
- Clearing the host table on Checkpoint
- Provider-1 Quick Guide
- When are Proxy Arps required on Checkpoint devices
- Unable to delete tunnels on a Checkpoint VIA VPN TU?
- Checkpoint VPN stats
- View Checkpoint VPN traffic decrypted on the wire
- View last 10 policies installed on a Checkpoint fi...
- How to view Checkpoint tables in ASCII
- Checkpoint Splat source based routing
- Trobleshooting the Checkpoint Daemon (CPD)
- Checkpoint port list
- Modifying the SPLAT Webmanager port
- Creating a Read Only SPLAT user
- Configuring SNMP on SPLAT
- Allowing scp to SPLAT boxes
- Resolving local logging issues on Checkpoint
- How to globally change the expiration date of all ...
- rtm monitor in Checkpoint
- Everything you need to know about troubleshooting ...
- SPLAT - Route / Static ARP startup Script
- How do I change an IP address on a IPSO Nokia Fire...
- How do I create an IPSO backup via clish ?
- Nokia IPSO Password Recovery
- Useful Netscreen Commands for Troubleshooting
- How to Find the Speed of an Interface on a Solaris...
- How to Install Checkpoint Firewall NGX on SecurePl...
- How to fix Check Point High Availability State Syn...
- Basic Netscreen Commands
- Re-establishing SIC (Secure Internal Communication...
- Cisco site to site VPN Configuration Cheatsheet
- Troubleshooting VRRP on Nokia Checkpoint Firewalls
- Usefull Nokia IPSO Commands
- Nokia Top Clish Commands Reference
- IPSO - Commands
- Checkpoint - Commands
-
▼
May
(90)
Post a Comment