Commands
Commands
• Move log file to temp before extracting because unable to extract from log
file.
• Email protection – smtpd service
• Xstream firewall engine
• Sslx (snort)-service for web protection
• Ips (snort) service
• Sqllite (garner) - syslog (all events – heartbeat, endpoint certificates).
• Fast path fw doesn’t go through dpi.
===================================================================================
===========
Memory issues:
=====
Wed Nov 15 17:08:18 2023
Listerner is in UNFREEZED STATE
Freeze INIT wait val : 10
Freeze wait val : 120
Opcode queue len : 50
Service queue len: 50
==============================================================================
Hardware issues:
TAR file:
cd /log
===================================================================================
=========
TCPDUMP
tcpdump -veni any host IP_ADDRESS -s0 -w /var/tslog/tcpdump.pcap (to save to a pcap
file)
===================================================================================
==
DRP PKT
drppkt This command displays the packets dropped by firewall rules. It will provide
connection details and details of the packets processed by the device. This will
help administrators to troubleshoot errant firewall rules. You can also filter the
dropped packets.
drppkt host 10.10.10.1 and port 21 (This will display all dropped packets for host
10.10.10.1 and port 21)
drppkt command
Example
specific host
drppkt host <ipaddress>
specific network
===================================================================================
=======
Conttrack
-E = Events
Conntrack -D -d IP_ADDRESS
Conntrack -D -s IP_ADDRESS
===================================================================================
========
service -S | sort
https://community.sophos.com/sophos-xg-firewall/f/discussions/110323/restart-
application-and-url-filtering-services-from-cli
===================================================================================
=======================
CLI Links:
Device console
https://doc.sophos.com/nsg/sophos-firewall/19.0/Help/en-us/webhelp/onlinehelp/
CommandLineHelp/DeviceConsole/index.html#tcpdump
Sophos Firewall: CLI Troubleshooting Tools
https://community.sophos.com/sophos-xg-firewall/f/recommended-reads/117389/sophos-
firewall-cli-troubleshooting-tools
https://support.sophos.com/support/s/article/KB-000037007?language=en_US
https://doc.sophos.com/nsg/sophos-firewall/19.5/Help/en-us/webhelp/onlinehelp/
AdministratorHelp/Diagnostics/PacketCapture/
DiagnosticsPacketCaptureFilterConfigure/index.html
https://community.sophos.com/sophos-xg-firewall/f/recommended-reads/114837/sophos-
firewall-how-to-tcpdump
https://support.sophos.com/support/s/article/KB-000036858?language=en_US
===================================================================================
===================================
===================================================================================
===============================
===================================================================================
================================
FSCK reboot
https://support.sophos.com/support/s/article/KB-000035769?language=en_US
https://docs.sophos.com/nsg/sophos-firewall/20.0/Help/en-us/webhelp/onlinehelp/
CommandLineHelp/SystemSettings/SkipMFAforAdmin/index.html
===================================================================================
=======================
Please refer the below docs for var size increase and workaround on it:
https://community.sophos.com/sophos-xg-firewall/f/discussions/136642/sophos-xg-
450---var-newdb-base-16386-full
https://support.sophos.com/support/s/article/KB-000042543?language=en_US
https://community.sophos.com/sophos-xg-firewall/f/discussions/136211/sophos-xg---
config-disk-usage-exceeded-the-threshold
https://community.sophos.com/sophos-xg-firewall/f/discussions/137145/reports-disk-
usage-reached-90-exceeding-the-higher-watermark-of-90
===================================================================================
=======================
Log settings
https://docs.sophos.com/nsg/sophos-firewall/20.0/Help/en-us/webhelp/onlinehelp/
AdministratorHelp/SystemServices/LogSettings/index.html
Data management
https://docs.sophos.com/nsg/sophos-firewall/20.0/Help/en-us/webhelp/onlinehelp/
AdministratorHelp/Reports/ReportSettings/configdatabase/index.html
Manual purge
https://docs.sophos.com/nsg/sophos-firewall/20.0/Help/en-us/webhelp/onlinehelp/
AdministratorHelp/Reports/ReportSettings/manualpurge/index.html