< Home

display firewall session statistics

Function

The display firewall session statistics command displays statistics on the session table.

Format

display firewall session statistics [ vsys vsysname | all-systems ] [ source-cpe ipv6-address ] [ source { inside ip-address | global ip-address } ] [ destination-cpe ipv6-address ] [ destination { inside ip-address | global ip-address } ] [ slot slot-id cpu cpu-id ] [ protocol protocol ] [ application application ] [ fastflow | fastflow-deny ] [ { forward-type | forward-type rev } ipsec ] [ source-port { inside inside-source-port | global global-source-port } ] [ destination-port { inside inside-destination-port | global global-destination-port } ] [ long-link ] [ service service-name ]

display firewall ipv6 session statistics [ vsys vsysname | all-systems ] [ source { inside ipv6-address | global ipv6-address ] [ destination { inside ipv6-address | global ipv6-address ] [ slot slot-id cpu cpu-id ] [ protocol protocol ] [ application application ] [ { forward-type | forward-type rev } ipsec ] [ source-port { inside inside-source-port | global global-source-port } ] [ destination-port { inside inside-destination-port | global global-destination-port } ] [ long-link ] [ service service-name ]

display firewall session statistics all-systems verbose [ slot slot-id cpu cpu-id ]

display firewall ipv6 session statistics all-systems verbose [ slot slot-id cpu cpu-id ]

Parameters

Parameter Description Value

vsys vsys-name

Specifies a virtual system.

NOTE:

The root system is a specific virtual system existing on the FW by default. To view the session statistics of the root system separately, set vsys-name to public.

-

all-systems

Displays the session statistics of the entire device.

-

source-cpe ipv6-address

Specifies the IPv6 address of the Customer Premise Equipment (CPE).

-

destination-cpe ipv6-address

Specifies the IPv6 address of the CPE.

-

source

Indicates the source IP address.

-

destination

Indicates the destination IP address.

-

ip-address

Specifies an IP address.

The value is in dotted decimal notation.

ipv6-address

Specifies an IPv6 address.

-

inside

Specifies the private network IP address.

-

global

Specifies the public network IP address.

-

verbose

Displays session table details.
  • If verbose is not specified behind all-systems, the session statistics of the root system and virtual system are not distinguished in the command output.
  • If verbose is specified behind all-systems, the command output includes the session statistics of the entire device, the session statistics of virtual systems, and session statistics of the root system.

-

slot slot-id

Specifies the slot ID.Only the USG6610E/6620E, USG6615E/6625E, USG6630E/6650E, USG6635E/6655E, USG6680E, and USG6712E/6716E support this parameter.

-

cpu cpu-id

Specifies the ID of CPU.Only the USG6610E/6620E, USG6615E/6625E, USG6630E/6650E, USG6635E/6655E, USG6680E, and USG6712E/6716E support this parameter.

-

protocol protocol

Specifies a protocol.

The value of the protocol is AH, ESP, GRE, ICMP, TCP and UDP.

application application

Specifies an application.

-

fastflow

Displays statistics on sessions for hardware-based fast forwarding.

In versions earlier than V600R007C20SPC200, all models support this parameter. For V600R007C20SPC200 and later versions, device batches are distinguished by BomID Version (which can be checked using the display version command). All models except the USG6680E and USG6712E/6716E whose BomID Version is 003 or later or whose device BOM numbers contain "-001" support this parameter.

-

fastflow-deny

Displays statistics on sessions not for hardware-based fast forwarding.

In versions earlier than V600R007C20SPC200, all models support this parameter. For V600R007C20SPC200 and later versions, device batches are distinguished by BomID Version (which can be checked using the display version command). All models except the USG6680E and USG6712E/6716E whose BomID Version is 003 or later or whose device BOM numbers contain "-001" support this parameter.

-

forward-type

Specifies the forwarding type of the initiator's traffic.

-

forward-type-rev

Specifies the forwarding type of the responder's traffic.

-

ipsec

Displays statistics about IPSec sessions.

-

source-port { inside inside-source-port | global global-source-port }

Specifies a source port.

The value is an integer. When you view the statistics of the IPv4 session table, the value ranges from 0 to 65535. When you view the statistics of the IPv6 session table, the value ranges from 1 to 65535.

destination-port { inside inside-destination-port | global global-destination-port }

Specifies a destination port.

The value is 1 to 65535 in integer.

long-link

Displays the session statistics of the persistent connection.

-

service service-name

Specifies the name of a service or service group.

-

Views

All views

Default Level

1: Monitoring level

Usage Guidelines

None

Example

# Display statistics on the session table with public system.
<sysname> display firewall session statistics
 Session Statistics:                                                            
 Slot 11 cpu 0:       132675                                                         
 Total 132675 [1.11%] session(s) on all slots.                                       
                                                                                
 Session Creation Rate(num/s):                                                  
 Slot 11 cpu 0:       2360                                                       
 Total session(s) creation rate on all slots is 2360.                              
                                                                                
 Max Session Statistics:                                                        
 Slot 11 cpu 0:      136157, time:2017/04/19 19:03:54                               
 Total max session(s) on all slot is 136157, time is 2017/04/19 19:03:54.           
                                                                                
 Max Session Creation Rate(num/s):                                              
 Slot 11 cpu 0:      12271, time:2017/04/19 19:11:50                               
 Total max session(s) creation rate on all slot is 12271, time is 2017/04/19 19:11:
50. 
# Display the session statistics of the entire device.
<sysname> display firewall session statistics all-systems
 Session Statistics:                                                            
 Slot 11 cpu 0:       132675                                                         
 Total 132675 [1.11%] session(s) on all slots.                                       
                                                                                
 Session Creation Rate(num/s):                                                  
 Slot 11 cpu 0:       2360                                                       
 Total session(s) creation rate on all slots is 2360.                              
                                                                                
 Max Session Statistics:                                                        
 Slot 11 cpu 0:      136157, time:2017/04/19 19:03:54                               
 Total max session(s) on all slot is 136157, time is 2017/04/19 19:03:54.           
                                                                                
 Max Session Creation Rate(num/s):                                              
 Slot 11 cpu 0:      12271, time:2017/04/19 19:11:50                               
 Total max session(s) creation rate on all slot is 12271, time is 2017/04/19 19:11:
50. 
# Display the session statistics of the entire device, the session statistics of virtual systems, and session statistics of the root system.
<sysname> display firewall session statistics all-systems verbose
 Session Statistics:                                                            
 Slot 11 cpu 0:       132675                                                         
 Total 132675 [1.11%] session(s) on all slots.                                       
                                                                                
 Session Creation Rate(num/s):                                                  
 Slot 11 cpu 0:       2360                                                       
 Total session(s) creation rate on all slots is 2360.                              
                                                                                
 Max Session Statistics:                                                        
 Slot 11 cpu 0:      136157, time:2017/04/19 19:03:54                               
 Total max session(s) on all slot is 136157, time is 2017/04/19 19:03:54.           
                                                                                
 Max Session Creation Rate(num/s):                                              
 Slot 11 cpu 0:      12271, time:2017/04/19 19:11:50                               
 Total max session(s) creation rate on all slot is 12271, time is 2017/04/19 19:11:
50.                                                                              
                                                                                
--------------------------------------------------------------------------------
Vsys name: public                           ID: 0                               
 Session Statistics:                                                            
 Slot 11 cpu 0:       132675                                                         
 Total 132675 session(s) on all slots.                                               
 Total session creation rate on all slot is 2360.                                  
 Total max session(s) on all slot is 136157, time is 2017/04/19 19:03:54.           
 Total max session creation rate on all slot is 12271, time is 2017/04/19 19:11:50.
                                                                                
--------------------------------------------------------------------------------
# Display statistics on the session table with all systems.
<sysname> display firewall session statistics all-systems
 Session Statistics:                                                            
 Slot 11 cpu 0:       132675                                                         
 Total 132675 [1.11%] session(s) on all slots.                                       
                                                                                
 Session Creation Rate(num/s):                                                  
 Slot 11 cpu 0:       2360                                                       
 Total session(s) creation rate on all slots is 2360.                              
                                                                                
 Max Session Statistics:                                                        
 Slot 11 cpu 0:      136157, time:2017/04/19 19:03:54                               
 Total max session(s) on all slot is 136157, time is 2017/04/19 19:03:54.           
                                                                                
 Max Session Creation Rate(num/s):                                              
 Slot 11 cpu 0:      12271, time:2017/04/19 19:11:50                               
 Total max session(s) creation rate on all slot is 12271, time is 2017/04/19 19:11:
50.
Table 1 Description of the display firewall session statistics all-systems verbose command output

Item

Description

Session Statistics

Current session statistics

  • Slot x cpu y: indicates the session statistics of CPU y in slot x.
  • Total 132675 [1.11%] session(s) on all slots.: indicates that the total number of sessions is 132675, accounting for 1.11% of the device session specification. The total number of sessions equals to the sum of the number of sessions in each slot.
    NOTE:

    As for session statistics in the virtual view, [1.11%] indicates that the total number of sessions of all slots in the virtual system accounts for 1.11% of the available session resources in this virtual system.

Session Creation Rate(num/s)

Current new session rate

  • Slot x cpu y: indicates the new session rate of CPU y in slot x.
  • Total session(s) creation rate on all slots is 2360. The sum of the new session rates of all slots is 2360. The total of new session rates is the sum of the new session rate of each slot.

Max Session Statistics

Maximum session statistics

  • Slot x cpu y: 136157, time:2017/04/19 19:03:54: The number of sessions on CPU y in slot x reached the peak value (136157) at 19:03:54 on April 19, 2017.
  • Total max session(s) on all slot is 136157, time is 2017/04/19 19:03:54.: The sum of the number of sessions in each slot reached the peak value (136157) at 19:03:54 on April 19, 2017.

Max Session Creation Rate(num/s)

Maximum new session rate

  • Slot x cpu y: 12271, time:2017/04/19 19:11:50: The new session rate of CPU y in slot x reached the peak value (12271) at 19:11:50 on April 19, 2017.
  • Total max session(s) creation rate on all slot is 12271, time is 2017/04/19 19:11: 50.: The sum of the new session rate in each slot reached the peak value (12271) at 19:11: 50 on April 19, 2017.

Vsys name

Session statistics of the virtual system. Public indicates the session statistics of the public system.

  • Total 132675 session(s) on all slots.: indicates the total number of sessions.
  • Total session creation rate on all slot is 2360.: indicates the total of new session rates.
  • Total max session(s) on all slot is 136157, time is 2017/04/19 19:03:54.: indicates the maximum number of sessions.
  • Total max session creation rate on all slot is 12271, time is 2017/04/19 19:11:50.: indicates the sum of the new session rate of each slot.

ID

Virtual system ID

# Displays statistics on sessions for hardware-based fast forwarding in the root system.
<sysname> display firewall session statistics fastflow
 Session Statistics:                                                            
 Slot  11 cpu 0:       100                                                         
 Total 200 session(s) on all slots.
Table 2 Description of the display firewall session statistics fastflow command output

Item

Description

Session Statistics

Statistics on sessions for hardware-based fast forwarding.

  • Slot x cpu y: indicates statistics on sessions for hardware-based fast forwarding on CPU y of the board in slot x.
  • Total 200 session(s) on all slots.: indicates that the total number of sessions for hardware-based fast forwarding is 200. The total number of sessions in the sum of the number of sessions on the board in each slot.
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >