Displays the traffic statistics of packets on a Generic Routing Encapsulation (GRE) whitelist, a port whitelist, and a network whitelist.
Note
When you enable each whitelist on the Network Security appliance, no further analysis is performed. You can track the number of whitelist entries that are bypassed based on the matched known network, GRE, and port packets.
Syntax
show policymgr whitelist statsParameters
None
Output fields
The following table describes the output fields for the show policymgr whitelist stats command on a Trellix NX 10000 model. Fields are listed in the approximate order in which they appear in the output.
Field | Description |
|---|---|
Non-whitelisted packets | Number of packets that the Network Security appliance will submit for analysis. |
Policymgr whitelisted packets | Number of network packets that are whitelisted. |
Policymgr session whitelisted packets | Number of packets that belong to a particular session and are marked as whitelisted. All incoming packets that belong to the same session are automatically whitelisted. |
Whitelisted GRE packets | Number of GRE packets that are whitelisted. |
Port Whitelisted packets | Number of port packets that are whitelisted. |
Note
When the NX appliance processes NVGRE packets, it increments the GRE packet count, rather than having a dedicated counter for NVGRE packets.
Examples
The following example displays the statistics for all packets that are whitelisted on a Trellix NX 10000 model.
hostname (config) # show policymgr whitelist stats ..... subnetf : Enabled wl_gre : Enabled wl_port: Enabled Non-whitelisted packets - 32219171199 Policymgr whitelisted packets - 231 Policymgr session whitelisted packets - 21581 Bxtract whitelisted packet - 0 Bxtract session whitelisted packets - 0 Whitelisted GRE packets - 119 Port Whitelisted packets - 3478
The following example displays the statistics for all packets that are whitelisted on other Network Security models.
hostname (config) # show policymgr whitelist stats subnetf stats data : received: 161443545 no whitelist: 5228 no_whitelist_session: 4204542 sb_whitelist: 3454793 sb_whitelist_session: 153774128 bx_whitelist: 0 bx_whitelist_session: 0 gre_whitelist: 76 port_whitelist: 6660550
User role
Administrator, Monitor, or Analyst
Command mode
Enable
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Network Security: Release 8.0