show policymgr whitelist stats

Prev Next

Displays the traffic statistics of packets on a Generic Routing Encapsulation (GRE) whitelist, a port whitelist, and a network whitelist.

Note

When you enable each whitelist on the Network Security appliance, no further analysis is performed. You can track the number of whitelist entries that are bypassed based on the matched known network, GRE, and port packets.

Syntax

show policymgr whitelist stats

Parameters

None

Output fields

The following table describes the output fields for the show policymgr whitelist stats command on a Trellix NX 10000 model. Fields are listed in the approximate order in which they appear in the output.

Field

Description

Non-whitelisted packets

Number of packets that the Network Security appliance will submit for analysis.

Policymgr whitelisted packets

Number of network packets that are whitelisted.

Policymgr session whitelisted packets

Number of packets that belong to a particular session and are marked as whitelisted. All incoming packets that belong to the same session are automatically whitelisted.

Whitelisted GRE packets

Number of GRE packets that are whitelisted.

Port Whitelisted packets

Number of port packets that are whitelisted.

Note

When the NX appliance processes NVGRE packets, it increments the GRE packet count, rather than having a dedicated counter for NVGRE packets.

Examples

The following example displays the statistics for all packets that are whitelisted on a Trellix NX 10000 model.

hostname (config) # show policymgr whitelist stats 
..... 
subnetf : Enabled 
wl_gre : Enabled 
wl_port: Enabled 

Non-whitelisted packets - 32219171199 
Policymgr whitelisted packets - 231 
Policymgr session whitelisted packets - 21581 
Bxtract whitelisted packet - 0 
Bxtract session whitelisted packets - 0 
Whitelisted GRE packets - 119 
Port Whitelisted packets - 3478

The following example displays the statistics for all packets that are whitelisted on other Network Security models.

hostname (config) # show policymgr whitelist stats 
subnetf stats data : 
received: 161443545 
no whitelist: 5228 
no_whitelist_session: 4204542 
sb_whitelist: 3454793 
sb_whitelist_session: 153774128 
bx_whitelist: 0 
bx_whitelist_session: 0 
gre_whitelist: 76 
port_whitelist: 6660550

User role

Administrator, Monitor, or Analyst

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Network Security: Release 8.0