Showing results for 
Show  only  | Search instead for 
Did you mean: 
Former Member
Not applicable
Report Inappropriate Content
Message 1 of 2

total current connection command needed.

does anyone know how to get an accurate current connection using command line?

I am now adding numbers from connect_mon and ipfilter -v to get the number.  but it does not look like that i am getting the correct number.

when i checked on command center, total number of proxy session and ipfilter sessions are much higher than numbers i get from CLI.

1 Reply
Former Member
Not applicable
Report Inappropriate Content
Message 2 of 2

Re: total current connection command needed.

If you run the command 'alias' on the CLI you'll see the all the aliased commands on the firewall by default.

You'll see these 4 among your alias commands:
nn      netstat -naf inet | egrep -cv "LISTEN|TIME|SYN|\*.\*|Active|Address"
nt      netstat -naf inet | grep -c ESTABLISHED
nu      netstat -naf inet | egrep -cv "LISTEN|TIME|SYN|\*.\*|Active|Address|ESTABLISHED"
nw      netstat -naf inet | grep -c TIME_WAIT

If you look at the .cshrc file in your home directory (if you're using the tcsh shell) you'll see an explanation for these 4 commands:

# To count total connections to and from SW
alias nn 'netstat -naf inet | egrep -cv "LISTEN|TIME|SYN|\*.\*|Active|Address"'

# To count total TCP connections to and from SW
alias nt 'netstat -naf inet | grep -c ESTABLISHED'

# To count total UDP connections tp (sic) and from SW
alias nu 'netstat -naf inet | egrep -cv "LISTEN|TIME|SYN|\*.\*|Active|Address|ESTABLISHED"'

# To count total sessions in TIME_WAIT
alias nw 'netstat -naf inet | grep -c TIME_WAIT'

These 4 commands (nn, nt, nu, nw) show a count (grep -c) of the number of sessions that match the grep string.  If you copy the command inside the single-quotes and run it without the -c you can see the details of the sessions it's counting.

The 'nt' command seems to match the number of TCP 'Proxy Connections' shown in the Dashboard (the 'count' of ESTABLISHED connections).
The 'nu' command does not match the UDP 'Proxy Connections' count from the Dashboard.  The Dashboard count looks to be the same as output of this command: 'netstat -an | grep -c udp4'.
For the 'Packet Filter Sessions' counts from the dashboard you can run 'ipfilter -v|less' and look at the 'The current number of TCP[UDP] IP Filter sessions' lines at the top of the output.

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community