<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Fw monitor troubleshooting in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fw-monitor-troubleshooting/m-p/101550#M10161</link>
    <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21670"&gt;@HeikoAnkenbrand&lt;/a&gt;&amp;nbsp; for your notes&lt;/P&gt;</description>
    <pubDate>Mon, 09 Nov 2020 18:26:55 GMT</pubDate>
    <dc:creator>Ven</dc:creator>
    <dc:date>2020-11-09T18:26:55Z</dc:date>
    <item>
      <title>Fw monitor troubleshooting</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fw-monitor-troubleshooting/m-p/101187#M10157</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a question about Fw monitor Inspection Points iIoO.&amp;nbsp; What does if i don`t see these inspection points in the fw monitor output and what could be the cause for each and also how to troubleshoot ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example :&amp;nbsp; If i don`t see ' i ' ----I am thinking that the traffic/connection is not even reaching the firewall and I would look at the forwarding device if it is sending the tarffic to fw or not ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;If i don`t see 'I' --&lt;/P&gt;&lt;P&gt;If i don`t see 'o' ---&amp;nbsp;&lt;/P&gt;&lt;P&gt;If i don`t see 'O' ---&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help appreciated&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Nov 2020 08:50:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fw-monitor-troubleshooting/m-p/101187#M10157</guid>
      <dc:creator>Ven</dc:creator>
      <dc:date>2020-11-05T08:50:03Z</dc:date>
    </item>
    <item>
      <title>Re: Fw monitor troubleshooting</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fw-monitor-troubleshooting/m-p/101401#M10158</link>
      <description>&lt;P&gt;You're correct on i.&lt;BR /&gt;If something doesn't get to I, it's most likely got dropped by a policy/access rule&lt;BR /&gt;If something doesn't get to o, the packet probably didn't get routed properly or it's being handled directly by the gateway.&lt;BR /&gt;If something doesn't get to O...well, it depends on the precise situation.&lt;/P&gt;
&lt;P&gt;See also:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/How-To-Videos/How-to-use-fw-monitor/m-p/97582" target="_blank"&gt;https://community.checkpoint.com/t5/How-To-Videos/How-to-use-fw-monitor/m-p/97582&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Nov 2020 03:29:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fw-monitor-troubleshooting/m-p/101401#M10158</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-11-08T03:29:13Z</dc:date>
    </item>
    <item>
      <title>Re: Fw monitor troubleshooting</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fw-monitor-troubleshooting/m-p/101416#M10159</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/53289"&gt;@Ven&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;.&amp;nbsp;Here is a small note.&amp;nbsp;&lt;BR /&gt;In different versions the "fw monitor inspection points" are displayed differently.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_20201108-122634_Edge.jpg" style="width: 649px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8805i3F8745AC54FA943E/image-dimensions/649x287?v=v2" width="649" height="287" role="button" title="Screenshot_20201108-122634_Edge.jpg" alt="Screenshot_20201108-122634_Edge.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;For example, you cannot see "i" or "O" when it is VPN traffic&amp;nbsp;on certain GAIA versions.&lt;BR /&gt;&lt;BR /&gt;More read here:&lt;BR /&gt;&lt;A href="https://community.checkpoint.com/docs/DOC-3041-r80x-security-gateway-architecture-logical-packet-flow" target="_blank" rel="noopener"&gt;- R80.x - Security Gateway Architecture (Logical Packet Flow)&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://community.checkpoint.com/docs/DOC-3351-r80x-performance-tuning-and-debug-tips-fw-monitor" target="_blank" rel="noopener"&gt;- R80.x - Performance Tuning and Debug Tips - fw monitor&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;-&amp;nbsp;&lt;/SPAN&gt;&lt;A class="jive-link-wiki-small" href="https://community.checkpoint.com/docs/DOC-3475-r8020-update-cheat-sheet-fw-monitor" target="_blank" rel="noopener" data-containerid="2057" data-containertype="14" data-objectid="3475" data-objecttype="102"&gt;R80.x - cheat sheet - fw monitor&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Nov 2020 11:33:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fw-monitor-troubleshooting/m-p/101416#M10159</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2020-11-08T11:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: Fw monitor troubleshooting</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fw-monitor-troubleshooting/m-p/101548#M10160</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;for your help.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2020 18:25:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fw-monitor-troubleshooting/m-p/101548#M10160</guid>
      <dc:creator>Ven</dc:creator>
      <dc:date>2020-11-09T18:25:40Z</dc:date>
    </item>
    <item>
      <title>Re: Fw monitor troubleshooting</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fw-monitor-troubleshooting/m-p/101550#M10161</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21670"&gt;@HeikoAnkenbrand&lt;/a&gt;&amp;nbsp; for your notes&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2020 18:26:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fw-monitor-troubleshooting/m-p/101550#M10161</guid>
      <dc:creator>Ven</dc:creator>
      <dc:date>2020-11-09T18:26:55Z</dc:date>
    </item>
    <item>
      <title>Re: Fw monitor troubleshooting</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fw-monitor-troubleshooting/m-p/110068#M15086</link>
      <description>&lt;P&gt;Just to add on to Daemon's post: if traffic disappears at I it may have been dropped as he says (&lt;STRONG&gt;fw ctl zdebug + drop&lt;/STRONG&gt; to check this), but it is also possible that your filter was matching against only the pre-NAT destination IP address.&amp;nbsp; If it is the destination IP address that is subject to NAT, the actual replacement of the destination IP address in the packet happens between i and I.&amp;nbsp; So in this case the packet "disappears" in your capture and never reaches I (as far as you can see), but the packet actually just stopped matching your pre-NAT destination IP address filtering condition and continued onwards through I.&lt;/P&gt;
&lt;P&gt;By the same token if the traffic seems to disappear after o, it is possible that the packet was dropped (though much less likely than between i and I) for some reason.&amp;nbsp; What is far more probable is that you were matching against the pre-NAT source IP address, which will be transformed to the post-NAT source IP address between o and O, and the packet will once again seem to "disappear" in your capture, when in reality the packet was not dropped and continued through O.&lt;/P&gt;</description>
      <pubDate>Sun, 07 Feb 2021 19:21:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fw-monitor-troubleshooting/m-p/110068#M15086</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-02-07T19:21:15Z</dc:date>
    </item>
  </channel>
</rss>

