<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: fw monitor output in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor-output/m-p/53212#M12813</link>
    <description>This is where you need to break out the debug commands to find out why it dropped.&lt;BR /&gt;You can start with fw ctl zdebug drop | grep 10.42.14.60.&lt;BR /&gt;A little bit more about fw ctl zdebug, which should generally be used with care: &lt;A href="https://community.checkpoint.com/t5/Enterprise-Appliances-and-Gaia/quot-fw-ctl-zdebug-quot-Helpful-Command-Combinations/m-p/40680" target="_blank"&gt;https://community.checkpoint.com/t5/Enterprise-Appliances-and-Gaia/quot-fw-ctl-zdebug-quot-Helpful-Command-Combinations/m-p/40680&lt;/A&gt;</description>
    <pubDate>Sat, 11 May 2019 22:06:19 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2019-05-11T22:06:19Z</dc:date>
    <item>
      <title>fw monitor output</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor-output/m-p/53032#M12812</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I need some help with fw monitor output.&amp;nbsp; (R80.20 gaia T47)&lt;/P&gt;&lt;P&gt;Our GRE/SIP&amp;nbsp; communication doesn't work, and as you can see below, the last captured packet was stopped in pre-outbound (o4) chain position. It is the tunnel-inside traffic.&lt;/P&gt;&lt;P&gt;We have bidirectional rules between peers without NAT.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CP.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1123iCA272845051E0BE7/image-size/large?v=v2&amp;amp;px=999" role="button" title="CP.PNG" alt="CP.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Cou&lt;SPAN&gt;ld you please somebody explain what caused this behavior?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Here is also the relevant wireshark capture:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cp2.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1124iBE920290DE515D27/image-size/large?v=v2&amp;amp;px=999" role="button" title="cp2.PNG" alt="cp2.PNG" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;There are many articles/ cheat sheets ,etc. about how fw monitor is working, but i cant find any information about the output interpretation...&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in chain (14):&lt;BR /&gt;0: -7fffffff (0000000000000000) (00000000) SecureXL inbound (sxl_in)&lt;BR /&gt;1: -7ffffffe (0000000000000000) (00000000) SecureXL inbound CT (sxl_ct)&lt;BR /&gt;2: -7f800000 (ffffffff8a32eb80) (ffffffff) IP Options Strip (in) (ipopt_strip)&lt;BR /&gt;3: - 1fffff8 (ffffffff8a32c9b0) (00000001) Stateless verifications (in) (asm)&lt;BR /&gt;4: - 1fffff7 (ffffffff8a32c4d0) (00000001) fw multik misc proto forwarding&lt;BR /&gt;5: - 1fffff5 (ffffffff8a3e2ec0) (00000001) fw early SIP NAT (sipnat)&lt;BR /&gt;6: 0 (ffffffff8a48cc10) (00000001) fw VM inbound (fw)&lt;BR /&gt;7: 2 (ffffffff8a32efd0) (00000001) fw SCV inbound (scv)&lt;BR /&gt;8: 5 (ffffffff8a21a4d0) (00000003) fw offload inbound (offload_in)&lt;BR /&gt;9: 10 (ffffffff8a47eca0) (00000001) fw post VM inbound (post_vm)&lt;BR /&gt;10: 7f730000 (ffffffff89ffc520) (00000001) passive streaming (in) (pass_str)&lt;BR /&gt;11: 7f750000 (ffffffff89c8c7d0) (00000001) TCP streaming (in) (cpas)&lt;BR /&gt;12: 7f800000 (ffffffff8a32eb30) (ffffffff) IP Options Restore (in) (ipopt_res)&lt;BR /&gt;13: 7fb00000 (ffffffff89628750) (00000001) Cluster Late Correction (ha_for)&lt;BR /&gt;out chain (11):&lt;BR /&gt;0: -7f800000 (ffffffff8a32eb80) (ffffffff) IP Options Strip (out) (ipopt_strip)&lt;BR /&gt;1: - 1fffff0 (ffffffff89c76dd0) (00000001) TCP streaming (out) (cpas)&lt;BR /&gt;2: - 1ffff50 (ffffffff89ffc520) (00000001) passive streaming (out) (pass_str)&lt;BR /&gt;3: - 1f00000 (ffffffff8a32c9b0) (00000001) Stateless verifications (out) (asm)&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;4: 0 (ffffffff8a48cc10) (00000001) fw VM outbound (fw)&lt;/FONT&gt;&lt;BR /&gt;5: 10 (ffffffff8a47eca0) (00000001) fw post VM outbound (post_vm)&lt;BR /&gt;6: 18000000 (ffffffff89f28210) (00000001) fw record data outbound&lt;BR /&gt;7: 7f700000 (ffffffff89c8b2f0) (00000001) TCP streaming post VM (cpas)&lt;BR /&gt;8: 7f800000 (ffffffff8a32eb30) (ffffffff) IP Options Restore (out) (ipopt_res)&lt;BR /&gt;9: 7f900000 (0000000000000000) (00000000) SecureXL outbound (sxl_out)&lt;BR /&gt;10: 7fa00000 (0000000000000000) (00000000) SecureXL deliver (sxl_deliver)&lt;BR /&gt;monitor: monitoring (control-C to stop)&lt;/P&gt;&lt;P&gt;**********&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;outside traffic:&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond2.654:i2 (IP Options Strip (in))[448]: 10.42.14.60 -&amp;gt; 10.7.8.4 (47) len=448 id=62203&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond2.654:i3 (Stateless verifications (in))[448]: 10.42.14.60 -&amp;gt; 10.7.8.4 (47) len=448 id=62203&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond2.654:i4 (fw multik misc proto forwarding)[448]: 10.42.14.60 -&amp;gt; 10.7.8.4 (47) len=448 id=62203&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond2.654:i5 (fw early SIP NAT)[448]: 10.42.14.60 -&amp;gt; 10.7.8.4 (47) len=448 id=62203&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond2.654:i6 (fw VM inbound )[448]: 10.42.14.60 -&amp;gt; 10.7.8.4 (47) len=448 id=62203&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond2.654:I7 (fw SCV inbound)[448]: 10.42.14.60 -&amp;gt; 10.7.8.4 (47) len=448 id=62203&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond2.654:I8 (fw offload inbound)[448]: 10.42.14.60 -&amp;gt; 10.7.8.4 (47) len=448 id=62203&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond2.654:I9 (fw post VM inbound )[448]: 10.42.14.60 -&amp;gt; 10.7.8.4 (47) len=448 id=62203&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond2.654:I10 (passive streaming (in))[448]: 10.42.14.60 -&amp;gt; 10.7.8.4 (47) len=448 id=62203&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond2.654:I11 (TCP streaming (in))[448]: 10.42.14.60 -&amp;gt; 10.7.8.4 (47) len=448 id=62203&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond2.654:I12 (IP Options Restore (in))[448]: 10.42.14.60 -&amp;gt; 10.7.8.4 (47) len=448 id=62203&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond2.654:I13 (Cluster Late Correction)[448]: 10.42.14.60 -&amp;gt; 10.7.8.4 (47) len=448 id=62203&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond2.654:I14 (Chain End)[448]: 10.42.14.60 -&amp;gt; 10.7.8.4 (47) len=448 id=62203&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond1.509:o0 (IP Options Strip (out))[448]: 10.42.14.60 -&amp;gt; 10.7.8.4 (47) len=448 id=62203&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond1.509:o1 (TCP streaming (out))[448]: 10.42.14.60 -&amp;gt; 10.7.8.4 (47) len=448 id=62203&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond1.509:o2 (passive streaming (out))[448]: 10.42.14.60 -&amp;gt; 10.7.8.4 (47) len=448 id=62203&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond1.509:o3 (Stateless verifications (out))[448]: 10.42.14.60 -&amp;gt; 10.7.8.4 (47) len=448 id=62203&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;[vs_0][fw_2] bond1.509:o4 (fw VM outbound)[448]: 10.42.14.60 -&amp;gt; 10.7.8.4 (47) len=448 id=62203&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;*********************outside traffic was stopped in 04 position&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;inside traffic:&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond1.509:i2 (IP Options Strip (in))[441]: 10.7.8.4 -&amp;gt; 10.42.14.60 (47) len=441 id=958&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond1.509:i3 (Stateless verifications (in))[441]: 10.7.8.4 -&amp;gt; 10.42.14.60 (47) len=441 id=958&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond1.509:i4 (fw multik misc proto forwarding)[441]: 10.7.8.4 -&amp;gt; 10.42.14.60 (47) len=441 id=958&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond1.509:i5 (fw early SIP NAT)[441]: 10.7.8.4 -&amp;gt; 10.42.14.60 (47) len=441 id=958&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond1.509:i6 (fw VM inbound )[441]: 10.7.8.4 -&amp;gt; 10.42.14.60 (47) len=441 id=958&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond2.654:i2 (IP Options Strip (in))[444]: 10.42.14.60 -&amp;gt; 10.7.8.4 (47) len=444 id=62204&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond2.654:i3 (Stateless verifications (in))[444]: 10.42.14.60 -&amp;gt; 10.7.8.4 (47) len=444 id=62204&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond2.654:i4 (fw multik misc proto forwarding)[444]: 10.42.14.60 -&amp;gt; 10.7.8.4 (47) len=444 id=62204&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond2.654:i5 (fw early SIP NAT)[444]: 10.42.14.60 -&amp;gt; 10.7.8.4 (47) len=444 id=62204&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond2.654:i6 (fw VM inbound )[444]: 10.42.14.60 -&amp;gt; 10.7.8.4 (47) len=444 id=62204&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond2.654:I7 (fw SCV inbound)[444]: 10.42.14.60 -&amp;gt; 10.7.8.4 (47) len=444 id=62204&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond2.654:I8 (fw offload inbound)[444]: 10.42.14.60 -&amp;gt; 10.7.8.4 (47) len=444 id=62204&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond2.654:I9 (fw post VM inbound )[444]: 10.42.14.60 -&amp;gt; 10.7.8.4 (47) len=444 id=62204&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond2.654:I10 (passive streaming (in))[444]: 10.42.14.60 -&amp;gt; 10.7.8.4 (47) len=444 id=62204&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond2.654:I11 (TCP streaming (in))[444]: 10.42.14.60 -&amp;gt; 10.7.8.4 (47) len=444 id=62204&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond2.654:I12 (IP Options Restore (in))[444]: 10.42.14.60 -&amp;gt; 10.7.8.4 (47) len=444 id=62204&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond2.654:I13 (Cluster Late Correction)[444]: 10.42.14.60 -&amp;gt; 10.7.8.4 (47) len=444 id=62204&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond2.654:I14 (Chain End)[444]: 10.42.14.60 -&amp;gt; 10.7.8.4 (47) len=444 id=62204&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond1.509:o0 (IP Options Strip (out))[444]: 10.42.14.60 -&amp;gt; 10.7.8.4 (47) len=444 id=62204&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond1.509:o1 (TCP streaming (out))[444]: 10.42.14.60 -&amp;gt; 10.7.8.4 (47) len=444 id=62204&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond1.509:o2 (passive streaming (out))[444]: 10.42.14.60 -&amp;gt; 10.7.8.4 (47) len=444 id=62204&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond1.509:o3 (Stateless verifications (out))[444]: 10.42.14.60 -&amp;gt; 10.7.8.4 (47) len=444 id=62204&lt;/P&gt;&lt;P&gt;[vs_0][fw_2] bond1.509:o4 (fw VM outbound)[444]: 10.42.14.60 -&amp;gt; 10.7.8.4 (47) len=444 id=62204&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;Norbert&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2019 15:21:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor-output/m-p/53032#M12812</guid>
      <dc:creator>Norbert_Papirny</dc:creator>
      <dc:date>2019-05-09T15:21:51Z</dc:date>
    </item>
    <item>
      <title>Re: fw monitor output</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor-output/m-p/53212#M12813</link>
      <description>This is where you need to break out the debug commands to find out why it dropped.&lt;BR /&gt;You can start with fw ctl zdebug drop | grep 10.42.14.60.&lt;BR /&gt;A little bit more about fw ctl zdebug, which should generally be used with care: &lt;A href="https://community.checkpoint.com/t5/Enterprise-Appliances-and-Gaia/quot-fw-ctl-zdebug-quot-Helpful-Command-Combinations/m-p/40680" target="_blank"&gt;https://community.checkpoint.com/t5/Enterprise-Appliances-and-Gaia/quot-fw-ctl-zdebug-quot-Helpful-Command-Combinations/m-p/40680&lt;/A&gt;</description>
      <pubDate>Sat, 11 May 2019 22:06:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor-output/m-p/53212#M12813</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-05-11T22:06:19Z</dc:date>
    </item>
  </channel>
</rss>

