<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: fw monitor -F does not seems to show accurately in fw ctl chain in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor-F-does-not-seems-to-show-accurately-in-fw-ctl-chain/m-p/153189#M25696</link>
    <description>&lt;P&gt;The first column are the modules number and they are not indicating in which order packets are traversing the firewall? Is it the second column that shows the "order of operation" The fw VM has a absolute value of 0 and operation that takes place before fw VM have a - (minus) hexadecimal number?&lt;/P&gt;</description>
    <pubDate>Mon, 18 Jul 2022 07:54:55 GMT</pubDate>
    <dc:creator>Marre96</dc:creator>
    <dc:date>2022-07-18T07:54:55Z</dc:date>
    <item>
      <title>fw monitor -F does not seems to show accurately in fw ctl chain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor-F-does-not-seems-to-show-accurately-in-fw-ctl-chain/m-p/152563#M25452</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;When I use the -F switch in fw monitor I see the fw ctl chain output showing the default Inspect Filter (fw monitor) capture positions, which are above the SecureXL 'kernel chain modules'.&lt;BR /&gt;&lt;BR /&gt;This seems to be implying that the capture is done after SecureXL. Meaning that it is the old-style slow path only capture, which is is not.&lt;/P&gt;&lt;P&gt;Can anyone in Check Point offer an explanation please?&lt;/P&gt;&lt;P&gt;Is the fw ctl chain output simply inaccurate?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Don&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jul 2022 09:52:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor-F-does-not-seems-to-show-accurately-in-fw-ctl-chain/m-p/152563#M25452</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2022-07-08T09:52:46Z</dc:date>
    </item>
    <item>
      <title>Re: fw monitor -F does not seems to show accurately in fw ctl chain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor-F-does-not-seems-to-show-accurately-in-fw-ctl-chain/m-p/152564#M25453</link>
      <description>&lt;P&gt;version in use, screenshots?&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jul 2022 10:01:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor-F-does-not-seems-to-show-accurately-in-fw-ctl-chain/m-p/152564#M25453</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-07-08T10:01:50Z</dc:date>
    </item>
    <item>
      <title>Re: fw monitor -F does not seems to show accurately in fw ctl chain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor-F-does-not-seems-to-show-accurately-in-fw-ctl-chain/m-p/152565#M25454</link>
      <description>&lt;P&gt;R81.10&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Don&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jul 2022 10:02:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor-F-does-not-seems-to-show-accurately-in-fw-ctl-chain/m-p/152565#M25454</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2022-07-08T10:02:34Z</dc:date>
    </item>
    <item>
      <title>Re: fw monitor -F does not seems to show accurately in fw ctl chain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor-F-does-not-seems-to-show-accurately-in-fw-ctl-chain/m-p/152583#M25455</link>
      <description>&lt;P&gt;Will update with screenshots later today but if you run fw monitor -F xyz and then in another console session fw ctl chain you will see fw monitor (i/f side) in chain position 12 (for example) and that implies it's capturing after SecureXL (in the first positions on the in chain).&lt;/P&gt;&lt;P&gt;That's what the question is all about.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Don&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jul 2022 11:42:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor-F-does-not-seems-to-show-accurately-in-fw-ctl-chain/m-p/152583#M25455</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2022-07-08T11:42:22Z</dc:date>
    </item>
    <item>
      <title>Re: fw monitor -F does not seems to show accurately in fw ctl chain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor-F-does-not-seems-to-show-accurately-in-fw-ctl-chain/m-p/152585#M25456</link>
      <description>&lt;P&gt;My impression is that &lt;STRONG&gt;fw monitor -F&lt;/STRONG&gt; captures traffic directly in the sim driver via a debug filter which is why you can capture fully-accelerated traffic with it.&amp;nbsp; While running &lt;STRONG&gt;fw monitor -F&lt;/STRONG&gt; does place the capturing modules in the chain sequence similar to &lt;STRONG&gt;fw monitor -e&lt;/STRONG&gt;, I don't think those modules are actually capturing anything while &lt;STRONG&gt;fw monitor -F&lt;/STRONG&gt; is running unless the traffic happens to be F2F and traversing the full chain sequence.&amp;nbsp; This may also be the case for Medium Path traffic (PSL &amp;amp; CPAS) or even F2V but that is less clear to me.&amp;nbsp; In the F2F case there could be modifications to the packet visible at I and o-&amp;gt;O that the sim driver would not necessarily be able to "see" happening until it reached O and re-entered the sim driver on the outbound side.&amp;nbsp; So I would assume placing the capturing chain modules while &lt;STRONG&gt;fw monitor -F&lt;/STRONG&gt; is running handles this corner case and ensures a full capture of F2F traffic.&lt;/P&gt;
&lt;P&gt;In R80.20 some of SecureXL's original responsibilities such as path determination and formation/matching of Accept/NAT templates were moved into the Firewall worker/instances which muddies the waters a bit here, and is why you see SecureXL "chain modules" in the output of &lt;STRONG&gt;fw ctl chain&lt;/STRONG&gt;&amp;nbsp;in R80.20+.&amp;nbsp; The EA release notes for R81.20 state that even more of SecureXL/Performance Pack's functions are being moved out of sim into the Firewall Workers/Instances, but I haven't had a chance to check it out yet.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jul 2022 13:51:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor-F-does-not-seems-to-show-accurately-in-fw-ctl-chain/m-p/152585#M25456</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-07-08T13:51:20Z</dc:date>
    </item>
    <item>
      <title>Re: fw monitor -F does not seems to show accurately in fw ctl chain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor-F-does-not-seems-to-show-accurately-in-fw-ctl-chain/m-p/153189#M25696</link>
      <description>&lt;P&gt;The first column are the modules number and they are not indicating in which order packets are traversing the firewall? Is it the second column that shows the "order of operation" The fw VM has a absolute value of 0 and operation that takes place before fw VM have a - (minus) hexadecimal number?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jul 2022 07:54:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor-F-does-not-seems-to-show-accurately-in-fw-ctl-chain/m-p/153189#M25696</guid>
      <dc:creator>Marre96</dc:creator>
      <dc:date>2022-07-18T07:54:55Z</dc:date>
    </item>
    <item>
      <title>Re: fw monitor -F does not seems to show accurately in fw ctl chain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor-F-does-not-seems-to-show-accurately-in-fw-ctl-chain/m-p/153199#M25700</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/34062"&gt;@Marre96&lt;/a&gt;&amp;nbsp;I assume you are talking about something like this:&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="fw ctl chain.png" style="width: 785px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17209iE5451D39EFDE150A/image-size/large?v=v2&amp;amp;px=999" role="button" title="fw ctl chain.png" alt="fw ctl chain.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The first number is&amp;nbsp;&lt;STRONG&gt;location of the module in the chain (or order in the chain)&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;The second number is the absolute position in the chain. As you mentioned, fw VM is assumed position 0, chain modules before it have negative position numbers&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;STRONG&gt;The third -&amp;nbsp;&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;STRONG style="font-family: inherit; background-color: #ffffff;"&gt;pointer to the function in the chain module&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 18 Jul 2022 09:47:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor-F-does-not-seems-to-show-accurately-in-fw-ctl-chain/m-p/153199#M25700</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-07-18T09:47:59Z</dc:date>
    </item>
  </channel>
</rss>

