<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WireShark profile for `fw monitor` in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WireShark-profile-for-fw-monitor/m-p/7761#M26020</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;cool &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;I even more like this one :&amp;nbsp;&lt;A class="link-titled" href="http://hugo.vanderkooij.org/technical/powershell-ad-computers-to-check-point-objects" title="http://hugo.vanderkooij.org/technical/powershell-ad-computers-to-check-point-objects"&gt;Hugo's website: PowerShell, AD computers to Check Point objects&lt;/A&gt;&amp;nbsp;&amp;nbsp;-&amp;gt;&amp;nbsp;&lt;A class="link-titled" href="https://tkoopman.github.io/psCheckPoint/index.html" title="https://tkoopman.github.io/psCheckPoint/index.html"&gt;psCheckPoint Documentation&lt;/A&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 22 Oct 2017 07:09:39 GMT</pubDate>
    <dc:creator>Ofir_Shikolski</dc:creator>
    <dc:date>2017-10-22T07:09:39Z</dc:date>
    <item>
      <title>WireShark profile for `fw monitor`</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WireShark-profile-for-fw-monitor/m-p/7756#M26015</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I write a Wireshark profile to help you with reading `fw monitor` files.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wrote a Dutch description on&amp;nbsp;&lt;A href="http://hugo.vanderkooij.org/technical/wireshark-profiles"&gt;Wireshark Profiles&lt;/A&gt;&amp;nbsp;and I guess the screenshots will be sufficient help to get you started for those not savvy in Dutch &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Short English Version:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Create a Dummy personal profile (Name it whatever you like)&lt;/LI&gt;&lt;LI&gt;In WireShark, Goto Help =&amp;gt; Folders and then proceed to your Personal Configuration directory&lt;/LI&gt;&lt;LI&gt;Put the ZIP file in the Profiles directory and unpack it.&lt;/LI&gt;&lt;LI&gt;Now you have your own Check Point profile that has coloring rules and some other smart things.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Feel free to mention any smart tricks with Wireshark you use the speed up reading `fw monitor` files.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Oct 2017 07:16:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WireShark-profile-for-fw-monitor/m-p/7756#M26015</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2017-10-20T07:16:37Z</dc:date>
    </item>
    <item>
      <title>Re: WireShark profile for `fw monitor`</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WireShark-profile-for-fw-monitor/m-p/7757#M26016</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://translate.google.com/translate?hl=de&amp;amp;sl=nl&amp;amp;tl=en&amp;amp;u=http%3A%2F%2Fhugo.vanderkooij.org%2Ftechnical%2Fwireshark-profiles"&gt;Wireshark Profiles - English version via Google Translate&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Related SKs:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk39510"&gt;How to configure Wireshark for analysis of FW Monitor captures&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk99949"&gt;Maximum recommended capture file size for Wireshark&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk43076"&gt;How to work with large traffic capture files&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk30583"&gt;What is FW Monitor? &lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://downloads.checkpoint.com/dc/download.htm?ID=9068"&gt;How to use FW Monitor&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk41104"&gt;What happened to Check Point Ethereal (CPEthereal)?&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="60193" class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/60193_pastedImage_1.png" style="width: auto; height: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Oct 2017 07:44:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WireShark-profile-for-fw-monitor/m-p/7757#M26016</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2017-10-20T07:44:34Z</dc:date>
    </item>
    <item>
      <title>Re: WireShark profile for `fw monitor`</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WireShark-profile-for-fw-monitor/m-p/7758#M26017</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;nbsp;&lt;A class="link-titled" href="https://translate.google.com/translate?sl=nl&amp;amp;tl=en&amp;amp;u=http%3A%2F%2Fhugo.vanderkooij.org%2Ftechnical%2Fwireshark-profiles" title="https://translate.google.com/translate?sl=nl&amp;amp;tl=en&amp;amp;u=http%3A%2F%2Fhugo.vanderkooij.org%2Ftechnical%2Fwireshark-profiles"&gt;WireShark profiles (Translated by Google)&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If some lines don't make sense in English. .... That's what you get from bot translators.&lt;/P&gt;&lt;P&gt;You can always try to learn Dutch &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Oct 2017 08:02:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WireShark-profile-for-fw-monitor/m-p/7758#M26017</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2017-10-20T08:02:30Z</dc:date>
    </item>
    <item>
      <title>Re: WireShark profile for `fw monitor`</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WireShark-profile-for-fw-monitor/m-p/7759#M26018</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Wow, I see my&amp;nbsp;post&amp;nbsp;from 2008 on CPUG found it's way back again....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Oct 2017 20:59:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WireShark-profile-for-fw-monitor/m-p/7759#M26018</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2017-10-20T20:59:14Z</dc:date>
    </item>
    <item>
      <title>Re: WireShark profile for `fw monitor`</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WireShark-profile-for-fw-monitor/m-p/7760#M26019</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Been a while since I've seen this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Oct 2017 23:37:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WireShark-profile-for-fw-monitor/m-p/7760#M26019</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-10-20T23:37:38Z</dc:date>
    </item>
    <item>
      <title>Re: WireShark profile for `fw monitor`</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WireShark-profile-for-fw-monitor/m-p/7761#M26020</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;cool &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;I even more like this one :&amp;nbsp;&lt;A class="link-titled" href="http://hugo.vanderkooij.org/technical/powershell-ad-computers-to-check-point-objects" title="http://hugo.vanderkooij.org/technical/powershell-ad-computers-to-check-point-objects"&gt;Hugo's website: PowerShell, AD computers to Check Point objects&lt;/A&gt;&amp;nbsp;&amp;nbsp;-&amp;gt;&amp;nbsp;&lt;A class="link-titled" href="https://tkoopman.github.io/psCheckPoint/index.html" title="https://tkoopman.github.io/psCheckPoint/index.html"&gt;psCheckPoint Documentation&lt;/A&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Oct 2017 07:09:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WireShark-profile-for-fw-monitor/m-p/7761#M26020</guid>
      <dc:creator>Ofir_Shikolski</dc:creator>
      <dc:date>2017-10-22T07:09:39Z</dc:date>
    </item>
    <item>
      <title>Re: WireShark profile for `fw monitor`</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WireShark-profile-for-fw-monitor/m-p/154046#M26021</link>
      <description>&lt;P&gt;I found that in the PCAP file we loose something. If you run fw monitor on the screens you can see how things are picked up internally.&lt;/P&gt;
&lt;P&gt;The first (i) will be part of the performance pack. And then you get a second (i) on the actual core that picks up the packet. On TCP this is only on the SYN packet. But on UDP this happens a lot more.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It would be cool if fw monitor could be enhanced to put this information into comments if you use pcapng as output format.&lt;/P&gt;
&lt;P&gt;Who should we buy strooopwafels to get this into a future version?&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jul 2022 07:46:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/WireShark-profile-for-fw-monitor/m-p/154046#M26021</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2022-07-28T07:46:48Z</dc:date>
    </item>
  </channel>
</rss>

