<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with Packet Captures in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-Packet-Captures/m-p/159920#M28136</link>
    <description>&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Thank you for your reply.&lt;BR /&gt;When I offer the mouse near packet captures, the possibility of saving is not given, but only open directly. Therefore, I have configured the .cap format to be opened with Wireshark. But even with Wireshark I'm getting the error that I described in the previous post . Is there any other possibility in the checkpoint to save the capture not in this way but in another way?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;Enes&lt;/P&gt;</description>
    <pubDate>Wed, 19 Oct 2022 07:57:18 GMT</pubDate>
    <dc:creator>Enes_Morina</dc:creator>
    <dc:date>2022-10-19T07:57:18Z</dc:date>
    <item>
      <title>Problem with Packet Captures</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-Packet-Captures/m-p/159705#M28134</link>
      <description>&lt;P&gt;Hello&lt;BR /&gt;I have a problem with Checkpoint Firewall (R81.10).&lt;/P&gt;&lt;P&gt;When I'm trying to check the monitoring in the Logs section/ When I&amp;nbsp;click on Packet Captures, which I made to open with Wireshark, the message "the file "time1665992763.cap" does not exist.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Please help me...&lt;/P&gt;&lt;P&gt;Enes.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Oct 2022 10:05:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-Packet-Captures/m-p/159705#M28134</guid>
      <dc:creator>Enes_Morina</dc:creator>
      <dc:date>2022-10-17T10:05:22Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Packet Captures</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-Packet-Captures/m-p/159913#M28135</link>
      <description>&lt;P&gt;You need to download the file before Wireshark can open it. Opening the link with Wireshark will not work. Download the capture file first.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 07:32:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-Packet-Captures/m-p/159913#M28135</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-10-19T07:32:25Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Packet Captures</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-Packet-Captures/m-p/159920#M28136</link>
      <description>&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Thank you for your reply.&lt;BR /&gt;When I offer the mouse near packet captures, the possibility of saving is not given, but only open directly. Therefore, I have configured the .cap format to be opened with Wireshark. But even with Wireshark I'm getting the error that I described in the previous post . Is there any other possibility in the checkpoint to save the capture not in this way but in another way?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;Enes&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 07:57:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-Packet-Captures/m-p/159920#M28136</guid>
      <dc:creator>Enes_Morina</dc:creator>
      <dc:date>2022-10-19T07:57:18Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Packet Captures</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-Packet-Captures/m-p/159922#M28138</link>
      <description>&lt;P&gt;This is odd, it should actually allow you download. Please check if the file mentioned in the logs actually exists on the log server. Look into&amp;nbsp;&lt;SPAN&gt;sk120773 for the location, then search by name. In case of the old captures, they may be cleaned already.&lt;BR /&gt;&lt;BR /&gt;If the file does exist, but you cannot query it from the SmartConsole, please open a TAC case&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 08:15:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-Packet-Captures/m-p/159922#M28138</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-10-19T08:15:21Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Packet Captures</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-Packet-Captures/m-p/159927#M28137</link>
      <description>&lt;P&gt;I have double-checked, you should be able to save the capture. Here is the quote from Threat Prevention Admin guide:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;H2&gt;Packet&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="SearchHighlight SearchHighlight1"&gt;Capture&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;You can&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="SearchHighlight SearchHighlight1"&gt;capture&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;network traffic. The content of the packet&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="SearchHighlight SearchHighlight1"&gt;capture&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;provides a greater insight into the traffic which generated the log. With this feature activated, the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;&lt;A class="MCTextPopup MCTextPopupHotSpot MCTextPopupHotSpot_ #text MCTextPopup_Closed" role="button" href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_ThreatPrevention_AdminGuide/Topics-TPG/Monitoring_Threat_Prevention.htm?Highlight=capture#" data-mc-state="closed" data-aria-describedby="c40ad07a-5b81-4e68-a877-a9b9416fe5a6" target="_blank"&gt;Security Gateway&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;sends a packet&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="SearchHighlight SearchHighlight1"&gt;capture&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;file with the log to the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_logserv variable"&gt;&lt;A class="MCTextPopup MCTextPopupHotSpot MCTextPopupHotSpot_ #text MCTextPopup_Closed" role="button" href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_ThreatPrevention_AdminGuide/Topics-TPG/Monitoring_Threat_Prevention.htm?Highlight=capture#" data-mc-state="closed" data-aria-describedby="13a3480b-2f8d-4a9e-87f6-8814963b4936" target="_blank"&gt;Log Server&lt;/A&gt;&lt;/SPAN&gt;. &lt;U&gt;You can open the file, or save it to a file location to retrieve the information a later time.&lt;/U&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 08:23:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-Packet-Captures/m-p/159927#M28137</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-10-19T08:23:34Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Packet Captures</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-Packet-Captures/m-p/159969#M28150</link>
      <description>&lt;P&gt;It is possible that only one packet capture (the latest one) is available for that particular protection and the old one you are attempting to access has rolled off.&amp;nbsp; How many subsequent packet captures for the same protection are going to be saved will vary depending upon whether the packet capture was taken for an IPS ThreatCloud Protection, a Core Protection/Activation, or an Inspection Setting and whether the capture was called for in the Track column of the Threat Prevention policy, the settings of the protection itself, or no capture was called for in the configuration at all but the firewall automatically saved a packet capture upon the latest triggering of that protection by default, but older ones for that protection are not retained.&lt;/P&gt;
&lt;P&gt;In some cases a packet capture will not be available in the logs when it seems there should be; this can be caused in the following situations stated in the R81 Known Limitations:&lt;/P&gt;
&lt;P&gt;• The detection occurred in the Check Point ThreatCloud (i.e. not locally on the gateway due to its own cache)&lt;BR /&gt;• The DeepScan engine portion of the firewall made the determination&lt;BR /&gt;• The connection was SSL/HTTPS encrypted by the firewall&lt;/P&gt;
&lt;P&gt;What is the specific protection name, and do you have a packet capture set in the Track field of the TP rule matching the protection, the "capture packets" checkbox set on the protection itself, or both?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 13:50:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-Packet-Captures/m-p/159969#M28150</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-10-19T13:50:24Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Packet Captures</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-Packet-Captures/m-p/161092#M28486</link>
      <description>&lt;P&gt;We have the version of protection within our infrastructure on premises , we do not have it in the cloud.&lt;/P&gt;&lt;P&gt;Thank you for your reply...&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2022 07:16:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-Packet-Captures/m-p/161092#M28486</guid>
      <dc:creator>Enes_Morina</dc:creator>
      <dc:date>2022-11-03T07:16:04Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Packet Captures</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-Packet-Captures/m-p/165425#M29659</link>
      <description>&lt;P&gt;If you have MDPS configured on the gateway you are not able to download captures from SmartConsole.&lt;/P&gt;&lt;P&gt;This is a bug and not solved.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2022 14:55:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-Packet-Captures/m-p/165425#M29659</guid>
      <dc:creator>Alexander_Wilke</dc:creator>
      <dc:date>2022-12-16T14:55:54Z</dc:date>
    </item>
  </channel>
</rss>

