<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: tcpdump, fw monitor and fw ctl zdebug commands and performance impact in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/tcpdump-fw-monitor-and-fw-ctl-zdebug-commands-and-performance/m-p/196410#M36652</link>
    <description>&lt;P&gt;Can you please explain why you need tcpdump and fw monitor for traffic analysis ? Usually cpview gives you the needed look into secureXL state, see the following:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk167553" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk167553: &lt;STRONG&gt;Performance&lt;/STRONG&gt; &lt;STRONG&gt;Investigation&lt;/STRONG&gt; Procedure - How To&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk98348" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk98348: Best Practices - Security Gateway &lt;STRONG&gt;Performance&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 27 Oct 2023 13:42:12 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2023-10-27T13:42:12Z</dc:date>
    <item>
      <title>tcpdump, fw monitor and fw ctl zdebug commands and performance impact</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/tcpdump-fw-monitor-and-fw-ctl-zdebug-commands-and-performance/m-p/196395#M36647</link>
      <description>&lt;P&gt;Good day&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have highly loaded security gateways that currently need traffic analysis.&lt;/P&gt;&lt;P&gt;In this article &lt;A href="https://community.checkpoint.com/t5/Security-Gateways/quot-fw-ctl-zdebug-quot-Helpful-Command-Combinations/td-p/40680" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/Security-Gateways/quot-fw-ctl-zdebug-quot-Helpful-Command-Combinations/td-p/40680&lt;/A&gt; I came across information that the utility negatively affects on performance .&lt;/P&gt;&lt;P&gt;Please tell me how critically it can affect on performance, which of the systems (CPU, RAM, traffic) is loaded the most?&lt;/P&gt;&lt;P&gt;Is it possible to reduce resource consumption through parameters like specifying the interface that will be dump?&lt;/P&gt;&lt;P&gt;How much traffic can &lt;EM&gt;fw monitor&lt;/EM&gt; and &lt;EM&gt;tcpdump&lt;/EM&gt;&amp;nbsp;also load?&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2023 12:48:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/tcpdump-fw-monitor-and-fw-ctl-zdebug-commands-and-performance/m-p/196395#M36647</guid>
      <dc:creator>DmitriyDubovik</dc:creator>
      <dc:date>2023-10-27T12:48:43Z</dc:date>
    </item>
    <item>
      <title>Re: tcpdump, fw monitor and fw ctl zdebug commands and performance impact</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/tcpdump-fw-monitor-and-fw-ctl-zdebug-commands-and-performance/m-p/196397#M36648</link>
      <description>&lt;P&gt;Use &lt;A href="https://support.checkpoint.com/results/sk/sk141412" target="_blank" rel="noopener"&gt;cppcap&lt;/A&gt; instead of tcpdump.&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_Quantum_SecurityGateway_Guide/Topics-FWG/Kernel-Debug/Kernel-Debug-Procedure.htm?tocpath=Kernel%20Debug%7C_____3" target="_blank" rel="noopener"&gt;Kernel debug&lt;/A&gt; will have an impact on your FW, especially if it's already loaded as you say. They have to be started and stopped properly.&lt;/P&gt;&lt;P&gt;It's best to consult first with TAC to review your situation.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2023 13:01:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/tcpdump-fw-monitor-and-fw-ctl-zdebug-commands-and-performance/m-p/196397#M36648</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2023-10-27T13:01:53Z</dc:date>
    </item>
    <item>
      <title>Re: tcpdump, fw monitor and fw ctl zdebug commands and performance impact</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/tcpdump-fw-monitor-and-fw-ctl-zdebug-commands-and-performance/m-p/196398#M36649</link>
      <description>&lt;P&gt;TAC give you an answer for multiple days, we can t wait so long. Problem is in thing, that documentation don t describe important things like how much impact of performance, in what situation we can it on, in what we cant and another things...&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2023 13:09:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/tcpdump-fw-monitor-and-fw-ctl-zdebug-commands-and-performance/m-p/196398#M36649</guid>
      <dc:creator>DmitriyDubovik</dc:creator>
      <dc:date>2023-10-27T13:09:25Z</dc:date>
    </item>
    <item>
      <title>Re: tcpdump, fw monitor and fw ctl zdebug commands and performance impact</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/tcpdump-fw-monitor-and-fw-ctl-zdebug-commands-and-performance/m-p/196399#M36650</link>
      <description>&lt;P&gt;And the most interesting question is whether the load will change depending on the parameters that you set&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2023 13:11:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/tcpdump-fw-monitor-and-fw-ctl-zdebug-commands-and-performance/m-p/196399#M36650</guid>
      <dc:creator>DmitriyDubovik</dc:creator>
      <dc:date>2023-10-27T13:11:10Z</dc:date>
    </item>
    <item>
      <title>Re: tcpdump, fw monitor and fw ctl zdebug commands and performance impact</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/tcpdump-fw-monitor-and-fw-ctl-zdebug-commands-and-performance/m-p/196410#M36652</link>
      <description>&lt;P&gt;Can you please explain why you need tcpdump and fw monitor for traffic analysis ? Usually cpview gives you the needed look into secureXL state, see the following:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk167553" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk167553: &lt;STRONG&gt;Performance&lt;/STRONG&gt; &lt;STRONG&gt;Investigation&lt;/STRONG&gt; Procedure - How To&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk98348" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk98348: Best Practices - Security Gateway &lt;STRONG&gt;Performance&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2023 13:42:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/tcpdump-fw-monitor-and-fw-ctl-zdebug-commands-and-performance/m-p/196410#M36652</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-10-27T13:42:12Z</dc:date>
    </item>
    <item>
      <title>Re: tcpdump, fw monitor and fw ctl zdebug commands and performance impact</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/tcpdump-fw-monitor-and-fw-ctl-zdebug-commands-and-performance/m-p/196413#M36654</link>
      <description>&lt;P&gt;unstable traffic in video conferences without any negative symptoms (packet drops in the smartlog, CPU overload, and etc) is a main problem&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2023 13:47:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/tcpdump-fw-monitor-and-fw-ctl-zdebug-commands-and-performance/m-p/196413#M36654</guid>
      <dc:creator>DmitriyDubovik</dc:creator>
      <dc:date>2023-10-27T13:47:59Z</dc:date>
    </item>
  </channel>
</rss>

