<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to read packet-captured file by fw monitor:R81.20 open server in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-read-packet-captured-file-by-fw-monitor-R81-20-open/m-p/225840#M43454</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/114102"&gt;@saitoh&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is a discussion about this:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Wireshark-modification-for-FW-Monitor-files/td-p/40953" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/Wireshark-modification-for-FW-Monitor-files/td-p/40953&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Check it!&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
    <pubDate>Fri, 06 Sep 2024 07:30:45 GMT</pubDate>
    <dc:creator>AkosBakos</dc:creator>
    <dc:date>2024-09-06T07:30:45Z</dc:date>
    <item>
      <title>How to read packet-captured file by fw monitor:R81.20 open server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-read-packet-captured-file-by-fw-monitor-R81-20-open/m-p/225831#M43453</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am testing how DLP works by FTPing text file containing non-existent organization identity.&lt;/P&gt;&lt;P&gt;The test itself turned out to be successful, apart from the point CP does not produce any alert mail.&lt;/P&gt;&lt;P&gt;I configured it with SmartDashboard to use internal AlmaLinux mail server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In order to make the problem clear, I firstly tried fw monitor on the CP where DLP is working,&lt;/P&gt;&lt;P&gt;restaging the same scenario.&lt;/P&gt;&lt;P&gt;The console says something, so I read the captured file by cat, only to find it not human-friendly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That is what I am having trouble with.&lt;/P&gt;&lt;P&gt;The two points I would like to make clear follows;&lt;/P&gt;&lt;P&gt;1. fw monitor file is supposed to be analysed with Wireshark? If so is there any specific procedure to&lt;/P&gt;&lt;P&gt;make it Wireshark-readable?&lt;/P&gt;&lt;P&gt;2. What else do you suggest I should check&amp;nbsp; in this case?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have only a few month experience of CP and Linux system.&lt;/P&gt;&lt;P&gt;Therefore, your personal experience as well as documentation would much appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;Shuto&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2024 05:07:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-read-packet-captured-file-by-fw-monitor-R81-20-open/m-p/225831#M43453</guid>
      <dc:creator>saitoh</dc:creator>
      <dc:date>2024-09-06T05:07:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to read packet-captured file by fw monitor:R81.20 open server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-read-packet-captured-file-by-fw-monitor-R81-20-open/m-p/225840#M43454</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/114102"&gt;@saitoh&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is a discussion about this:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Wireshark-modification-for-FW-Monitor-files/td-p/40953" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/Wireshark-modification-for-FW-Monitor-files/td-p/40953&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Check it!&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2024 07:30:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-read-packet-captured-file-by-fw-monitor-R81-20-open/m-p/225840#M43454</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-09-06T07:30:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to read packet-captured file by fw monitor:R81.20 open server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-read-packet-captured-file-by-fw-monitor-R81-20-open/m-p/225860#M43457</link>
      <description>&lt;P&gt;P.S.&lt;/P&gt;&lt;P&gt;I just tried extracting the file, made it .pcap and let Wireshark read it.&lt;/P&gt;&lt;P&gt;Wireshark shows what I expect to see, but it contains no smtp traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyway I solve how to read fw monitored file somehow.&lt;/P&gt;&lt;P&gt;(Any comments to this procedure is more than appreciated! I just extracted, renamed, and Wiresharked it. Is that good enough?)&lt;/P&gt;&lt;P&gt;Since it contains no smtp traffic, there are two possible causes:&lt;/P&gt;&lt;P&gt;1. simply misoptioned fw monitor command, resulting in capturing non-related traffics.&lt;/P&gt;&lt;P&gt;2. not configured enough associated with alertmail&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2024 08:39:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-read-packet-captured-file-by-fw-monitor-R81-20-open/m-p/225860#M43457</guid>
      <dc:creator>saitoh</dc:creator>
      <dc:date>2024-09-10T08:39:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to read packet-captured file by fw monitor:R81.20 open server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-read-packet-captured-file-by-fw-monitor-R81-20-open/m-p/225880#M43462</link>
      <description>&lt;P&gt;I assume you followed the sk on this topic (referenced in the thread &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/28415"&gt;@AkosBakos&lt;/a&gt;&amp;nbsp;pointed to):&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk39510" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk39510&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;What precise fw monitor syntax did you use the capture traffic?&lt;BR /&gt;Also; what version/JHF since that does matter to a degree.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2024 12:52:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-read-packet-captured-file-by-fw-monitor-R81-20-open/m-p/225880#M43462</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-09-06T12:52:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to read packet-captured file by fw monitor:R81.20 open server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-read-packet-captured-file-by-fw-monitor-R81-20-open/m-p/225882#M43464</link>
      <description>&lt;P&gt;The reason that you are experiencing difficulty is that&amp;nbsp;&lt;STRONG&gt;fw monitor&lt;/STRONG&gt; writes its raw packet capture output (via -o) in Sun snoop format, whereas &lt;STRONG&gt;tcpdump&lt;/STRONG&gt; via -w saves it in pcap format.&amp;nbsp; There is no way I know of to "replay" or make human readable a raw &lt;STRONG&gt;fw monitor&lt;/STRONG&gt; capture file from the CLI of Gaia, unless you want to feed it to something like &lt;STRONG&gt;cpmonitor&lt;/STRONG&gt;&amp;nbsp;(sk103212) for statistical analysis.&amp;nbsp; pcap captures can be replayed by &lt;STRONG&gt;tcpdump&lt;/STRONG&gt;, but &lt;STRONG&gt;tcpdump&lt;/STRONG&gt; does not understand snoop format.&amp;nbsp; In the old days on Solaris the &lt;STRONG&gt;snoop&lt;/STRONG&gt; command itself could be used to replay these captures, but that command is long gone.&amp;nbsp; Wireshark has to be used now as it can still decode snoop format.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;sk39510 and such only talk about how to display the iIoO capture points in Wireshark and adjust the colorization to adapt to the same packet being shown more than once.&amp;nbsp; This is all covered in my &lt;A href="http://www.maxpowerfirewalls.com/max-capture-course.html" target="_blank" rel="noopener"&gt;Max Capture: Know Your Packets&lt;/A&gt; self-guided video course.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2024 13:13:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-read-packet-captured-file-by-fw-monitor-R81-20-open/m-p/225882#M43464</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2024-09-06T13:13:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to read packet-captured file by fw monitor:R81.20 open server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-read-packet-captured-file-by-fw-monitor-R81-20-open/m-p/226082#M43488</link>
      <description>&lt;P&gt;Hi Akos,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for sharing the link!&lt;/P&gt;&lt;P&gt;I did not know I could modify the configuration of Wireshark like that.&lt;/P&gt;&lt;P&gt;I will try testing it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Saitoh&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2024 02:32:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-read-packet-captured-file-by-fw-monitor-R81-20-open/m-p/226082#M43488</guid>
      <dc:creator>saitoh</dc:creator>
      <dc:date>2024-09-10T02:32:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to read packet-captured file by fw monitor:R81.20 open server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-read-packet-captured-file-by-fw-monitor-R81-20-open/m-p/226083#M43489</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I actually did not know that I had to make changes to the configuration of Wireshark.&lt;/P&gt;&lt;P&gt;I somehow surmised fw monitor capture should be able to be analysed by Wireshark.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The syntax I used is as follows.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;#fw monitor -d -ci 100 -co 100 -F “10.11.1.1,0” -F “10.31.10.110,25” -o /var/log/fwmonitor -w&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also, R81.20 built 631 with Accumulator T76, and T53 installed.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Saitoh&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2024 02:42:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-read-packet-captured-file-by-fw-monitor-R81-20-open/m-p/226083#M43489</guid>
      <dc:creator>saitoh</dc:creator>
      <dc:date>2024-09-10T02:42:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to read packet-captured file by fw monitor:R81.20 open server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-read-packet-captured-file-by-fw-monitor-R81-20-open/m-p/226084#M43490</link>
      <description>&lt;P&gt;Hi Tim,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the highly detailed explanation!&lt;/P&gt;&lt;P&gt;This helps me a lot as it contains the term I did not get to see. I have learnt new things!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Other community members are also telling me that I can actually analyse fw monitor capture by adjusting Wireshark a little.&lt;/P&gt;&lt;P&gt;So I am going to start that point to make it clear whether I did not see any smtp packet because I misconfigured CP or mis-syntaxed fw monitor.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Saitoh&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2024 02:58:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-read-packet-captured-file-by-fw-monitor-R81-20-open/m-p/226084#M43490</guid>
      <dc:creator>saitoh</dc:creator>
      <dc:date>2024-09-10T02:58:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to read packet-captured file by fw monitor:R81.20 open server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-read-packet-captured-file-by-fw-monitor-R81-20-open/m-p/226205#M43509</link>
      <description>&lt;P&gt;Dear all that thankfully helped me a lot,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The cause why CP does not produce any alert email is still unclear, and&lt;/P&gt;&lt;P&gt;somehow my test environment is not working as I expect.&lt;/P&gt;&lt;P&gt;Therefore I recreate it, and test alert mail function the other way than DLP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Even though I was not able to find out the root cause,&lt;/P&gt;&lt;P&gt;your comments are really instructive in light of the format of fw monitor-captured file.&lt;/P&gt;&lt;P&gt;(especially Snoop format is intriguing to me since I have never heard of it!)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Much appreciated to three legends;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/28415"&gt;@AkosBakos&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;!&lt;/P&gt;&lt;P&gt;Thanks to your advice I successfully open fw monitor capture file by Wireshark and analysed it.&lt;/P&gt;&lt;P&gt;There is was smtp negotiation observed, so perhaps I should check CP config with detail.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Saitoh&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 00:26:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-read-packet-captured-file-by-fw-monitor-R81-20-open/m-p/226205#M43509</guid>
      <dc:creator>saitoh</dc:creator>
      <dc:date>2024-09-11T00:26:47Z</dc:date>
    </item>
  </channel>
</rss>

