<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FW Monitor in VSX in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Monitor-in-VSX/m-p/251426#M49219</link>
    <description>&lt;P&gt;There you go buddy &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;fw monitor -v 5 -o vs5.cap -F "172.16.10.5,0,10.100.20.10,8080,0"&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Tue, 17 Jun 2025 11:37:46 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-06-17T11:37:46Z</dc:date>
    <item>
      <title>FW Monitor in VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Monitor-in-VSX/m-p/251387#M49204</link>
      <description>&lt;P&gt;Hi Guys&lt;/P&gt;
&lt;P&gt;Is it possible to run a "fw monitor" from the VS0 of a VSX Cluster environment?&lt;/P&gt;
&lt;P&gt;I have several VS's, and I want to capture traffic from a particular VS (VS 5).&lt;/P&gt;
&lt;P&gt;Is this possible, without having to "jump" to the instance?&lt;/P&gt;
&lt;P&gt;Can you share with me the syntax of the command, how it could be done, based on the following example:&lt;/P&gt;
&lt;P&gt;Source: 172.16.10.5&lt;BR /&gt;Destination: 10.100.20.10&lt;BR /&gt;Port: TCP 8080&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jun 2025 00:42:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Monitor-in-VSX/m-p/251387#M49204</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-06-17T00:42:48Z</dc:date>
    </item>
    <item>
      <title>Re: FW Monitor in VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Monitor-in-VSX/m-p/251389#M49205</link>
      <description>&lt;P&gt;fw monitor -v 0 -e accept "host 172.16.10.5 and host 10.200.20.10 and port 8080;"&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jun 2025 00:59:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Monitor-in-VSX/m-p/251389#M49205</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-17T00:59:45Z</dc:date>
    </item>
    <item>
      <title>Re: FW Monitor in VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Monitor-in-VSX/m-p/251390#M49206</link>
      <description>&lt;P&gt;This applies if you are ‘standing’ on VS0 and want to capture traffic from VS 5?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jun 2025 01:31:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Monitor-in-VSX/m-p/251390#M49206</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-06-17T01:31:20Z</dc:date>
    </item>
    <item>
      <title>Re: FW Monitor in VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Monitor-in-VSX/m-p/251391#M49207</link>
      <description>&lt;P&gt;Just replace 0 with 5 &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jun 2025 01:32:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Monitor-in-VSX/m-p/251391#M49207</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-17T01:32:36Z</dc:date>
    </item>
    <item>
      <title>Re: FW Monitor in VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Monitor-in-VSX/m-p/251392#M49208</link>
      <description>&lt;P&gt;The command syntax varies greatly if you need to send the command result to a file such as Wireshark?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jun 2025 02:24:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Monitor-in-VSX/m-p/251392#M49208</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-06-17T02:24:48Z</dc:date>
    </item>
    <item>
      <title>Re: FW Monitor in VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Monitor-in-VSX/m-p/251393#M49209</link>
      <description>&lt;P&gt;Just add -o /path/filename.cap at the end&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jun 2025 02:32:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Monitor-in-VSX/m-p/251393#M49209</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-17T02:32:11Z</dc:date>
    </item>
    <item>
      <title>Re: FW Monitor in VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Monitor-in-VSX/m-p/251399#M49212</link>
      <description>&lt;P&gt;This is all you need:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://tcpdump101.com/#" target="_blank"&gt;https://tcpdump101.com/#&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Under Check Point -&amp;gt; FW Monitor -&amp;gt; New version&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jun 2025 07:24:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Monitor-in-VSX/m-p/251399#M49212</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-06-17T07:24:39Z</dc:date>
    </item>
    <item>
      <title>Re: FW Monitor in VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Monitor-in-VSX/m-p/251426#M49219</link>
      <description>&lt;P&gt;There you go buddy &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;fw monitor -v 5 -o vs5.cap -F "172.16.10.5,0,10.100.20.10,8080,0"&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jun 2025 11:37:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Monitor-in-VSX/m-p/251426#M49219</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-17T11:37:46Z</dc:date>
    </item>
    <item>
      <title>Re: FW Monitor in VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Monitor-in-VSX/m-p/251480#M49236</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/82839"&gt;@Matlu&lt;/a&gt;&amp;nbsp;Did command we shared work for you?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jun 2025 23:29:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Monitor-in-VSX/m-p/251480#M49236</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-17T23:29:04Z</dc:date>
    </item>
    <item>
      <title>Re: FW Monitor in VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Monitor-in-VSX/m-p/251481#M49237</link>
      <description>&lt;P&gt;One doubt, is there much difference in the ‘fw monitor ...’ command between using the -e vs -F parameter?&lt;/P&gt;
&lt;P&gt;Is one better than the other?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jun 2025 23:36:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Monitor-in-VSX/m-p/251481#M49237</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-06-17T23:36:40Z</dc:date>
    </item>
    <item>
      <title>Re: FW Monitor in VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Monitor-in-VSX/m-p/251482#M49238</link>
      <description>&lt;P&gt;Buddy,&lt;/P&gt;
&lt;P&gt;Have a look at your own post &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Traffic-capture-with-FW-MONITOR/m-p/245408" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Traffic-capture-with-FW-MONITOR/m-p/245408&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jun 2025 23:44:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Monitor-in-VSX/m-p/251482#M49238</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-17T23:44:26Z</dc:date>
    </item>
    <item>
      <title>Re: FW Monitor in VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Monitor-in-VSX/m-p/251532#M49244</link>
      <description>&lt;P&gt;Use -F if you can deal with the extremely limited matching syntax.&amp;nbsp; You will always get a complete capture regardless of the acceleration state of the traffic.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2025 15:12:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Monitor-in-VSX/m-p/251532#M49244</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2025-06-18T15:12:45Z</dc:date>
    </item>
    <item>
      <title>Re: FW Monitor in VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Monitor-in-VSX/m-p/251533#M49245</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;So, as a "best practice" it is always better to use the "-F" before the "-e"?&lt;BR /&gt;Greetings.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2025 15:16:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Monitor-in-VSX/m-p/251533#M49245</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-06-18T15:16:13Z</dc:date>
    </item>
    <item>
      <title>Re: FW Monitor in VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Monitor-in-VSX/m-p/251534#M49246</link>
      <description>&lt;P&gt;I'd say so, there are still some limited situations where &lt;STRONG&gt;-e&lt;/STRONG&gt; is needed instead but they are fairly obscure.&amp;nbsp; The upcoming CCTA R82 class is being heavily updated to explore packet capturing &amp;amp; analysis in detail, and it covers this very topic.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2025 15:20:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Monitor-in-VSX/m-p/251534#M49246</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2025-06-18T15:20:41Z</dc:date>
    </item>
    <item>
      <title>Re: FW Monitor in VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Monitor-in-VSX/m-p/251536#M49247</link>
      <description>&lt;P&gt;For what its worth, I usually use -F flag and works real well.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2025 15:25:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Monitor-in-VSX/m-p/251536#M49247</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-18T15:25:22Z</dc:date>
    </item>
  </channel>
</rss>

