<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic fw monitor in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor/m-p/255783#M50072</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I need to monitor inbound traffic between an external source and Check Point security gateway external interface on port 443.&lt;/P&gt;&lt;P&gt;R82 Take 12 runs on the security gateway.&lt;/P&gt;&lt;P&gt;Here is the syntaxis of fw monitor that I use on the gateway:&lt;/P&gt;&lt;P&gt;fw monitor -F "0.0.0.0, 0, 12.69.98.28, 443, 6" -pi&lt;/P&gt;&lt;P&gt;And here is output:&lt;/P&gt;&lt;P&gt;PPAK 0: Get before set operation succeeded of fwmonitor_kiss_enable&lt;BR /&gt;PPAK 0: Get before set operation succeeded of fwmonitor_debug_filter_off&lt;BR /&gt;PPAK 0: Get before set operation succeeded of fwmonitorfreebufs&lt;BR /&gt;Invalid destination IP address 12.X.X.28 in debug filter&lt;/P&gt;&lt;P&gt;I replaced part of the public IP address of my gateway with X.&lt;/P&gt;&lt;P&gt;Any suggestions to get correct output?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 23 Aug 2025 03:33:15 GMT</pubDate>
    <dc:creator>Vladimir_S</dc:creator>
    <dc:date>2025-08-23T03:33:15Z</dc:date>
    <item>
      <title>fw monitor</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor/m-p/255783#M50072</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I need to monitor inbound traffic between an external source and Check Point security gateway external interface on port 443.&lt;/P&gt;&lt;P&gt;R82 Take 12 runs on the security gateway.&lt;/P&gt;&lt;P&gt;Here is the syntaxis of fw monitor that I use on the gateway:&lt;/P&gt;&lt;P&gt;fw monitor -F "0.0.0.0, 0, 12.69.98.28, 443, 6" -pi&lt;/P&gt;&lt;P&gt;And here is output:&lt;/P&gt;&lt;P&gt;PPAK 0: Get before set operation succeeded of fwmonitor_kiss_enable&lt;BR /&gt;PPAK 0: Get before set operation succeeded of fwmonitor_debug_filter_off&lt;BR /&gt;PPAK 0: Get before set operation succeeded of fwmonitorfreebufs&lt;BR /&gt;Invalid destination IP address 12.X.X.28 in debug filter&lt;/P&gt;&lt;P&gt;I replaced part of the public IP address of my gateway with X.&lt;/P&gt;&lt;P&gt;Any suggestions to get correct output?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Aug 2025 03:33:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor/m-p/255783#M50072</guid>
      <dc:creator>Vladimir_S</dc:creator>
      <dc:date>2025-08-23T03:33:15Z</dc:date>
    </item>
    <item>
      <title>Re: fw monitor</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor/m-p/255788#M50076</link>
      <description>&lt;P&gt;Try:&lt;/P&gt;
&lt;P&gt;fw monitor -m i -F "0,0,1.1.1.1,443,0"&lt;BR /&gt;replace 1.1.1.1 with your ip and please edit your post in the output you still can see the full public ip&lt;/P&gt;</description>
      <pubDate>Sat, 23 Aug 2025 07:53:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor/m-p/255788#M50076</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-08-23T07:53:03Z</dc:date>
    </item>
    <item>
      <title>Re: fw monitor</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor/m-p/255808#M50079</link>
      <description>&lt;P&gt;Hi Lesley,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The command worked!! Another question, for the&amp;nbsp;&lt;/SPAN&gt;fw monitor&lt;SPAN&gt;&amp;nbsp;filter, what expression should be added to capture ICMP traffic?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Vlad.&lt;/P&gt;</description>
      <pubDate>Sun, 24 Aug 2025 01:37:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor/m-p/255808#M50079</guid>
      <dc:creator>Vladimir_S</dc:creator>
      <dc:date>2025-08-24T01:37:31Z</dc:date>
    </item>
    <item>
      <title>Re: fw monitor</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor/m-p/255816#M50085</link>
      <description>&lt;P&gt;fw monitor -m i -F "0,0,1.1.1.1,0,1"&lt;/P&gt;</description>
      <pubDate>Sun, 24 Aug 2025 05:52:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor/m-p/255816#M50085</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-08-24T05:52:03Z</dc:date>
    </item>
    <item>
      <title>Re: fw monitor</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor/m-p/255843#M50099</link>
      <description>&lt;P&gt;Thank you Lesley, it works too!!&lt;/P&gt;&lt;P&gt;Vlad.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Aug 2025 01:07:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor/m-p/255843#M50099</guid>
      <dc:creator>Vladimir_S</dc:creator>
      <dc:date>2025-08-25T01:07:47Z</dc:date>
    </item>
  </channel>
</rss>

