<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: fw monitor stops working after upgrade to R80.40 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor-stops-working-after-upgrade-to-R80-40/m-p/86886#M9159</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/16718"&gt;@Lincoln_Webber&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i tried same command in my lab and it works, as i mention before it looks like buffer issue.&lt;/P&gt;
&lt;P&gt;Are you sure you don't have any debugs turned on?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 31 May 2020 17:54:12 GMT</pubDate>
    <dc:creator>Ilya_Yusupov</dc:creator>
    <dc:date>2020-05-31T17:54:12Z</dc:date>
    <item>
      <title>fw monitor stops working after upgrade to R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor-stops-working-after-upgrade-to-R80-40/m-p/86542#M9154</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;We upgrade our R80.30 VSX cluster to R80.40 JHF Take 45 over the weekend and fw monitor complains that it cant allocate buffer then throws me back to the shell. See the screenshot for the actual messages.&lt;/P&gt;&lt;P&gt;Has anyone experienced this of has insight into the cause and solution?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="fw_monitor_error.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6263iF9E6B09AA1F9EC84/image-size/large?v=v2&amp;amp;px=999" role="button" title="fw_monitor_error.PNG" alt="fw_monitor_error.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2020 00:20:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor-stops-working-after-upgrade-to-R80-40/m-p/86542#M9154</guid>
      <dc:creator>Lincoln_Webber</dc:creator>
      <dc:date>2020-05-28T00:20:01Z</dc:date>
    </item>
    <item>
      <title>Re: fw monitor stops working after upgrade to R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor-stops-working-after-upgrade-to-R80-40/m-p/86553#M9155</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/16718"&gt;@Lincoln_Webber&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Add your VS to fw monitor:&lt;/P&gt;
&lt;P&gt;fw monitor &lt;FONT color="#FF0000"&gt;-v &amp;lt;vsx instance&amp;gt;&lt;/FONT&gt; -e "accept(host ...);"&lt;/P&gt;
&lt;P&gt;Specifies the capture filter (for both accelerated and non-accelerated traffic):&lt;BR /&gt;&lt;BR /&gt;-F "&amp;lt;Source IP&amp;gt;,&amp;lt;Source Port&amp;gt;,&amp;lt;Dest IP&amp;gt;,&amp;lt;Dest Port&amp;gt;,&amp;lt;Protocol Number&amp;gt;"&lt;/P&gt;
&lt;P&gt;If that doesn't help, I'd open a TAC case.&lt;/P&gt;
&lt;P&gt;PS:&lt;BR /&gt;With R80.40 fw monitor works slightly different than in older versions. Showing list of chain modules with the "fw monitor", when you do not change the &lt;FONT color="#FF0000"&gt;default capture positions&lt;/FONT&gt;:&lt;/P&gt;
&lt;P&gt;in chain (17):&lt;BR /&gt;0: -7fffffff (0000000000000000) (00000000) SecureXL inbound (sxl_in)&lt;BR /&gt;1: -7ffffffe (0000000000000000) (00000000) SecureXL inbound CT (sxl_ct)&lt;BR /&gt;2: -7f800000 (ffffffff8b6718c0) (ffffffff) IP Options Strip (in) (ipopt_strip)&lt;BR /&gt;3: -70000000 (ffffffff8b6774d0) (ffffffff) &lt;FONT color="#FF0000"&gt;fwmonitor (i/f side)&lt;/FONT&gt;&lt;BR /&gt;4: - 1fffff8 (ffffffff8b66f6f0) (00000001) Stateless verifications (in) (asm)&lt;BR /&gt;5: - 1fffff7 (ffffffff8b66f210) (00000001) fw multik misc proto forwarding&lt;BR /&gt;6: 0 (ffffffff8b8506a0) (00000001) fw VM inbound (fw)&lt;BR /&gt;7: 2 (ffffffff8b671d10) (00000001) fw SCV inbound (scv)&lt;BR /&gt;8: 4 (ffffffff8b061ed0) (00000003) QoS inbound offload chain module&lt;BR /&gt;9: 5 (ffffffff8b564d30) (00000003) fw offload inbound (offload_in)&lt;BR /&gt;10: 10 (ffffffff8b842710) (00000001) fw post VM inbound (post_vm)&lt;BR /&gt;11: 100000 (ffffffff8b7fd6c0) (00000001) fw accounting inbound (acct)&lt;BR /&gt;12: 22000000 (ffffffff8b0638d0) (00000003) QoS slowpath inbound chain mod (fg_sched)&lt;BR /&gt;13: 70000000 (ffffffff8b6774d0) (ffffffff) &lt;FONT color="#FF0000"&gt;fwmonitor (IP side)&lt;/FONT&gt;&lt;BR /&gt;14: 7f730000 (ffffffff8b3c40b0) (00000001) passive streaming (in) (pass_str)&lt;BR /&gt;15: 7f750000 (ffffffff8b0e5b40) (00000001) TCP streaming (in) (cpas)&lt;BR /&gt;16: 7f800000 (ffffffff8b671870) (ffffffff) IP Options Restore (in) (ipopt_res)&lt;/P&gt;
&lt;P&gt;out chain (16):&lt;BR /&gt;0: -7f800000 (ffffffff8b6718c0) (ffffffff) IP Options Strip (out) (ipopt_strip)&lt;BR /&gt;1: -70000000 (ffffffff8b6774d0) (ffffffff) &lt;FONT color="#FF0000"&gt;fwmonitor (i/f side)&lt;/FONT&gt;&lt;BR /&gt;2: - 1fffff0 (ffffffff8b0d0190) (00000001) TCP streaming (out) (cpas)&lt;BR /&gt;3: - 1ffff50 (ffffffff8b3c40b0) (00000001) passive streaming (out) (pass_str)&lt;BR /&gt;4: - 1f00000 (ffffffff8b66f6f0) (00000001) Stateless verifications (out) (asm)&lt;BR /&gt;5: - 1ff (ffffffff8aeec0a0) (00000001) NAC Packet Outbound (nac_tag)&lt;BR /&gt;6: 0 (ffffffff8b8506a0) (00000001) fw VM outbound (fw)&lt;BR /&gt;7: 10 (ffffffff8b842710) (00000001) fw post VM outbound (post_vm)&lt;BR /&gt;8: 15000000 (ffffffff8b062540) (00000003) QoS outbound offload chain modul (fg_pol)&lt;BR /&gt;9: 21000000 (ffffffff8b0638d0) (00000003) QoS slowpath outbound chain mod (fg_sched)&lt;BR /&gt;10: 70000000 (ffffffff8b6774d0) (ffffffff) &lt;FONT color="#FF0000"&gt;fwmonitor (IP side)&lt;/FONT&gt;&lt;BR /&gt;11: 7f000000 (ffffffff8b7fd6c0) (00000001) fw accounting outbound (acct)&lt;BR /&gt;12: 7f700000 (ffffffff8b0e4660) (00000001) TCP streaming post VM (cpas)&lt;BR /&gt;13: 7f800000 (ffffffff8b671870) (ffffffff) IP Options Restore (out) (ipopt_res)&lt;BR /&gt;14: 7f900000 (0000000000000000) (00000000) SecureXL outbound (sxl_out)&lt;BR /&gt;15: 7fa00000&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2020 06:18:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor-stops-working-after-upgrade-to-R80-40/m-p/86553#M9155</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2020-05-28T06:18:02Z</dc:date>
    </item>
    <item>
      <title>Re: fw monitor stops working after upgrade to R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor-stops-working-after-upgrade-to-R80-40/m-p/86566#M9156</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/16718"&gt;@Lincoln_Webber&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you share the exact command you used for fw monitor? it's not seen in the screenshot.&lt;/P&gt;
&lt;P&gt;Also any chance that you run some debug on the system before running the fw monitor command?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In general looks like your buffer is full this is why the fw monitor is not able to load.&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2020 09:01:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor-stops-working-after-upgrade-to-R80-40/m-p/86566#M9156</guid>
      <dc:creator>Ilya_Yusupov</dc:creator>
      <dc:date>2020-05-28T09:01:32Z</dc:date>
    </item>
    <item>
      <title>Re: fw monitor stops working after upgrade to R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor-stops-working-after-upgrade-to-R80-40/m-p/86630#M9157</link>
      <description>Hi Ilya,&lt;BR /&gt;The command is in the first line of the screenshot (fw monitor -e 'accept host(x.x.x.x);'</description>
      <pubDate>Thu, 28 May 2020 17:05:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor-stops-working-after-upgrade-to-R80-40/m-p/86630#M9157</guid>
      <dc:creator>Lincoln_Webber</dc:creator>
      <dc:date>2020-05-28T17:05:23Z</dc:date>
    </item>
    <item>
      <title>Re: fw monitor stops working after upgrade to R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor-stops-working-after-upgrade-to-R80-40/m-p/86631#M9158</link>
      <description>&lt;P&gt;Hey Heiko,&lt;/P&gt;&lt;P&gt;I got it to run by adding the -v option.&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2020 17:22:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor-stops-working-after-upgrade-to-R80-40/m-p/86631#M9158</guid>
      <dc:creator>Lincoln_Webber</dc:creator>
      <dc:date>2020-05-28T17:22:34Z</dc:date>
    </item>
    <item>
      <title>Re: fw monitor stops working after upgrade to R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor-stops-working-after-upgrade-to-R80-40/m-p/86886#M9159</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/16718"&gt;@Lincoln_Webber&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i tried same command in my lab and it works, as i mention before it looks like buffer issue.&lt;/P&gt;
&lt;P&gt;Are you sure you don't have any debugs turned on?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 31 May 2020 17:54:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-monitor-stops-working-after-upgrade-to-R80-40/m-p/86886#M9159</guid>
      <dc:creator>Ilya_Yusupov</dc:creator>
      <dc:date>2020-05-31T17:54:12Z</dc:date>
    </item>
  </channel>
</rss>

