<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FW MONITOR shows in IN, out Out, but tcpdump only shows incoming in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/FW-MONITOR-shows-in-IN-out-Out-but-tcpdump-only-shows-incoming/m-p/81200#M16404</link>
    <description>&lt;P&gt;Figured it out. The gateway for the destination was a VIP (router pair). However it was not configured, only the single router nodes were. Changed my route to point to one of the routers and tcpdump started showing forward and return traffic. Is that a feature? I would at least expect to see the traffic leaving via tcpdump even tho the destination gateway wasn't available.&lt;/P&gt;&lt;P&gt;Thanks for all the help&lt;/P&gt;</description>
    <pubDate>Tue, 07 Apr 2020 20:32:55 GMT</pubDate>
    <dc:creator>J_Saun</dc:creator>
    <dc:date>2020-04-07T20:32:55Z</dc:date>
    <item>
      <title>FW MONITOR shows in IN, out Out, but tcpdump only shows incoming</title>
      <link>https://community.checkpoint.com/t5/General-Topics/FW-MONITOR-shows-in-IN-out-Out-but-tcpdump-only-shows-incoming/m-p/80748#M16320</link>
      <description>&lt;P&gt;Trying to troubleshoot a connection. src=10.250.96.68, dest=10.129.3.191, port=445. Smartconsole logger shows it being permitted.&lt;/P&gt;&lt;P&gt;FW MONITOR shows the following:&lt;/P&gt;&lt;P&gt;[vs_0][fw_1] eth1:i[52]: 10.250.96.68 -&amp;gt; 10.129.3.191 (TCP) len=52 id=13271&lt;BR /&gt;[vs_0][fw_1] eth1:I[52]: 10.250.96.68 -&amp;gt; 10.129.3.191 (TCP) len=52 id=13271&lt;BR /&gt;[vs_0][fw_1] eth2:o[52]: 10.250.96.68 -&amp;gt; 10.129.3.191 (TCP) len=52 id=13271&lt;BR /&gt;[vs_0][fw_1] eth2:O[52]: 10.250.96.68 -&amp;gt; 10.129.3.191 (TCP) len=52 id=13271&lt;BR /&gt;[vs_0][fw_1] eth1:i[52]: 10.250.96.68 -&amp;gt; 10.129.3.191 (TCP) len=52 id=13272&lt;BR /&gt;[vs_0][fw_1] eth1:I[52]: 10.250.96.68 -&amp;gt; 10.129.3.191 (TCP) len=52 id=13272&lt;BR /&gt;[vs_0][fw_1] eth2:o[52]: 10.250.96.68 -&amp;gt; 10.129.3.191 (TCP) len=52 id=13272&lt;BR /&gt;[vs_0][fw_1] eth2:O[52]: 10.250.96.68 -&amp;gt; 10.129.3.191 (TCP) len=52 id=13272&lt;/P&gt;&lt;P&gt;When I do a tcpdump on eth1 I see the inbound packets from src-10.250.96.68 to dest-10.129.3.191, but a tcpdump on eth2 shows nothing.&lt;/P&gt;&lt;P&gt;I have tried with fwaccel off anf on. No difference.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2020 14:23:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/FW-MONITOR-shows-in-IN-out-Out-but-tcpdump-only-shows-incoming/m-p/80748#M16320</guid>
      <dc:creator>J_Saun</dc:creator>
      <dc:date>2020-04-03T14:23:54Z</dc:date>
    </item>
    <item>
      <title>Re: FW MONITOR shows in IN, out Out, but tcpdump only shows incoming</title>
      <link>https://community.checkpoint.com/t5/General-Topics/FW-MONITOR-shows-in-IN-out-Out-but-tcpdump-only-shows-incoming/m-p/80757#M16321</link>
      <description>&lt;P&gt;If this is a VSX cluster with a vSwitch connected to the eth1, you may have the egress/ingress traffic happening on a different cluster member.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2020 15:36:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/FW-MONITOR-shows-in-IN-out-Out-but-tcpdump-only-shows-incoming/m-p/80757#M16321</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2020-04-03T15:36:30Z</dc:date>
    </item>
    <item>
      <title>Re: FW MONITOR shows in IN, out Out, but tcpdump only shows incoming</title>
      <link>https://community.checkpoint.com/t5/General-Topics/FW-MONITOR-shows-in-IN-out-Out-but-tcpdump-only-shows-incoming/m-p/80758#M16322</link>
      <description>&lt;P&gt;Code version and Jumbo HFA?&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2020 15:37:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/FW-MONITOR-shows-in-IN-out-Out-but-tcpdump-only-shows-incoming/m-p/80758#M16322</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-04-03T15:37:57Z</dc:date>
    </item>
    <item>
      <title>Re: FW MONITOR shows in IN, out Out, but tcpdump only shows incoming</title>
      <link>https://community.checkpoint.com/t5/General-Topics/FW-MONITOR-shows-in-IN-out-Out-but-tcpdump-only-shows-incoming/m-p/80760#M16324</link>
      <description>&lt;P&gt;This is a 5900 series appliance cluster (not VSX). R77.30 - Build 024&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2020 15:43:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/FW-MONITOR-shows-in-IN-out-Out-but-tcpdump-only-shows-incoming/m-p/80760#M16324</guid>
      <dc:creator>J_Saun</dc:creator>
      <dc:date>2020-04-03T15:43:32Z</dc:date>
    </item>
    <item>
      <title>Re: FW MONITOR shows in IN, out Out, but tcpdump only shows incoming</title>
      <link>https://community.checkpoint.com/t5/General-Topics/FW-MONITOR-shows-in-IN-out-Out-but-tcpdump-only-shows-incoming/m-p/80762#M16325</link>
      <description>&lt;P&gt;ClusterXL or VRRP?&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2020 15:53:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/FW-MONITOR-shows-in-IN-out-Out-but-tcpdump-only-shows-incoming/m-p/80762#M16325</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2020-04-03T15:53:13Z</dc:date>
    </item>
    <item>
      <title>Re: FW MONITOR shows in IN, out Out, but tcpdump only shows incoming</title>
      <link>https://community.checkpoint.com/t5/General-Topics/FW-MONITOR-shows-in-IN-out-Out-but-tcpdump-only-shows-incoming/m-p/80765#M16327</link>
      <description>&lt;P&gt;Try:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;tcpdump -eP -i any -nnnl host 10.250.96.68 and host 10.129.3.191 and port 445&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;if that gives a syntax error try:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;tcpdump -e -i any -nnnl host 10.250.96.68 and host 10.129.3.191 and port 445&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Be aware that if the traffic is NATted, &lt;STRONG&gt;tcpdump&lt;/STRONG&gt; may not display it correctly on your code version, see &lt;A class="cp_link sc_ellipsis" style="max-width: 840px;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk100194&amp;amp;partition=Advanced&amp;amp;product=Security" target="_blank"&gt;sk100194: TCPdump shows wrong IP addresses for NATed traffic when SecureXL is enabled&lt;/A&gt; and &lt;A class="cp_link sc_ellipsis" style="max-width: 840px;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk100071&amp;amp;partition=Advanced&amp;amp;product=Security" target="_blank"&gt;sk100071: "tcpdump" output does not show the NATed IP address correctly&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2020 16:01:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/FW-MONITOR-shows-in-IN-out-Out-but-tcpdump-only-shows-incoming/m-p/80765#M16327</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-04-03T16:01:06Z</dc:date>
    </item>
    <item>
      <title>Re: FW MONITOR shows in IN, out Out, but tcpdump only shows incoming</title>
      <link>https://community.checkpoint.com/t5/General-Topics/FW-MONITOR-shows-in-IN-out-Out-but-tcpdump-only-shows-incoming/m-p/80767#M16328</link>
      <description>&lt;P&gt;We're using ClusterXL.&lt;/P&gt;&lt;P&gt;tcpdump results:&lt;/P&gt;&lt;P&gt;16:15:14.482890 eth1[in ]: 10.250.96.68.60206 &amp;gt; 10.129.3.192.445: S 3030511392:3030511392(0) win 8192 &amp;lt;mss 1334,nop,wscale 8,nop,nop,sackOK&amp;gt;&lt;BR /&gt;16:15:14.482956 eth1[in ]: 10.250.96.68.60204 &amp;gt; 10.129.3.192.445: S 3875771840:3875771840(0) win 8192 &amp;lt;mss 1334,nop,wscale 8,nop,nop,sackOK&amp;gt;&lt;BR /&gt;16:15:14.483055 eth1[in ]: 10.250.96.68.60202 &amp;gt; 10.129.3.192.445: S 1196378115:1196378115(0) win 8192 &amp;lt;mss 1334,nop,wscale 8,nop,nop,sackOK&amp;gt;&lt;BR /&gt;16:15:14.483062 eth1[in ]: 10.250.96.68.60207 &amp;gt; 10.129.3.192.445: S 2233876772:2233876772(0) win 8192 &amp;lt;mss 1334,nop,wscale 8,nop,nop,sackOK&amp;gt;&lt;BR /&gt;16:15:14.483141 eth1[in ]: 10.250.96.68.60200 &amp;gt; 10.129.3.192.445: S 1879131292:1879131292(0) win 8192 &amp;lt;mss 1334,nop,wscale 8,nop,nop,sackOK&amp;gt;&lt;BR /&gt;16:15:14.483166 eth1[in ]: 10.250.96.68.60209 &amp;gt; 10.129.3.192.445: S 2463373099:2463373099(0) win 8192 &amp;lt;mss 1334,nop,wscale 8,nop,nop,sackOK&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note: we're testing multiple hosts hence the 3.192 (not 3.191)&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2020 16:39:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/FW-MONITOR-shows-in-IN-out-Out-but-tcpdump-only-shows-incoming/m-p/80767#M16328</guid>
      <dc:creator>J_Saun</dc:creator>
      <dc:date>2020-04-03T16:39:04Z</dc:date>
    </item>
    <item>
      <title>Re: FW MONITOR shows in IN, out Out, but tcpdump only shows incoming</title>
      <link>https://community.checkpoint.com/t5/General-Topics/FW-MONITOR-shows-in-IN-out-Out-but-tcpdump-only-shows-incoming/m-p/80820#M16340</link>
      <description>&lt;P&gt;The traffic is actually leaving the firewall on the egress interface and connectivity is working correct?&amp;nbsp; Not sure why &lt;STRONG&gt;tcpdump&lt;/STRONG&gt; can't see the traffic leaving on the egress interface.&amp;nbsp; I guess next step is to see if it is a problem with your filter or the libpcap portion.&amp;nbsp; Try this:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;tcpdump -eQ out -i (egress interface for your test traffic) -nnnl &lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Does &lt;STRONG&gt;tcpdump&lt;/STRONG&gt; see anything at all leaving that interface outbound?&amp;nbsp; If it does then it is some kind of problem with your filter, if not it has got to be some kind of bug in libpcap.&amp;nbsp; Next:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;tcpdump -e -i (egress interface for your test traffic) -nnnl -w capfile.out&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;(Run for a minute or so while initiating test traffic then CNTRL-C)&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;tcpdump -nnnl -r capfile.out&lt;/STRONG&gt; (Make sure you have output)&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;tcpdump -nnnl -r capfile.out host 10.250.96.68 and host 10.129.3.191 and port 445&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;If the former command shows output, but the latter does not you have a problem with your filter.&lt;/P&gt;</description>
      <pubDate>Sat, 04 Apr 2020 12:53:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/FW-MONITOR-shows-in-IN-out-Out-but-tcpdump-only-shows-incoming/m-p/80820#M16340</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-04-04T12:53:37Z</dc:date>
    </item>
    <item>
      <title>Re: FW MONITOR shows in IN, out Out, but tcpdump only shows incoming</title>
      <link>https://community.checkpoint.com/t5/General-Topics/FW-MONITOR-shows-in-IN-out-Out-but-tcpdump-only-shows-incoming/m-p/80821#M16341</link>
      <description>&lt;P&gt;Please run same tcpdump on a different cluster member.&lt;/P&gt;</description>
      <pubDate>Sat, 04 Apr 2020 13:58:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/FW-MONITOR-shows-in-IN-out-Out-but-tcpdump-only-shows-incoming/m-p/80821#M16341</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2020-04-04T13:58:27Z</dc:date>
    </item>
    <item>
      <title>Re: FW MONITOR shows in IN, out Out, but tcpdump only shows incoming</title>
      <link>https://community.checkpoint.com/t5/General-Topics/FW-MONITOR-shows-in-IN-out-Out-but-tcpdump-only-shows-incoming/m-p/81200#M16404</link>
      <description>&lt;P&gt;Figured it out. The gateway for the destination was a VIP (router pair). However it was not configured, only the single router nodes were. Changed my route to point to one of the routers and tcpdump started showing forward and return traffic. Is that a feature? I would at least expect to see the traffic leaving via tcpdump even tho the destination gateway wasn't available.&lt;/P&gt;&lt;P&gt;Thanks for all the help&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2020 20:32:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/FW-MONITOR-shows-in-IN-out-Out-but-tcpdump-only-shows-incoming/m-p/81200#M16404</guid>
      <dc:creator>J_Saun</dc:creator>
      <dc:date>2020-04-07T20:32:55Z</dc:date>
    </item>
    <item>
      <title>Re: FW MONITOR shows in IN, out Out, but tcpdump only shows incoming</title>
      <link>https://community.checkpoint.com/t5/General-Topics/FW-MONITOR-shows-in-IN-out-Out-but-tcpdump-only-shows-incoming/m-p/81205#M16407</link>
      <description>&lt;P&gt;Thanks for the followup.&amp;nbsp; The traffic won't show up in tcpdump if a MAC address cannot be learned for the nonexistent gateway via ARP.&amp;nbsp; There is no way to create a frame without a destination hardware address, and therefore the packet will never be transmitted.&amp;nbsp; fw monitor showed it leaving via O out of INSPECT but it never went anywhere, tcpdump is plumbed in much lower in the networking stack than O.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2020 21:01:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/FW-MONITOR-shows-in-IN-out-Out-but-tcpdump-only-shows-incoming/m-p/81205#M16407</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-04-07T21:01:12Z</dc:date>
    </item>
    <item>
      <title>Re: FW MONITOR shows in IN, out Out, but tcpdump only shows incoming</title>
      <link>https://community.checkpoint.com/t5/General-Topics/FW-MONITOR-shows-in-IN-out-Out-but-tcpdump-only-shows-incoming/m-p/81206#M16408</link>
      <description>&lt;P&gt;Excellent. Thank you for the info. Much appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2020 21:05:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/FW-MONITOR-shows-in-IN-out-Out-but-tcpdump-only-shows-incoming/m-p/81206#M16408</guid>
      <dc:creator>J_Saun</dc:creator>
      <dc:date>2020-04-07T21:05:53Z</dc:date>
    </item>
  </channel>
</rss>

