<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: fwmonitor on decrypted traffic in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/fwmonitor-on-decrypted-traffic/m-p/13681#M2292</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The use case for the feature is sending the unencrypted traffic to another system for analysis or archive.&lt;/P&gt;&lt;P&gt;And sure, you could probably tcpdump it also.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 07 Dec 2018 14:10:05 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2018-12-07T14:10:05Z</dc:date>
    <item>
      <title>fwmonitor on decrypted traffic</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fwmonitor-on-decrypted-traffic/m-p/13678#M2289</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;CheckMates,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In order to troubleshoot, is there a way to fwmonitor traffic decrypted by HTTPS Inspection?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am aware of the fact that it is only decrypted in the box: it will enter and leave the box encrypted. I am aware of the fact that it is bordering (malicious) MitM functionality, but it is sometimes essential to analysis.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Dec 2018 12:54:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fwmonitor-on-decrypted-traffic/m-p/13678#M2289</guid>
      <dc:creator>Marcel_Wildenbe</dc:creator>
      <dc:date>2018-12-06T12:54:34Z</dc:date>
    </item>
    <item>
      <title>Re: fwmonitor on decrypted traffic</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fwmonitor-on-decrypted-traffic/m-p/13679#M2290</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One of the features we added to R80.20 is "Mirror Decrypt and Forward."&lt;/P&gt;&lt;P&gt;This would allow you to look at decrypted traffic, but it would be sent out a specific interface.&lt;/P&gt;&lt;P&gt;So it is possible to see the traffic, but I don't think you can with fw monitor.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Dec 2018 00:13:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fwmonitor-on-decrypted-traffic/m-p/13679#M2290</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-12-07T00:13:57Z</dc:date>
    </item>
    <item>
      <title>Re: fwmonitor on decrypted traffic</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fwmonitor-on-decrypted-traffic/m-p/13680#M2291</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, sounds like a useful option. Once you can send it to an interface, you can tcpdump it, I guess.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Dec 2018 09:14:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fwmonitor-on-decrypted-traffic/m-p/13680#M2291</guid>
      <dc:creator>Marcel_Wildenbe</dc:creator>
      <dc:date>2018-12-07T09:14:40Z</dc:date>
    </item>
    <item>
      <title>Re: fwmonitor on decrypted traffic</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fwmonitor-on-decrypted-traffic/m-p/13681#M2292</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The use case for the feature is sending the unencrypted traffic to another system for analysis or archive.&lt;/P&gt;&lt;P&gt;And sure, you could probably tcpdump it also.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Dec 2018 14:10:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fwmonitor-on-decrypted-traffic/m-p/13681#M2292</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-12-07T14:10:05Z</dc:date>
    </item>
  </channel>
</rss>

