<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic TCPDUMP and SecureXL in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/TCPDUMP-and-SecureXL/m-p/17039#M2858</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;this question is mainly for Tim, but input from others is also appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question: Do I need for tcpdump&amp;nbsp;to disable SecureXL (fwaccel off) in order to see all packets?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From Book Max Power R80 - chapter Millisecond in the Life of a Frame - stage 6 - My understanding is that its not needed. Am I right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 20 Apr 2018 07:21:58 GMT</pubDate>
    <dc:creator>Martin_Raska</dc:creator>
    <dc:date>2018-04-20T07:21:58Z</dc:date>
    <item>
      <title>TCPDUMP and SecureXL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/TCPDUMP-and-SecureXL/m-p/17039#M2858</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;this question is mainly for Tim, but input from others is also appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question: Do I need for tcpdump&amp;nbsp;to disable SecureXL (fwaccel off) in order to see all packets?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From Book Max Power R80 - chapter Millisecond in the Life of a Frame - stage 6 - My understanding is that its not needed. Am I right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Apr 2018 07:21:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/TCPDUMP-and-SecureXL/m-p/17039#M2858</guid>
      <dc:creator>Martin_Raska</dc:creator>
      <dc:date>2018-04-20T07:21:58Z</dc:date>
    </item>
    <item>
      <title>Re: TCPDUMP and SecureXL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/TCPDUMP-and-SecureXL/m-p/17040#M2859</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, you must enter "fwaccel off" to see all packages.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you enter fwaccel off, all packets go through the F2F path and are visible in the software. Thus tcpdump can display the packages correctly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Heiko&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Apr 2018 07:40:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/TCPDUMP-and-SecureXL/m-p/17040#M2859</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2018-04-20T07:40:17Z</dc:date>
    </item>
    <item>
      <title>Re: TCPDUMP and SecureXL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/TCPDUMP-and-SecureXL/m-p/17041#M2860</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Martin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It depends, but usually &lt;STRONG&gt;tcpdump&lt;/STRONG&gt; will show you all packets while SecureXL is enabled.&amp;nbsp; If I had to put a percentage probability on it I'd say 75%.&amp;nbsp; Factors that will determine the outcome are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Packets being handled in the Accelerated Path (SXL) vs. Medium (PXL)/Firewall (F2F) paths.&amp;nbsp; All traffic in the PXL/F2F paths will show up in &lt;STRONG&gt;tcpdump&lt;/STRONG&gt;, and considering the typical blades enabled on firewalls today most traffic tends to be handled in PXL.&amp;nbsp; Traffic to and from the gateway itself (i.e. SSH management, logging, policy loads) and the ICMP protocol are *never* accelerated by SecureXL, will always go F2F, and will appear in &lt;STRONG&gt;tcpdump&lt;/STRONG&gt; and &lt;STRONG&gt;fw monitor&lt;/STRONG&gt; 100%.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Traffic handled in SXL will almost always show up on the inbound interface, but may not appear at all on the outbound interface, or will appear but with some odd issues such as showing pre-NAT addresses like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk100194&amp;amp;partition=Advanced&amp;amp;product=Security" style="max-width: 840px;"&gt;sk100194: &lt;STRONG&gt;TCPdump&lt;/STRONG&gt; shows wrong IP addresses for NATed traffic when SecureXL is enabled&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk100071&amp;amp;partition=Advanced&amp;amp;product=Security" style="max-width: 840px;"&gt;sk100071: "&lt;STRONG&gt;tcpdump&lt;/STRONG&gt;" output does not show the NATed IP address correctly&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;This is due to how SecureXL works with accelerated packets on the outbound side, so if in your &lt;STRONG&gt;tcpdump&lt;/STRONG&gt; capture you see NAT oddities or can't seem to see all packets of a connection, don't beat your head against the wall unnecessarily trying to figure out why you can't see everything.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) If there is hardware acceleration (i.e. 23000 SAM/ADP card) involved, chances are good that &lt;STRONG&gt;tcpdump&lt;/STRONG&gt; will not see that traffic at all.&amp;nbsp; I'm curious to see how this will be handled (or not) on the upcoming Falcon accelerator card.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are experiencing problems seeing all traffic with &lt;STRONG&gt;tcpdump&lt;/STRONG&gt; (or have a limited time window to execute the &lt;STRONG&gt;tcpdump&lt;/STRONG&gt; and want to maximize the chances of getting a complete capture), it is vastly preferable to selectively disable SecureXL for the IP address(es) you want to capture as described here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104468&amp;amp;partition=Advanced&amp;amp;product=SecureXL%22" style="max-width: 840px;"&gt;sk104468: How to &lt;STRONG&gt;disable&lt;/STRONG&gt; &lt;STRONG&gt;SecureXL&lt;/STRONG&gt; for specific IP addresses&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As described in the SK, this is easily accomplished by editing the table.def file on the SMS and pushing policy to the gateway ahead of time.&amp;nbsp; Once this is done &lt;STRONG&gt;tcpdump&lt;/STRONG&gt; (and &lt;STRONG&gt;fw monitor&lt;/STRONG&gt;) will give you a complete capture as all traffic matching the defined exclusion will go F2F.&amp;nbsp; If the IP address(es) cannot be known ahead of time, it is also possible to define a SecureXL exclusion based on destination port number.&amp;nbsp; Generally it is not a good idea to completely disable SecureXL via &lt;STRONG&gt;fwaccel off &lt;/STRONG&gt;for this purpose, especially on a gateway with more than 8 cores as it may cause severe performance issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One last warning: if you are capturing packets that are fragmented, &lt;STRONG&gt;tcpdump&lt;/STRONG&gt; will show the individual fragments in their original state, while &lt;STRONG&gt;fw monitor&lt;/STRONG&gt; will only show the packets after they have been virtually reassembled for inspection and not how they actually appear on the wire.&amp;nbsp; Fragmented packets always go F2F unless a SAM/ADP card is present.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; Second Edition of my "Max Power" Firewall Book&lt;BR /&gt; Now Available at &lt;A href="http://www.maxpowerfirewalls.com" target="_blank"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Apr 2018 13:44:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/TCPDUMP-and-SecureXL/m-p/17041#M2860</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2018-04-20T13:44:40Z</dc:date>
    </item>
    <item>
      <title>Re: TCPDUMP and SecureXL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/TCPDUMP-and-SecureXL/m-p/17042#M2861</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you very much Tim&amp;nbsp;for the exhausting explanation.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Apr 2018 06:34:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/TCPDUMP-and-SecureXL/m-p/17042#M2861</guid>
      <dc:creator>Martin_Raska</dc:creator>
      <dc:date>2018-04-23T06:34:35Z</dc:date>
    </item>
    <item>
      <title>Re: TCPDUMP and SecureXL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/TCPDUMP-and-SecureXL/m-p/17043#M2862</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 15px; color: #000000;"&gt;SecureXL "&lt;STRONG&gt;fwaccel off&lt;/STRONG&gt;" does &lt;STRONG&gt;not&lt;/STRONG&gt; have to be &lt;STRONG&gt;disabled on R80.20&lt;/STRONG&gt; to run "fw monitor". This is good for performance, so "fw monitor" does not affect performance any more.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 15px; color: #000000;"&gt;More see here: &lt;A href="https://community.checkpoint.com/docs/DOC-3351"&gt;R80.x Performance Tuning and Debug Tips – fw monitor&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 15px; color: #000000;"&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 15px; color: #000000;"&gt;Heiko&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 18 Nov 2018 19:59:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/TCPDUMP-and-SecureXL/m-p/17043#M2862</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2018-11-18T19:59:36Z</dc:date>
    </item>
  </channel>
</rss>

