<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: [tool] - https://tcpdump101.com in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22685#M4447</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Happy New Year everyone! I know we're a few weeks in but it's a New Year in this thread. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt; Since this board has been the most supportive and interactive I figured I'd give everyone an update on how things have been progressing with the site/tool... The answer is extremely well. I've put a lot of work into the dev site (&lt;A href="http://dev.tcpdump101.com"&gt;http://dev.tcpdump101.com&lt;/A&gt;) and was hoping that, if you have a few minutes (I know, I know...) you could check it out and provide some feedback (both positive and negative) on what you think. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's where it's at now for those who just want to read about it and may not have time to play around:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The dev site now has all the same modules as production (still missing the Cisco [Can I write that here? Should I put C***o instead? &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;] but I recently got my hands on a 5506-X so that's next on the list).&lt;/LI&gt;&lt;LI&gt;All the filters have been changed from the drop-down (select) list and are now styled buttons sorted by OSI layer.&lt;/LI&gt;&lt;LI&gt;The filters list can also be resized vertically if you want to see them all in one box. Just click-n-drag the handle on the bottom-right of the filters list box.&lt;/LI&gt;&lt;LI&gt;You can &lt;STRONG&gt;fully&lt;/STRONG&gt; add filters &lt;STRONG&gt;above&lt;/STRONG&gt; or &lt;STRONG&gt;below&lt;/STRONG&gt; existing filters regardless of how many filters you have. ::fist pump::&lt;/LI&gt;&lt;LI&gt;The "not" option on the filters just adds an icon on the top-right of the filter instead of changing the whole background colour of the filter.&lt;/LI&gt;&lt;LI&gt;The "cppcap" module works properly without the operand bug currently present in prod.&lt;/LI&gt;&lt;LI&gt;An RSS feed is now available (&lt;A href="http://dev.tcpdump101.com/rss/rss.xml"&gt;http://dev.tcpdump101.com/rss/rss.xml&lt;/A&gt;) which will be used for site updates as well as project-related notifications (see next item). There is an icon in the menu bar in the "social" area to get the link and put it in your RSS reader.&lt;/LI&gt;&lt;LI&gt;There is a link to my (so far empty) Youtube channel in the "social" area as well. I'm going to have PCap videos and some livestream events so if those interest you, stay tuned.&lt;/LI&gt;&lt;LI&gt;I've added a "CLI" area which will be used to create network and OS commands across all devices in a similar fashion. Right now, it has a placeholder to use the "ip" command to view interfaces but, as time goes on, will have things like configuring OSPF, running an nmap scan or clustering devices - So long as it can be done on the CLI of the device, I'll try to add things in over time. This will be worked on more after the Cisco PCap module is done.&lt;/LI&gt;&lt;LI&gt;There's contextual help on pretty much everything. &lt;EM&gt;Question marks... Question marks as far as the eye can see.&lt;/EM&gt;&lt;/LI&gt;&lt;LI&gt;I've added &amp;lt;label&amp;gt; tags to radio buttons so you can just click on the words instead of having to click on the button directly.&lt;/LI&gt;&lt;LI&gt;I've done away with some of the checkboxes. For instance, if you want to change the snaplength of the PCap, just type the number in. No need to check a box and then type a number in.&lt;/LI&gt;&lt;LI&gt;There's a handy "back to top" button that shows up if you scroll down.&lt;/LI&gt;&lt;LI&gt;Multi-line command (such as "&lt;EM&gt;fw ctl debug&lt;/EM&gt;" commands) will now copy the entire multi-line command instead of just highlighting it.&lt;/LI&gt;&lt;LI&gt;The back-end JavaScript has been reduced by about 40% while still having the same (if not a bit more) functionality than the original which is nice.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think that about covers it for the latest update (16.1.19) on the dev site. As I mentioned at the start of this, if you can find the time to tinker around with it and let me know your thoughts, I'd appreciate it a lot! If not, that's fine too - I'm pretty easy going. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sean (Gr@ve_Rose)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 16 Jan 2019 19:17:09 GMT</pubDate>
    <dc:creator>Grave_Rose</dc:creator>
    <dc:date>2019-01-16T19:17:09Z</dc:date>
    <item>
      <title>[tool] - https://tcpdump101.com</title>
      <link>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22604#M4366</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hopefully self-promotion isn't frowned upon but I was suggested to post here. Over the past few years, I've been working on a tool to help people capture packets by allowing users to have a web-based interface to create the commands for them. Today, I've launched the latest version into production which supports "fw monitor" as well as "fw ctl debug" commands. It's located here: &lt;A href="https://tcpdump101.com"&gt;https://tcpdump101.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm posting this in the hopes that people will find it useful (it supports tcpdump as well as other vendors) and maybe get some feedback from the community. If you use it, let me know if you find it handy, what you'd like to see improved and if you have any other suggestions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sean (Gr@ve_Rose)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Overview of Check Point module in tcpdump101" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/69760_CheckMates2.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Aug 2018 15:17:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22604#M4366</guid>
      <dc:creator>Grave_Rose</dc:creator>
      <dc:date>2018-08-24T15:17:05Z</dc:date>
    </item>
    <item>
      <title>Re: [tool] - https://tcpdump101.com</title>
      <link>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22605#M4367</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A _jive_internal="true" data-userid="61990" data-username="seanfa178d3c-f9ff-30cf-9362-c6ffc0bec1e4" href="https://community.checkpoint.com/people/seanfa178d3c-f9ff-30cf-9362-c6ffc0bec1e4"&gt;Sean,&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I like to program web apps myself. It must have been a lot of work. I like this tool.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Great work!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/migrated-users/55229"&gt;Heiko &lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Aug 2018 17:44:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22605#M4367</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2018-08-24T17:44:12Z</dc:date>
    </item>
    <item>
      <title>Re: [tool] - https://tcpdump101.com</title>
      <link>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22606#M4368</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks &lt;A href="https://community.checkpoint.com/migrated-users/54411"&gt;Heiko Ankenbrand&lt;/A&gt;‌. It took almost three years to get to this point and I'm looking forward to improving it more. I'm always open to suggestions from people to make it better as well so if you use it (or know people who would use it) and have ideas, please let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sean&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Aug 2018 18:28:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22606#M4368</guid>
      <dc:creator>Grave_Rose</dc:creator>
      <dc:date>2018-08-24T18:28:14Z</dc:date>
    </item>
    <item>
      <title>Re: [tool] - https://tcpdump101.com</title>
      <link>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22607#M4369</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/69785_ChrisFarley.gif" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Aug 2018 19:34:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22607#M4369</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2018-08-24T19:34:35Z</dc:date>
    </item>
    <item>
      <title>Re: [tool] - https://tcpdump101.com</title>
      <link>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22608#M4370</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/69786_high-five.gif" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Aug 2018 19:42:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22608#M4370</guid>
      <dc:creator>Grave_Rose</dc:creator>
      <dc:date>2018-08-24T19:42:27Z</dc:date>
    </item>
    <item>
      <title>Re: [tool] - https://tcpdump101.com</title>
      <link>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22609#M4371</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I saw someone else mention the tool in the &lt;A href="https://community.checkpoint.com/group/1125"&gt;CheckMates en Français&lt;/A&gt;‌ section, glad you posted about it in English. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 25 Aug 2018 00:31:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22609#M4371</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-08-25T00:31:44Z</dc:date>
    </item>
    <item>
      <title>Re: [tool] - https://tcpdump101.com</title>
      <link>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22610#M4372</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have to say that even as a Canadian, my French still isn't on par to where it should be. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt; In all seriousness, though, I'm glad it's helping people out. I've been fortunate to have learned from good people throughout my years and now it's my turn to give something back. I'm looking forward to adding more features which (hopefully) won't take another three years for a major release. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 25 Aug 2018 01:42:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22610#M4372</guid>
      <dc:creator>Grave_Rose</dc:creator>
      <dc:date>2018-08-25T01:42:32Z</dc:date>
    </item>
    <item>
      <title>Re: [tool] - https://tcpdump101.com</title>
      <link>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22611#M4373</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maybe you can add options into fw monitor to specify source, destionation, port ? And also opposites - like not source, not destination,...&lt;/P&gt;&lt;P&gt;The same for tcpdump &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;There are tons of parameters available in both cases which can be added into next release &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 25 Aug 2018 08:28:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22611#M4373</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2018-08-25T08:28:38Z</dc:date>
    </item>
    <item>
      <title>Re: [tool] - https://tcpdump101.com</title>
      <link>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22612#M4374</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;They're already there - That's the point of the tool. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt; On any module (tcpdump, fw monitor, fw ctl debug), use the right-hand side to create your filters. Use the drop-down box that is under "Filter Option" to get started and use "Add New Filter Option" to create a new one. Once the filters are created, your full PCap/Debug command appears at the top. You can then use the "Copy Command" or "Highlight Command" to get your command to paste into a terminal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/69790_CheckMates3.png" /&gt;&lt;IMG alt="" class="image-2 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/69791_CheckMates4.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 25 Aug 2018 11:41:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22612#M4374</guid>
      <dc:creator>Grave_Rose</dc:creator>
      <dc:date>2018-08-25T11:41:36Z</dc:date>
    </item>
    <item>
      <title>Re: [tool] - https://tcpdump101.com</title>
      <link>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22613#M4375</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, wasnt aware about it as I am using mobile to check it &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;But anyway, in case your filter is setup and you realized you did mistake in IP, it will add new condition instead of correct the wrong one:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/69787_Screenshot_20180825-152403.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 25 Aug 2018 13:26:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22613#M4375</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2018-08-25T13:26:27Z</dc:date>
    </item>
    <item>
      <title>Re: [tool] - https://tcpdump101.com</title>
      <link>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22614#M4376</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good catch! Thanks for letting me know. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&amp;nbsp;I'll try to fix this bug before Monday (hopefully) and will update again.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 25 Aug 2018 13:46:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22614#M4376</guid>
      <dc:creator>Grave_Rose</dc:creator>
      <dc:date>2018-08-25T13:46:46Z</dc:date>
    </item>
    <item>
      <title>Re: [tool] - https://tcpdump101.com</title>
      <link>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22615#M4377</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sean,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for the excellent tool.&lt;/P&gt;&lt;P&gt;I believe there are two more options that should be included for the Chain Position Options: "e" and "E"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vladimir&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 25 Aug 2018 20:06:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22615#M4377</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-08-25T20:06:06Z</dc:date>
    </item>
    <item>
      <title>Re: [tool] - https://tcpdump101.com</title>
      <link>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22616#M4378</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;But these 2 Chains are only in R80, so maybe just simple chexbox to tick if user will run fw monitor on R80 would be enough.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 25 Aug 2018 22:20:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22616#M4378</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2018-08-25T22:20:23Z</dc:date>
    </item>
    <item>
      <title>Re: [tool] - https://tcpdump101.com</title>
      <link>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22617#M4379</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good option.&lt;/P&gt;&lt;P&gt;May be include the "fwaccel off; " at the beginning of the string as another?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 25 Aug 2018 23:20:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22617#M4379</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-08-25T23:20:33Z</dc:date>
    </item>
    <item>
      <title>Re: [tool] - https://tcpdump101.com</title>
      <link>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22618#M4380</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="color: #333333; border: 0px;"&gt;Right, but in general I don't recommend doing this on a production firewall the performance impact can be noticeable. &amp;nbsp;I would always recommend disabling SecureXL selectively for the IP addresses you want to capture ahead of time, then you can use &lt;SPAN style="border: 0px; font-weight: bold;"&gt;&lt;STRONG&gt;tcpdump&lt;/STRONG&gt;&lt;/SPAN&gt; and/or &lt;SPAN style="border: 0px; font-weight: bold;"&gt;&lt;STRONG&gt;fw monitor&lt;/STRONG&gt;&lt;/SPAN&gt; to see all inbound and outbound traffic:&lt;/P&gt;&lt;P style="color: #333333; border: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="color: #333333; border: 0px;"&gt;&lt;A class="" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104468&amp;amp;partition=Advanced&amp;amp;product=SecureXL%22" rel="nofollow" style="color: #6d6e71; border: 0px; font-weight: inherit; padding: 0px calc(12px + 0.35ex) 0px 0px;"&gt;sk104468: How to &lt;SPAN style="border: 0px; font-weight: bold;"&gt;&lt;STRONG&gt;disable&lt;/STRONG&gt;&lt;/SPAN&gt; &lt;SPAN style="border: 0px; font-weight: bold;"&gt;&lt;STRONG&gt;SecureXL&lt;/STRONG&gt;&lt;/SPAN&gt; for specific IP addresses&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #333333; border: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #333333; border: 0px;"&gt;Regards&lt;/P&gt;&lt;P style="color: #333333; border: 0px;"&gt;Heiko&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 26 Aug 2018 06:16:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22618#M4380</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2018-08-26T06:16:26Z</dc:date>
    </item>
    <item>
      <title>Re: [tool] - https://tcpdump101.com</title>
      <link>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22619#M4381</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you Heiko!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was not aware of this sk and, in my experience, even TAC consistently resorts to using blanket "fwaccel off" during troubleshooting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone chime in if there is a way to achieve the same selective acceleration manipulation without policy installation in R80.++?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 26 Aug 2018 13:45:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22619#M4381</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-08-26T13:45:26Z</dc:date>
    </item>
    <item>
      <title>Re: [tool] - https://tcpdump101.com</title>
      <link>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22620#M4382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey folks... I've patched the bug and the "fw monitor" portion now edits the proper filter instead of always editing the last one. Thanks to &lt;A href="https://community.checkpoint.com/migrated-users/42431"&gt;Jozko Mrkvicka&lt;/A&gt;‌ for reporting this to me. I owe you one Internet beer. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Aug 2018 00:13:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22620#M4382</guid>
      <dc:creator>Grave_Rose</dc:creator>
      <dc:date>2018-08-27T00:13:32Z</dc:date>
    </item>
    <item>
      <title>Re: [tool] - https://tcpdump101.com</title>
      <link>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22621#M4383</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the kind words, &lt;A href="https://community.checkpoint.com/migrated-users/47844"&gt;Vladimir Yakovlev&lt;/A&gt;‌. I like your idea of adding in the "eE" inspection options as well as putting some sort of switch for versioning that the users can select. Adding the "eE" should be pretty quick and, for now, I think I'll put a note on them to let people know that these are R80 switches only. In a future major release, I'll probably have some sort of R80.xx/R7X.xx switch that will hide and display different options.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With regards to putting in the command for disabling SecureXL at the start, I've added a note in the module that people can turn it off if they want to. I don't want to have "fwaccel off" at the start of the command in case it causes issues for people. By having the note there, it's an active choice the user makes themselves - Not me making the choice for them. As goofy&amp;nbsp; and paranoid as this may sound, it makes me a little less responsible if they bring down their firewall by disabling acceleration. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt; I do have a few warnings (including on the splash page, the module itself and the Help section) about people being responsible for their own actions but in todays day and age, you can never be too careful. &lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/wink.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again for the ideas! Keep your eyes open since the "eE" chains will be in soon-ish.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sean (Gr@ve_Rose)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Aug 2018 00:25:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22621#M4383</guid>
      <dc:creator>Grave_Rose</dc:creator>
      <dc:date>2018-08-27T00:25:47Z</dc:date>
    </item>
    <item>
      <title>Re: [tool] - https://tcpdump101.com</title>
      <link>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22622#M4384</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Totally dig the caution in choosing what to include for auto execution.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Aug 2018 01:48:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22622#M4384</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-08-27T01:48:50Z</dc:date>
    </item>
    <item>
      <title>Re: [tool] - https://tcpdump101.com</title>
      <link>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22623#M4385</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No plan to add support for Juniper and Palo Alto ? I am not sure if these vendors has some specific in-build tools for traffic capturing like Check Point (fw monitor).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Aug 2018 06:19:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/tool-https-tcpdump101-com/m-p/22623#M4385</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2018-08-27T06:19:54Z</dc:date>
    </item>
  </channel>
</rss>

