<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Wireshark modification for FW Monitor files in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Wireshark-modification-for-FW-Monitor-files/m-p/40955#M8653</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Gunther,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have written and&lt;A href="https://www.cpug.org/forums/showthread.php/8625-Wireshark-modification-for-FW-Monitor-files?highlight=wireshark"&gt; posted this text on CPUG&amp;nbsp;&lt;/A&gt;around august 2008, so if there is any referencing to be made it would be the other way around.&lt;/P&gt;&lt;P&gt;But to be frank, the way to view the packets as described above with colorization is not something they show in that SK.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 05 Feb 2019 16:16:44 GMT</pubDate>
    <dc:creator>Maarten_Sjouw</dc:creator>
    <dc:date>2019-02-05T16:16:44Z</dc:date>
    <item>
      <title>Wireshark modification for FW Monitor files</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Wireshark-modification-for-FW-Monitor-files/m-p/40953#M8651</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 15px;"&gt;This is the description of how Check Point used to modify Ethereal and called it CPEthereal, Ethereal has since moved on to become Wireshark.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;SPAN style="color: #333333; background-color: #fafafa;"&gt;To customize&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="" style="color: #417394; background: none repeat-x #ffeb90;"&gt;Wireshark&lt;/SPAN&gt;&lt;SPAN style="color: #333333; background-color: #fafafa;"&gt;&amp;nbsp;to properly read and interpret FW Monitor files this is the way to do it:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR style="color: #333333; background-color: #fafafa; font-size: 13px;" /&gt;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 15px;"&gt;From the Menu Edit choose Preferences, go to protocols Ethernet Select the ‘Attempt to interpret as Firewall-1 monitor file’ option&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 15px;"&gt;In the columns add a new column and name it Interface, from the possible fields choose “FW-1 monitor if/direction”&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 15px;"&gt;Now you will be able to properly read FW Monitor files but to make the result more readable you can also add some colorization rules by going to the View menu and choose the Coloring rules option&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 15px;"&gt;Add these new rules:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/78231_pastedImage_1.png" /&gt;&lt;BR style="color: #333333; background-color: #fafafa; font-size: 13px;" /&gt;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 15px;"&gt;After creation move these rules to the top.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The result (this was a very old file capture on a Nokia):&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/78232_pastedImage_2.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #333333; background-color: #fafafa; font-size: 13px;" /&gt;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 15px;"&gt;Regards, Maarten.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Feb 2019 06:27:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Wireshark-modification-for-FW-Monitor-files/m-p/40953#M8651</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-02-05T06:27:35Z</dc:date>
    </item>
    <item>
      <title>Re: Wireshark modification for FW Monitor files</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Wireshark-modification-for-FW-Monitor-files/m-p/40954#M8652</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is just an excerpt from&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk39510&amp;amp;partition=General&amp;amp;product=Other&amp;quot;"&gt;sk39510: How to configure &lt;STRONG&gt;Wireshark&lt;/STRONG&gt; to display Check Point FireWall chains in an FW Monitor packet&lt;/A&gt;&amp;nbsp;without referencing the sk and leaving out a lot of details. Also, you may need&amp;nbsp;&lt;A class="" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk43076&amp;amp;partition=General&amp;amp;product=Other&amp;quot;"&gt;sk43076: How to work with large traffic capture files&lt;/A&gt;&amp;nbsp;!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Feb 2019 12:07:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Wireshark-modification-for-FW-Monitor-files/m-p/40954#M8652</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-02-05T12:07:08Z</dc:date>
    </item>
    <item>
      <title>Re: Wireshark modification for FW Monitor files</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Wireshark-modification-for-FW-Monitor-files/m-p/40955#M8653</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Gunther,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have written and&lt;A href="https://www.cpug.org/forums/showthread.php/8625-Wireshark-modification-for-FW-Monitor-files?highlight=wireshark"&gt; posted this text on CPUG&amp;nbsp;&lt;/A&gt;around august 2008, so if there is any referencing to be made it would be the other way around.&lt;/P&gt;&lt;P&gt;But to be frank, the way to view the packets as described above with colorization is not something they show in that SK.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Feb 2019 16:16:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Wireshark-modification-for-FW-Monitor-files/m-p/40955#M8653</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-02-05T16:16:44Z</dc:date>
    </item>
    <item>
      <title>Re: Wireshark modification for FW Monitor files</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Wireshark-modification-for-FW-Monitor-files/m-p/165177#M27533</link>
      <description>&lt;P&gt;You can import a file with the following text&lt;/P&gt;&lt;P&gt;----------------------------------------------------&lt;/P&gt;&lt;P&gt;@FW1-o@fw1.direction contains "o"@[51657,63993,51400][0,0,0]&lt;BR /&gt;@FW1-O@fw1.direction contains "O"@[36494,65535,46260][0,0,0]&lt;BR /&gt;@FW1-oe@fw1.direction contains "oe"@[0,65535,0][21845,0,65535]&lt;BR /&gt;@FW1-OE@fw1.direction contains "OE"@[0,57825,0][21845,0,65535]&lt;BR /&gt;@FW1-i@fw1.direction contains "i"@[64764,55255,65535][0,0,0]&lt;BR /&gt;@FW1-I@fw1.direction contains "I"@[65535,43690,65535][0,0,0]&lt;BR /&gt;@FW1-id@fw1.direction contains "id"@[65535,21845,65535][21845,0,65535]&lt;BR /&gt;@FW1-ID@fw1.direction contains "ID"@[65535,0,65535][21845,0,65535]&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 14:04:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Wireshark-modification-for-FW-Monitor-files/m-p/165177#M27533</guid>
      <dc:creator>Thomas_Hesse</dc:creator>
      <dc:date>2022-12-14T14:04:09Z</dc:date>
    </item>
  </channel>
</rss>

