<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R80.x Performance Tuning and Debug Tips – TCPDUMP vs. CPPCAP in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-and-Debug-Tips-TCPDUMP-vs-CPPCAP/m-p/41542#M8682</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Will this integated in the next jumbo hotfix for R80.10, R77.30?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 08 Dec 2018 11:03:39 GMT</pubDate>
    <dc:creator>Maik_H_</dc:creator>
    <dc:date>2018-12-08T11:03:39Z</dc:date>
    <item>
      <title>R80.x Performance Tuning and Debug Tips – TCPDUMP vs. CPPCAP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-and-Debug-Tips-TCPDUMP-vs-CPPCAP/m-p/41541#M8681</link>
      <description>&lt;TABLE style="border: 1px solid #c6c6c6; border-collapse: separate; border-radius: 5px; background-color: #e15180; padding: 6px; text-indent: 10px;" width="100%"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH align="left"&gt;&lt;FONT size="4" color="#ffffff"&gt;What is CPPCAP?&lt;/FONT&gt;&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;IMG class="image-9 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/76120_pastedImage_10.png" border="0" /&gt;&lt;BR /&gt;TCPDUMP is a Linux tool which at times is not suitable for use with Gaia. Running TCPDUMP causes a significant increase in CPU usage and as a result impact the performance of the device. Even while filtering by specific interface or port still high CPU occurs. Check Point created a tool which works better with Gaia OS.&lt;/P&gt;
&lt;TABLE style="border: 1px solid #c6c6c6; border-collapse: separate; border-radius: 5px; background-color: #e15180; padding: 6px; text-indent: 10px;" width="100%"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH align="left"&gt;&lt;FONT size="4" color="#ffffff"&gt;Chapter&lt;/FONT&gt;&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;STRONG&gt;More interesting articles:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/R80-x-Architecture-and-Performance-Tuning-Link-Collection/m-p/47883#M9336" target="_blank" rel="noopener" data-objecttype="102"&gt;- R80.x Architecture and Performance Tuning - Link Collection&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://cp.ankenbrand24.de" target="_blank" rel="noopener nofollow noopener noreferrer noopener noreferrer noopener noreferrer"&gt;- Article list (Heiko Ankenbrand)&lt;/A&gt;&lt;/P&gt;
&lt;TABLE style="border: 1px solid #c6c6c6; border-collapse: separate; border-radius: 5px; background-color: #e15180; padding: 6px; text-indent: 10px;" width="100%"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH align="left"&gt;&lt;FONT size="4" color="#ffffff"&gt;CPPCAP&lt;/FONT&gt;&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;/TABLE&gt;
&lt;P style="min-height: 8pt; padding: 0px;"&gt;&lt;SPAN style="color: #33cccc; font-size: 22px;"&gt;&lt;STRONG&gt;Tip 1&lt;/STRONG&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"CPPCAP" is a traffic capture tool which provides the most relevant outputs and is similar to Tcpdump. The tool is adjusted to Gaia operating system yet requires installation of an applicable RPM.&lt;/P&gt;
&lt;P&gt;The good news!&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;SecureXL can be enabled&lt;/STRONG&gt;&lt;/SPAN&gt; or disabled to capture with CPPCAP.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;You can download this tool for R77.30, R80.10 and R80.20. Get more details here:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk141412" target="_blank" rel="noopener"&gt;sk141412&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Instal and use:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Download the RPM package (&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk141412" target="_blank" rel="noopener"&gt;sk141412&lt;/A&gt;) and transfer the RPM package with winscp to appliance or open server.&lt;/LI&gt;
&lt;LI&gt;Install the RPM using the following command:&lt;BR /&gt;&lt;EM&gt;#&lt;/EM&gt; &lt;STRONG&gt;rpm -ivh --force --nodeps&lt;/STRONG&gt; &lt;EM&gt;&amp;lt;RPM_FILE&amp;gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;#&lt;/EM&gt; &lt;STRONG&gt;/etc/init.d/start_cppcap start&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Start cppcap to sniffing packages (for example on interface eth0 with parameter "N"):&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;STRONG&gt;&lt;BR /&gt;On internal Interface (example "ping 8.8.8.8" from client IP 10.1.2.1 to server IP 8.8.8.8)&lt;/STRONG&gt;:&lt;EM&gt;&lt;BR /&gt;#&lt;/EM&gt; &lt;STRONG&gt;&lt;SPAN style="color: #000000;"&gt;cppcap -i eth0 -N&lt;/SPAN&gt;&amp;nbsp; |grep ICMP&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;IMG class="jive-image image-10" src="https://community.checkpoint.com/legacyfs/online/checkpoint/76123_pastedImage_1.png" border="0" /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;On external Interface&lt;/STRONG&gt;&lt;EM&gt;:&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; # &lt;STRONG&gt;&lt;SPAN style="color: #000000;"&gt;cppcap -i eth2 -N&lt;/SPAN&gt;&amp;nbsp; |grep ICMP&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG class="image-11 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/76128_pastedImage_11.png" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Notes:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;- To have all verbos information add "-DNT" to the syntax to filter out specific interface or VS by using capital letters.&lt;BR /&gt;- It will provide outputs on ARP IPV4/IPV6, TCP and UDP traffic. Dynamic routing information will not show all verbose information.&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #33cccc; font-size: 22px;"&gt;&lt;STRONG&gt;Tip 2&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;In and out (see red marked point in picture):&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;In&lt;/STRONG&gt;&lt;/SPAN&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;- Is the incoming packet on the firewall on the inbound interface from the point of view of the first packet. It is simalary to fw monitor inspection point "&lt;STRONG&gt;i&lt;/STRONG&gt;" client to server packet.&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;Out&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt; - Is the outgoing packet on the firewall on the inbound interface from the point of view of the first packet. It is simalary to fw monitor inspection point "&lt;STRONG&gt;O&lt;/STRONG&gt;" server to client packet.&lt;/P&gt;
&lt;P&gt;On the outgoing interface&amp;nbsp;(see blue marked point in picture), the view is exactly inverse.&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #33cccc; font-size: 22px;"&gt;&lt;STRONG&gt;Tip 3&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style="text-align: left;"&gt;&lt;STRONG&gt;Flag&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD style="text-align: left;"&gt;&lt;STRONG&gt;Explanation&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&amp;nbsp;-vV VSID&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;lowercase to capture only from specific VSID, uppercase for all exec pt VSID&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&amp;nbsp;-iI DEVICE&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;lowercase to capture only from specific DEVICE, uppercase for all execpt DEVICE&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&amp;nbsp;-d DIR&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;capture specific direction ('in' for inbound, 'out' for outbound)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&amp;nbsp;-f "EXPR"&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;filter specific expression, for syntax, see pcap-filter(7)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&amp;nbsp;-o FILE&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;save capture to a FILE&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&amp;nbsp;-c NUM&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;capture up to NUM bytes of frame (default 96, '0' for any size)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&amp;nbsp;-p NUM&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;capture NUM frames before stopping&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&amp;nbsp;-b NUM&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;capture NUM bytes before stopping&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&amp;nbsp;-D&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;verbose datalink layer&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&amp;nbsp;-N&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;verbose network layer&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&amp;nbsp;-T&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;verbose transport layer&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&amp;nbsp;-Q&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;omit time from output&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 May 2020 17:16:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-and-Debug-Tips-TCPDUMP-vs-CPPCAP/m-p/41541#M8681</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2020-05-22T17:16:23Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning and Debug Tips – TCPDUMP vs. CPPCAP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-and-Debug-Tips-TCPDUMP-vs-CPPCAP/m-p/41542#M8682</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Will this integated in the next jumbo hotfix for R80.10, R77.30?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Dec 2018 11:03:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-and-Debug-Tips-TCPDUMP-vs-CPPCAP/m-p/41542#M8682</guid>
      <dc:creator>Maik_H_</dc:creator>
      <dc:date>2018-12-08T11:03:39Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning and Debug Tips – TCPDUMP vs. CPPCAP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-and-Debug-Tips-TCPDUMP-vs-CPPCAP/m-p/41543#M8683</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;great&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Dec 2018 15:35:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-and-Debug-Tips-TCPDUMP-vs-CPPCAP/m-p/41543#M8683</guid>
      <dc:creator>Patricia_OSulli</dc:creator>
      <dc:date>2018-12-08T15:35:18Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning and Debug Tips – TCPDUMP vs. CPPCAP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-and-Debug-Tips-TCPDUMP-vs-CPPCAP/m-p/41544#M8684</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;FYI: As said in&amp;nbsp;&lt;A _jive_internal="true" href="https://community.checkpoint.com/thread/10595-new-tool-cppcap"&gt;https://community.checkpoint.com/thread/10595-new-tool-cppcap&lt;/A&gt;&amp;nbsp;the CPPCAP tool cannot be run on 32 bit systems, only on 64 bit systems.&lt;/P&gt;&lt;P&gt;Currently this is not written in the&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk141412"&gt;sk141412&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Update 11/12: SK team modified the SK, under solution it is now stated: "&lt;STRONG style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;Note:&lt;/STRONG&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;The tool is supported only on 64 bit OS."&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Dec 2018 12:38:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-and-Debug-Tips-TCPDUMP-vs-CPPCAP/m-p/41544#M8684</guid>
      <dc:creator>Sean_Van_Loon</dc:creator>
      <dc:date>2018-12-10T12:38:54Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning and Debug Tips – TCPDUMP vs. CPPCAP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-and-Debug-Tips-TCPDUMP-vs-CPPCAP/m-p/41545#M8685</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;GREAT JOB!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 02 Feb 2019 21:08:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-and-Debug-Tips-TCPDUMP-vs-CPPCAP/m-p/41545#M8685</guid>
      <dc:creator>Nabeel_Saeed</dc:creator>
      <dc:date>2019-02-02T21:08:03Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning and Debug Tips – TCPDUMP vs. CPPCAP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-and-Debug-Tips-TCPDUMP-vs-CPPCAP/m-p/47537#M9270</link>
      <description>&lt;P&gt;Interresting information.&lt;/P&gt;&lt;P&gt;Is it also with fw monitor?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 21:35:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-and-Debug-Tips-TCPDUMP-vs-CPPCAP/m-p/47537#M9270</guid>
      <dc:creator>Lee_SoonFat</dc:creator>
      <dc:date>2019-03-18T21:35:13Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning and Debug Tips – TCPDUMP vs. CPPCAP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-and-Debug-Tips-TCPDUMP-vs-CPPCAP/m-p/57960#M11698</link>
      <description>&lt;P&gt;Great post!&lt;/P&gt;&lt;P&gt;After installing the RPM, trying to start it causes an error. why is that?&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;# rpm -ivh --force --nodeps /home/admin/Check_point_R80.20_cp_pcap_sk141412.rpm&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Preparing... ########################################### [100%]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;1:cp_pcap ########################################### [100%]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;# /etc/init.d/start_cppcap start&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;insmod: error inserting '/lib/modules/cppcap/cppcap_kern_64.o': -1 Unknown symbol in module&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Failed to find major number for cppcap&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2019 20:17:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-and-Debug-Tips-TCPDUMP-vs-CPPCAP/m-p/57960#M11698</guid>
      <dc:creator>Yonathan_Grunew</dc:creator>
      <dc:date>2019-07-10T20:17:21Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning and Debug Tips – TCPDUMP vs. CPPCAP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-and-Debug-Tips-TCPDUMP-vs-CPPCAP/m-p/81649#M16506</link>
      <description>&lt;P&gt;I faces the same issue and I did this.....&lt;/P&gt;&lt;P&gt;Delete the file...&lt;/P&gt;&lt;P&gt;#rm -r&amp;nbsp;&lt;SPAN&gt;/lib/modules/cppcap/cppcap_kern_64.o&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Stop the service&lt;/P&gt;&lt;P&gt;#&lt;EM&gt;/etc/init.d/start_cppcap stop&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Uninstall it&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;#rpm -e cp_pcap&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;======&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Now just reinstall and start....&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;#rpm -ivh --force --nodeps Check_point_R80.30_3.10_cp_pcap_sk141412.rpm&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;#/etc/init.d/start_cppcap start&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;This time prompt cameout without any error.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Hope this helps.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;--Pritam&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Apr 2020 14:23:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-and-Debug-Tips-TCPDUMP-vs-CPPCAP/m-p/81649#M16506</guid>
      <dc:creator>pbanerjee</dc:creator>
      <dc:date>2020-04-12T14:23:28Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning and Debug Tips – TCPDUMP vs. CPPCAP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-and-Debug-Tips-TCPDUMP-vs-CPPCAP/m-p/92568#M18410</link>
      <description>&lt;P&gt;Hi Heiko, I'm the author of cppcap,&lt;/P&gt;
&lt;P&gt;You don't need to use grep icmp like "&lt;STRONG&gt;&lt;SPAN&gt;cppcap -i eth2 -N&lt;/SPAN&gt;&amp;nbsp; |grep ICMP",&amp;nbsp;&lt;/STRONG&gt;for That you can simply run 'cppcap -i eth2 -N -f "icmp"'&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2020 06:30:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-and-Debug-Tips-TCPDUMP-vs-CPPCAP/m-p/92568#M18410</guid>
      <dc:creator>Aviad_Hadarian</dc:creator>
      <dc:date>2020-07-28T06:30:31Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning and Debug Tips – TCPDUMP vs. CPPCAP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-and-Debug-Tips-TCPDUMP-vs-CPPCAP/m-p/98268#M19225</link>
      <description>&lt;P&gt;Does anyone know why I receive duplicated traffic?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Oct 2020 06:24:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-and-Debug-Tips-TCPDUMP-vs-CPPCAP/m-p/98268#M19225</guid>
      <dc:creator>SerB</dc:creator>
      <dc:date>2020-10-06T06:24:04Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning and Debug Tips – TCPDUMP vs. CPPCAP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-and-Debug-Tips-TCPDUMP-vs-CPPCAP/m-p/98269#M19226</link>
      <description>&lt;P&gt;what do you mean, duplicated?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Oct 2020 06:26:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-and-Debug-Tips-TCPDUMP-vs-CPPCAP/m-p/98269#M19226</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-10-06T06:26:09Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning and Debug Tips – TCPDUMP vs. CPPCAP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-and-Debug-Tips-TCPDUMP-vs-CPPCAP/m-p/98274#M19228</link>
      <description>&lt;P&gt;Like this one.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Oct 2020 07:18:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-and-Debug-Tips-TCPDUMP-vs-CPPCAP/m-p/98274#M19228</guid>
      <dc:creator>SerB</dc:creator>
      <dc:date>2020-10-06T07:18:41Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning and Debug Tips – TCPDUMP vs. CPPCAP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-and-Debug-Tips-TCPDUMP-vs-CPPCAP/m-p/100802#M19569</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/24548"&gt;@Aviad_Hadarian&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Really loving the new cppcap tool, and I'm trying to understand the major differences between cppcap and tcpdump.&amp;nbsp; I have a few questions and assumptions that I was hoping you could look at:&lt;/P&gt;
&lt;P&gt;1) cppcap is using libpcap for the actual grab of packets just like tcpdump correct?&lt;/P&gt;
&lt;P&gt;2) It seems like the main advantages of cppcap over tcpdump are the ability to capture only to/from a specific VS, the ability to see direction (In|Out) and interface name in the CLI output, and the ability to capture traffic on VTI's.&amp;nbsp;&amp;nbsp;&amp;nbsp; Are there other major advantages to cppcap over tcpdump?&lt;/P&gt;
&lt;P&gt;3) Can you be a bit more specific about how cppcap has less overhead than tcpdump, I assume it is mainly the ability to capture only from one VS (-Vv) on VSX systems?&amp;nbsp; Or erphaps that cppcap only captures the first 96 bytes of packets by default, instead of tcpdump and fw monitor that capture the whole thing?&lt;/P&gt;
&lt;P&gt;4) Check Point added the -eP option to tcpdump to overcome a limitation in the standard tcpdump that did not allow the interface name to be displayed in the CLI output.&amp;nbsp; Are there other "hidden" command line switches Check Point added to tcpdump beyond -eP that might be useful?&lt;/P&gt;
&lt;P&gt;5) Did anything change in cppcap for the R81 release?&amp;nbsp; I can see that capture output size can be limited in R81 (-w) and there are some file rotation settings, anything else new?&lt;/P&gt;
&lt;P&gt;6) Does cppcap have any kind of indication that the capture taken was not complete due to overload, similar to the "packets dropped by kernel" counter tcpdump shows at the end of a capture?&lt;/P&gt;
&lt;P&gt;7) Can cppcap capture VLAN tagged frames?&amp;nbsp; There are reports that it cannot here: &lt;A href="https://community.checkpoint.com/t5/General-Topics/Limitations-of-cppcap/td-p/33923" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/General-Topics/Limitations-of-cppcap/td-p/33923&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;8)&lt;/img&gt; Any chance cppcap might have trouble with NAT on the outbound side of the firewall as described here: &lt;A class="cp_link sc_ellipsis" style="max-width: 840px;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk100194&amp;amp;partition=Advanced&amp;amp;product=Security" target="_blank" rel="noopener"&gt;sk100194: &lt;STRONG&gt;TCPdump&lt;/STRONG&gt; shows wrong IP addresses for NATed traffic when SecureXL is enabled&lt;/A&gt; and &lt;A class="cp_link sc_ellipsis" style="max-width: 840px;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk100071&amp;amp;partition=Advanced&amp;amp;product=Security" target="_blank" rel="noopener"&gt;sk100071: "tcpdump" output does not show the NATed IP address correctly.&amp;nbsp;&lt;/A&gt;Does this problem not happen anymore for tcpdump?&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Sun, 01 Nov 2020 22:38:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-and-Debug-Tips-TCPDUMP-vs-CPPCAP/m-p/100802#M19569</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-11-01T22:38:12Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning and Debug Tips – TCPDUMP vs. CPPCAP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-and-Debug-Tips-TCPDUMP-vs-CPPCAP/m-p/100825#M19572</link>
      <description>&lt;P&gt;1. cppcap is using libpcap to match packets according to filter.&lt;/P&gt;&lt;P&gt;2. Isn't it enough :)?&lt;/P&gt;&lt;P&gt;3. tcpdump by default captures 96 bytes (same as cppcap), use '-c' to capture the different packet size, It just works differently from tcpdump on how packets are copied from the NIC into the tool itself.&lt;/P&gt;&lt;P&gt;4. I'm not familiar with those tcpdump addons&lt;/P&gt;&lt;P&gt;5. Indeed, Capture file size and rotation (including number of files) has been added, As well As details SCTP traffic.&lt;/P&gt;&lt;P&gt;6. No such indication.&lt;/P&gt;&lt;P&gt;7. I'm not familiar with such limitation.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Nov 2020 06:07:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-and-Debug-Tips-TCPDUMP-vs-CPPCAP/m-p/100825#M19572</guid>
      <dc:creator>Aviad_Hadarian</dc:creator>
      <dc:date>2020-11-02T06:07:52Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning and Debug Tips – TCPDUMP vs. CPPCAP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-and-Debug-Tips-TCPDUMP-vs-CPPCAP/m-p/100906#M19582</link>
      <description>&lt;P&gt;Hi Aviad thanks so much for the answers!&amp;nbsp; Just FYI the default snaplen for tcpdump 4.9.0 included with Gaia 3.10 appears to now be 262144 bytes, whereas the default snaplen for tcpdump 3.9.4 included with Gaia kernel 2.6.18 was 96 bytes, so the default behavior has changed under the new Gaia kernel.&lt;/P&gt;
&lt;P&gt;Also have you seen any issues with cppcap showing the correct post-NAT address similar to the issues tcpdump had with that as mentioned in sk100194 and sk100171 referenced above?&amp;nbsp; It seems like this was an issue with SecureXL fixed in R80.10+, but just curious if you have heard about anyone running into it again given the major SecureXL changes in R80.20+.&amp;nbsp; Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 02 Nov 2020 14:23:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-and-Debug-Tips-TCPDUMP-vs-CPPCAP/m-p/100906#M19582</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-11-02T14:23:52Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning and Debug Tips – TCPDUMP vs. CPPCAP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-and-Debug-Tips-TCPDUMP-vs-CPPCAP/m-p/100990#M19603</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;, &lt;SPAN&gt;sk100194 is relevant&amp;nbsp;to R7x versions (which are no longer supported) I did not encountered&amp;nbsp;such issues like you described on newer versions.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2020 09:39:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-and-Debug-Tips-TCPDUMP-vs-CPPCAP/m-p/100990#M19603</guid>
      <dc:creator>Aviad_Hadarian</dc:creator>
      <dc:date>2020-11-03T09:39:35Z</dc:date>
    </item>
  </channel>
</rss>

