<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: tcpdump issues in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/tcpdump-issues/m-p/215410#M2603</link>
    <description>&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Maestro_AdminGuide/Content/Topics-Maestro-AG/Multi-Blade-Traffic-Capture.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Maestro_AdminGuide/Content/Topics-Maestro-AG/Multi-Blade-Traffic-Capture.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 28 May 2024 18:42:44 GMT</pubDate>
    <dc:creator>Lesley</dc:creator>
    <dc:date>2024-05-28T18:42:44Z</dc:date>
    <item>
      <title>tcpdump issues</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/tcpdump-issues/m-p/215336#M2593</link>
      <description>&lt;P&gt;HI:&lt;/P&gt;&lt;P&gt;We have two mho140 and two checkpoint6200 in mho topology, no traffic packet (mho140 or checkpoint6200) when I using tcpdump in expert mode.&lt;/P&gt;&lt;P&gt;MHO topology is support for tcpdump in expert mode?&lt;/P&gt;&lt;P&gt;Which one(mho140 or checkpoint6200) using tcpdump?&lt;/P&gt;&lt;P&gt;thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2024 05:06:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/tcpdump-issues/m-p/215336#M2593</guid>
      <dc:creator>tonyhsueh</dc:creator>
      <dc:date>2024-05-28T05:06:24Z</dc:date>
    </item>
    <item>
      <title>tcpdump issues</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/tcpdump-issues/m-p/215315#M2596</link>
      <description>&lt;P&gt;Hi bro:&lt;/P&gt;&lt;P&gt;We have two mho140 and two checkpoint6200 in topology, but no traffic packet using expert mode by tcpdump.&lt;/P&gt;&lt;P&gt;Whether mho140 or checkpoint are no traffic packet.&lt;/P&gt;&lt;P&gt;How to capture traffic packet by tcpdump?&lt;/P&gt;</description>
      <pubDate>Mon, 27 May 2024 13:35:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/tcpdump-issues/m-p/215315#M2596</guid>
      <dc:creator>tonyhsueh</dc:creator>
      <dc:date>2024-05-27T13:35:45Z</dc:date>
    </item>
    <item>
      <title>Re: tcpdump issues</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/tcpdump-issues/m-p/215339#M2594</link>
      <description>&lt;P&gt;You can only do packet captures with tcpdump at the SGMs.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2024 05:22:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/tcpdump-issues/m-p/215339#M2594</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2024-05-28T05:22:18Z</dc:date>
    </item>
    <item>
      <title>Re: tcpdump issues</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/tcpdump-issues/m-p/215340#M2595</link>
      <description>&lt;P&gt;you need to run tcpdump from the 6200 appliances , from the SMO.&lt;/P&gt;
&lt;P&gt;use g_tcpdump command to see traffic from all members&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2024 05:22:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/tcpdump-issues/m-p/215340#M2595</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2024-05-28T05:22:34Z</dc:date>
    </item>
    <item>
      <title>Re: tcpdump issues</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/tcpdump-issues/m-p/215410#M2603</link>
      <description>&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Maestro_AdminGuide/Content/Topics-Maestro-AG/Multi-Blade-Traffic-Capture.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Maestro_AdminGuide/Content/Topics-Maestro-AG/Multi-Blade-Traffic-Capture.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2024 18:42:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/tcpdump-issues/m-p/215410#M2603</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-05-28T18:42:44Z</dc:date>
    </item>
    <item>
      <title>Re: tcpdump issues</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/tcpdump-issues/m-p/215417#M2604</link>
      <description>&lt;P&gt;&lt;STRONG&gt;g_tcpdump&lt;/STRONG&gt; will certainly work, but should be used with caution on a busy Maestro security group; use &lt;STRONG&gt;asg perf -vp&lt;/STRONG&gt; run from any SGM to see how utilized the security group is.&amp;nbsp; Below is a screenshot from my &lt;A href="http://www.maxpowerfirewalls.com/gw-optimization-course.html" target="_blank" rel="noopener"&gt;Gateway Performance Optimization Course&lt;/A&gt; showing this great command.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Another alternative if under high load is using the &lt;STRONG&gt;asg search&lt;/STRONG&gt; command to identify which specific SGM is handling all the packets of the connection you want to capture, then logging into that SGM and running a local &lt;STRONG&gt;tcpdump&lt;/STRONG&gt;&amp;nbsp;from expert mode locally.&amp;nbsp; For subsequent connections with the same attributes (sIP, dIP, and possibly dPort if L4 is enabled), the same SGM will always handle that same connection unless the number of active SGMs changes or the distribution algorithm is changed.&amp;nbsp; However if the connection is NATted you may not always get a complete capture with this latter technique, depending upon how the pre-NAT and post-NAT flows are distributed in the security group.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="asgperf.png" style="width: 809px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25894iB9B88AF8F1CF64FE/image-size/large?v=v2&amp;amp;px=999" role="button" title="asgperf.png" alt="asgperf.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2024 19:52:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/tcpdump-issues/m-p/215417#M2604</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2024-05-28T19:52:11Z</dc:date>
    </item>
  </channel>
</rss>

