<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: no more tcpdump in file with -w in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/no-more-tcpdump-in-file-with-w/m-p/260101#M3700</link>
    <description>&lt;P&gt;Check on all your SGMs for the&amp;nbsp;&lt;SPAN&gt;/var/tmp/file output file.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 16 Oct 2025 15:59:17 GMT</pubDate>
    <dc:creator>emmap</dc:creator>
    <dc:date>2025-10-16T15:59:17Z</dc:date>
    <item>
      <title>no more tcpdump in file with -w</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/no-more-tcpdump-in-file-with-w/m-p/260073#M3694</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I used to save the tcpdump in a file with the command below&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;g_tcpdump -nni &amp;lt;interface&amp;gt; host &amp;lt;x&amp;gt; and host &amp;lt;y&amp;gt; -s 65535 -w /var/tmp/file&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;This was before applying take 113 to R81.20&lt;/P&gt;&lt;P&gt;Now I see that is not exporting anymore the packets but when I ran&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;g_tcpdump -nni &amp;lt;interface&amp;gt; host &amp;lt;x&amp;gt; and host &amp;lt;y&amp;gt; -s 65535&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;I see the packets on console.&lt;/P&gt;&lt;P&gt;I don't see the problem here, could you help?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 16 Oct 2025 13:58:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/no-more-tcpdump-in-file-with-w/m-p/260073#M3694</guid>
      <dc:creator>Catalin_Ciubot2</dc:creator>
      <dc:date>2025-10-16T13:58:09Z</dc:date>
    </item>
    <item>
      <title>Re: no more tcpdump in file with -w</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/no-more-tcpdump-in-file-with-w/m-p/260076#M3695</link>
      <description>&lt;P&gt;&lt;CODE&gt;[Expert@SG-s01-01:0]# gclish&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;[Global] SG-s01-01 &amp;gt; tcpdump -mcap -w /tmp/capture.cap&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;Capturing packets...&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;Write "stop" and press enter to stop the packets capture process.&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;1_01:&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;tcpdump: listening on eth1-Mgmt4, link-type EN10MB (Ethernet), capture size 96 bytes&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;&amp;nbsp;&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Clarification about this output:&lt;BR /&gt;At this moment, an&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_admin variable"&gt;administrator&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;pressed the CTRL+C keys&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;&amp;nbsp;&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;stop&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;Received user request to stop the packets capture process.&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;&amp;nbsp;&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;Copying captured packets from all&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_ScalablePlatforms.tp_sgms variable"&gt;SGMs&lt;/SPAN&gt;...&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;Merging captured packets from&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_ScalablePlatforms.tp_sgms variable"&gt;SGMs&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to /tmp/capture.cap...&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;Done.&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;[Global] SG-s01-01&amp;gt;&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Oct 2025 13:32:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/no-more-tcpdump-in-file-with-w/m-p/260076#M3695</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-10-16T13:32:22Z</dc:date>
    </item>
    <item>
      <title>Re: no more tcpdump in file with -w</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/no-more-tcpdump-in-file-with-w/m-p/260080#M3696</link>
      <description>&lt;P&gt;Thanks, but I have to capture on a specific interface with a filter, to avoid too many packets, and maybe performance load.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Oct 2025 13:43:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/no-more-tcpdump-in-file-with-w/m-p/260080#M3696</guid>
      <dc:creator>Catalin_Ciubot2</dc:creator>
      <dc:date>2025-10-16T13:43:49Z</dc:date>
    </item>
    <item>
      <title>Re: no more tcpdump in file with -w</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/no-more-tcpdump-in-file-with-w/m-p/260083#M3697</link>
      <description>&lt;P&gt;add -i flag all tcpdump Linux flags work here&lt;/P&gt;</description>
      <pubDate>Thu, 16 Oct 2025 14:00:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/no-more-tcpdump-in-file-with-w/m-p/260083#M3697</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-10-16T14:00:41Z</dc:date>
    </item>
    <item>
      <title>Re: no more tcpdump in file with -w</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/no-more-tcpdump-in-file-with-w/m-p/260084#M3698</link>
      <description>&lt;P&gt;Once I add&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;-w /var/tmp/file&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;to the command, is creating an empty file 1 KB.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I repeat, without sending the output to file, the command is working.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For me this looks like another bug.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Oct 2025 14:19:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/no-more-tcpdump-in-file-with-w/m-p/260084#M3698</guid>
      <dc:creator>Catalin_Ciubot2</dc:creator>
      <dc:date>2025-10-16T14:19:54Z</dc:date>
    </item>
    <item>
      <title>Re: no more tcpdump in file with -w</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/no-more-tcpdump-in-file-with-w/m-p/260086#M3699</link>
      <description>&lt;P&gt;&lt;SPAN&gt;MyChassis-ch01-01 &amp;gt; tcpdump -mcap -w /tmp/capture.cap -nnni eth1-Mgmt4&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Oct 2025 14:27:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/no-more-tcpdump-in-file-with-w/m-p/260086#M3699</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-10-16T14:27:01Z</dc:date>
    </item>
    <item>
      <title>Re: no more tcpdump in file with -w</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/no-more-tcpdump-in-file-with-w/m-p/260101#M3700</link>
      <description>&lt;P&gt;Check on all your SGMs for the&amp;nbsp;&lt;SPAN&gt;/var/tmp/file output file.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Oct 2025 15:59:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/no-more-tcpdump-in-file-with-w/m-p/260101#M3700</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2025-10-16T15:59:17Z</dc:date>
    </item>
    <item>
      <title>Re: no more tcpdump in file with -w</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/no-more-tcpdump-in-file-with-w/m-p/260127#M3701</link>
      <description>&lt;P&gt;Worked fine for me last time I tried on R81.20 and R82.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Oct 2025 21:18:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/no-more-tcpdump-in-file-with-w/m-p/260127#M3701</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-16T21:18:54Z</dc:date>
    </item>
    <item>
      <title>Re: no more tcpdump in file with -w</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/no-more-tcpdump-in-file-with-w/m-p/260140#M3702</link>
      <description>&lt;P&gt;We are using SMO (&lt;SPAN class=""&gt;Single Management Object&lt;/SPAN&gt;). I'm pretty sure that I was using that syntax, I mentioned previously.&lt;/P&gt;&lt;P&gt;Now, I discover that is the one below.&lt;/P&gt;&lt;P&gt;g_tcpdump -mcap -w /var/tmp/testp.pcap -nni bond1.200 host x and host y&lt;/P&gt;&lt;P&gt;Why syntax changed?&lt;/P&gt;</description>
      <pubDate>Fri, 17 Oct 2025 08:43:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/no-more-tcpdump-in-file-with-w/m-p/260140#M3702</guid>
      <dc:creator>Catalin_Ciubot2</dc:creator>
      <dc:date>2025-10-17T08:43:04Z</dc:date>
    </item>
    <item>
      <title>Re: no more tcpdump in file with -w</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/no-more-tcpdump-in-file-with-w/m-p/260290#M3707</link>
      <description>&lt;P&gt;As far as I am aware it's always needed the mcap flag to merge the output files. It's in the R80.20SP admin guide at least.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Oct 2025 01:50:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/no-more-tcpdump-in-file-with-w/m-p/260290#M3707</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2025-10-20T01:50:15Z</dc:date>
    </item>
    <item>
      <title>Re: no more tcpdump in file with -w</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/no-more-tcpdump-in-file-with-w/m-p/260310#M3711</link>
      <description>&lt;P&gt;Same issue!&lt;/P&gt;</description>
      <pubDate>Mon, 20 Oct 2025 09:14:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/no-more-tcpdump-in-file-with-w/m-p/260310#M3711</guid>
      <dc:creator>Hauke</dc:creator>
      <dc:date>2025-10-20T09:14:57Z</dc:date>
    </item>
  </channel>
</rss>

