<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Monitor mode and PCAP on Quantum Spark gateways in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Monitor-mode-and-PCAP-on-Quantum-Spark-gateways/m-p/126568#M5509</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;The shared link points to a wiki.checkpoint.com URL, but the domain is not being resolved by DNS:&lt;/P&gt;&lt;P&gt;&amp;gt; wiki.checkpoint.com&lt;BR /&gt;Servidor: dns.google&lt;BR /&gt;Address: 8.8.8.8&lt;/P&gt;&lt;P&gt;*** dns.google no encuentra wiki.checkpoint.com: Non-existent domain&lt;BR /&gt;&amp;gt;&lt;/P&gt;&lt;P&gt;And the sk number is present on&amp;nbsp;supportcenter.checkpoint.com. So maybe you can fix the link.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Wed, 11 Aug 2021 13:36:18 GMT</pubDate>
    <dc:creator>RS_Daniel</dc:creator>
    <dc:date>2021-08-11T13:36:18Z</dc:date>
    <item>
      <title>Monitor mode and PCAP on Quantum Spark gateways</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Monitor-mode-and-PCAP-on-Quantum-Spark-gateways/m-p/126527#M5506</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Traffic capture on a SPARK appliance with the&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;tcpdump&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;tool on a port configured in the Monitor mode (SPAN) shows only broadcast and multicast packets. By default, acceleration is enabled on the SPARK appliances. The acceleration module does not send the traffic it inspected to the&amp;nbsp;&lt;CODE&gt;tcpdump&amp;nbsp;&lt;/CODE&gt;tool.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;To capture traffic on a monitor port's logical interface (brS-LAN&amp;lt;x&amp;gt;):&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;Configure all the applicable ports to work in monitor mode.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Connect to the command line on the SPARK appliance.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Log in to the Expert mode.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Run:&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;/opt/fw1/bin/cap_monitor_port.sh&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Capture the traffic with the&amp;nbsp;&lt;EM&gt;tcpdump&lt;/EM&gt;&amp;nbsp;tool.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;To make this change persistent (to survive reboot), run this command in the Expert mode (do not change the syntax):&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;echo /opt/fw1/bin/cap_monitor_port.sh &amp;gt;&amp;gt; /pfrm2.0/etc/userScript&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Notes:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;This command is available starting from R80.20.20.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Traffic that is dropped by the Security Policy is not captured.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;For more information, check out&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk172286&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank" rel="noopener" data-linked-resource-id="403082184" data-linked-resource-version="1" data-linked-resource-type="attachment" data-linked-resource-default-alias="cronjob.JPG" data-nice-type="Image" data-linked-resource-content-type="image/jpeg" data-linked-resource-container-id="323176871" data-linked-resource-container-version="389"&gt;sk172286&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Aug 2021 13:46:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Monitor-mode-and-PCAP-on-Quantum-Spark-gateways/m-p/126527#M5506</guid>
      <dc:creator>AntoinetteHodes</dc:creator>
      <dc:date>2021-08-11T13:46:23Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor mode and PCAP on Quantum Spark gateways</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Monitor-mode-and-PCAP-on-Quantum-Spark-gateways/m-p/126568#M5509</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;The shared link points to a wiki.checkpoint.com URL, but the domain is not being resolved by DNS:&lt;/P&gt;&lt;P&gt;&amp;gt; wiki.checkpoint.com&lt;BR /&gt;Servidor: dns.google&lt;BR /&gt;Address: 8.8.8.8&lt;/P&gt;&lt;P&gt;*** dns.google no encuentra wiki.checkpoint.com: Non-existent domain&lt;BR /&gt;&amp;gt;&lt;/P&gt;&lt;P&gt;And the sk number is present on&amp;nbsp;supportcenter.checkpoint.com. So maybe you can fix the link.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 11 Aug 2021 13:36:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Monitor-mode-and-PCAP-on-Quantum-Spark-gateways/m-p/126568#M5509</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2021-08-11T13:36:18Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor mode and PCAP on Quantum Spark gateways</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Monitor-mode-and-PCAP-on-Quantum-Spark-gateways/m-p/126569#M5510</link>
      <description>&lt;P&gt;Hi Daniel, it is fixed. Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 11 Aug 2021 13:46:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Monitor-mode-and-PCAP-on-Quantum-Spark-gateways/m-p/126569#M5510</guid>
      <dc:creator>AntoinetteHodes</dc:creator>
      <dc:date>2021-08-11T13:46:55Z</dc:date>
    </item>
  </channel>
</rss>

