- Products
- Learn
- Local User Groups
- Partners
- More
CheckMates Fifth Birthday
Celebrate with Us!
days
hours
minutes
seconds
Join the CHECKMATES Everywhere Competition
Submit your picture to win!
Check Point Proactive support
Free trial available for 90 Days!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
The 2022 MITRE Engenuity ATT&CK®
Evaluations Results Are In!
Now Available: SmartAwareness Security Training
Training Built to Educate and Engage
MITRE ATT&CK
Inside Check Point products!
CheckFlix!
All Videos In One Space
Hi,
A new Ongoing Jumbo Hotfix Accumulator take for R80.20 (take 74) is available. Please refer to sk137592.
R80.20 JHF T74 is the same as T73 (including only alignment to Mail Transfer Agent engine).
R80.20 JHF Take #74 content:
PRJ-503 - Alignment to Mail Transfer Agent Engine Update. Refer to sk123174.
fw monitor filters still appear to be broken in this release (as reported on previous release thread). Tested on R80.20 VM management and 3100 single gateway,
Shame really, as there are a few stability fixes that really should be rolled out; but will be sticking with T47 (on customer environments) until these issues are resolved.
There was indeed a behavioral change of FW monitor in this take.
Up until R80.20 FW monitor was not monitoring accelerated traffic by PPAK. In R80.20 we introduced the ability to monitor this traffic, however it was not enabled by default (Due to high performance impact). One of the reasons for this high performance impact is the inability to use the "-e" filter which is not supported on PPAK.
Now, starting from take 73, we have made substantial changes to FW monitor. Together with performance optimizations we have also embedded new filtering abilities in FW monitor.
By using "-F" flag you can filter certain connection. For example, to filter a host with the IP “8.8.8.8” you should use: fw monitor -F "8.8.8.8,0,0,0,0" -F "0,0,8.8.8.8,0,0".
The syntax is simple. -F "{src IP}, {src port}, {dst IP},{dst port}, {protocol num}". “0” can be used as a wild card.
For more information about this check sk30583 ("what is FW monitor") or ask me.
Is it intended that "-e" doesn't filter any more, so "-F" is not an additional option but replaces "-e"?
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY