- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
This is the description of how Check Point used to modify Ethereal and called it CPEthereal, Ethereal has since moved on to become Wireshark.
To customize Wireshark to properly read and interpret FW Monitor files this is the way to do it:
From the Menu Edit choose Preferences, go to protocols Ethernet Select the ‘Attempt to interpret as Firewall-1 monitor file’ option
In the columns add a new column and name it Interface, from the possible fields choose “FW-1 monitor if/direction”
Now you will be able to properly read FW Monitor files but to make the result more readable you can also add some colorization rules by going to the View menu and choose the Coloring rules option
Add these new rules:

After creation move these rules to the top.
The result (this was a very old file capture on a Nokia):

Regards, Maarten.
This is just an excerpt from sk39510: How to configure Wireshark to display Check Point FireWall chains in an FW Monitor packet without referencing the sk and leaving out a lot of details. Also, you may need sk43076: How to work with large traffic capture files !
This is just an excerpt from sk39510: How to configure Wireshark to display Check Point FireWall chains in an FW Monitor packet without referencing the sk and leaving out a lot of details. Also, you may need sk43076: How to work with large traffic capture files !
Gunther,
I have written and posted this text on CPUG around august 2008, so if there is any referencing to be made it would be the other way around.
But to be frank, the way to view the packets as described above with colorization is not something they show in that SK.
You can import a file with the following text
----------------------------------------------------
@FW1-o@fw1.direction contains "o"@[51657,63993,51400][0,0,0]
@FW1-O@fw1.direction contains "O"@[36494,65535,46260][0,0,0]
@FW1-oe@fw1.direction contains "oe"@[0,65535,0][21845,0,65535]
@FW1-OE@fw1.direction contains "OE"@[0,57825,0][21845,0,65535]
@FW1-i@fw1.direction contains "i"@[64764,55255,65535][0,0,0]
@FW1-I@fw1.direction contains "I"@[65535,43690,65535][0,0,0]
@FW1-id@fw1.direction contains "id"@[65535,21845,65535][21845,0,65535]
@FW1-ID@fw1.direction contains "ID"@[65535,0,65535][21845,0,65535]
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY