Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
dj0Nz
Advisor

fw monitor and cppcap on VSX R80.20 (JHF 91)

I just want to share my findings on fw monitor and cppcap on a VSX R80.20 JHF 91 environment:

  • fw monitor just segfaults if I use the -v <VSID> switch
  • fw monitor just ignores the VS context if running without -v switch and captures packets in all VS
  • cppcap does not work in VSX R80.20 JHF 91 with acceleration enabled, I had to do a fwaccel off in the specific VS to capture traffic

I may be wrong. But if not, some documents should be corrected, including Heiko's excellent cheat sheet... 

0 Kudos
3 Replies
PhoneBoy
Admin
Admin

The first and third issues might be worth TAC cases.
0 Kudos
Danny
Champion Champion
Champion

@dj0Nz , this is all known. See..

  1. Documented in sk162402
  2. Documented in sk159152, either use the -F switch with simple capture syntax or disable SecureXL (for specific IPs if you like) before using -e
  3. Documented here
0 Kudos
dj0Nz
Advisor

Thank you very much.

This would have helped a lot ... if sk162402 has been released earlier. Concerning the third topic: I would expect Check Point to include this in the official documentation, when it's certain that cppcap won't work with acceleration on. 

But, again, thank you for clarifying!

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events