- Products
- Learn
- Local User Groups
- Partners
- More
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
Join our TechTalk: Malware 2021 to Present Day
Building a Preventative Cyber Program
Be a CloudMate!
Check out our cloud security exclusive space!
Check Point's Cyber Park is Now Open
Let the Games Begin!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
I have been wondering for years what you can I do with the iketool. To me this looks like an ike.elg logfile parser similar to ikeview.
/opt/CPsuite-R80.40/fw1/bin/iketool
I have tried the following and only get the following message:
# iketool -f /opt/CPsuite-R80.40/fw1/log/ike.elg -v
Unrecognized file format
When I search for iketool in the KB I don't find anything!
PS:
An ike parser on the gateway would be a dream for me. Then you don't have to copy the files via winscp and analyze them with ikeview.
strings iketool shows:
##### END PACKET DEBUG ##### Check Point SecuRemote / SecureClient NG with Application Intelligence R54 NG with Application Intelligence R55 or above NG With Application Intelligence post-R55 Support for Microsoft NAT traversal ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Usage: iketool -f file [OPTIONS]... -f file the file to parse -b shows a summary of the log (does not work with -s) -h display this help and exit -i cookie filter by init cookie, unspaced -v prints a more detailed output -p IP filter by ip -s start in stream mode Version String=NGX Interface Version=0 Company Name=Check Point Software Technologies LTD. Legal Copyright=(c) 2005-2009 Copyright Check Point Software Technologies Ltd Internal Name=iketool
So this looks like an ancient ike.elg viewer back from the NGX days.
However, opening ike.elg files in vi shows that they are already pretty much readable.
Some BASH magic to pretty format their content and VPN could be easily debugged at CLI.
Sep 23-24 2020 | 9:30 – 14:30 GMT+3 | VPN Concepts and Troubleshooting |
As a followup iketool seems to work for me on R80.40 vanilla at least with IKEv1 ike.elg files (see screenshot); I don't have a ikev2.xmll file handy to test with IKEv2 though.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY