- Products
- Learn
- Local User Groups
- Partners
- More
Maestro Masters
Round Table session with Maestro experts
HI:
We have two mho140 and two checkpoint6200 in mho topology, no traffic packet (mho140 or checkpoint6200) when I using tcpdump in expert mode.
MHO topology is support for tcpdump in expert mode?
Which one(mho140 or checkpoint6200) using tcpdump?
thanks!
You can only do packet captures with tcpdump at the SGMs.
you need to run tcpdump from the 6200 appliances , from the SMO.
use g_tcpdump command to see traffic from all members
g_tcpdump will certainly work, but should be used with caution on a busy Maestro security group; use asg perf -vp run from any SGM to see how utilized the security group is. Below is a screenshot from my Gateway Performance Optimization Course showing this great command.
Another alternative if under high load is using the asg search command to identify which specific SGM is handling all the packets of the connection you want to capture, then logging into that SGM and running a local tcpdump from expert mode locally. For subsequent connections with the same attributes (sIP, dIP, and possibly dPort if L4 is enabled), the same SGM will always handle that same connection unless the number of active SGMs changes or the distribution algorithm is changed. However if the connection is NATted you may not always get a complete capture with this latter technique, depending upon how the pre-NAT and post-NAT flows are distributed in the security group.
Hi bro:
We have two mho140 and two checkpoint6200 in topology, but no traffic packet using expert mode by tcpdump.
Whether mho140 or checkpoint are no traffic packet.
How to capture traffic packet by tcpdump?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
10 | |
8 | |
5 | |
4 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 |
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY