Create a Post
Showing results for 
Search instead for 
Did you mean: 

tcpdump issues


We have two mho140 and two checkpoint6200 in mho topology, no traffic packet (mho140 or checkpoint6200) when I using tcpdump in expert mode.

MHO topology is support for tcpdump in expert mode?

Which one(mho140 or checkpoint6200) using tcpdump?



5 Replies

You can only do packet captures with tcpdump at the SGMs. 

Employee Employee

you need to run tcpdump from the 6200 appliances , from the SMO.

use g_tcpdump command to see traffic from all members

Legend Legend

g_tcpdump will certainly work, but should be used with caution on a busy Maestro security group; use asg perf -vp run from any SGM to see how utilized the security group is.  Below is a screenshot from my Gateway Performance Optimization Course showing this great command.  

Another alternative if under high load is using the asg search command to identify which specific SGM is handling all the packets of the connection you want to capture, then logging into that SGM and running a local tcpdump from expert mode locally.  For subsequent connections with the same attributes (sIP, dIP, and possibly dPort if L4 is enabled), the same SGM will always handle that same connection unless the number of active SGMs changes or the distribution algorithm is changed.  However if the connection is NATted you may not always get a complete capture with this latter technique, depending upon how the pre-NAT and post-NAT flows are distributed in the security group.



Attend my online "Be your Own TAC: Part Deux" CheckMates event
March 27th with sessions for both the EMEA and Americas time zones

Hi bro:

We have two mho140 and two checkpoint6200 in topology, but no traffic packet using expert mode by tcpdump.

Whether mho140 or checkpoint are no traffic packet.

How to capture traffic packet by tcpdump?