Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
tonyhsueh
Explorer

tcpdump issues

HI:

We have two mho140 and two checkpoint6200 in mho topology, no traffic packet (mho140 or checkpoint6200) when I using tcpdump in expert mode.

MHO topology is support for tcpdump in expert mode?

Which one(mho140 or checkpoint6200) using tcpdump?

thanks!

 

0 Kudos
5 Replies
emmap
Employee
Employee

You can only do packet captures with tcpdump at the SGMs. 

0 Kudos
Nir_Shamir
Employee Employee
Employee

you need to run tcpdump from the 6200 appliances , from the SMO.

use g_tcpdump command to see traffic from all members

0 Kudos
Timothy_Hall
Champion Champion
Champion

g_tcpdump will certainly work, but should be used with caution on a busy Maestro security group; use asg perf -vp run from any SGM to see how utilized the security group is.  Below is a screenshot from my Gateway Performance Optimization Course showing this great command.  

Another alternative if under high load is using the asg search command to identify which specific SGM is handling all the packets of the connection you want to capture, then logging into that SGM and running a local tcpdump from expert mode locally.  For subsequent connections with the same attributes (sIP, dIP, and possibly dPort if L4 is enabled), the same SGM will always handle that same connection unless the number of active SGMs changes or the distribution algorithm is changed.  However if the connection is NATted you may not always get a complete capture with this latter technique, depending upon how the pre-NAT and post-NAT flows are distributed in the security group.

asgperf.png

 

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
0 Kudos
tonyhsueh
Explorer

Hi bro:

We have two mho140 and two checkpoint6200 in topology, but no traffic packet using expert mode by tcpdump.

Whether mho140 or checkpoint are no traffic packet.

How to capture traffic packet by tcpdump?

0 Kudos
Lesley
Advisor

https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Maestro_AdminGuide/Content/T...

 

 

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos