- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
I did some research regarding packet capture option, and couldn't find clear answer so I have to ask here 🙂
Documentation states that this option is enabled by default for some blades, and I cannot find for which blades it is enabled by default.
Also, in log entry I can find link to download pcap just for malicious trafffic (for example, IPS prevented traffic). What about Threat Emulation blade?
Threat Emulation packet capture would mean you capture the whole file as part of the logs. That would be too heavy.
Hi, thanks for the reply. What about other blades?
Pretty sure only the Threat Emulation, IPS, Anti-Virus, and Anti-Bot blades can generate packet captures. Content Awareness can show a redacted copy of the offending Data Type, but it is not a full packet capture.
Pretty sure PCAP is only done for IPS and only for the malicious packet.
Packet Captures are done for Anti-Virus too:
Thanks!
Is it safe to keep these default settings, cause security gateways are having some performance issues at the moment (memory consumption is too high)?
AB/AV - have a packet capture but not all the time, depends on the attack type and prevention method.
IPS - defined per attack. For some attacks it's on by default and for some it's off.
Threat Emulation - not a packet capture but a Forensic Report. See Attached.
You can keep default settings, no performance degradation should be caused by normal usage.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 16 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY