Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
G_W_Albrecht
Legend Legend
Legend

cppcap for GAiA Embedded

sk141412: cppcap - A Check Point Traffic Capture Tool does not list Embeded GAiA as supported, and it is not pre-installed there as in GAiA since R80.40. Is cppcap supported in Embedded GAiA at all ?

CCSE / CCTE / CCME / CCSM Elite / SMB Specialist
0 Kudos
8 Replies
Lesley
Leader Leader
Leader

As far as I know, it does not run it. If it is supported yes or no I cannot answers. But I know that tcpdump is still the way to go on embedded. For normal GAIA OS my preference is still old school tcpdump and I have never used cppcap to be honest. Also I see TAC still requesting tcpdump output(not cppcap) so not sure if this still the way to go. 

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
Lesley
Leader Leader
Leader

Btw the Tcpdump Tool in de webinterfaces -> Logs & monitoring -> Diagnostics -> Tcpdump Tool uses tcpdump in the background 🙂

psaux:

root 21818 0.0 0.0 7040 4224 ? S 16:00 0:00 tcpdump -t -q -nnn -c1000 -i any host 8.8.8.8

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
G_W_Albrecht
Legend Legend
Legend

cppcap is pre-installed since R80.40 (2018). On SMB i would prefer fw monitor for its filtering capabilities that are very valuable on the flash based appliances with little disk space...

 

CCSE / CCTE / CCME / CCSM Elite / SMB Specialist
0 Kudos
Lesley
Leader Leader
Leader

To be honest I don't want to compare fwmonitor with tcpdump (NAT,Routing etc). SMB indeed have little space, but you can increase it in a simple way, stick USB inside for more space. Or tcpdump with filter and / or let run for not to long. 

If I check a random SMB I have around 15gb free in /logs and /storage, would be a real massive capture 😉 

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
_Val_
Admin
Admin

The answer is no. If you think it is a good idea to have cppcap on Embedded, please open an RFE

0 Kudos
G_W_Albrecht
Legend Legend
Legend

cppcap was made to use less CPU than tcpdump, so support on SMB would be a very good idea.

 

CCSE / CCTE / CCME / CCSM Elite / SMB Specialist
0 Kudos
Lesley
Leader Leader
Leader

Smaller box, smaller traffic and therefore smaller capture 😉 

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
_Val_
Admin
Admin

It is also optimized for a completely different kernel version and CPU type. Just saying...

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events