Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Matlu
Advisor
Jump to solution

FW Monitor in VSX

Hi Guys

Is it possible to run a "fw monitor" from the VS0 of a VSX Cluster environment?

I have several VS's, and I want to capture traffic from a particular VS (VS 5).

Is this possible, without having to "jump" to the instance?

Can you share with me the syntax of the command, how it could be done, based on the following example:

Source: 172.16.10.5
Destination: 10.100.20.10
Port: TCP 8080

Thanks

0 Kudos
2 Solutions

Accepted Solutions
Lesley
Authority Authority
Authority

This is all you need:

https://tcpdump101.com/#

Under Check Point -> FW Monitor -> New version

-------
If you like this post please give a thumbs up(kudo)! 🙂

View solution in original post

the_rock
Legend
Legend

There you go buddy 🙂

fw monitor -v 5 -o vs5.cap -F "172.16.10.5,0,10.100.20.10,8080,0"

Andy

View solution in original post

0 Kudos
14 Replies
the_rock
Legend
Legend

fw monitor -v 0 -e accept "host 172.16.10.5 and host 10.200.20.10 and port 8080;"

0 Kudos
Matlu
Advisor

This applies if you are ‘standing’ on VS0 and want to capture traffic from VS 5?

0 Kudos
the_rock
Legend
Legend

Just replace 0 with 5 🙂

0 Kudos
Matlu
Advisor

The command syntax varies greatly if you need to send the command result to a file such as Wireshark?

0 Kudos
the_rock
Legend
Legend

Just add -o /path/filename.cap at the end

0 Kudos
Lesley
Authority Authority
Authority

This is all you need:

https://tcpdump101.com/#

Under Check Point -> FW Monitor -> New version

-------
If you like this post please give a thumbs up(kudo)! 🙂
the_rock
Legend
Legend

There you go buddy 🙂

fw monitor -v 5 -o vs5.cap -F "172.16.10.5,0,10.100.20.10,8080,0"

Andy

0 Kudos
Matlu
Advisor

One doubt, is there much difference in the ‘fw monitor ...’ command between using the -e vs -F parameter?

Is one better than the other?

the_rock
Legend
Legend
0 Kudos
Timothy_Hall
Legend Legend
Legend

Use -F if you can deal with the extremely limited matching syntax.  You will always get a complete capture regardless of the acceleration state of the traffic.

Gaia 4.18 (R82) Immersion Tips, Tricks, & Best Practices Video Course
Now Available at https://shadowpeak.com/gaia4-18-immersion-course
0 Kudos
Matlu
Advisor

Hello,
So, as a "best practice" it is always better to use the "-F" before the "-e"?
Greetings.

0 Kudos
Timothy_Hall
Legend Legend
Legend

I'd say so, there are still some limited situations where -e is needed instead but they are fairly obscure.  The upcoming CCTA R82 class is being heavily updated to explore packet capturing & analysis in detail, and it covers this very topic.

Gaia 4.18 (R82) Immersion Tips, Tricks, & Best Practices Video Course
Now Available at https://shadowpeak.com/gaia4-18-immersion-course
0 Kudos
the_rock
Legend
Legend

For what its worth, I usually use -F flag and works real well.

Andy

0 Kudos
the_rock
Legend
Legend

@Matlu Did command we shared work for you?

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events