Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Flanger
Participant
Jump to solution

R80.30 TCP Ping tool

Hello.

I'm relatively new with checkpoint firewalls. Previously I've worked with Cisco ASA devices, which have TCP Ping tool letting you test TCP connectivity on specified destination's TCP port (ASA sends TCP SYN packets and evaluates reply on specified destination IP:Port). This utility also lets you source it from any source IP you want. That way you're not limited only to appliance's local interfaces' IP addresses and can emulate traffic, as if it was forwarded by the appliance.

This is very handy when troubleshooting network access issues, to make sure security policies are correct and that destination host/server is causing the problem.

Is there any similar tool/functionality within Checkpoint R80.30 virtual security gateways?

0 Kudos
2 Solutions

Accepted Solutions
PhoneBoy
Admin
Admin

hping2?
From the CLI help it appears to allow spoofing a source address.
Will admit haven’t tried.
Goes without saying you need to be an admin user with uid 0.

View solution in original post

Flanger
Participant

It works! Generated traffic shows in logs as well. Thank you again.

View solution in original post

0 Kudos
10 Replies
Alex-
Leader Leader
Leader

Check maybe the packet injector?

0 Kudos
Timothy_Hall
Legend Legend
Legend

There used to be a tool called pinj that did exactly what you want, but it stopped working in R80.20, closest you can get now is the tcptraceroute tool.

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
0 Kudos
Flanger
Participant

Thank you for the reply.
I've read SK link provided by Alex and Packet Injector seems to be exactly what I want. I was going to install it on one of my R80.30 security gateways. Too bad it does not work now. Does it fail during installation as well, or maybe I should give it a try?

0 Kudos
John_Fleming
Advisor

so tcptraceroute and traceroute are the same binary. I guess its just using the -T flag by default?

0 Kudos
PhoneBoy
Admin
Admin

GNU netcat is available on Gaia.

0 Kudos
Flanger
Participant

Thank you for the information. I'm afraid I'm unable to specify arbitrary source IP addresses with netcat to test the connectivity, as it accepts only security gateway's real interface addresses:

Error: Couldn't create connection (err=-3): Cannot assign requested address


This limitation makes it impossible to emulate specific connection traffic from security gw.

0 Kudos
PhoneBoy
Admin
Admin

hping2?
From the CLI help it appears to allow spoofing a source address.
Will admit haven’t tried.
Goes without saying you need to be an admin user with uid 0.

Flanger
Participant

It works! Generated traffic shows in logs as well. Thank you again.

0 Kudos
vikassharma
Explorer

this is very simple

ping -s --source ip--  destination ip

 

0 Kudos
irek
Explorer

ping -I [source_ip|interface] destination

from clish, just like regular linux ping 

limited to addresses configured on the firewall

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events