Create a Post
Showing results for 
Search instead for 
Did you mean: 

R80.40, fw monitor -F not capturing HTTP/Get & OK ?

Hello everyone,

I am currently trying to get a better understanding on how "fw monitor" works and how to use it. For that, I am currently comparing output from R80.10 and R80.40(take_67) in my Lab.

I am capturing http traffic from Host A to Webserver B . My topology looks like this:

Webserver B ---- FW R80.10  ---- FW R80.40 ---- Host A

Webserver B IP:

Host A: - NAT to R80.40)

I am capturing the traffic from Host A to Webserver B in both directions on both Gateways.

On R80.10 I disabled SecureXL to capture accelerated packets aswell and on R80.40 I am using the -F flag to capture accelerated and non accelerated traffic.

It works to a certain point, but I am running into an issue which I haven't found a solution for  so far.

I can see the 3-way handshake in both captures, on R80.10 I see the HTTP/Get & OK but on R80.40 it is not beeing captured...

These are the filters I am using:


fwaccell off

fw monitor -e "accept (src= and dst= or (src= and dst=;" -o fwmonR8010AccCap.pcap



fw monitor -F ",0,,80" -F ",80,,0" -o fwmonR8040AccCap.pcap
Can you tell me what I am doing wrong or missing here?
Thank you very much!!


0 Kudos
8 Replies
This widget could not be displayed.