- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- WireShark profile for `fw monitor`
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
WireShark profile for `fw monitor`
I write a Wireshark profile to help you with reading `fw monitor` files.
I wrote a Dutch description on Wireshark Profiles and I guess the screenshots will be sufficient help to get you started for those not savvy in Dutch 😉
The Short English Version:
- Create a Dummy personal profile (Name it whatever you like)
- In WireShark, Goto Help => Folders and then proceed to your Personal Configuration directory
- Put the ZIP file in the Profiles directory and unpack it.
- Now you have your own Check Point profile that has coloring rules and some other smart things.
Feel free to mention any smart tricks with Wireshark you use the speed up reading `fw monitor` files.
- Tags:
- wireshark
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
WireShark profiles (Translated by Google)
If some lines don't make sense in English. .... That's what you get from bot translators.
You can always try to learn Dutch 😉
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Wow, I see my post from 2008 on CPUG found it's way back again....
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Been a while since I've seen this.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
cool
I even more like this one : Hugo's website: PowerShell, AD computers to Check Point objects -> psCheckPoint Documentation
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I found that in the PCAP file we loose something. If you run fw monitor on the screens you can see how things are picked up internally.
The first (i) will be part of the performance pack. And then you get a second (i) on the actual core that picks up the packet. On TCP this is only on the SYN packet. But on UDP this happens a lot more.
It would be cool if fw monitor could be enhanced to put this information into comments if you use pcapng as output format.
Who should we buy strooopwafels to get this into a future version?
