TCPDUMP is a Linux tool which at times is not suitable for use with Gaia. Running TCPDUMP causes a significant increase in CPU usage and as a result impact the performance of the device. Even while filtering by specific interface or port still high CPU occurs. Check Point created a tool which works better with Gaia OS.
"CPPCAP" is a traffic capture tool which provides the most relevant outputs and is similar to Tcpdump. The tool is adjusted to Gaia operating system yet requires installation of an applicable RPM. The good news! SecureXL can be enabled or disabled to capture with CPPCAP.
More read here:
- R80.x - Performance Tuning and Debug Tips - TCPDUMP vs. CPPCAP
➜ CCSM Elite, CCME, CCTE ➜ www.checkpoint.tips