Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Vladimir_S
Contributor
Jump to solution

fw monitor

Hello,

I need to monitor inbound traffic between an external source and Check Point security gateway external interface on port 443.

R82 Take 12 runs on the security gateway.

Here is the syntaxis of fw monitor that I use on the gateway:

fw monitor -F "0.0.0.0, 0, 12.69.98.28, 443, 6" -pi

And here is output:

PPAK 0: Get before set operation succeeded of fwmonitor_kiss_enable
PPAK 0: Get before set operation succeeded of fwmonitor_debug_filter_off
PPAK 0: Get before set operation succeeded of fwmonitorfreebufs
Invalid destination IP address 12.X.X.28 in debug filter

I replaced part of the public IP address of my gateway with X.

Any suggestions to get correct output?

Thank you.

 

 

0 Kudos
1 Solution

Accepted Solutions
Lesley
Authority Authority
Authority

fw monitor -m i -F "0,0,1.1.1.1,0,1"

-------
If you like this post please give a thumbs up(kudo)! 🙂

View solution in original post

0 Kudos
(1)
4 Replies
Lesley
Authority Authority
Authority

Try:

fw monitor -m i -F "0,0,1.1.1.1,443,0"
replace 1.1.1.1 with your ip and please edit your post in the output you still can see the full public ip

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
Vladimir_S
Contributor

Hi Lesley,

The command worked!! Another question, for the fw monitor filter, what expression should be added to capture ICMP traffic?

Thank you,

Vlad.

0 Kudos
Lesley
Authority Authority
Authority

fw monitor -m i -F "0,0,1.1.1.1,0,1"

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
(1)
Vladimir_S
Contributor

Thank you Lesley, it works too!!

Vlad.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events