- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- Re: IPS packet capture
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
IPS packet capture
In R77.30 and earlier IPS packet capture was stored on the gateways as .pcap files and we could retrieve them using "fwm getpcap" over SSH. In R80+, IPS has been moved to Threat Prevention and it seems that packet capture is now being stored as .EML files. Looking at the logs from "fw log", the "packet_capture_unique_id" is now a name, where on earlier versions this was a ID number. Tried running "fwm getpcap" with different ID's from the logs, but all returning errors.
I heard that there are plans to stop using .EML files, but until then, are there any ways to get the IPS packet captures out from SSH?
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I don't know if this is too late, but maybe sk120773 helps:
IPS packet captures are located on on the Security Gateway in:
- Before R80.x - $FWDIR/log/captures_repository
- In R80.10 - $FWDIR/log/forensics and /var/log/spool/mail/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hm... good question.
Let me ping my friends in R&D about this one.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Turns out that’s in R80.10+, the packet captures are stored on the log server, not the gateway as was the case in R77.30 and earlier.
Consequentially, the fwm getpcap command does not work for R80.10+ Gateways
An API for this is planned in R80.20.
Also, in R80.20, we plan to make the pcap available as a pcap (not EML).
Meanwhile, in R80.10, the only way to get the capture is via SmartConsole.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks, will await for R80.20 then
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Did the ability to pull pcaps from the API make it into the R80.20 EA?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I don't see anything in the API docs for it offhand...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I don't know if this is too late, but maybe sk120773 helps:
IPS packet captures are located on on the Security Gateway in:
- Before R80.x - $FWDIR/log/captures_repository
- In R80.10 - $FWDIR/log/forensics and /var/log/spool/mail/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Never too late for a correct answer
The nice thing is in R80.10, these files are stored as .cap files directly, which means Wireshark and other tools can read them.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In a R80.10 installation it seems that there is only .cap files for the last couple of days. Does anyone know for how long the .cap files are stored and where it can be configured?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It's my understanding that these settings are configured from 'Disk Space Management' (GW Properties -> Logs -> Local Storage). Here you can also define how much disk space will be allocated for packet capturing. Files should be stored until we start running out of space (then log rotation starts working as per the settings)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It seems that R81.10 does not offer the possibility to configure this anymore:
Same on R80.30:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This is configured on the gateway object, not the SMS. The Local Storage screens you are showing are for an SMS.
March 27th with sessions for both the EMEA and Americas time zones
