CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-01-14
evo22 evo22 is offline
Member
 
Join Date: 2007-05-10
Posts: 37
Rep Power: 0
evo22 has an average reputation (10+)
Default tcpdump syntax...

I'm new to IPSO and I have two Nokia IP560s and I need to run tcpdump on some of the interfaces. What is the syntax to do so?

Thank you in advance
Reply With Quote
  #2 (permalink)  
Old 2008-01-14
cciesec2006 cciesec2006 is online now
Senior Member
 
Join Date: 2006-09-26
Posts: 755
Rep Power: 3
cciesec2006 has an average reputation (10+)
Default Re: tcpdump syntax...

dca-Nokia-1-P[admin]# tcpdump -i eth1 -nn -n port 22
tcpdump: listening on eth1
20:00:24.894795 O 192.168.0.253.22 > 192.168.15.10.42451: P 958050273:958050337(64) ack 3650470713 win 17376 <nop,nop,timestamp 626688 244304747> [tos 0x10]
20:00:24.895436 I 192.168.15.10.42451 > 192.168.0.253.22: . ack 64 win 9328 <nop,nop,timestamp 244304750 626688> (DF) [tos 0x10]
20:00:25.895845 O 192.168.0.253.22 > 192.168.15.10.42451: P 64:256(192) ack 1 win 17376 <nop,nop,timestamp 626690 244304750> [tos 0x10]
20:00:25.896079 O 192.168.0.253.22 > 192.168.15.10.42451: P 256:432(176) ack 1 win 17376 <nop,nop,timestamp 626690 244304750> [tos 0x10]
20:00:25.896636 I 192.168.15.10.42451 > 192.168.0.253.22: . ack 256 win 9328 <nop,nop,timestamp 244304850 626690> (DF) [tos 0x10]
20:00:25.896814 I 192.168.15.10.42451 > 192.168.0.253.22: . ack 432 win 9328 <nop,nop,timestamp 244304850 626690> (DF) [tos 0x10]
20:00:26.895537 O 192.168.0.253.22 > 192.168.15.10.42451: P 432:608(176) ack 1 win 17376 <nop,nop,timestamp 626692 244304850> [tos 0x10]
20:00:26.895752 O 192.168.0.253.22 > 192.168.15.10.42451: P 608:784(176) ack 1 win 17376 <nop,nop,timestamp 626692 244304850> [tos 0x10]
20:00:26.895944 O 192.168.0.253.22 > 192.168.15.10.42451: P 784:960(176) ack 1 win 17376 <nop,nop,timestamp 626692 244304850> [tos 0x10]
20:00:26.896134 O 192.168.0.253.22 > 192.168.15.10.42451: P 960:1136(176) ack 1 win 17376 <nop,nop,timestamp 626692 244304850> [tos 0x10]
20:00:26.896692 I 192.168.15.10.42451 > 192.168.0.253.22: . ack 608 win 9328 <nop,nop,timestamp 244304950 626692> (DF) [tos 0x10]
20:00:26.896889 I 192.168.15.10.42451 > 192.168.0.253.22: . ack 784 win 9328 <nop,nop,timestamp 244304950 626692> (DF) [tos 0x10]
20:00:26.897088 I 192.168.15.10.42451 > 192.168.0.253.22: . ack 960 win 9328 <nop,nop,timestamp 244304950 626692> (DF) [tos 0x10]
20:00:26.897226 I 192.168.15.10.42451 > 192.168.0.253.22: . ack 1136 win 9328 <nop,nop,timestamp 244304950 626692> (DF) [tos 0x10]
^C
76 packets received by filter
0 packets dropped by kernel
dca-Nokia-1-P[admin]#
Reply With Quote
  #3 (permalink)  
Old 2008-01-15
icarus icarus is offline
Junior Member
 
Join Date: 2007-12-27
Posts: 1
Rep Power: 0
icarus has an average reputation (10+)
Default Re: tcpdump syntax...

Alternatively you can also use fw monitor.

More on fw monitor:
http://www.checkpoint.com/techsuppor...or_rev1_01.pdf

And then a little help when creating those hard to encode fw monitor input strings:
http://www.decock.org/ginspect/index...nfo=TRUE&mode=

have fun!
Reply With Quote
  #4 (permalink)  
Old 2008-01-15
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,648
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: tcpdump syntax...

Also see our resource page at cpug (http://www.cpug.org/check_point_resources.htm) for some good how-tos
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 03:59.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0