CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-12-30
breakdan breakdan is offline
Junior Member
 
Join Date: 2006-12-25
Location: Italy
Posts: 19
Rep Power: 0
breakdan has an average reputation (10+)
Default fw monitor

hi at all,
question about fw monitor....i've not understand actually how to use properly the 'lenght' value ('byte', 'word', 'dword').

THK a lot for clarifing my confusion :)

bye, daniel
Reply With Quote
  #2 (permalink)  
Old 2006-12-30
kva.kva kva.kva is offline
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: fw monitor

Do you want to know dimension of "-l" parameter?

-l <length>: limits the packet length; determines the number of bytes read from the kernel for each packet. If you use this option, include enough bytes, so the IP and protocol headers fit. If you use "-x" to print packet data, ensure the data you requested also fits. The default is calculated, so it will have all headers and data used by -x.

You can see default value in monitor's output in square brackets.
Reply With Quote
  #3 (permalink)  
Old 2006-12-30
breakdan breakdan is offline
Junior Member
 
Join Date: 2006-12-25
Location: Italy
Posts: 19
Rep Power: 0
breakdan has an average reputation (10+)
Default Re: fw monitor

I may have written just a bit cryptic :)

I'll explain again
accept [9:1] = 1;

see bold number...value can be: 1(byte), 2(word),4(dword) and, for ex, if i hava to filter icmp expression would be
accept [9:1]=1;
filter on ports: accept [20:2,b]=80;

i'm not able to understand meaning of :1, :2, :4.....

THK a lot

Daniel
Reply With Quote
  #4 (permalink)  
Old 2006-12-30
kva.kva kva.kva is offline
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: fw monitor

This number - how many bytes value takes.
So 9:1 - value is stored after 9 byte (I number bytes from 1) from beginning of packet and takes 1 byte.
20:2 - after 20 byte and takes 2 bytes (word).

Last edited by kva.kva; 2006-12-30 at 10:45.
Reply With Quote
  #5 (permalink)  
Old 2006-12-31
breakdan breakdan is offline
Junior Member
 
Join Date: 2006-12-25
Location: Italy
Posts: 19
Rep Power: 0
breakdan has an average reputation (10+)
Default Re: fw monitor

Quote:
Originally Posted by kva.kva View Post
This number - how many bytes value takes.
So 9:1 - value is stored after 9 byte (I number bytes from 1) from beginning of packet and takes 1 byte.
20:2 - after 20 byte and takes 2 bytes (word).
THK a lot :) ive well understood now

biez

Daniel
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 17:00.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0