CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartView Tracker/Logging And Alerting
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-09-26
jchrisos jchrisos is offline
Junior Member
 
Join Date: 2006-09-26
Posts: 18
Rep Power: 0
jchrisos has an average reputation (10+)
Default Packet capture in Firewall Logs?

Is there an option or a way to capture a packet(s) for each event in the SmartView Tracker logs?
Reply With Quote
  #2 (permalink)  
Old 2006-09-26
kva.kva kva.kva is offline
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: Packet capture in Firewall Logs?

Command "fw monitor"?
Reply With Quote
  #3 (permalink)  
Old 2006-09-26
jchrisos jchrisos is offline
Junior Member
 
Join Date: 2006-09-26
Posts: 18
Rep Power: 0
jchrisos has an average reputation (10+)
Default Re: Packet capture in Firewall Logs?

Quote:
Originally Posted by kva.kva View Post
Command "fw monitor"?
Thanks for the reply. Where do you issue this command? Will it allow packet captures to show up in SmartView Tracker?

Thanks again!
Reply With Quote
  #4 (permalink)  
Old 2006-09-26
david david is offline
Senior Member
 
Join Date: 2006-06-28
Posts: 140
Rep Power: 3
david has an average reputation (10+)
Default Re: Packet capture in Firewall Logs?

fw monitor is a command line utility.
are you wanting to open a capture file to view in smartracker? this is not possible.

you can use tcpdump & redirect the output to a file, then open with a tool such as ethereal to view/analyse 'offline'

Last edited by david; 2006-09-26 at 12:57.
Reply With Quote
  #5 (permalink)  
Old 2006-09-26
jchrisos jchrisos is offline
Junior Member
 
Join Date: 2006-09-26
Posts: 18
Rep Power: 0
jchrisos has an average reputation (10+)
Default Re: Packet capture in Firewall Logs?

Quote:
Originally Posted by david View Post
fw monitor is a command line utility.
are you wanting to open a capture file to view in smartracker? this is not possible.

you can use tcpdump & redirect the output to a file, then open with a tool such as ethereal to view/analyse 'offline'
I was looking more for packet(s) related to an event that was dropped and thus shows up in my logs.

For example, lets say I deny outbound http access and log the drops. Then a user went to www.google.com. I would like to be able to see the actual packet of the http fetch to www.google.com from this user.

Is that possible?

Thanks for the reply btw.
Reply With Quote
  #6 (permalink)  
Old 2006-09-26
Porter Porter is offline
Senior Member
 
Join Date: 2006-07-10
Posts: 164
Rep Power: 3
Porter has an average reputation (10+)
Default Re: Packet capture in Firewall Logs?

http://checkpoint.com/techsupport/do...nitor%20pdf%22

fw monitor shows you everthing
__________________
misery is optional
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 20:53.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0