Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
0 8 16 24 32<br />
header<br />
length<br />
TCP source port number<br />
reserved<br />
Figure 33: IP pro<strong>to</strong>cols – TCP header<br />
TCP sequence number<br />
TCP acknoledgment number<br />
FYN<br />
SYN<br />
RST<br />
PSH<br />
ACK<br />
URG<br />
TCP options (if any)<br />
TCP destination port number<br />
TCP window size<br />
TCP checksum TCP urgent pointer<br />
TCP payload (if any)<br />
Simple Checks can be <strong>use</strong>d for a wide variety of checks. Some examples:<br />
Filter on source or destination IP address. The IP addresses are s<strong>to</strong>red as dwords at offset 12 (source<br />
address) and 16 (destination address):<br />
address filter expression<br />
source accept [12, b]=172.16.1.2;<br />
destination accept [16, b]=10.2.4.12;<br />
Figure 34: <strong>fw</strong> moni<strong>to</strong>r simple checks – IP addresses<br />
! Please note the <strong>use</strong> of IP addresses instead of simple numbers in the example above. INSPECT<br />
“knows” IP addresses and converts them au<strong>to</strong>matically <strong>to</strong> an integer. There is no need <strong>to</strong> do this<br />
manually although this is possible. Please refer <strong>to</strong> the Check Point Reference Guide for more<br />
information.<br />
Filter on the IP pro<strong>to</strong>col. The IP pro<strong>to</strong>col is s<strong>to</strong>red as a byte at offset 9 in the IP packet:<br />
IP pro<strong>to</strong>col filter expression<br />
ICMP accept [9:1] = 1;<br />
TCP accept [9:1] = 6;<br />
UDP accept [9:1] = 17;<br />
ESP accept [9:1] = 50;<br />
Figure 35: <strong>fw</strong> moni<strong>to</strong>r simple checks – IP pro<strong>to</strong>col examples<br />
<strong>How</strong> <strong>to</strong> <strong>use</strong> <strong>fw</strong> moni<strong>to</strong>r Page 33 of 70<br />
Revision: 1.01