15.07.2012 Views

How to use fw monitor

How to use fw monitor

How to use fw monitor

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

0 8 16 24 32<br />

header<br />

length<br />

TCP source port number<br />

reserved<br />

Figure 33: IP pro<strong>to</strong>cols – TCP header<br />

TCP sequence number<br />

TCP acknoledgment number<br />

FYN<br />

SYN<br />

RST<br />

PSH<br />

ACK<br />

URG<br />

TCP options (if any)<br />

TCP destination port number<br />

TCP window size<br />

TCP checksum TCP urgent pointer<br />

TCP payload (if any)<br />

Simple Checks can be <strong>use</strong>d for a wide variety of checks. Some examples:<br />

Filter on source or destination IP address. The IP addresses are s<strong>to</strong>red as dwords at offset 12 (source<br />

address) and 16 (destination address):<br />

address filter expression<br />

source accept [12, b]=172.16.1.2;<br />

destination accept [16, b]=10.2.4.12;<br />

Figure 34: <strong>fw</strong> moni<strong>to</strong>r simple checks – IP addresses<br />

! Please note the <strong>use</strong> of IP addresses instead of simple numbers in the example above. INSPECT<br />

“knows” IP addresses and converts them au<strong>to</strong>matically <strong>to</strong> an integer. There is no need <strong>to</strong> do this<br />

manually although this is possible. Please refer <strong>to</strong> the Check Point Reference Guide for more<br />

information.<br />

Filter on the IP pro<strong>to</strong>col. The IP pro<strong>to</strong>col is s<strong>to</strong>red as a byte at offset 9 in the IP packet:<br />

IP pro<strong>to</strong>col filter expression<br />

ICMP accept [9:1] = 1;<br />

TCP accept [9:1] = 6;<br />

UDP accept [9:1] = 17;<br />

ESP accept [9:1] = 50;<br />

Figure 35: <strong>fw</strong> moni<strong>to</strong>r simple checks – IP pro<strong>to</strong>col examples<br />

<strong>How</strong> <strong>to</strong> <strong>use</strong> <strong>fw</strong> moni<strong>to</strong>r Page 33 of 70<br />

Revision: 1.01

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!