15.07.2012 Views

How to use fw monitor

How to use fw monitor

How to use fw monitor

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Check Point enhanced search<br />

Using CheckPoint/Find… it is possible <strong>to</strong> search packets according <strong>to</strong> their Check Point specific<br />

properties:<br />

Figure 74: CPEthereal – Check Point enhanced search<br />

The Check Point enhanced search dialog consists of three search areas.<br />

The <strong>to</strong>p area allows you <strong>to</strong> find packets based on connection properties:<br />

• NAT: Find packets which where NATed<br />

• SEQT Find packets where the sequence number or the acknowledge number was changes<br />

• UUID: Find packets belonging <strong>to</strong> specific connection based on their UUID<br />

The pane in the middle allow you <strong>to</strong> filter the packets based on their capture position in the chain.<br />

In addition it’s possible <strong>to</strong> specify additional restrictions using Ethereal filters (refer <strong>to</strong> Using display and<br />

color filters on <strong>fw</strong> moni<strong>to</strong>r parameters for an overview about Ethereal filter syntax) in the bot<strong>to</strong>m pane.<br />

! Please note that the chain positions in the enhanced search do only make sense for capture files<br />

captured with NG with Application Intelligence (FP4) or higher. This feature requires absolute chain<br />

positions (Use absolute chain positions [-a]) which are only available since NG with Application<br />

Intelligence.<br />

<strong>How</strong> <strong>to</strong> <strong>use</strong> <strong>fw</strong> moni<strong>to</strong>r Page 60 of 70<br />

Revision: 1.01

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!