You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
Check Point enhanced search<br />
Using CheckPoint/Find… it is possible <strong>to</strong> search packets according <strong>to</strong> their Check Point specific<br />
properties:<br />
Figure 74: CPEthereal – Check Point enhanced search<br />
The Check Point enhanced search dialog consists of three search areas.<br />
The <strong>to</strong>p area allows you <strong>to</strong> find packets based on connection properties:<br />
• NAT: Find packets which where NATed<br />
• SEQT Find packets where the sequence number or the acknowledge number was changes<br />
• UUID: Find packets belonging <strong>to</strong> specific connection based on their UUID<br />
The pane in the middle allow you <strong>to</strong> filter the packets based on their capture position in the chain.<br />
In addition it’s possible <strong>to</strong> specify additional restrictions using Ethereal filters (refer <strong>to</strong> Using display and<br />
color filters on <strong>fw</strong> moni<strong>to</strong>r parameters for an overview about Ethereal filter syntax) in the bot<strong>to</strong>m pane.<br />
! Please note that the chain positions in the enhanced search do only make sense for capture files<br />
captured with NG with Application Intelligence (FP4) or higher. This feature requires absolute chain<br />
positions (Use absolute chain positions [-a]) which are only available since NG with Application<br />
Intelligence.<br />
<strong>How</strong> <strong>to</strong> <strong>use</strong> <strong>fw</strong> moni<strong>to</strong>r Page 60 of 70<br />
Revision: 1.01