15.07.2012 Views

How to use fw monitor

How to use fw monitor

How to use fw monitor

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

A new feature in NG with Application Intelligence (FP4) is <strong>fw</strong> moni<strong>to</strong>r’s ability <strong>to</strong> write absolute chain<br />

IDs (Use absolute chain positions [-a]) <strong>to</strong> the capture files rather than relative chain Ids which do only<br />

make sense with the corresponding <strong>fw</strong> ctl chain output. CPEthereal knows the absolute chain Ids<br />

<strong>use</strong>d by <strong>fw</strong> moni<strong>to</strong>r and is therefore able <strong>to</strong> display the mnemonic for the chain position as additional<br />

information in the FW-1 chain column and in the decode pane:<br />

Figure 77: CPEthereal – display absolute FW-1 chain positions<br />

Additional <strong>fw</strong> moni<strong>to</strong>r header properties<br />

CPEthereal includes an improved <strong>fw</strong> moni<strong>to</strong>r decoding. This includes the possibility <strong>to</strong> <strong>use</strong> display or<br />

color filters on additional packet properties:<br />

Field Property Value<br />

<strong>fw</strong> moni<strong>to</strong>r direction <strong>fw</strong>1.direction “i”, “I”, “o” or “O”<br />

<strong>fw</strong> moni<strong>to</strong>r interface <strong>fw</strong>1.interface An Interface name (e.g. “eth0”)<br />

<strong>fw</strong> moni<strong>to</strong>r connection uuid/suid <strong>fw</strong>1.uuid 32bit integer<br />

<strong>fw</strong> moni<strong>to</strong>r chain module <strong>fw</strong>1.chain Chain module alias name<br />

<strong>fw</strong> moni<strong>to</strong>r NAT mode <strong>fw</strong>1.nat “HIDE”, “STATIC_SRC” or “STATIC_DST”<br />

Figure 78: CPEthereal – Useful filter properties<br />

<strong>How</strong> <strong>to</strong> <strong>use</strong> <strong>fw</strong> moni<strong>to</strong>r Page 63 of 70<br />

Revision: 1.01

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!