You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
A new feature in NG with Application Intelligence (FP4) is <strong>fw</strong> moni<strong>to</strong>r’s ability <strong>to</strong> write absolute chain<br />
IDs (Use absolute chain positions [-a]) <strong>to</strong> the capture files rather than relative chain Ids which do only<br />
make sense with the corresponding <strong>fw</strong> ctl chain output. CPEthereal knows the absolute chain Ids<br />
<strong>use</strong>d by <strong>fw</strong> moni<strong>to</strong>r and is therefore able <strong>to</strong> display the mnemonic for the chain position as additional<br />
information in the FW-1 chain column and in the decode pane:<br />
Figure 77: CPEthereal – display absolute FW-1 chain positions<br />
Additional <strong>fw</strong> moni<strong>to</strong>r header properties<br />
CPEthereal includes an improved <strong>fw</strong> moni<strong>to</strong>r decoding. This includes the possibility <strong>to</strong> <strong>use</strong> display or<br />
color filters on additional packet properties:<br />
Field Property Value<br />
<strong>fw</strong> moni<strong>to</strong>r direction <strong>fw</strong>1.direction “i”, “I”, “o” or “O”<br />
<strong>fw</strong> moni<strong>to</strong>r interface <strong>fw</strong>1.interface An Interface name (e.g. “eth0”)<br />
<strong>fw</strong> moni<strong>to</strong>r connection uuid/suid <strong>fw</strong>1.uuid 32bit integer<br />
<strong>fw</strong> moni<strong>to</strong>r chain module <strong>fw</strong>1.chain Chain module alias name<br />
<strong>fw</strong> moni<strong>to</strong>r NAT mode <strong>fw</strong>1.nat “HIDE”, “STATIC_SRC” or “STATIC_DST”<br />
Figure 78: CPEthereal – Useful filter properties<br />
<strong>How</strong> <strong>to</strong> <strong>use</strong> <strong>fw</strong> moni<strong>to</strong>r Page 63 of 70<br />
Revision: 1.01