a command line to capture packets in Checkpoint:
fw monitor -m i -e "accept [20:2,b]=445 or [22:2,b]=445;" -o monitor.cap -ci 10 -co 10
will save 10 packets on port 445 in the file monitor.cap.
You can upload it using tftp from Checkpoint to another server and analyse it with wireshark.
However my preference is to set switch monitoring of the port to another port and use Microsoft Network monitor 3.3 to capture packets.
Search This Blog
Showing posts with label checkpoint. Show all posts
Showing posts with label checkpoint. Show all posts
Tuesday, September 1, 2009
Thursday, January 25, 2007
Checkpoint authentication with Microsoft Radius (IAS)
For some reasons Checkpoint VPN (R60) does not send NAS-Port-Type in authentication request. Microsoft IAS wizard by default creates policy that expects that NAS-Port-Type = Virtual. Remove this field from IAS policy and add other like NAS-IP-Address etc, to identify the VPN component
Subscribe to:
Posts (Atom)