fw monitor Builderv0.4.1
Build Check Point fw monitor capture commands. Packets are intercepted at kernel inspection points before and after the security policy — a packet that disappears between points was dropped at that stage.
// generated command
$
fw monitor -m iIoO -u -e "accept;"
// capture options
pcap readable by Wireshark ·
use default path
· clear
// inspection points (-m)
fw monitor intercepts packets at four kernel checkpoints. Enable the points you need — a packet that disappears between points was dropped at that stage of processing.
// filter expression (-e)
SOURCE
DESTINATION
EITHER DIRECTION