Тёмный

Check Point Firewall - fw monitor 

Magnus Holmberg
Подписаться 10 тыс.
Просмотров 15 тыс.
50% 1

Опубликовано:

 

11 окт 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 41   
@afbraganza
@afbraganza 4 года назад
Great video as always!. Was always apprehensive about using fw monitor in production, but this video has given some confidence. So was working with Checkpoint TAC two weeks ago troubleshooting some issue on R80.20 and they ran fw monitor and stopped it after the capture. Suddenly CPU0 spiked to 100% and crashed the 6800 firewall. After going through the crash logs, they identified a bug with the fw monitor process not getting terminated properly and suggested we upgrade to R80.40. We applied a HF for now and will be upgrading soon. Would also love to see a video about CoreXL and multi queue tuning on VSX..
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 4 года назад
Thank you! Ye commands such fw monitor is something to use carfully within a prod enviroment. Its getting better as its dosn´t require fwaccel off anymore on the new versions. Within VSX is something to be extra carefull as you need to check the specific vs. If you need to use it on something u need to turn of securexl, then check how much of your traffic is actually accelerated. Done the misstake on a VS that i tought was fine as its only hade 20-30% load and 4 instanses allocated but as only FW blade was used more or less 98% of all traffic was accelerated. Meaning the VS did go up to 400% load and started to throw traffic when we started to debug :( Multi queue is more or less not an issue anymore. on R80.30 3.10 its on by default and fixing pretty much itself :D Even better in R80.40 HFA something with dynamic dispatcher (only on appliances so far), so alot of the tweaking is going away! Honestly i would not go for R80.40 just yet for critical infra. I try to wait untill the HFA is above 100 (but i do use open servers so its more problematic then appliances) Same for VSX i would go for R80.30 latest GA and then upgrade to R80.40 in a month or two. For mgmt upgrade to R80.40 should be no issue. Regarding videos, ye i think its time to start to show more VSX stuff. I tought most of you guys was going for CCSA but most seams to have alot more experiance and want to see the more cool stuff :)
@tyserie9057
@tyserie9057 4 года назад
@@MagnusHolmberg-NetSec Yeah, I would say the most important thing is always use some filter. Capture all traffic in production can cause dropping of packets and then you will be punished :) Btw, in this Danny's tool. If I want to check for source and destination do you just add two host IPs?
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 4 года назад
Learned that the hard way :) There is also a lot of undocumented stuff when it comes to debug commands
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 4 года назад
When it comes to debug/strange behaviors, involve the TAC quickly, dont wait hours/days for it. They have so much more information and SK that you as a customer or partner dont have access to.
@winmohan
@winmohan 2 года назад
thanks for sharing knowledge about fw moniter !!!!
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 2 года назад
No problem 👍
@ahmedareem9599
@ahmedareem9599 3 года назад
man, your videos are really helpful, thank you so much for your efforts.
@aeronjorge98
@aeronjorge98 2 года назад
Wow it's nice to learn this thing
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 2 года назад
its one of the things i always need to look up on google when using ;) i never learn :D
@rahulnamdev5985
@rahulnamdev5985 2 года назад
Excellent Magnus. You showed us how to use command. Can you please tell us how to read the output as well?
@thetone69
@thetone69 10 месяцев назад
what template do you use to highlight the output, very cool ! :)
@donint9871
@donint9871 3 года назад
Hi Magnus, Great work !!!
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 3 года назад
thank you :)
@poseidon8510
@poseidon8510 3 года назад
Thanks Mag !!
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 3 года назад
your welcome, abit easier to use fw montiro after dannys tool there :D
@mohsinarif2659
@mohsinarif2659 4 года назад
Excellent videos.Will you be covering tcpdump ?
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 4 года назад
Thank you! Yes i will be doing a video regarding tcpdump. I will do a few videos before that, need to cover the vpn part as it has been requested by alot of ppl.
@Enodun
@Enodun 3 года назад
Hi Magnus. Danny's tool used ip_p=6 and ip_p=11 when you chose TCP and UDP. Protocol 6 is TCP but protocol 11 is NVP-II. Shouldn't it be protocol number 17 for UDP instead?
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 2 года назад
I think this is a question for Danny :) he is good in responding on the check mates community
@pikotsky0906
@pikotsky0906 2 года назад
Hi @Magnus this supertool is safe to run in production? We’re running R80.30. Thanks!
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 2 года назад
Hi, I have used it multiple times in production on r80.30 :) You should be fine, it has great comments in the checkmates community also.
@dikshasrivastava9771
@dikshasrivastava9771 4 года назад
Great Series and very helpful.. Can you finish the series ASAP as it's interesting :P
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 4 года назад
Thank you! Are you going for a CCSA certificate :)? We are almost done with the content covered within the CCSA. Have some topics left regarding smartevent, compliance and backup solutions.
@dikshasrivastava9771
@dikshasrivastava9771 4 года назад
@@MagnusHolmberg-NetSec Yes, I am preparing for CCSA and luckily got this series 😀😀
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 4 года назад
@@dikshasrivastava9771 aha nice! When I first wrote ccsa (was R71 then ) i passed with 1% :) I thought it was pretty hard but it has been very helpfully. Make sure to check the study guide so you know what more is covered. This serie is focus on actually working with the stuff and not only taking the certification. I bring up most but not everything and I am planning to make ~10 or so videos more on this level. www.checkpoint.com/downloads/professional-services/training/r80-system-administrator-study-guide.pdf
@ranghelsoto6516
@ranghelsoto6516 4 года назад
Hi Magnus. A query, in your example I think you are trying to export all the logs to a ".cap" file, is that true? That extension is only to be able to open the file in a Wireshark, right? Could you tell me how I should apply the command, if what I'm looking for is to export all the logs, to a simple TXT file, with the name of "November" for example? Could you give me that scope, please. Thanks. 🙈
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 4 года назад
Hi, I think what you are looking for is log exporter. Here you can send all our logs to something else then check point, in most cases a siem system. But log exporter allows you to export it was syslog messages. supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk122323 If not, well maybe check out the video I made about the log types :)
@ranghelsoto6516
@ranghelsoto6516 4 года назад
@@MagnusHolmberg-NetSec Thanks for the reply. Basically what I am looking for is that all the logs that normally the result of applying a "fw monitor" gives you, I can send it to a notepad, in such a way that it allows me to read it better, because I want to apply some changes in the Firewall, and I want to make a comparison of what happens applying and not applying a particular policy, since I currently have problems with a VOIP scenario.
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 4 года назад
@@ranghelsoto6516 not sure if possible, notepad isn’t really fast to search big files in. Save the screen output from putty or your terminal window then you will get a .txt file :) Generally when it comes to check point. Don’t use the default sip object in the rulebase. Create standard TCP-5060 objects so check point don’t do a lot of strange things to the package. (More or less always issues with voip if using the sip objects in the rulebase)
@RajivKumar-ee7xv
@RajivKumar-ee7xv 3 года назад
-o november.txt
@gaborm4767
@gaborm4767 Год назад
How is it possible to trace VPN traffic? I would like to see the unencrypted packets on VPN interface or make sure the packets are being sent. As far as I know fw monitor can't do this...
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec Год назад
Check out the sk33327
@gaborm4767
@gaborm4767 Год назад
Unfortunately I don't have access for KB.
@desaironak11
@desaironak11 4 года назад
Magnus you have been brilliant. are you going to to do VPN ???
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 4 года назад
Thank you! Yes I will make one or two with site to site vpn. Thinking of showing one within your own mgmt and one that is towards a partner. As VPN within r80.40 is changed to the better maybe I also need to do one with the differences
@desaironak11
@desaironak11 4 года назад
Magnus Holmberg that would be great.
@desaironak11
@desaironak11 4 года назад
when are you plan to upload the next videos?
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 4 года назад
It will be uploaded on Saturday :) Sadly been very busy the last weeks so haven't been able to upload anything the last 2 weeks.
@kiran80863
@kiran80863 2 года назад
learn how to generate but kindly explain i I o O which was generated on output.. how to analyze
Далее
Check Point | Backups
26:24
Просмотров 7 тыс.
Check Point MDS | Basic CLI commands
17:01
Просмотров 5 тыс.
Check Point Firewall - Bulk operations in mgmt_cli
16:22
Understanding fw monitor utility
27:13
Просмотров 10 тыс.
Check Point | 3rd Party Site to Site VPN
26:58
Просмотров 18 тыс.
Basic Troubleshooting Command in CheckPoint Firewall
17:08
Install Checkpoint Firewall R81 on Eve ng
19:28
Просмотров 9 тыс.