Using System Tools
R81.10.X Quantum Spark 1500, 1600, 1800, 1900, 2000 Appliances Locally Managed Administration Guide|67
Action
Available
From
Description
Firewall Monitor
Tool
R81.10.10 Opens a popup window, in which you can capture traffic
that passes through appliance interfaces.
Warnings:
n
When you use this tool, the CPU load
increases. Schedule a maintenance window.
n
When you select the option "-p all", the
CPU load increases significantly because this
tool shows the information for each inspection
chain module.
Notes:
n
The appliance runs the "fw monitor"
command with the specified parameters.
See the:
l
Quantum Spark R81.10.X CLI
Reference Guide for 1500, 1600, 1800,
1900, 2000 Appliances
> Chapter
"Miscellaneous Commands" > Section
"fw commands".
l
R81.10 CLI Reference Guide
> Chapter
"Security Gateway Commands" >
Section "fw" > Section "fw monitor".
n
Compared to the Tcpdump Tool:
l
This tool shows how each packet
passes through the Security Gateway
inspection chain modules.
l
This tool saves the captured traffic only
in the plain-text format (filename is "fw_
monitor.log").
n
You can view the captured traffic in real time
or save it into a plain-text file.
n
When you start a new traffic capture and save
it into a file, and a file with such name already
exists, the appliance adds a running number
to the default filename (this way, it does not
overwrite an existing file).
n
The appliance captures traffic only on
interfaces with a configured IP address.
n
The packet capture stops automatically if the
WebUI session ends.
Procedure: