To export Check Point Firewall-1 Log files for Net Report you must be familiar with the following. Check Point commands: • fw logswitch (please see Section. Sometimes you may face error when try to access SecurePlatform via Win SCP. This user is needed when we want to copy some files into Checkpoint or upload. Connection to the Security Gateway through the WinSCP application fails, although the SSH connection works.

In my lab, I am running the R The lab environment consists of a Windows 10 PC which will be both the source of traffic capture and act as SCP-client to extract the packet capture files from the firewall on the internal network, and a pair of Check Point Security Gateways firewalls working together as a cluster with SG1 being the currently active firewall. The cluster is also connected to the internet and has basic rules set up to allow the lab-PC to access the internet, as well.

You can download it from their website link. For the configuration of the actual firewalls, you can use either CLI or the web-GUI, instructions for both ways will follow down below. If you have a redundant setup using clustered firewalls, make sure you are doing these steps on the firewall that is currently active , as this is where we will want the user to exist since we will be capturing traffic on this firewall. Next, we need to create a new user account in Gaia that is going to be used to access the packet capture files once we have created them using TCPdump.

Create a username, password and assign the correct Shell and also the correct Role , that we created in the previous step. Now, there are thousands of ways to specify what kind of traffic you want TCPdump to capture, and you can find the syntax for these commands by searching the web, as I am no expert.

To make things simple, navigate to the home directory of your newly created user scpAccount and run the packet capture from there, which will also save the resulting packet capture file here and ready to be picked up using SCP later. After starting your TCPdump, you can see a live counter showing how many packets have been captured so far. You will see a final counter displaying many packets that have been recorded in the file.

We can see that the file has been created by listing the files in the current directory:. Now that the packet capture is done, all we need to do is grab the file from our Windows 10 PC and launch it in WireShark to see the content. Do note that the username is case-sensitive! By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.

Off-Topic Discussions. Create a Post. Turn on suggestions. Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type. Showing results for. Search instead for. Did you mean:. Sign In Help. CheckMates : Products : General Topics : winscp issue with checkpoint. As you can see below in the screenshots nothing shows up on the path- As you can see above the backup is clearly there but nothing in winscp path. Thanks and Regards. All forum topics Previous Topic Next Topic.

PhoneBoy Admin. First of all, there is no need to panic here because your trial license will expire. It just means you will not be able to use SmartConsole to change the security policy, etc. Once you apply a new license, everything will still be there.

