Tuesday, 14 February 2017

interface groups on checkpoint

Network objects -> Right click on cluster -> details -> Topology
Click details on the IP addresses
Right click on the cluster IP -> Edit interface
Go to Topology tab
Look for the radio button
IP addresses behind this interface
Specific
The interface group should be selected there

The interface groups can be found under

Network objects -> groups ->



Thursday, 2 February 2017

investigating NAT issues on checkpoint firewalls

In Network Objects (bottom left)
Right click Nodes -> More -> Query Objects
Refine by: Search by IP

Double click on the object and check the NAT section for auto NAT

Also you can do Actions -> Where used -> Active policy
Look for any manual NAT's here

Try the traffic while watching the logs in the tracker
You can add the columns xlatesrc and NAT rule into the tracker
Also you can double click the log entry and get more details on the NAT rule and xlated source

Auto NAT's are processed first
Manual NAT's second


In some cases you may need to add and arp
SSH to CLI of CP firewall
clish 
show configuration
Looks for arp
add arp proxy ipv4-address x.x.x.x. interface eth1-02 real-ipv4-address y.y.y.1

x.x.x.x is the IP of your server
y.y.y.y is the IP of your gateway

Tuesday, 10 January 2017

3com / hp switch commands

Find what port a mac address is learned on
display mac-address 0860-6EE5-DFBD

Show all mac addresses learned on a port
display mac-address interface GigabitEthernet 1/0/9

Show connected switches like show cdp on cisco
display ndp
display ndp interface GigabitEthernet 1/0/9

Disable paging (5500)
user-interface vty 0 4
screen-length 0

Display what interfaces are up/down
display brief interfaces

Show the IP address on the VLAN interfaces
display ip interface brief

Create SVI interface
interface vlan-interface 10
ip address etc

Create loopback interface
interface loopback 1
ip address etc

Show running config
display current-configuration

Enable mode
system-view (sometimes you need to type super first)

Show stp status
display stp brief

Show saved config (in case of switch reboot with blank cfg)
display saved-config
display startup

List files on disk
dir (not in expert mode)


debug a single vpn on cisco asa


debug crypto condition

https://supportforums.cisco.com/blog/150056/ipsec-important-debugging-and-logging


Friday, 6 January 2017

setting up packet captures on the cisco ASA

cap capin interface inside match ip host 192.168.1.50 host 200.100.100.100 circular-buffer

This will capture data in both directions
circular buffer means it will overwrite when buffer is full
Otherwise it will fill up and stop capturing
You can use clear cap capin to clear out the data

Will capture all the drops of any type
capture asp-drop type asp-drop all
sh cap asp-drop

You can also look in sh asp drop to see if they are increasing

The capture file can be saved and copied off the ASA:

https://100.100.100.200/capture/my-cap-name/pcap

To save the capture file
copy /pcap capture: disk0:

Copy the file off with CLI or ASDM file transfer.

There is also a way to connect ASDM directly to wireshark.

time based ACL on ASA

It can be easier to setup in the ASDM


Set up the time range to end on a certain date
time-range TR_expire_acl
 absolute end 14:00 07 January 2017

Create your ACL as normal and add the time range on the end.
access-list INSIDE-OUT extended permit ip host 192.168.10.50 any time-range TR_expire_acl