Cppcap - A Check Point Traffic Capture Tool
Cppcap - A Check Point Traffic Capture Tool
NS
My Favorites
Symptoms
Running TCPDUMP causes a significant increase in CPU usage and as a result impact the
performance of the device.
Even while filtering by specific interface or port still high CPU occurs.
Cause
TCPDUMP is a Linux tool which at times is not suitable for use with Gaia. Its design might
increase CPU usage.
Solution
A New tool was created by Check Point which better fits Gaia OS - CPPCAP.
The tool is included in the R80.40 and higher versions.
'CPPCAP' is a traffic capture tool which provides the most relevant outputs and is similar to
TCPdump.
https://support.checkpoint.com/results/sk/sk141412 1/5
2/11/24, 9:51 PM cppcap - A Check Point Traffic Capture Tool
The tool is adjusted to Gaia operating system yet requires installation of an applicable RPM.
NS
Notes:
Downloads:
Installation instruction:
/etc/init.d/start_cppcap stop
rpm -e cp_pcap
Note: Installation has no impact on performance, and does not require a reboot.
On Scalable Platforms:
NS
Instructions for running the CPPCAP tool:
[Expert@admin]# cppcap -h
Flag Description
-d <DIR> capture specific direction ('in' for inbound, 'out' for outbound)
-c <NUM> capture up to NUM bytes of frame (default 96, '0' for any size)
-w <FMT> file size limit with rotation followed by 'K'ilo,'M'ega or 'G'iga. Default is bytes
To have all verbose information add "-DNT" to the syntax to filter out specific interface or VS
by using capital letters.
https://support.checkpoint.com/results/sk/sk141412 3/5
2/11/24, 9:51 PM cppcap - A Check Point Traffic Capture Tool
Important notes:
It will provide outputs on ARP IPV4/IPV6, TCP and UDP traffic. Dynamic routing information will
not show all verbose information.
Example Output
Article Properties
Access Level
Advanced
Date Created
2018-11-29
Last Modified
2023-09-18
Our customer support team is only a click away and ready to help you 24 hours a day.
NS
Follow Us
™
YOU DESERVE THE BEST SECURITY
https://support.checkpoint.com/results/sk/sk141412 5/5