Syntax: fw ctl debug -m fw + {all | <
List of Debug Flags>}
Flag |
Description |
---|---|
|
Accounting data in logs for Application Control (also enable the debug of the module ' |
|
Advanced Patterns (signatures over port ranges) - runs under ASPII and CMI |
|
Accelerated Stateful Protocol Inspection Infrastructure (INPSECT streaming) |
|
ConnectControl - logical servers in kernel, load balancing |
|
Bridge mode |
|
Mirror and Decrypt feature - only mirror operations on all traffic |
|
Carrier Grade NAT (CGN/CGNAT) |
|
Connection Chain modules, cookie chain |
|
Chain forwarding - related to cluster kernel parameter |
|
Processing of Microsoft Common Internet File System (CIFS) protocol |
|
Processing of Citrix connections |
|
Context Management Interface/Infrastructure - IPS signature manager |
|
Processing of all connections |
|
Connections statistics for Evaluation of Heavy Connections in CPView (see sk105762) |
|
Anti-Virus content inspection |
|
Operations on Memory context and CPU context in the module ' |
|
Virtual de-fragmentation , cookie issues (cookies in the data structure that holds the packets) |
|
Correction layer |
|
CRYPTO-PRO Transport Layer Security (HTTPS Inspection) - Russian VPN GOST |
|
Encryption and decryption of packets (algorithms and keys are printed in clear text and cipher text) |
|
Processing of connections handled by the Mobile Access daemon |
|
Operations in the debug filters |
|
Processing of Data Loss Prevention connections |
|
DNS tunnels |
|
DNS queries |
|
DDoS attack mitigation (part of IPS) |
|
Check Point kernel attachment (access to kernel is shown as log entries) |
|
Reason for (almost) every dropped packet |
|
Operations in Drop Templates |
|
Dynamic log enhancement (INSPECT logs) |
|
End Point Quarantine (also AMD) |
|
General errors |
|
Event App features (DNS, HTTP, SMTP, FTP) |
|
Expiration issues (time-outs) in dynamic kernel tables |
|
Packet filtering performed by the Check Point kernel and all data loaded into kernel |
|
Processing of FTP Data connections (used to call applications over FTP Data - i.e., Anti-Virus) |
|
Operations related to the Context Management Interface/Infrastructure Loader Also see the Module ' |
|
Cluster configuration - changes in the configuration and information about interfaces during traffic processing |
|
Holding mechanism and all packets being held / released |
|
ICMP tunnels |
|
interface-related information (accessing the interfaces, installing a filter on an interfaces) |
|
Driver installation - NIC attachment (actions performed by the |
|
Integrity Client (enforcement cooperation) |
|
IOCTL control messages (communication between kernel and daemons, loading and unloading of the FireWall) |
|
Enforcement of IP Options |
|
IPS logs and IPS IOCTL |
|
Processing of IPv6 traffic |
|
Kernel-buffer memory pool (for example, encryption keys use these memory allocations) |
|
Kernel dynamic tables infrastructure (reads from / writes to the tables) Warning - Security Gateway can freeze / hang! |
|
Memory leak detection mechanism |
|
Creation of links in Connections kernel table (ID 8158) |
|
Everything related to calls in the log |
|
INSPECT Virtual Machine (actual assembler commands being processed) Warning - Security Gateway can freeze / hang! |
|
Issues with e-mails over POP3, IMAP |
|
Matching of connections to Threat Prevention Layers (multiple rulebases) |
|
Does not apply anymore Only on Security Gateway that runs on Windows OS: Transport Driver Interface information (interface-related information) |
|
Memory allocation operations |
|
Media Gateway Control Protocol (complementary to H.323 and SIP) |
|
Miscellaneous helpful information (not shown with other debug flags) |
|
ISP Redundancy |
|
Printsoutputsimilartothe " Also enable the debug flag ' |
|
Printsoutputsimilartothe " Also enable the debug flag ' |
|
Synchronization between cluster members of Multicast Routes that are added when working with Dynamic Routing Multicast protocols |
|
MSN over MSMS (MSN Messenger protocol) Also always enable the debug flag ' |
|
CoreXL-related (enables all the debug flags in the debug module ' |
|
Network Access Control (NAC) feature in Identity Awareness |
|
NAT issues - basic information |
|
NAT issues - 6in4 tunnels (IPv6 over IPv4) and 4in6 tunnels (IPv4 over IPv6) |
|
IPS protection "Network Quota" |
|
Non-TCP / Non-UDP traffic policy (traffic parser) |
|
Actions performed on packets (like Accept, Drop, Fragment) |
|
Stateless verifications (sequences, fragments, translations and other header verifications) |
|
Prevention of port scanning |
|
Connection profiler for Firewall Priority Queues (see sk105762) |
|
Driver queue (for example, cluster synchronization operations) This debug flag is crucial for the debug of Check Point cluster synchronization issues |
|
QoS (FloodGate-1) |
|
Resource Advisor policy (for Application Control, URL Filtering, and others) |
|
Routing issues This debug flag is crucial for the debug of ISP Redundancy issues |
|
Suspicious Activity Monitoring |
|
Processing of Stream Control Transmission Protocol (SCTP) connections |
|
SecureClient Verification |
|
Currently is not used |
|
VoIP traffic - SIP and H.323 Also see the: |
|
Issues with e-mails over SMTP |
|
Sockstress TCP DoS attack (CVE-2008-4609) |
|
Monitor mode (mirror / span port) |
|
Stateful Protocol Inspection Infrastructure and INSPECT Streaming Infrastructure |
|
IPS protection 'SYN Attack' (SYNDefender) |
|
Synchronization operations in Check Point cluster |
|
TCP streaming mechanism |
|
Prints the name of an interface for incoming connection from Threat Emulation Machine |
|
Currently is not used |
|
Processing of Universal Alcatel "UA" connections |
|
Processing of UserCheck connections in Check Point cluster |
|
User Space communication with Kernel Space (most useful for configuration and VSX debug) |
|
Currently is not used |
|
Virtual Machine chain decisions on traffic going through the |
|
Processing of Wireless Application Protocol (WAP) connections |
|
General warnings |
|
Wire-mode Virtual Machine chain module |
|
NAT issues - basic information |
|
NAT issues - additional information - going through NAT rulebase |
|
Memory allocations in the Zero-Copy kernel module |