sk141412 - cppcap - Check Point Traffic Capture Tool

cppcap - Check Point Traffic Capture Tool

Solution ID: sk141412
Technical Level: Basic
OS: Gaia
Last Modified: 2026-06-02

Solution

Table of Contents:

Overview

Check Point created a traffic capture tool for Gaia OS - CPPCAP.

This is a traffic capture tool that provides the most relevant outputs and is similar to the Linux tool TCPdump.

This tool was created to resolve various issues in the Linux tool TCPdump that significantly increased CPU load on Security Gateways.

Notes:

Availability

Version CPUSE Online Identifier Offline Download
R80.40 and higher The tool is built-in. N / A
R80.30 kernel 3.10 Check_point_R80.30_3.10_cp_pcap_sk141412.rpm Download (RPM)
R80.30SP kernel 3.10 Check_point_R80.30SP_cp_pcap_sk141412.rpm Download (RPM)
R80.30 kernel 2.6 Check_point_R80.30_cp_pcap_sk141412.rpm Download (RPM)
R80.20SP Check_point_R80.20SP_cp_pcap_sk141412.rpm Download (RPM)
R80.20 Check_point_R80.20_cp_pcap_sk141412.rpm Download (RPM)
R80.10 Check_point_R80.10_cp_pcap_sk141412.rpm Download (RPM)
R77.30 Check_point_R77.30_cp_pcap_sk141412.rpm Download (RPM)
R76SP.50 Check_point_R76SP.50_cp_pcap_sk141412.rpm Download (RPM)

Installation Instructions (for R80.30 and lower)

Note - Reboot or restart of Check Point services are not required.

See the CPUSE Administration Guide.

Platform Installation Instructions Uninstall Instructions
Security Gateways,
ClusterXL,
VRRP Cluster,
VSX Gateway,
VSX Cluster
1. Download the required offline RPM package.
2. Transfer the RPM package to the Security Gateway / each Cluster Member to some directory (for example, /var/log/).
3. Connect to the command line on the Security Gateway / each Cluster Member.
4. Log in to the Expert mode.
5. Install the RPM:

rpm -ivh --force --nodeps /<PATH>/<RPM_FILE>
6. Start the CPPCAP service:

/etc/init.d/start_cppcap start
1. Connect to the command line on the Security Gateway / each Cluster Member.
2. Log in to the Expert mode.
3. Stop the CPPCAP service:

/etc/init.d/start_cppcap stop
4. Uninstall the RPM:

rpm -e cp_pcap
Scalable Platforms 1. Download the required offline RPM package.
2. Transfer the RPM package to the Security Group to some directory (for example, /var/log/).
3. Connect to the command line on the Security Group.
4. Log in to the Expert mode.
5. Copy the RPM to all Security Group Members:

asg_cp2blades /<PATH>/<RPM_FILE>
6. Install the RPM on all Security Group Members:

g_all rpm -ivh --force --nodeps /<PATH>/<RPM_FILE>
7. Start the CPPCAP service on all Security Group Members:

g_all /etc/init.d/start_cppcap start
1. Connect to the command line on the Security Group.
2. Log in to the Expert mode.
3. Stop the CPPCAP service on all Security Group Members:

g_all /etc/init.d/start_cppcap stop
4. Uninstall the RPM on all Security Group Members:

g_all rpm -e cp_pcap

CLI Syntax

Important Note - On Scalable Platforms, the cppcap command does not support the g_all command (nor the g_cppcap command). You must move to the relevant Security Group Member and run the cppcap command.

cppcap -h
cppcap
-b <Limit of Bytes>
`-c {0

Parameters

Parameter Description
-h Shows the built-in help.
-b <Limit of Bytes> Specifies the maximum number of bytes to capture before the tool stops.
`-c {0 }`
`-d {in out}`
-D Captures verbose data for the Datalink Layer (Layer 2).
This parameter applies only if you do not use the parameter "-o" and show the captured traffic on the screen.
This parameter does not support dynamic routing protocols.
-f "<Filter>" Specifies the filter expression for traffic capture.
See pcap-filter(7).
-i <Interface> Captures traffic only in the specified interface.
To capture traffic in all interfaces, enter "-i any".
Such traffic capture increases the CPU utilization!
This parameter is mutually exclusive with the parameter "-I <Interface>".
This parameter is mandatory in:
- Check Point R82 and higher
-I <Interface> Captures traffic only in all interfaces, except the specified interface.
Such traffic capture increases the CPU utilization!
This parameter is mutually exclusive with the parameter "-i <Interface>".
-o <Output File> Specifies the path and the name of the output file.
If you do not specify this file, the tool shows the captured traffic on the screen.
To control the rotation of output files, use the parameters "-w <Limit of Files>" and "-W <Limit of Files>".
-N Captures verbose data for the Network Layer (Layer 3).
This parameter applies only if you do not use the parameter "-o" and show the captured traffic on the screen.
This parameter does not support dynamic routing protocols.
-p <Limit of Frames> Specifies the maximum number of frames to capture before the tool stops.
-Q Remove the timestamp from the traffic capture.
This parameter applies only if you do not use the parameter "-o" and show the captured traffic on the screen.
-T Captures verbose data for the Transport Layer (Layer 4).
This parameter applies only if you do not use the parameter "-o" and show the captured traffic on the screen.
This parameter does not support dynamic routing protocols.
-v <VSID to Include> In the VSX mode, captures traffic only in the specified Virtual System.
This parameter is mutually exclusive with the parameter "-V <VSID to Exclude>".
Support for this parameter is available in:
- R81 and higher
- R80.40 Jumbo Hotfix Accumulator, Take 38 and higher
-V <VSID to Exclude> In the VSX mode, captures traffic in all Virtual Systems, except the specified Virtual System.
This parameter is mutually exclusive with the parameter "-v <VSID to Include>".
Support for this parameter is available in:
- R81 and higher
- R80.40 Jumbo Hotfix Accumulator, Take 38 and higher
-w <Limit of File Size>
-w <Limit of File Size>K
-w <Limit of File Size>M
-w <Limit of File Size>G
Specifies the maximum size of the output file before the tool rotates this file.
To use this parameter "-w", you must use the parameter "-o <Output File>".
- "<Limit of File Size>" - Specifies the maximum size in bytes (this is the default).
- "<Limit of File Size>K" - Specifies the maximum size in kilobytes.
- "<Limit of File Size>M" - Specifies the maximum size in megabytes.
- "<Limit of File Size>G" - Specifies the maximum size in gigabytes.
-W <Limit of Files> Specifies the maximum number of rotated output files.
To use this parameter "-W", you must use the parameters "`-o -w [{K

Usage Examples

Example Traffic Capture Example Syntax
ARP and traffic with a specific host 192.168.3.57 cppcap -i eth0 -f "arp and host 192.168.3.57" -o /var/log/capture.pcap
Traffic with a specific host 192.168.3.57 - exclude SSH cppcap -i eth0 -f "host 192.168.3.57 and not tcp port 22"
ICMP with a specific host 192.168.3.57 - only in Virtual System 3 cppcap -i eth0 -f "icmp and host 192.168.3.57" -v 3 -o /var/log/capture.pcap
Traffic with a specific host 192.168.3.57 - save traffic in a maximum of 10 rotated output files, each file has a maximum size of 1 gigabyte cppcap -i eth0 -f "host 192.168.3.57" -W 10 -w 1G -o /var/log/capture.pcap

Known Limitations

ID Description
N/A Capturing traffic on all interfaces may cause high CPU usage and potential performance issues.
PRHF-32577,
PMTR-102272
Capturing does not require the -i or -I flags.
This problem was fixed and included starting from:
- Check Point R82
- Jumbo Hotfix Accumulator for R81.20 starting from Take 99
- Jumbo Hotfix Accumulator for R81.10 starting from Take 173

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access Level: General
Status: Approved by TAC
Date Created: 2018-11-29
Last Modified: 2026-06-02