Working with SNMP

You can use SNMP to monitor different aspects of the Security GroupClosed A logical group of Security Gateway Modules that provides Active/Active cluster functionality. A Security Group can contain one or more Security Gateway Modules. Security Groups work separately and independently from each other. To the production networks, a Security Group appears a single Security Gateway., including:

  • Software versions

  • Hardware status

  • Key performance indicators

  • High Availability status

Enabling SNMP Monitoring of Security Groups

Step

Instructions

1

Upload these Check Point MIB files from the Chassis to your third-party SNMP monitoring software:

  • The SNMP MIB file:

    $CPDIR/lib/snmp/chkpnt.mib

  • The SNMP Trap MIB file:

    $CPDIR/lib/snmp/chkpnt-trap.mib

2

Connect to the command line on the Security Group.

3

Log in to Gaia ClishClosed The name of the default command line shell in Check Point Gaia operating system. This is a restricted shell (role-based administration controls the number of commands available in the shell)..

4

Go to Gaia gClishClosed The name of the global command line shell in Check Point Gaia operating system for Security Gateway Modules. Commands you run in this shell apply to all Security Gateway Module in the Security Group.: enter gclish and press Enter.

5

Enable the GaiaClosed Check Point security operating system that combines the strengths of both SecurePlatform and IPSO operating systems. SNMP Agent:

set snmp agent on

save config

Supported SNMP OIDs for Security Groups

Only this branches is supported:

Branch

OID

asg

Numerical

1.3.6.1.4.1.2620.1.48

Full Text

.iso.org.dod.internet.private.enterprise.checkpoint.products.asg

Supported SNMP Trap OIDs for Security Groups

Only this SNMP Trap is supported:

Branch

OID

asgTrap

Numerical

1.3.6.1.4.1.2620.1.2001

Full Text

.iso.org.dod.internet.private.enterprise.checkpoint.products.asgTrap

Notes:

Common SNMP OIDs for Security Groups

This table shows frequently used SNMP OIDs that are applicable to Security Groups:

Name

Type

Numerical OID

Comments

System Throughput

String

IPv4:
.1.3.6.1.4.1.2620.1.48.20.1

IPv6:
.1.3.6.1.4.1.2620.1.48.21.1

 

System Connection Rate (connections per second)

String

IPv4:
.1.3.6.1.4.1.2620.1.48.20.2

IPv6:
.1.3.6.1.4.1.2620.1.48.21.2

 

System Packet Rate (packet per second)

String

IPv4:
.1.3.6.1.4.1.2620.1.48.20.3

IPv6:
.1.3.6.1.4.1.2620.1.48.21.3

 

System Concurrent Connections

String

IPv4:
.1.3.6.1.4.1.2620.1.48.20.4

IPv6:
.1.3.6.1.4.1.2620.1.48.21.4

 

System Accelerated Connections Per Second

String

IPv4:
.1.3.6.1.4.1.2620.1.48.20.6

IPv6:
.1.3.6.1.4.1.2620.1.48.21.6

 

System non-accelerated Connections Per Second

String

IPv4:
.1.3.6.1.4.1.2620.1.48.20.7

IPv6:
.1.3.6.1.4.1.2620.1.48.21.7

 

System Accelerated Concurrent Connections

String

IPv4:
.1.3.6.1.4.1.2620.1.48.20.8

IPv6:
.1.3.6.1.4.1.2620.1.48.21.8

 

System Non-accelerated Concurrent Connections

String

IPv4:
.1.3.6.1.4.1.2620.1.48.20.9

IPv6:
.1.3.6.1.4.1.2620.1.48.21.9

 

System CPU load - average

String

IPv4:
.1.3.6.1.4.1.2620.1.48.20.10

IPv6:
.1.3.6.1.4.1.2620.1.48.21.10

 

System Acceleration CPU load - average

String

IPv4:
.1.3.6.1.4.1.2620.1.48.20.11

IPv6:
.1.3.6.1.4.1.2620.1.48.21.11

 

System FW instances load - average

String

IPv4:
.1.3.6.1.4.1.2620.1.48.20.14

IPv6:
.1.3.6.1.4.1.2620.1.48.21.14

 

System VPN Throughput

String

IPv4:
.1.3.6.1.4.1.2620.1.48.20.17

IPv6:
.1.3.6.1.4.1.2620.1.48.21.17

 

System Path distribution (fast, medium, slow, drops)

Table

IPv4:
.1.3.6.1.4.1.2620.1.48.20.24

IPv6:
.1.3.6.1.4.1.2620.1.48.21.24

Path distribution of:

  • throughput

  • pps

  • cps

  • concurrent connections

Per-Security Group Member counters

Table

IPv4:
.1.3.6.1.4.1.2620.1.48.20.25

IPv6:
.1.3.6.1.4.1.2620.1.48.21.25

Counters of:

Performance peaks

Table

IPv4:
.1.3.6.1.4.1.2620.1.48.20.26

IPv6:
.1.3.6.1.4.1.2620.1.48.21.26

 

Sensors on every Chassis

Table

1.3.6.1.4.1.2620.1.48.22.1.1

Status details of:

  • Fans

  • SSMs

  • CPU temperature

  • CMM

  • PSUs

  • PSU Fans

Resources on every Security Group Member

Table

1.3.6.1.4.1.2620.1.48.23

Memory and Hard Disk utilization

CPU Utilization on every Security Group Member

Table

1.3.6.1.4.1.2620.1.48.29