SNMP for Security Groups
|
Important - This topic described the steps to get aggregated SNMP data from all Security Group Members. To get SNMP data from a specific Security Group Member, see SNMP for Security Group Members. |
You can use SNMP to monitor different aspects of a Security Group, including:
-
Software versions
-
Hardware status
-
Key performance indicators
-
High Availability status
Prerequisites
Step |
Instructions |
||
---|---|---|---|
1 |
On the Security Group, in Gaia Portal or Gaia gClish:
See the R82 Gaia Administration Guide > Chapter "System Management" > Section "SNMP". |
||
2 |
Upload these Check Point MIB files from the Security Group to your third-party SNMP monitoring software:
|
Supported SNMP OIDs for Security Groups
Supported SNMP OIDs from the $CPDIR/lib/snmp/chkpnt.mib
file

OID Name |
OID Numerical Value |
OID Description |
||
---|---|---|---|---|
|
|
Main OID branch. |
||
|
|
Product name. |
||
|
|
Build version. |
||
|
|
Kernel version. |
||
|
|
Build number. |
||
|
|
Maximum number of Security Group Members per Site. |
||
|
|
Bitmask of active Security Group Members:
Example:
|
||
|
|
Bitmask of installed Security Group Members:
Example:
|
||
|
|
Date and time of the software installation. |
||
|
|
Time elapsed since the last startup. |
||
|
|
A string that contains the last SNMP Trap sent. |
||
|
|
Status code. |
||
|
|
Status short description. |
||
|
|
Status long description. |
||
|
|
Bitmask of the SecureXL status:
Example:
|
||
|
|
Bitmask of attached Security Group Members:
Example:
|
||
|
|
Various IPv4 performance counters:
|
||
|
|
Various IPv6 performance counters:
|
||
|
|
Hardware sensors (only on Scalable Chassis). |
||
|
|
Table that contains information and measured values of memory and disk partitions. |
||
|
|
Various counters for processed traffic protocols:
|
||
|
|
Various counters for processed traffic ports (services):
|
||
|
|
Network information:
|
||
|
|
|
||
|
|
Information about the Dual Site:
|
||
|
|
CPU utilization (in %) on each Security Group Member. |
||
|
|
Information about Traditional VSX mode for each Virtual System and in total:
|
||
|
|
List of diagnostic tests and their result.
|
Supported SNMP Trap OIDs for Security Groups
|
Note - The |
Supported SNMP Trap OIDs from the $CPDIR/lib/snmp/chkpnt-trap.mib
file

OID Name |
OID Numerical Value |
OID Description |
---|---|---|
|
|
Main OID branch. |
|
|
Information about the SNMP Trap message:
|
|
|
In Dual Site:
|
|
|
Information about an interface:
|
|
|
Information about storage devices:
|
|
|
Information about CPU cores:
|
|
|
Information about memory:
|
|
|
Information about a license |
|
|
Information about hardware sensors (only on Scalable Chassis):
|
|
|
Information about performance:
|
|
|
Additional information:
|
Supported additional SNMP Trap OIDs

-
Syntax in Gaia gClish on a Security Group to see all supported thresholds:
show cluster alert_threshold[Esc][Esc]
-
Syntax in Gaia gClish on a Security Group to see the description of a threshold:
show cluster alert_threshold <Threshold Name>[Space][Shift+?]
-
Syntax in Gaia gClish on a Security Group to see the current threshold value:
show cluster alert_threshold <Threshold Name>
-
Syntax in Gaia gClish on a Security Group to configure a threshold value:
set cluster alert_threshold <Threshold Name> <Threshold Value>
SNMP Trap Name |
SNMP Trap Description |
---|---|
|
Sends an SNMP Trap with the results of all applicable tests. |
|
The state of a Security Group Member changed. |
|
The state of a Site changed. |
|
The number of concurrent connections is above or lower than the configured thresholds. Thresholds:
|
|
The rate of connections is above or lower than the configured thresholds. Thresholds:
|
|
The CPU utilization is above or lower than the configured thresholds. Thresholds:
|
|
The hard disk utilization is above or lower than the configured thresholds. Thresholds:
|
|
Applies only to Scalable Chassis. One of these:
|
|
Applies only to Scalable Chassis. One of these:
|
|
Applies only to Scalable Chassis. One of these:
|
|
Applies only to Scalable Chassis. An event occurred in a Chassis Management Module (CMM). |
|
Applies only to Scalable Chassis. One of these:
|
|
The state of a port that is configured in a Link State Propagation (LSP) Group changed. See: |
|
A memory leak was detected. |
|
The memory utilization is above or lower than the configured thresholds. Thresholds:
|
|
|
|
The packet rate is above or lower than the configured thresholds. Thresholds:
|
|
The state of a port link changed. |
|
The throughput is above or lower than the configured thresholds. Thresholds:
|
SNMP Monitoring of Security Groups in the VSNext / Traditional VSX Mode
For more information, see the:
Common SNMP OIDs for Security Groups
This table shows frequently used SNMP OIDs that are applicable to Security Groups:
Name |
Type |
Numerical OID |
Comments |
||
---|---|---|---|---|---|
System Throughput |
String |
IPv4: IPv6: |
|
||
System Connection Rate (connections per second) |
String |
IPv4: IPv6: |
|
||
System Packet Rate (packet per second) |
String |
IPv4: IPv6: |
|
||
System Concurrent Connections |
String |
IPv4: IPv6: |
|
||
System Accelerated Connections Per Second |
String |
IPv4: IPv6: |
|
||
System non-accelerated Connections Per Second |
String |
IPv4: IPv6: |
|
||
System Accelerated Concurrent Connections |
String |
IPv4: IPv6: |
|
||
System Non-accelerated Concurrent Connections |
String |
IPv4: IPv6: |
|
||
System CPU load - average |
String |
IPv4: IPv6: |
|
||
System Acceleration CPU load - average |
String |
IPv4: IPv6: |
|
||
System FW instances load - average |
String |
IPv4: IPv6: |
|
||
System VPN Throughput |
String |
IPv4: IPv6: |
|
||
System Path distribution (fast, medium, slow, drops) |
Table |
IPv4: IPv6: |
Path distribution of:
|
||
Per-Security Group Member counters |
Table |
IPv4: IPv6: |
Counters of:
|
||
Performance peaks |
Table |
IPv4: IPv6: |
|
||
Sensors on every Chassis |
Table |
1.3.6.1.4.1.2620.1.48.22.1.1 |
Status details of:
|
||
Resources on every Security Group Member |
Table |
1.3.6.1.4.1.2620.1.48.23 |
Memory and Hard Disk utilization |
||
CPU Utilization on every Security Group Member |
Table |
1.3.6.1.4.1.2620.1.48.29 |
|