<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unrealistic number sent on SNMP in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unrealistic-number-sent-on-SNMP/m-p/230453#M44341</link>
    <description>&lt;P&gt;I know P is for push in tcpdump, but here, comparing screenshots you sent, from the 2nd one, number matches in billions, so logically, sounds like it would imply 15 billion packets? Just my ecucated guess...&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Tue, 22 Oct 2024 13:48:49 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-10-22T13:48:49Z</dc:date>
    <item>
      <title>Unrealistic number sent on SNMP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unrealistic-number-sent-on-SNMP/m-p/230423#M44338</link>
      <description>&lt;P&gt;Hello everyone!&lt;/P&gt;&lt;P&gt;Could anyone illuminate me if the number I see in Skyline actually is realistic?&lt;/P&gt;&lt;P&gt;We see a "P" suffix in TCP Established column in cpview:&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28158i648790A5F12A5E2B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And in Skyline we see this number:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28159i9E3E369E2AA56D27/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2.png" alt="2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, I'm pretty sure that the "P" doesn't stand for Psycho. But the number we see there surely is!&lt;/P&gt;&lt;P&gt;asg_perf -v shows this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-10-22 155846.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28160i8B8E86F28EF50E05/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2024-10-22 155846.png" alt="Screenshot 2024-10-22 155846.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;To be honest, I want to say that there is no problem, given the numbers here. But without knowing what P means, I can't really be confident.&lt;/P&gt;&lt;P&gt;Any opinions would be much appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2024 13:01:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unrealistic-number-sent-on-SNMP/m-p/230423#M44338</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2024-10-22T13:01:28Z</dc:date>
    </item>
    <item>
      <title>Re: Unrealistic number sent on SNMP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unrealistic-number-sent-on-SNMP/m-p/230447#M44339</link>
      <description>&lt;P&gt;Which SNMP (OID) number are you comparing, are you confusing Skyline vs SNMP?&lt;/P&gt;</description>
      <pubDate>Sun, 27 Oct 2024 22:29:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unrealistic-number-sent-on-SNMP/m-p/230447#M44339</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-10-27T22:29:19Z</dc:date>
    </item>
    <item>
      <title>Re: Unrealistic number sent on SNMP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unrealistic-number-sent-on-SNMP/m-p/230453#M44341</link>
      <description>&lt;P&gt;I know P is for push in tcpdump, but here, comparing screenshots you sent, from the 2nd one, number matches in billions, so logically, sounds like it would imply 15 billion packets? Just my ecucated guess...&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2024 13:48:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unrealistic-number-sent-on-SNMP/m-p/230453#M44341</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-10-22T13:48:49Z</dc:date>
    </item>
    <item>
      <title>Re: Unrealistic number sent on SNMP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unrealistic-number-sent-on-SNMP/m-p/230664#M44388</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;sorry for the late answer.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We have monitoring configured via Skyline (metrics from cpview are sent from the SGM to the Prometheus DB, after which they are visualized in Grafana).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Do you happen to know what "P" stands for in cpview?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2024 07:08:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unrealistic-number-sent-on-SNMP/m-p/230664#M44388</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2024-10-24T07:08:02Z</dc:date>
    </item>
    <item>
      <title>Re: Unrealistic number sent on SNMP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unrealistic-number-sent-on-SNMP/m-p/230674#M44393</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;I've tested the behavior of the "TCP Established" column in a lab, and the moment connections close, the number decreases. And it increases as new connections are made (I wrote a bash script to create concurrent connections).&lt;/P&gt;&lt;P&gt;Could it be that that Maestro is receiving an attack?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2024 08:33:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unrealistic-number-sent-on-SNMP/m-p/230674#M44393</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2024-10-24T08:33:12Z</dc:date>
    </item>
    <item>
      <title>Re: Unrealistic number sent on SNMP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unrealistic-number-sent-on-SNMP/m-p/230919#M44456</link>
      <description>&lt;P&gt;I think that number means "Peta", considering the number in Grafana starts with the same 5 digits. At least math check out there. So this means SNMPD actually sends the correct number ("18446P") from CPView.&lt;/P&gt;&lt;P&gt;Then my question is, whether the value in TCP Establised column decreases as the connections close. In my lab, I tried establishing some 500 connections from a host and I see the increase in numbers, but when I close the connections it goes back down.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So which one is the correct behavior, the total values of all times, or only the value of active TCP connections?&lt;/P&gt;</description>
      <pubDate>Sun, 27 Oct 2024 18:10:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unrealistic-number-sent-on-SNMP/m-p/230919#M44456</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2024-10-27T18:10:36Z</dc:date>
    </item>
  </channel>
</rss>

