<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Monitoring of connection tables in Firewall &amp; Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Monitoring-of-connection-tables/m-p/47251#M87331</link>
    <description>&lt;P&gt;Thats actually really great idea to have monitoring of provided (or all) kernel tables in place.&lt;/P&gt;
&lt;P&gt;I can imagine to have syntax something like:&lt;/P&gt;
&lt;PRE&gt;snmpwalk &amp;lt;kernel_table&amp;gt; &amp;lt;threshold&amp;gt;&lt;/PRE&gt;
&lt;P&gt;On the other hand, is there way to check name of all kernel tables ?&lt;/P&gt;</description>
    <pubDate>Sun, 17 Mar 2019 10:28:59 GMT</pubDate>
    <dc:creator>JozkoMrkvicka</dc:creator>
    <dc:date>2019-03-17T10:28:59Z</dc:date>
    <item>
      <title>Monitoring of connection tables</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Monitoring-of-connection-tables/m-p/47053#M87328</link>
      <description>&lt;P&gt;I'm looking for a way to monitor and alert on connection table usage and wondered if anyone has come across a way to do it this effectively. This could either be based on a figure or percentage.&amp;nbsp; Ideally I would like some sort of SNMP trap or email when a table reaches 75-80% of its capacity. This is something&amp;nbsp; I would then like use on all our firewalls.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our current setup is R80.10 management (take 189) with a mixture of R80.10 / R77.30 gateways all running VSX which the exception of one stand alone firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2019 12:20:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Monitoring-of-connection-tables/m-p/47053#M87328</guid>
      <dc:creator>Leandro_Nicolet</dc:creator>
      <dc:date>2019-03-15T12:20:15Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of connection tables</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Monitoring-of-connection-tables/m-p/47060#M87329</link>
      <description>&lt;P&gt;If you have the IPS blade, enable the Aggressive Aging signature with the parameters you want, then set the Track for that signature to Email or SNMP Trap.&amp;nbsp; Email recipient and/or trap receiver is configured under Global Properties...Log &amp;amp; Alert...Alerts.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2019 13:15:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Monitoring-of-connection-tables/m-p/47060#M87329</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-03-15T13:15:56Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of connection tables</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Monitoring-of-connection-tables/m-p/47075#M87330</link>
      <description>&lt;P&gt;You can certainly monitor the number of connections,&amp;nbsp;CheckPointfwNumConn, (not exactly connection table) via SNMP. We monitor that with Solarwinds, and could probably alert from there.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2019 15:15:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Monitoring-of-connection-tables/m-p/47075#M87330</guid>
      <dc:creator>Scott_Paisley</dc:creator>
      <dc:date>2019-03-15T15:15:15Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of connection tables</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Monitoring-of-connection-tables/m-p/47251#M87331</link>
      <description>&lt;P&gt;Thats actually really great idea to have monitoring of provided (or all) kernel tables in place.&lt;/P&gt;
&lt;P&gt;I can imagine to have syntax something like:&lt;/P&gt;
&lt;PRE&gt;snmpwalk &amp;lt;kernel_table&amp;gt; &amp;lt;threshold&amp;gt;&lt;/PRE&gt;
&lt;P&gt;On the other hand, is there way to check name of all kernel tables ?&lt;/P&gt;</description>
      <pubDate>Sun, 17 Mar 2019 10:28:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Monitoring-of-connection-tables/m-p/47251#M87331</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2019-03-17T10:28:59Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of connection tables</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Monitoring-of-connection-tables/m-p/47269#M87332</link>
      <description>&lt;P&gt;fw tab (no arguments) should show you all the different kernel table names.&lt;/P&gt;</description>
      <pubDate>Sun, 17 Mar 2019 15:22:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Monitoring-of-connection-tables/m-p/47269#M87332</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-03-17T15:22:31Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of connection tables</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Monitoring-of-connection-tables/m-p/47465#M87333</link>
      <description>&lt;P&gt;Thanks everyone. Will probably have a look at what we can do with SNMP and Solarwinds.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 14:39:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Monitoring-of-connection-tables/m-p/47465#M87333</guid>
      <dc:creator>Leandro_Nicolet</dc:creator>
      <dc:date>2019-03-18T14:39:24Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of connection tables</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Monitoring-of-connection-tables/m-p/195738#M87334</link>
      <description>&lt;P&gt;if i am not wrong when we enable the AA with the parameters, it will only delete the connections ?&lt;/P&gt;&lt;P&gt;how to get alerts when concurrent connections reach to max 80% ?&lt;/P&gt;&lt;P&gt;want to know the exact steps to set up alert .&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2023 07:28:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Monitoring-of-connection-tables/m-p/195738#M87334</guid>
      <dc:creator>tavi0906</dc:creator>
      <dc:date>2023-10-20T07:28:40Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of connection tables</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Monitoring-of-connection-tables/m-p/195745#M87335</link>
      <description>&lt;P&gt;These are the options Timothy has referenced:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GP Alert Settings.PNG" style="width: 774px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22889i9A0BB65AF57F3885/image-size/large?v=v2&amp;amp;px=999" role="button" title="GP Alert Settings.PNG" alt="GP Alert Settings.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AA Alert.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22890i8D3D0F96799A7061/image-size/large?v=v2&amp;amp;px=999" role="button" title="AA Alert.PNG" alt="AA Alert.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2023 07:51:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Monitoring-of-connection-tables/m-p/195745#M87335</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-10-20T07:51:05Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of connection tables</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Monitoring-of-connection-tables/m-p/195748#M87336</link>
      <description>&lt;P&gt;Yes, i have gone through this options before but my doubt is can we an alert when we set this options, when the concurrent connections reaches 80 % percent ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2023 09:56:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Monitoring-of-connection-tables/m-p/195748#M87336</guid>
      <dc:creator>tavi0906</dc:creator>
      <dc:date>2023-10-20T09:56:05Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of connection tables</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Monitoring-of-connection-tables/m-p/196237#M87337</link>
      <description>&lt;P&gt;we have 5 VSX&amp;nbsp; , we need to monitor the concurrent connections from solar winds. so, need OID values to monitor the concurrent connections ?&lt;/P&gt;&lt;P&gt;and also OID for all the VSX is same or different ?&lt;/P&gt;&lt;P&gt;i have gone through with the sk90860 and i am not sure what the exact OID values to use to monitor concurrent connections.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2023 02:59:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Monitoring-of-connection-tables/m-p/196237#M87337</guid>
      <dc:creator>tavi0906</dc:creator>
      <dc:date>2023-10-26T02:59:45Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of connection tables</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Monitoring-of-connection-tables/m-p/196243#M87338</link>
      <description>&lt;P&gt;80% of memory capacity or 80% of a static specified connection limit value, unless this is VSX the connection limit is usually "auto" and not defined with a set upper limit.&lt;/P&gt;
&lt;P&gt;The above would trigger when aggressive aging becomes active based on the AA defined thresholds.&lt;/P&gt;
&lt;P&gt;If your application is different potentially SNMP monitoring or Skyline might be better suited to your use case.&lt;/P&gt;
&lt;P&gt;What memory population does your system have versus what's possible for that system / appliance model?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SNMP.PNG" style="width: 708px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22953iB39FC15B8B8BAC81/image-size/large?v=v2&amp;amp;px=999" role="button" title="SNMP.PNG" alt="SNMP.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Source:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk90860" target="_blank" rel="noopener"&gt;How to configure SNMP on Gaia OS (checkpoint.com)&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2023 05:13:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Monitoring-of-connection-tables/m-p/196243#M87338</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-10-26T05:13:02Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of connection tables</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Monitoring-of-connection-tables/m-p/196637#M87340</link>
      <description>&lt;P&gt;Is this OID can use for VSX ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Because we already tries using this but couldn't get any results .&lt;/P&gt;&lt;P&gt;and OID's for all the VSX same or different ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Oct 2023 02:40:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Monitoring-of-connection-tables/m-p/196637#M87340</guid>
      <dc:creator>tavi0906</dc:creator>
      <dc:date>2023-10-31T02:40:43Z</dc:date>
    </item>
  </channel>
</rss>

