- Products
- Learn
- Local User Groups
- Partners
- More
Scaling Check Point Automation with Arodonata
7 October @ 5pm CET / 11am EDT
AI Security Masters
LGTM: Bypassing an LLM Build Gate
When Prompt Injection Fails
What's New in Check Point SASE
The State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
CheckMates Go:
Half is Not Enough
Hi
We allow SNMP through our gateways, and SNMP gets work fine. Recently we have a requirement to do a set via SNMP but the gateways are dropping it
Inspection Item: SNMP: Non read operation
Inspection Information: SNMP: Non read operation was detected
Severity: Medium
Performance Impact: Medium
Inspection Category: anomaly
Inspection Profile: Recommended Inspection
Action: Drop
We have a policy rule that explicitly allows SNMP traffic. We have an inspection exception for SNMP. Still it gets dropped.
We have a TAC case open but no answers yet.
Anybody know how to make this work?
Thanks
SNMP v3 is encrypted and fw should not be able to see it. Maybe as workaround? SNMP v3 is best practice anyway.
If does not help you need to make a IPS core protection expection. Firewall rule itself will not affect this. Even if ips blade is not enabled some core protections are enabled by default
We put in an exception. the gateway still drops the traffic
Need to see traffic log and exception rule screenshot
https://support.checkpoint.com/results/sk/sk98081
Need to see the full log card of the drop (mask sensitive details).
Time: 2026-05-27T10:21:04Z
Interface Direction: inbound
Interface Name: eth2
Source: x.x.x.x
Source Port: 57217
Destination: y.y.y.y
Destination Port: 161
IP Protocol: 17
Inspection Item: SNMP: Non read operation
Inspection Information: SNMP: Non read operation was detected
Severity: Medium
Performance Impact: Medium
Inspection Category: anomaly
Inspection Profile: Recommended Inspection
Action: Drop
Type: Log
Policy Name: zzz
Policy Management: Manager
Policy Date: 2026-05-27T10:19:26Z
Blade: Firewall
Origin: Gateway1
Service: UDP/161
Product Family: Access
Interface: eth2
This may be a protocol inspection drop rather than an IPS drop. Check Point includes two different service objects covering SNMP: one named 'snmp' and a separate object named 'snmp-read'. Right-click on the snmp-read object and pick Where Used. Is it in any of your rules or service groups? As the name suggests, that one only allows read operations.
we have the snmp object in the rule that should allow the traffic
Hi @Scott_Paisley ,
Any solution for this issue?
What does your rule allowing the traffic look like, which objects are in the services column of the rule?
SNMP services only is added in service column.
Defined like this?
Hi @Chris_Atkinson ,
Issue resolved, I have allowed the SNMP port like attached Image.
Also when i debug the traffic i am getting this error in CLI. Checkpoint is refers below document for this issue.
"dropped by fw_conn_post_inspect Reason: Handler 'snmp_ro_code' drop;"
https://support.checkpoint.com/results/sk/sk103405
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 34 | |
| 8 | |
| 6 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 | |
| 3 |
Thu 01 Oct 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point WAF | Preventing minus-zero-day attacksTue 06 Oct 2026 @ 12:00 PM (ACDT)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus APACTue 06 Oct 2026 @ 03:00 PM (CEST)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus EMEAThu 01 Oct 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point WAF | Preventing minus-zero-day attacksTue 06 Oct 2026 @ 12:00 PM (ACDT)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus APACTue 06 Oct 2026 @ 03:00 PM (CEST)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus EMEATue 06 Oct 2026 @ 02:00 PM (EDT)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus AMERAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY