- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Introducing Check Point Quantum Spark 2500:
Smarter Security, Faster Connectivity, and Simpler MSP Management!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hi All,
There is readily available script for Gaia based system on checkpoint. It checks almost all parameters. May be some are aware of this but who are unaware, it is very useful script.
You can refer sk121447 and download the readily available Health check Script. It is very useful and measure all the required parameters.
Hope This will be helpful.
Yep healthcheck.sh is definitely a great tool. A picture is worth a thousand words, so here are a few screenshots of it from the second edition of my book:
--
My Book "Max Power: Check Point Firewall Performance Optimization"
Second Edition Coming Soon
Yeah. I have started to run this script on our some of the firewall to health check. It gives all information with nice look.
Can we run health check commend in production hour?. Because warring about memory and cpu utilization.
Thanks Timothy,
The current book is quite useful as well. Cant wait for the next one.
Great tool. I didn't know my CPUSE was out of date until I ran the tool. Very useful!
Yeah.
It also gives sk number as well to rectify/update the things
Thanks Nathan Davieau and Rosemarie Rodriguez for this useful utility. We are looking forward to new additions, such as load and VPN statistics etc. I would like if this community could help making the script better and better. My colleagues are already asking to fork the script to add more functions to it.
Thank you! We'll continue to improve it. We'll see what we can do in regards to the requests for new additions.
Hi Rosemarie Rodriguez, if you think it should be a healthy check to verify if a Security Gateway is installation target of multiple policy packages (I was confronted with this situation and hopefully... more fear than harm), I've created https://community.checkpoint.com/docs/DOC-2624 which can verify that on a R77.* SMS (using dbedit).
Do you know how to propose new things to check ? I've created https://community.checkpoint.com/docs/DOC-2624 to verify if firewall(s) is/are installation target(s) of multiple policy packages (based on real story...). I assume that could be a healthy test on any environment with lot of firewalls and policy packages ?
Hi Xavier,
I have not customized any script but you can check with Rosemarie for more information. May be also you can edit the healthcheck.sh file and put your content on it.
Hello,
I tried the latest version of the healthcheck.sh script on our vsx cluster of three vsls Members. Unfortunately, Output for the "Backup" member is mangled (see below).
Does anyone know who to turn to for bug reports?
regards, Arne
You can write a comment in sk121447 or open a support ticket with TAC. Unfortunately the only updates Check Point has provided to the script since last year were just CPInfo version number updates, no real code improvements or additions. Maybe your request will make the script to receive further development and love from Check Point.
Hi Rosemarie Rodriguez, will you be able to take care of every modification Check Mates proposed on this thread? That's important for us Thanks in advance.
Do you still have this issue with the latest version?
Hello,
I just verified the latest version on our R80.20 VSX Cluster of three members with VSLS. It still reports the same error for the Backup member:
Current Script Release: 6.11 04-25-2019
Virtual System 10
Context is set to Virtual Device ******** (ID 10).
+-----------------------+-------------------------------+---------------+
| Category | Title | Result |
+=======================+===============================+===============+
| VSX | SIC Status | OK |
| | Security Policy | OK |
+-----------------------+-------------------------------+---------------+
| Fragments | Fragments | OK |
+-----------------------+-------------------------------+---------------+
| Connections Table | Peak Connections | OK |
| | Current Connections | OK |
| | NAT Connections | OK |
+-----------------------+-------------------------------+---------------+
| ClusterXL | Cluster Status | WARNING |
./healthcheck.sh: line 2746: printf: `B': invalid format character
./healthcheck.sh: line 2747: printf: `B': invalid format character
| | Problem Notifications | WARNING |
| | Sync Status | OK |
| | Number of Sync Interfaces | OK |
| | Cluster Failovers | OK |
+-----------------------+-------------------------------+---------------+
| SecureXL | SecureXL Status | OK |
| | Accept Templates | WARNING |
| | Drop Templates | INFO |
| | Aggressive Aging | OK |
+-----------------------+-------------------------------+---------------+
| Logging | Local Logging | OK |
+-----------------------+-------------------------------+---------------+
[Expert@********:10]# cphaprob stat
Cluster Mode: Virtual System Load Sharing
ID Unique Address Assigned Load State Name
1 x.y.z.241 0% STANDBY
2 (local) x.y.z.242 0% BACKUP
3 x.y.z.243 100% ACTIVE
Hi, is there a way run that kind of health check script in chassis family (41K & 61K). There is a limitation for this script written in sk121447
Yeah. There is limitations. May be developer team will take care this in future.
hi @Gaurav_Pandya the health check script (healthcheck.sh) is no more available in sk121447 where do I get it ?
Hi - this is the direct link
https://support.checkpoint.com/results/download/59369
There's also HealthCheck Point:
https://support.checkpoint.com/results/sk/sk171436
The first link only works if you are already logged into the support site. go to support.checkpoint.com, log in with your UC account and try it again.
Yea I did that but error 404 is coming.
Then try from the first link, and/or remove browser cache & cookies. It should work. I re-checked twice, the link is operational
can you please attach the script for me here. I think it is the ISP blocks some of links so we need to use proxies to access.
Many downloads from SupportCenter will return a 404 if you do not have Software Subscription associated with your account.
Please check this and consult with your local Check Point office for further assistance.
I have diamond support and the link is still 404 for me, even when loading the link from a session where I just logged in with my work User Center account.
Separately, 404 is objectively the wrong error code for that. 403 is right there.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
10 | |
7 | |
7 | |
6 | |
5 | |
5 | |
5 | |
5 | |
5 | |
4 |
Wed 10 Sep 2025 @ 11:00 AM (CEST)
Effortless Web Application & API Security with AI-Powered WAF, an intro to CloudGuard WAFWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY