- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: SNMP OID for VPN certificate expiry?
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SNMP OID for VPN certificate expiry?
Is there a way to monitor the VPN certificate expiry date via SNMP?
I've been searching for an OID to use in my monitoring platform and haven't found one yet 🙄
For bonus points, is there a way via SNMP to monitor the expiry date of InternalCA.p12 (as per sk158096)?
Thanks,
Matt
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Here are the OIDs
stattest get 1.3.6.1.4.1.2620.1.1.101 - status_code
stattest get 1.3.6.1.4.1.2620.1.1.102 - short_description
stattest get 1.3.6.1.4.1.2620.1.1.103 - long_description
We'll add it to the SK
https://support.checkpoint.com/results/sk/sk178304
SmartConsole shows a warning or error icon near the Security Gateway / Cluster object about an expiring VPN certificate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
snmpget on OID 1.3.6.1.4.1.2620.1.1.102.0 will give you some information.
We will use it to create a ticket as soon as it is not OK. Giving us enough time to renew the certifcate in time.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Improving monitoring of certificates is planned.
In general you can otherwise extend SNMP with bash scripts (refer sk90860) to achieve in lieu of official OIDs, if SNMP options are a must.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Here are the OIDs
stattest get 1.3.6.1.4.1.2620.1.1.101 - status_code
stattest get 1.3.6.1.4.1.2620.1.1.102 - short_description
stattest get 1.3.6.1.4.1.2620.1.1.103 - long_description
We'll add it to the SK
https://support.checkpoint.com/results/sk/sk178304
SmartConsole shows a warning or error icon near the Security Gateway / Cluster object about an expiring VPN certificate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is there any update of monitoring Certificates by SNMP?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Not as far as I know.
Note that in R82 we are adding additional monitoring for VPN…not sure how it will translate to SNMP.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
snmpget on OID 1.3.6.1.4.1.2620.1.1.102.0 will give you some information.
We will use it to create a ticket as soon as it is not OK. Giving us enough time to renew the certifcate in time.
