- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
What is SNMP OID for CP FW number of new connections?
Is this OID returning anything for you: .1.3.6.1.4.1.2620.1.1.26.11.6 ?
As Hristo said, 1.3.6.1.4.1.2620.1.1.26.11.6.0 is the correct one. Works on enterprise appliances.
For SMB appliances, you have to use delta of 1.3.6.1.4.1.2620.1.1.25.3.0.
Please review sk90860 section 2-D for more information.
Is it .1.3.6.1.4.1.2620.1.1.25.22 ? But OID Description: " Connections rate since last start of Check Point services. ". I feel uncertain.
[Expert@PNS-CP4607-02:0]# snmpwalk -v 2c -c vpn123 localhost .1.3.6.1.4.1.2620.1.1.25.22
SNMPv2-SMI::enterprises.2620.1.1.25.22 = No Such Instance currently exists at this OID
What is wrong with it?
Try dropping the leading '.' and appending .0 to the end.
[Expert@PNS-CP4607-02:0]# snmpwalk -v 2c -c vpn123 localhost .1.3.6.1.4.1.2620.1.1.25.22.0
SNMPv2-SMI::enterprises.2620.1.1.25.22.0 = No Such Instance currently exists at this OID
To confirm is this a standard security gateway or are you running VSX and what version?
Do the other OIDs in 2-D return integer values...
Jumbo Take 351 GA and is your snmp monitoring generally working or does restarting the service help?
[Expert@HostName]# service snmpd status
[Expert@HostName]# service snmpd start
Given the limited details provided...
If anything it might be related to the NET-SNMP package version, updates available via TAC.
Is this OID returning anything for you: .1.3.6.1.4.1.2620.1.1.26.11.6 ?
As Hristo said, 1.3.6.1.4.1.2620.1.1.26.11.6.0 is the correct one. Works on enterprise appliances.
For SMB appliances, you have to use delta of 1.3.6.1.4.1.2620.1.1.25.3.0.
I found it using this simple command:
# cat CHECKPOINT-MIB | grep -i conn | grep -i rate
It returns:
fwConnectionsStatConnectionRate OBJECT-TYPE
"connection rate (per second) passing through the FireWall-1 Module"
"Writing logs localy, To log servers(0), Local configured (1) Local due to connectivity(2) Local due to high rate(3)"
Paste fwConnectionsStatConnectionRate in Google and the first result is the OID 😀
Some tools to explore the mibs:
ManageEngine MIB Browser:
https://www.manageengine.com/products/mibbrowser-free-tool/
Paessler MIB Importer:
https://www.paessler.com/tools/mibimporter
There are OIDs that are not in the mibs, but it helps.
Hello.
Using the OID 1.3.6.1.4.1.2620.1.1.26.11.6.0 we do have what seem to be accurate values for at least either the old CP-13500 gateways (without VSX) and in OpenServer environments (also without VSX).
However, when using the same OID when VSX is in place, it seems that the returned values are for VS ID 0, where there is no traffic.
Are you aware of any way for having this same connection rate metric per VSX being returned via a specific OID?
We do have other per VSX OIDs but my understanding is that none is specific for the connection rate, only for metrics such as the total number of connections, traffic, etc.
Thank you.
NOTE: only valid for non SMB firewalls.
Is cpsnmpd running? I think this is the process snmpd hands off to for checkpoint related oids.
If its not running do the following
cpconfig
chose option for checkpoint snmp extensions
exit
WARNING: This will do a cpstop / cpstart meaing all services will reload and including firewall policy.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 31 | |
| 18 | |
| 16 | |
| 14 | |
| 7 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 3 |
Tue 11 Nov 2025 @ 10:00 AM (CET)
Your First Response: Immediate Actions for Cyber Incident Containment- EMEAThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERTue 11 Nov 2025 @ 06:00 PM (COT)
San Pedro Sula: Risk Management al Horno: ERM, TEM & Pizza NightTue 11 Nov 2025 @ 06:00 PM (COT)
San Pedro Sula: Risk Management al Horno: ERM, TEM & Pizza NightTue 11 Nov 2025 @ 10:00 AM (CET)
Your First Response: Immediate Actions for Cyber Incident Containment- EMEAThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 13 Nov 2025 @ 10:00 AM (CET)
Cloud Architect Series - Guarding Generative AI: Next-Gen Application Security with CloudGuard WAFFri 14 Nov 2025 @ 10:00 AM (CET)
CheckMates Live Netherlands - Veriti, Threat Exposure ManagementWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsTue 11 Nov 2025 @ 06:00 PM (COT)
San Pedro Sula: Risk Management al Horno: ERM, TEM & Pizza NightTue 11 Nov 2025 @ 06:00 PM (COT)
San Pedro Sula: Risk Management al Horno: ERM, TEM & Pizza NightAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY