- Products
- Learn
- Local User Groups
- Partners
- More
Ink Dragon: A Major Nation-State Campaign
Watch HereAI Security Masters E5:
Powering Prevention: The AI Driving Check Point’s ThreatCloud
The Great Exposure Reset
AI Security Masters E4:
Introducing Cyata, Securing the Agentic AI Era
CheckMates Go:
CheckMates Fest
What is SNMP OID for CP FW number of new connections?
Is this OID returning anything for you: .1.3.6.1.4.1.2620.1.1.26.11.6 ?
As Hristo said, 1.3.6.1.4.1.2620.1.1.26.11.6.0 is the correct one. Works on enterprise appliances.
For SMB appliances, you have to use delta of 1.3.6.1.4.1.2620.1.1.25.3.0.
Please review sk90860 section 2-D for more information.
Is it .1.3.6.1.4.1.2620.1.1.25.22 ? But OID Description: " Connections rate since last start of Check Point services. ". I feel uncertain.
[Expert@PNS-CP4607-02:0]# snmpwalk -v 2c -c vpn123 localhost .1.3.6.1.4.1.2620.1.1.25.22
SNMPv2-SMI::enterprises.2620.1.1.25.22 = No Such Instance currently exists at this OID
What is wrong with it?
Try dropping the leading '.' and appending .0 to the end.
[Expert@PNS-CP4607-02:0]# snmpwalk -v 2c -c vpn123 localhost .1.3.6.1.4.1.2620.1.1.25.22.0
SNMPv2-SMI::enterprises.2620.1.1.25.22.0 = No Such Instance currently exists at this OID
To confirm is this a standard security gateway or are you running VSX and what version?
Do the other OIDs in 2-D return integer values...
Jumbo Take 351 GA and is your snmp monitoring generally working or does restarting the service help?
[Expert@HostName]# service snmpd status
[Expert@HostName]# service snmpd start
Given the limited details provided...
If anything it might be related to the NET-SNMP package version, updates available via TAC.
Is this OID returning anything for you: .1.3.6.1.4.1.2620.1.1.26.11.6 ?
As Hristo said, 1.3.6.1.4.1.2620.1.1.26.11.6.0 is the correct one. Works on enterprise appliances.
For SMB appliances, you have to use delta of 1.3.6.1.4.1.2620.1.1.25.3.0.
I found it using this simple command:
# cat CHECKPOINT-MIB | grep -i conn | grep -i rate
It returns:
fwConnectionsStatConnectionRate OBJECT-TYPE
"connection rate (per second) passing through the FireWall-1 Module"
"Writing logs localy, To log servers(0), Local configured (1) Local due to connectivity(2) Local due to high rate(3)"
Paste fwConnectionsStatConnectionRate in Google and the first result is the OID 😀
Some tools to explore the mibs:
ManageEngine MIB Browser:
https://www.manageengine.com/products/mibbrowser-free-tool/
Paessler MIB Importer:
https://www.paessler.com/tools/mibimporter
There are OIDs that are not in the mibs, but it helps.
Hello.
Using the OID 1.3.6.1.4.1.2620.1.1.26.11.6.0 we do have what seem to be accurate values for at least either the old CP-13500 gateways (without VSX) and in OpenServer environments (also without VSX).
However, when using the same OID when VSX is in place, it seems that the returned values are for VS ID 0, where there is no traffic.
Are you aware of any way for having this same connection rate metric per VSX being returned via a specific OID?
We do have other per VSX OIDs but my understanding is that none is specific for the connection rate, only for metrics such as the total number of connections, traffic, etc.
Thank you.
NOTE: only valid for non SMB firewalls.
Is cpsnmpd running? I think this is the process snmpd hands off to for checkpoint related oids.
If its not running do the following
cpconfig
chose option for checkpoint snmp extensions
exit
WARNING: This will do a cpstop / cpstart meaing all services will reload and including firewall policy.
One of our customers SMB Appliance is running R81.10.17 and they wanted to query the connection rate. According to the MIB file the OID is .1.3.6.1.4.1.2620.1.1.26.11.6 but it doesn't seem to be the correct one:
#snmpwalk -v 2c -c mycommunity localhost .1.3.6.1.4.1.2620.1.1.26.11.6
SNMPv2-SMI::enterprises.2620.1.1.26.11.6 = No Such Instance currently exists at this OID
I checked the MIB file on the gateway and it is up to date, I have even replaced it with the current file from https://support.checkpoint.com/results/sk/sk90470 (I downloaded the file for Quantum Spark Appliances, R81.10.15).
Does anyone know what MIB to query?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 11 | |
| 7 | |
| 6 | |
| 6 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 |
Tue 17 Mar 2026 @ 02:00 PM (EDT)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - AMERWed 18 Mar 2026 @ 10:00 AM (CET)
The Cloud Architects Series: An introduction to Check Point Hybrid Mesh in 2026 - In Seven LanguagesThu 19 Mar 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #2: AI Security Challenges and SolutionsTue 24 Mar 2026 @ 04:00 PM (CET)
Maestro Masters EMEA: Hyperscale Firewall Architectures and OptimizationTue 17 Mar 2026 @ 02:00 PM (EDT)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - AMERWed 18 Mar 2026 @ 10:00 AM (CET)
The Cloud Architects Series: An introduction to Check Point Hybrid Mesh in 2026 - In Seven LanguagesThu 19 Mar 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #2: AI Security Challenges and SolutionsTue 24 Mar 2026 @ 04:00 PM (CET)
Maestro Masters EMEA: Hyperscale Firewall Architectures and OptimizationTue 24 Mar 2026 @ 03:00 PM (EDT)
Maestro Masters Americas: Hyperscale Firewall Architectures and OptimizationTue 24 Mar 2026 @ 06:00 PM (COT)
San Pedro Sula: Spark Firewall y AI-Powered Security ManagementThu 26 Mar 2026 @ 06:00 PM (COT)
Tegucigalpa: Spark Firewall y AI-Powered Security ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY