- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
What is SNMP OID for CP FW number of new connections?
Is this OID returning anything for you: .1.3.6.1.4.1.2620.1.1.26.11.6 ?
As Hristo said, 1.3.6.1.4.1.2620.1.1.26.11.6.0 is the correct one. Works on enterprise appliances.
For SMB appliances, you have to use delta of 1.3.6.1.4.1.2620.1.1.25.3.0.
Please review sk90860 section 2-D for more information.
Is it .1.3.6.1.4.1.2620.1.1.25.22 ? But OID Description: " Connections rate since last start of Check Point services. ". I feel uncertain.
[Expert@PNS-CP4607-02:0]# snmpwalk -v 2c -c vpn123 localhost .1.3.6.1.4.1.2620.1.1.25.22
SNMPv2-SMI::enterprises.2620.1.1.25.22 = No Such Instance currently exists at this OID
What is wrong with it?
Try dropping the leading '.' and appending .0 to the end.
[Expert@PNS-CP4607-02:0]# snmpwalk -v 2c -c vpn123 localhost .1.3.6.1.4.1.2620.1.1.25.22.0
SNMPv2-SMI::enterprises.2620.1.1.25.22.0 = No Such Instance currently exists at this OID
To confirm is this a standard security gateway or are you running VSX and what version?
Do the other OIDs in 2-D return integer values...
Jumbo Take 351 GA and is your snmp monitoring generally working or does restarting the service help?
[Expert@HostName]# service snmpd status
[Expert@HostName]# service snmpd start
Given the limited details provided...
If anything it might be related to the NET-SNMP package version, updates available via TAC.
Is this OID returning anything for you: .1.3.6.1.4.1.2620.1.1.26.11.6 ?
As Hristo said, 1.3.6.1.4.1.2620.1.1.26.11.6.0 is the correct one. Works on enterprise appliances.
For SMB appliances, you have to use delta of 1.3.6.1.4.1.2620.1.1.25.3.0.
I found it using this simple command:
# cat CHECKPOINT-MIB | grep -i conn | grep -i rate
It returns:
fwConnectionsStatConnectionRate OBJECT-TYPE
"connection rate (per second) passing through the FireWall-1 Module"
"Writing logs localy, To log servers(0), Local configured (1) Local due to connectivity(2) Local due to high rate(3)"
Paste fwConnectionsStatConnectionRate in Google and the first result is the OID 😀
Some tools to explore the mibs:
ManageEngine MIB Browser:
https://www.manageengine.com/products/mibbrowser-free-tool/
Paessler MIB Importer:
https://www.paessler.com/tools/mibimporter
There are OIDs that are not in the mibs, but it helps.
Hello.
Using the OID 1.3.6.1.4.1.2620.1.1.26.11.6.0 we do have what seem to be accurate values for at least either the old CP-13500 gateways (without VSX) and in OpenServer environments (also without VSX).
However, when using the same OID when VSX is in place, it seems that the returned values are for VS ID 0, where there is no traffic.
Are you aware of any way for having this same connection rate metric per VSX being returned via a specific OID?
We do have other per VSX OIDs but my understanding is that none is specific for the connection rate, only for metrics such as the total number of connections, traffic, etc.
Thank you.
NOTE: only valid for non SMB firewalls.
Is cpsnmpd running? I think this is the process snmpd hands off to for checkpoint related oids.
If its not running do the following
cpconfig
chose option for checkpoint snmp extensions
exit
WARNING: This will do a cpstop / cpstart meaing all services will reload and including firewall policy.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
9 | |
7 | |
6 | |
6 | |
5 | |
5 | |
5 | |
5 | |
5 | |
5 |
Fri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationTue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationTue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY