Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
David_Evans
Collaborator
Jump to solution

Skyline NAT Stats

The Skyline Metrics Repository lists 4 NAT items in the NAT section:

system.network.nat.connections.count

system.network.nat.connections.rate

system.network.nat.ports

system.network.nat.ports.limit


I can get the first two to work and they work well.

but the next two are not in my pull downs for the code builder in Grafana and typing them in manually gives no data even on firewalls with NAT and running R81.20 Jumbo 41.   

Anyone else get the ports and ports limit to provide the data that is visible in cpview?


0 Kudos
1 Solution

Accepted Solutions
Elad_Chomsky
Employee
Employee

Hi @David_Evans,

We are aware of this issue, this should be fixed us part of one of the upcoming jumbo releases.

Contact me on eladch@checkpoint.com and we can give you a workaround for now to resolve this issue.

View solution in original post

0 Kudos
14 Replies
Elad_Chomsky
Employee
Employee

Hi @David_Evans,

We are aware of this issue, this should be fixed us part of one of the upcoming jumbo releases.

Contact me on eladch@checkpoint.com and we can give you a workaround for now to resolve this issue.

0 Kudos
David_Evans
Collaborator

Thankyou for the fix.   This allow me to keep an eye on some of our maestro servers that still do not do GNAT and get close to running out of NAT ports at times.

NAT2.pngNAT1.png

0 Kudos
Vincent_Bacher
Advisor
Advisor

Hi @David_Evans ,

i am struggling with the Grafana dashboard for NAT port usage, better said with the prom query.
How is your query looking like, your panels look fine and your legends as well.

Best regards
Vincent

and now to something completely different - CCVS, CCAS, CCTE, CCCS, CCSM elite
0 Kudos
David_Evans
Collaborator

I do not think they have fixed this yet, you need to have them modify the configuration so these stats pull correctly from the devices.

0 Kudos
Elad_Chomsky
Employee
Employee

Hi@Vincent_Bacher ,

The fix to this issue will be part of one of the upcoming jumbos, aimed to be released soon. 

0 Kudos
David_Evans
Collaborator

I noticed Jumbo 150 overwrote the fixes to the config file you provided and so does not include these stats.    Do we have a updated ETA?

0 Kudos
Elad_Chomsky
Employee
Employee

Hi @David_Evans ,

Still not definite one, however, it is still aimed to be released in a soon upcoming release. 

0 Kudos
David_Evans
Collaborator

R81.20 Jumbo 70  appears to include this fix.

0 Kudos
Sven_Glock
Advisor

@David_Evans  @Vincent_Bacher I am looking for some help with the grafana query for a NAT dashboard as well. Would you mind to share your knowledge?  Thanks in advance!

Best regards
Sven

0 Kudos
Vincent_Bacher
Advisor
Advisor

I created a panel for nat port usage statistics per vs. I did it as follows:

system_network_nat_ports{hostname="$d_hostname", environment="$d_environment", service_namespace="$d_namespace"} / system_network_nat_ports_limit{hostname="$d_hostname", environment="$d_environment", service_namespace="$d_namespace"}



where i use variables set for the dashboard globally. 
In case of more questions, just ask.

One info: For the variables, Checkpoint per default use query on metric system_update but we experienced the issue that many of our devices (round about 100 of 300 physical and OpenServer devices) don't send this metric. We use system_gaia_os_role instead. It showed that this is sent by all devices. Don't have the status of investigations in mind done by CP R&D.

Cheers
Vince

 

 

and now to something completely different - CCVS, CCAS, CCTE, CCCS, CCSM elite
Sven_Glock
Advisor

I experienced the same problem with system_uptime. The system_uptime-problem should be fixed with otlp_agent >= take 90

0 Kudos
Vincent_Bacher
Advisor
Advisor

Another useful info regarding nat metrics.

You will face the issue of gaps in your NAT panels looking like this:

nat-panel-gaps.png

(panel looks not nice enough but will be modified once we have everything including automation of skyline and prometheus onboarding in production. waiting for scraping to be productive in the field instead of using remote_write)

Reason for that: As per CP statement, metrics are sent for the two biggest pools only, so the shown metrics frequently change. You would not face the issue when using sum in the query but in general if you have a lot of NAT pools, this is an important detail that you might want to know.

and now to something completely different - CCVS, CCAS, CCTE, CCCS, CCSM elite
Sven_Glock
Advisor

Thanks for your fast response. The "sum"-thing was the latest problem I dealt with... Good to know! 

0 Kudos
Vincent_Bacher
Advisor
Advisor

I have just realised that I have expressed myself somewhat unhappily. If you use the sum function in promq for the panel, you may not see any gaps, in extreme cases perhaps strange steps, but probably no gaps. This is probably ‘ironed out’ or ‘smoothed out’ with sum, but the gaps in the sent metric series will still occur when looking at the prom server itself.

and now to something completely different - CCVS, CCAS, CCTE, CCCS, CCSM elite
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 20 May 2025 @ 11:30 AM (PDT)

    Las Vegas: Check Point Hybrid Mesh

    Wed 21 May 2025 @ 11:30 AM (MST)

    Tempe, AZ: Check Point Hybrid Mesh

    Tue 03 Jun 2025 @ 06:00 PM (EDT)

    Montreal: CPX Recap

    Tue 10 Jun 2025 @ 06:00 PM (EDT)

    Quebec City: CPX Recap
    CheckMates Events