- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Introducing Check Point Quantum Spark 2500:
Smarter Security, Faster Connectivity, and Simpler MSP Management!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
The Skyline Metrics Repository lists 4 NAT items in the NAT section:
system.network.nat.connections.count
system.network.nat.connections.rate
system.network.nat.ports
system.network.nat.ports.limit
I can get the first two to work and they work well.
but the next two are not in my pull downs for the code builder in Grafana and typing them in manually gives no data even on firewalls with NAT and running R81.20 Jumbo 41.
Anyone else get the ports and ports limit to provide the data that is visible in cpview?
Hi @David_Evans,
We are aware of this issue, this should be fixed us part of one of the upcoming jumbo releases.
Contact me on eladch@checkpoint.com and we can give you a workaround for now to resolve this issue.
Hi @David_Evans,
We are aware of this issue, this should be fixed us part of one of the upcoming jumbo releases.
Contact me on eladch@checkpoint.com and we can give you a workaround for now to resolve this issue.
Thankyou for the fix. This allow me to keep an eye on some of our maestro servers that still do not do GNAT and get close to running out of NAT ports at times.
Hi @David_Evans ,
i am struggling with the Grafana dashboard for NAT port usage, better said with the prom query.
How is your query looking like, your panels look fine and your legends as well.
Best regards
Vincent
I do not think they have fixed this yet, you need to have them modify the configuration so these stats pull correctly from the devices.
Hi@Vincent_Bacher ,
The fix to this issue will be part of one of the upcoming jumbos, aimed to be released soon.
I noticed Jumbo 150 overwrote the fixes to the config file you provided and so does not include these stats. Do we have a updated ETA?
Hi @David_Evans ,
Still not definite one, however, it is still aimed to be released in a soon upcoming release.
R81.20 Jumbo 70 appears to include this fix.
@David_Evans @Vincent_Bacher I am looking for some help with the grafana query for a NAT dashboard as well. Would you mind to share your knowledge? Thanks in advance!
Best regards
Sven
I created a panel for nat port usage statistics per vs. I did it as follows:
system_network_nat_ports{hostname="$d_hostname", environment="$d_environment", service_namespace="$d_namespace"} / system_network_nat_ports_limit{hostname="$d_hostname", environment="$d_environment", service_namespace="$d_namespace"}
where i use variables set for the dashboard globally.
In case of more questions, just ask.
One info: For the variables, Checkpoint per default use query on metric system_update but we experienced the issue that many of our devices (round about 100 of 300 physical and OpenServer devices) don't send this metric. We use system_gaia_os_role instead. It showed that this is sent by all devices. Don't have the status of investigations in mind done by CP R&D.
Cheers
Vince
I experienced the same problem with system_uptime. The system_uptime-problem should be fixed with otlp_agent >= take 90
Another useful info regarding nat metrics.
You will face the issue of gaps in your NAT panels looking like this:
(panel looks not nice enough but will be modified once we have everything including automation of skyline and prometheus onboarding in production. waiting for scraping to be productive in the field instead of using remote_write)
Reason for that: As per CP statement, metrics are sent for the two biggest pools only, so the shown metrics frequently change. You would not face the issue when using sum in the query but in general if you have a lot of NAT pools, this is an important detail that you might want to know.
Thanks for your fast response. The "sum"-thing was the latest problem I dealt with... Good to know!
I have just realised that I have expressed myself somewhat unhappily. If you use the sum function in promq for the panel, you may not see any gaps, in extreme cases perhaps strange steps, but probably no gaps. This is probably ‘ironed out’ or ‘smoothed out’ with sum, but the gaps in the sent metric series will still occur when looking at the prom server itself.
Wed 10 Sep 2025 @ 11:00 AM (CEST)
Effortless Web Application & API Security with AI-Powered WAF, an intro to CloudGuard WAFWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY