Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Mk_83
Contributor

How to Monitor VPN Tunnel Traffic on Standalone 1550 Appliances?

Hello everyone,

Appliance: 2x 1550
Mode: Standalone
Version: R81.10.10

I have set up an IPSec Site-to-Site VPN connection between these two 1550 appliances, and the tunnel is successfully UP.

However, I’m facing a small issue:

I want to monitor which traffic is going through the VPN tunnel, specifically to see which sessions or services are consuming the most bandwidth inside the tunnel.

Currently, under the Monitor and Reports tabs, the system displays the total traffic of the appliance, not specific traffic for the VPN tunnel.

06f467ff-3d6c-40a4-8346-430c9cf50ee9.jpg

Is there a way to filter or view tunnel-specific traffic statistics on a standalone Quantum Spark 1550 appliance?

I would greatly appreciate any guidance or suggestions on this.

 

Thank you, guys, so much.

0 Kudos
9 Replies
Danny
Champion Champion
Champion

For advanced VPN tunnel bandwidth monitoring on Check Point standalone SMB appliances I recommend using packet capturing on the CLI in expert mode. Neither the built-in monitoring via Web UI nor the "Traffic Monitoring" tab would provide that level of detail you are looking for. This is usually a demand for centrally managed SMB appliances, not purely locally configured ones as in your case. Also SNMP monitoring for VPN won't provide you the insights you asked for.

Mk_83
Contributor

Hello Danny,

Thank you for your information.

As I understand, using packet capture tools like tcpdump only provides packet-level data and does not offer aggregated traffic statistics — such as total bandwidth usage per services. Please correct me if I’m mistaken.

What I’m specifically looking for is a way to view a breakdown of source-destination-service pairs that are consuming the most bandwidth through the VPN tunnel, ideally in a summarized or report-style format.

Previously, I’ve worked with Check Point appliances running Gaia OS, which included the Monitoring blade and support for SmartView Monitor — allowing visibility into detailed traffic statistics. However, I haven’t found a similar feature available on this Gaia Embedded 1550.

0 Kudos
Danny
Champion Champion
Champion

You asked for advanced dashboards and reports for standalone SMB appliances that are not available by the product itself, so I suggested to build them on your own regarding to your needs.

  • Wireshark – You can filter packets and use its built-in graphs to show bandwidth usage and connections between sources and destinations.

  • Grafana + Prometheus + Others – Import your packet captures and logs and create the dashboards you are looking for.
  • JavaScript - Just like other projects in our Toolbox, e.g. SARchart, you could utilize JavaScript libraries to convert your packet captures into charts and reports
  • GitHub - There are many PCAP analyzing & visualizing tools available. Just search for one that suits your needs.
G_W_Albrecht
Legend Legend
Legend

You have to use the SMP Infinity Portal (license is included) to see such statistics:

Screenshot 2025-05-21 143744.png

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
Mk_83
Contributor

Thank you so much!! I will try this portal.

0 Kudos
Martin_Raska
Advisor
Advisor

SMP portal will show some statistics but I don't think it will show you the cumulative traffic between hosts.

 

If you have capture you can use Check Point tool for analysis - sk103212

Mk_83
Contributor

Hello Martin,

As I see the tool CPMonitor  in sk103212 only support Gaia, Linux OS and doesn't support Gaia Embedded right?

 

Thanks & Best Regards.

0 Kudos
G_W_Albrecht
Legend Legend
Legend

That is correct ! Only supported by GAiA / Linux.

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
G_W_Albrecht
Legend Legend
Legend

But no need to run it on the GW - use a Linux PC or GAiA VM to analyze thr captures. So you will see what you wanted in the post!

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events