- Products
- Learn
- Local User Groups
- Partners
- More
Access Control and Threat Prevention Best Practices
5 November @ 5pm CET / 11am ET
Ask Check Point Threat Intelligence Anything!
October 28th, 9am ET / 3pm CET
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
Spark Management Portal and More!
Slides attached below, Q&A is below.
Please post a comment on the post before 31 August 2021 to be entered in a drawing for an Amazon Gift Card!
It is supported on any (virtual) appliance that runs regular Gaia, including VSX and Maestro. VSX is supported from R80.10 and you can get historical data starting with R80.40.
Unfortunately no plans currently exist to integrate it in the near future, however it is planned.
Not currently, though perhaps as part of a planned REST API it will be possible. Some of the data can be obtained via SNMP.
Currently, the existing solution is to use DiagnosticsView to visualize the data, which requires taking a cpinfo from the relevant gateway. You can also use the community-provided CPviewer solution. The CPview database is a SQLite database, which can be visualized with a number of third party tools.
We now have historical data saved on the device, which can be exported as a SQLite 3 database. Please use that instead.
Not all statistics are collected in VSX mode as there may be a performance impact in doing so. It is recommended only to activate statistics (e.g. in Advanced > VSX > VSs) when troubleshooting a specific issue.
R80.20 and above have a different SecureXL implementation, which impacted the availability of this feature until it was added to recent JHF releases. Also, this feature requires specific steps to enable. Refer to sk167903 for details. We do plan to simplify this in the future.
1 month
Not currently. If there is something you'd like to see via SNMP, let us know!
We will consider the suggestion, right now you can only navigate on CPView using mouse or keyboard.
cpview -t
Most of the features/functionality are relevant for all R8x versions. Some features require being on a specific version/JHF as noted.
Only SMO for now.
Not at the moment, but this is planned for future releases.
There are 2 measurements: packets per second (average of amount of packets per second) and megabytes / bits per second.
RX / TX only shows received / sent data (not counting packet headers, etc) while the general throughput is for all the overall traffic.
Not all data available in realtime is collected in a historical fashion. We do plan to offer the ability to collect additional data in the future.
This is on the roadmap.
No, and it would require a fairly significant amount of storage to do this on a busy gateway. However, you can query the connections table via the CLI using: fw tab -t connections -u
Not currently.
The API is still on development so it is still early to answer this question, however the information source should be the same, the format and UX will be of course completely different.
Yes, it will keep the data flow open and may cause performance hiccups.
Not planned currently.
They have some common ground but CPView has a more in depth data compared to the monitoring data, which is more summarized.
There are multiple paths, the file is easily searchable using a 'find' command - CPViewDB.dat or cpview_services.dat. You can also easily get an export of the current database via the command cpview -s export.
Planned for R81.20
Generally, yes.
Is it possible to save samples to the CPView history more frequently than once a minute? At least when a troubleshooting in a gateway is in progress. live answered
No, that is outside the purview of CPview.
Yes, for the overall gateway. Not for specific VS.
It will be the same as the shell.
Single threaded.
Not currently, however the names come from /etc/services.
cpsizeme gathers slightly more sizing details over a period of time, whereas CPview will give you a snapshot as the system exists currently.
In R80.40, you have the CPU Spike Detective, available from JHF 69. See sk166454.
A more detailed session is in the works. If there are specific items you wish to see, please leave them as a comment to this post!
Thanks for sharing, i have to admit i expected a little bit more. Wonderful job everyone, also if there's a way that after the session ends add the Q&A section in here and follow up on the not responded questions for the benefit of everyone.
The post has been updated with the (summarized) Q&A.
If there was a specific question not answered above, please ask it here, we'll make sure you get an answer.
@PhoneBoythanks!
Great work, and information very useful
Pretty good guys!
Great work guys. It was very informative.
Thank you gentlemen for the live demonstration. Hopefully this is something that I can learn more on and have the needed answers when they are brought to me from our customers.
Regarding Top-Connections/Top Talker, once enabled per SK167903, is there a limit on the number of top talkers recorded? Visible in DiagnosticsView? Imagine 300 remote access vpn users complain of poor performance, turns out they are getting a surprise OS patch all at the same time or something like that, kind of mass elephant flow. Will cpview help document that reason behind the performance hit?
Hi,
CPview shows the top 5 connections.
CPview can help to find heavy connections via throughput, less so via CPU usage. If you need to view the CPU usage, there is the Top-Connections/Protocols under the CPU view.
Thanks Arik. Given the limitation of 5 top connections, what is another method of measuring/analyzing the throughput/performance related to hundreds of remote access users?
I really enjoy the TechTalks. Even when you already have some knowledge about a topic or tool there are always many things to learn about it. Thank you guys, great job.
Great material, very informative! Thank you!
Hi,
Thanks for the session.
As far I know there is a limitation for top connections section on the usfw. We can not see these information in the cpview menu. Is there any plan to improve this or possibility to change this behavior?
Load the latest GA Jumbo HFA for your release and that screen will return, see sk167903: CPview Top Connections and Protocols tabs show no data
I totally forgot this, my bad. I haven't been applied this to any of my customer. Do you have any information about impact of this change?
Shouldn't be an impact that I know of, these "Top" screens in cpview went away when SecureXL was overhauled in R80.20 and it took awhile for them to get implemented back into SecureXL again by popular demand.
Good info.
Thanks
Thank you for this valuable information.
Very helpful! Thank you!
Thank you for the presentation.
 
					
				
				
			
		
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count | 
|---|---|
| 22 | |
| 17 | |
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 7 | |
| 7 | |
| 7 | |
| 5 | 
Tue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewTue 28 Oct 2025 @ 12:30 PM (EDT)
Check Point & AWS Virtual Immersion Day: Web App ProtectionTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewTue 28 Oct 2025 @ 12:30 PM (EDT)
Check Point & AWS Virtual Immersion Day: Web App ProtectionThu 30 Oct 2025 @ 03:00 PM (CET)
Cloud Security Under Siege: Critical Insights from the 2025 Security Landscape - EMEAThu 30 Oct 2025 @ 11:00 AM (EDT)
Tips and Tricks 2025 #15: Become a Threat Exposure Management Power User!About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY