- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi Guys,
I have found many interesting articles about VSX tuning here in the forum:
https://community.checkpoint.com/t5/VSX/Interface-Affinity-with-VSX/td-p/51136
I understand that, but how exactly do I set this up under VSV and which CLI commands do I have to use?
Is here a sample file that allows me to set the SecureXL and CoreXL instances?
For example, how do I set Multiqueueing/SecureXL for Core 0,1,2,3,17,18,19,20 and CoreXL for VS1 to Core 4,5,21,22
Which CLI commands do I have to use to make the settings permanent?
Regards
Christian
You can't tell with SNMP how much CPU is single VS / VSW using if they are sharing resources I'm afraid. Unless you have dedicated cores per VS.
If I'm honest VSW takes nearly nothing in my experience. Two VSWs sharing the same single hyper-threaded core pushing 30Gbps used 25% peak hour. On 26000T appliance.
Thanks, the CPU question was aimed more at the VS, but this really is a a missing part for external monitoring and capacity management, and I can't see how this could be monitored via SNMP unless, as you suggested have dedicate cores, even then how would SNMP be able to monitor it as its the same issue, SNMP only seems to pick up the CPU OID for the overall tin.
Actually you can pull all process load for a given VS. We do this with: CHECKPOINT-MIB::fwInstancesCPUTable
This allows us to graph each VS individually and collectively, see below:
All VS share the same some 24 cores and 8 SNDs
fwk load of a VS with 5 cores assigned
all VS fwk load SUM'ed per VS
VSX load
fwk 5 cores
all VS on cluster fwk load
general VSX load
I take it there is a OID for this and its different per VS? How you you actually use this from an SNMP MGR such as PRTG?
I did a snmpwalk and could not see this.
Downloaded the last (R81) MIB file from Checkpoint (SK90470)
The MIB file has syntax errors so corrected theses.
converted and uploaded to PRTG using the below link:
But not really seeing any difference.
Additionally search the MIB file for 'fwInstancesCPUTable' and it does not exist? (See attached)
Hey,
I poll each VS through the VSX DMI. Use snmp v3 with the flag -n ctxname_vsid17 - to poll a specific VS through the DMI.
The oid is there. Check the official mib in sk90470 (I use r80.40)
But without knowing prtg I can only recommend to look into a TIG stack - Telegraf/InfluxDB/Grafana solution. It will improve your monitoring level many times.
I have attached a telegraf config to get you started for single VS monitoring.
Very nice! 🙂
I saw you mentioned Solarwinds as well.
You cannot add devices with the same IP address through the webinterface. The IP address is a unique identifier within Solarwinds and they will not support multiple devices, even with different context flags - horrible design choice.
We have it working by adding the nodes directly into the mssql db, but it is not supported and is a stupid workaround.
There is an RFE on thwack regarding this. It has existed since 2008.
/Henrik
Awesome thanks, will give this a go.
Good old MRTG had a similar limitation so I managed to suss out from the code that it was case sensitive, so I just had to create targets with different combinations of upper lower case letters 🙂
Remember that you should be able to poll VS directly by setting vs-direct-access
hah that is a great limitation 🙂
I rerely see a design where direct VS polling is doable. Many VS are simply cut off from the monitoring platform (implicit by design).
I like we can poll each VS from the DMI, but I would like that Check Point was more consistent offering VS data from VS0 snmp tables.
Some data is available others not.
I managed to use the MIB file on PRTG, however still not able to see '::fwInstancesCPUTable' reference within the snmpwalk. I have at least got the VSWs in and now Connections Limit, Peak and concurrent values, even managed to figure how how to combine the values into one chart.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 26 | |
| 15 | |
| 14 | |
| 13 | |
| 12 | |
| 7 | |
| 6 | |
| 5 | |
| 5 | |
| 4 |
Thu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY