Skip to main content
Version: NG-2.16

Checkpoint Firewall

Introduction

Checkpoint Firewall is an advanced network security device that provides comprehensive threat prevention, traffic inspection, and access control. It safeguards enterprise networks by blocking unauthorized access while enabling secure communication across internal and external networks

Getting Started

Compatibility

Checkpoint Firewall O11ySource supports SNMP versions v1, v2c and v3.

Data Collection Method

Checkpoint Firewall supports SNMP, Syslog, and API-based access to export security events, logs, and performance metrics, making it easy to integrate with SIEMs and observability platforms.

Prerequisites

Dependent Configuration

To configure this O11ySource, create a 'credential' of type 'snmp' under the 'Definition' tab.

Inputs for Configuring Data Source

  • Group Name: This field is for grouping devices for SNMP polling, making it easier to manage devices with common characteristics or within the same network segment.
  • No. of Retries: Number of times the system should reattempt polling if the initial attempt fails. Default is set to 7 retries
  • Timeout Duration: Specify how long the system should wait for a response from a device before considering the attempt unsuccessful. Default timeout is 5 seconds
  • Device: Details needed to collect health data from the devices using SNMP
  • Device IP: Enter the IP address of the device.
  • SNMP Credential: Select the SNMP credential from the dropdown list that corresponds to this device.
  • Vendor: Select the vendor of the device from the dropdown list
  • Model: Select the model of the device from dropdown list.
  • MIB Groups: Define what MIBs to be queried and how often
  • MIB Group: Default: 'ALL_SUPPORTED_MIB_GROUPS'.
  • Interval: Default: 360 seconds

Firewall Requirement

To collect data from this O11ySource, ensure the following ports are opened:

Source IPDestination IPDestination PortProtocolDirection
vuSmartMaps IPIP address of the SNMP device161*UDPOutbound

*Before providing the firewall requirements, please update the port based on the customer environment.

Configuring the Target

Configure SNMP on Checkpoint Firewall devices and grant SNMP access permissions to vuSmartMaps designated IP address.

Configuration Steps

  • Enable the O11ySource.
  • Select the sources tab and press the + button to add a new instance that has to be monitored.
  • Provide the required configurations:
  • *Resource Name
  • *Period (in seconds)
  • *Credential
  • *Resource ID
  • Click Save to close the data source window.

Metrics Collected

NameDescriptionData Type
@timestampTimestamp stringString
timestampTimestamp with precisionDateTime64
bu_idBusiness unit IDLowCardinality(String)
tenant_idTenant IDLowCardinality(String)
hostHost IP AddressIPv4
targetTarget systemString
DeviceIPDevice IP AddressIPv4
data_typeType of dataLowCardinality(String)
typeEvent typeLowCardinality(String)
vendor_nameVendor nameLowCardinality(String)
device_typeDevice typeLowCardinality(String)
periodTime periodInt32
system_nameSystem nameString
nameName of the InterfaceString
indexIndex valueString
vublock_nameVuBlock NameString
topic_ofTopic associatedString
CPU UtilizationCPU UtilizationFloat64 DEFAULT -1.0
CPU NameCPU NameLowCardinality(String)
Memory UtilizationMemory UtilizationFloat64 DEFAULT -1.0
UptimeSystem UptimeUInt64
Uptime in secondsSystem Uptime in SecondsFloat64
CPU Utilization Per CoreCPU Usage Per CoreFloat64
Total MemoryTotal Real MemoryUInt64
Used MemoryActive Real MemoryUInt64
Free MemoryFree Real MemoryUInt64
Temperature IdentifierTemperature IdentifierString
Temperatue ValueTemperature ValueInt64
Connection CountNumber of connectionsUInt64
Peak Connection CountPeak number of connectionsUInt64
New Connection RateRate of new connectionsUInt64
HA StateHigh Availability StateLowCardinality(String)
HA State of VSXHigh Availability State of Virtual System eXtensionLowCardinality(String)
Virtual System NameName of Virtual SystemString
Virtual System IPMain IP of the Virtual SystemString
Disk NameName of the diskString
Disk SizeTotal Size of the diskUInt64
Disk UsedUsed Size of the diskUInt64
Disk Used PercentagePercentage of disk usageFloat64
Power Supply Unit StatusStatus of PSUString
Blade IDIdentifer for the bladeString
Blade StatusStatus of the bladeString