All MIBs › CHECKPOINT-MIB-1
Category: VPN and Security, Vendor: Check Point
Description:
Provides management objects for Check Point firewall appliance monitoring including interface status and security policy enforcement.
Imported Objects
From RFC-1212
| OBJECT-TYPE |
From RFC1155-SMI
| Counter | |
| Gauge | |
| IpAddress | |
| NetworkAddress | |
| TimeTicks | |
| enterprises |
What Is CHECKPOINT-MIB-1?
CHECKPOINT-MIB-1 is a vendor-specific SNMP module associated with Check Point Software Technologies firewall/security-gateway appliances, exposing management objects for these devices. Based on its short description it covers appliance state such as network interface status and enforcement status of the security policy running on the gateway, rather than deep packet-level statistics. No module description text or sample object list was available for this particular entry, so its exact object hierarchy could not be independently confirmed here. Its practical monitoring role is nonetheless hardware/software status: tracking whether interfaces are up and whether the security policy is actively enforced, giving a view of the firewall's overall operational health. Check Point gateways often layer such enterprise MIBs alongside the standard IF-MIB and SNMPv2-MIB for interface and system-level data, and it would typically be deployed wherever Check Point firewall appliances rely on CHECKPOINT-MIB-1 SNMP monitoring within an enterprise security monitoring stack.
IPNetwork Monitor allows you to monitor SNMP objects defined in CHECKPOINT-MIB-1. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.
What Can Be Monitored
- interface status
- security policy enforcement status
Supported Devices
- Check Point firewall/security gateway appliance
Monitoring Examples
No concrete object or table names were provided for this MIB, so a specific OID-level polling example cannot be given without risking invented names. In general use, an admin would poll interface-status objects and a policy-enforcement-status object to confirm a Check Point gateway's interfaces are up and that the currently loaded security policy matches the intended one. An interface reporting down, or a policy-status flag indicating "not installed," would signal a fault requiring investigation.
OIDs
| OID symbolic | OID numeric | Type | Access | Description |
|---|---|---|---|---|
| checkpoint | 1.3.6.1.4.1.1919 | |||
| products | 1.3.6.1.4.1.1919.1 | |||
| fw | 1.3.6.1.4.1.1919.1.1 | |||
| STR fwModuleState | 1.3.6.1.4.1.1919.1.1.1 | DisplayString | read-only | The state of the fw module. |
| STR fwFilterName | 1.3.6.1.4.1.1919.1.1.2 | DisplayString | read-only | The name of the loaded filter. |
| STR fwFilterDate | 1.3.6.1.4.1.1919.1.1.3 | DisplayString | read-only | When was the filter installed (STRING!) |
| INT fwAccepted | 1.3.6.1.4.1.1919.1.1.4 | INTEGER | read-only | The number of accepted packets. |
| INT fwRejected | 1.3.6.1.4.1.1919.1.1.5 | INTEGER | read-only | The number of rejected packets. |
| INT fwDropped | 1.3.6.1.4.1.1919.1.1.6 | INTEGER | read-only | The number of dropped packets. |
| INT fwLogged | 1.3.6.1.4.1.1919.1.1.7 | INTEGER | read-only | The number of logged packets. |
| INT fwMajor | 1.3.6.1.4.1.1919.1.1.8 | INTEGER | read-only | FireWall-1 Major Version. |
| INT fwMinor | 1.3.6.1.4.1.1919.1.1.9 | INTEGER | read-only | FireWall-1 Minor Version. |
| INT fwProduct | 1.3.6.1.4.1.1919.1.1.10 | INTEGER | read-only | FireWall-1 Product. |
| STR fwEvent | 1.3.6.1.4.1.1919.1.1.11 | DisplayString | read-only | A string containing the last snmp trap sent via fw |
RFC description
Check Point firewall MIB for monitoring firewall module state, filter status, and packet acceptance/rejection statistics.
Start monitoring Check Point security gateway/firewall appliances with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.