CHECKPOINT-MIB

MIB Reference — IPNetwork Monitor · Updated September 09, 2026

All MIBsCHECKPOINT-MIB

Organization: Check Point

Last Updated: 2013-12-26

Category: VPN and Security, Vendor: Check Point

Description: Manages Check Point firewall and VPN gateway including policy status, connection table statistics, and security module health.

Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

What Is CHECKPOINT-MIB?

CHECKPOINT-MIB, commonly called the checkpoint mib by administrators, is Check Point Software Technologies' vendor MIB for managing Check Point firewall and VPN gateway appliances, covering security policy status, connection-table statistics, and overall Security Module/Gateway health. It exposes data spanning firewall policy state (which policy is currently installed and its install time), traffic/connection performance counters (active connection table size and utilization), and module health indicators reflecting whether the firewall's inspection engine and VPN daemons are running correctly. This directly supports monitoring both software status (policy installation state, connection table capacity/utilization as a load indicator, and Security Module process health) and, to a lesser extent, hardware health of the gateway appliance running Check Point's software. Check Point documents its most common OIDs in its own SNMP Best Practices Guide (sk98552) rather than layering heavily on other public MIBs, though it coexists with standard IF-MIB/HOST-RESOURCES-MIB data for interface and OS-level metrics on the same gateway. It is deployed on Check Point firewall/VPN gateway appliances (physical or virtual) in enterprise perimeter security and branch/VPN concentrator roles.

IPNetwork Monitor allows you to monitor SNMP objects defined in CHECKPOINT-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • Check Point Quantum Force 29200 (2025) — hyperscale security gateway appliance with dedicated AI processor, 200-800 Gbps firewall throughput

Monitoring Examples

No sample objects were extracted for this module, but per its description an admin would typically poll the connections table size/limit to detect approaching capacity (a classic cause of dropped new connections under load), check the currently installed policy name/timestamp to confirm the expected security policy is active, and monitor Security Module/daemon status objects to catch a crashed or unresponsive inspection process. Check Point's own SNMP Best Practices Guide (sk98552) is the authoritative reference for the specific OIDs used in these checks.

What Can Be Monitored

  • installed security policy name/timestamp
  • active connection table size/utilization
  • Security Module/gateway process health
  • VPN tunnel status
Imported Objects

From SNMPv2-CONF

OBJECT-GROUP

From SNMPv2-SMI

Integer32
IpAddress
MODULE-IDENTITY
NOTIFICATION-TYPE
OBJECT-TYPE
Unsigned32
enterprises

From SNMPv2-TC

DisplayString

How to Use in IPNetwork Monitor

Example using fwDropped OID:

Select a Check Point security gateway or firewall appliance as the target host to create a monitor — the SNMP service should be up and running on it. Click New Monitor, then check SNMP Custom on the Favorites tab, click Next, and confirm the host. On the next page, click Select... to open the built-in SNMP MIB Browser and type fwDropped into the Find box to locate it in the OID tree, then select it and click OK. It reports the number of packets the firewall has dropped. On the monitor's Main parameters page you can set the target's SNMP port (default 161), credentials, polling interval, and other settings — see the SNMP Monitor help for details. On the State conditions and Alerting tabs, configure when the monitor should change state and trigger an alert; since this is an INTEGER-type OID, Value bounds is the most useful condition here — trigger an alert if the counter increases sharply between polls, since a sudden jump in dropped packets often points to a policy misconfiguration or an active attack. Click Finish to create the monitor; you can adjust any parameter later.
OIDs

FAQ

What would a security team check with CHECKPOINT-MIB on a Check Point gateway?
They'd monitor which security policy is currently installed and its install time, the active connection table size/utilization as a load indicator, and Security Module/gateway process health to confirm the firewall's inspection engine and VPN daemons are running correctly.

Where does Check Point document the specific OIDs in CHECKPOINT-MIB?
Check Point documents its most common OIDs with detailed descriptions in its own SNMP Best Practices Guide (sk98552) rather than layering heavily on other public MIBs, though it's typically polled alongside standard IF-MIB/HOST-RESOURCES-MIB data on the same gateway.

RFC description

Check Point firewall vendor-private MIB for monitoring firewall module state, filter rules, and packet statistics.

Start monitoring Check Point security gateway/firewall appliances with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download CHECKPOINT-MIB