All MIBs › CP-MIB
Category: VPN and Security
Description: Provides management objects for Check Point security gateway and firewall policy status.
Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.
What Is CP-MIB?
Despite its short name, the sampled objects for CP-MIB (rsCPCIDR*) point to a CIDR-based routing/peering aggregation module rather than a Check Point firewall policy MIB - it manages CIDR route entries, static neighbor/router IP associations, and load statistics for a routing/peering feature. It exposes tables of CIDR subnet/mask entries, associated static neighbor and router IP addresses, prefix-list indices, and per-entry load/statistics counters, along with tuning parameters for maximum CIDR/peer table sizes. Its monitoring value is in tracking the operational state and scale of dynamic routing/peering data - e.g., how many CIDR entries or peers are configured versus the tuned maximum, and the recent load on a given CIDR entry - which can reveal routing-table exhaustion or peering instability. It clearly depends on underlying IP routing/BGP-style peering concepts and likely on a base vendor enterprise MIB for its object-identifier root. It would typically be deployed on a router, firewall, or gateway device where an operator needs CP-MIB SNMP monitoring to track CIDR-based route aggregation and peer-router relationships.
IPNetwork Monitor allows you to monitor SNMP objects defined in CP-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.
Supported Devices
- Radware application delivery controller/load balancer (CIDR-based route health injection) — identified via its explicit IMPORTS of RADWARE-MIB, not Check Point as previously guessed
Monitoring Examples
An operator would poll rsCPCIDRsTable/rsCPCIDREntry fields like rsCPCIDRSubnet, rsCPCIDRMask, and rsCPCIDRStaticNeighborIPAddress to confirm which CIDR blocks and peer routers are currently configured, and check rsCPCIDRLastMinuteLoad to spot an entry receiving unexpectedly high traffic. Comparing the current entry count against rsCPMaxCIDREntriesTuning or rsCPMaxPeersPerRouterEntriesTuning would reveal if the device is approaching a configured routing-table capacity limit. This gives visibility into route-aggregation health and peer-router relationships on the device.
What Can Be Monitored
- CIDR subnet/mask entries
- static neighbor/router IP associations
- per-entry load statistics
- configured vs. maximum CIDR/peer table size
Imported Objects
From RADWARE-MIB
| rndErrorDesc | OBJECT-TYPE |
| rndErrorSeverity | OBJECT-TYPE |
| rsCP | OBJECT-IDENTITY |
From RFC-1212
| OBJECT-TYPE |
From RFC1155-SMI
| IpAddress | |
| TimeTicks |
From RFC1213-MIB
| DisplayString |
From RFC1215
| TRAP-TYPE |
OIDs
RFC description
Manages CIDR routing configuration and Congestion Proof (CongestionProof) policy tables on Radware devices.
Start monitoring Radware application delivery controller/load balancer (CIDR route health injection) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.