Try it free

Check Point Firewall extension

  • Latest Dynatrace
  • Extension

Monitor Check Point firewall device performance, interface throughput, and cluster health with SNMP metrics, topology, and alerts.

Get started

Overview

Monitor health state and performance of your Check Point Firewall devices and provide a unified analysis for Ops, DevOps and IT Admins.

The Check Point Firewall extension leverages the SNMP protocol to provide a complete solution to monitor Check Point Firewall Devices. The extension is built on top of the Extension 2.0 Framework and its complete configuration is provided out-of-the-box.

Use cases

Use this extension to:

  • Monitor health and performance of your Check Point Firewall devices by polling data for Network Devices and Interfaces.
  • Set up alerts to get notified if a monitored interface goes into a down state.
  • Set up alerts to get notified by traffic anomalies.
  • Use the extension with the Infrastructure & Operations Infrastructure & Operations for an overview of all monitored Network Devices in the environment.

Requirements

  • Activated the extension in your environment using in-product Hub.
  • Provided device configuration.

For more information about the configuration, see SNMP Extension Documentation.

Compatibility information

  • This extension can only be used with Check Point Firewalls.
  • Only SNMPv2c and SNMPv3 are supported.

Details

The extension package contains:

  • SNMP Data Source configuration
  • New and Classic Dashboard Overviews
  • Unified Analysis Screens
  • Topology definition and entity extraction rules
  • Generic Network Topology Support

For more information, see Simplified observability for your SNMP devices.

Licensing and costs

There is no charge to use the extension. You are only charged for the data that the extension ingests.

The Check Point Firewall extension ingests custom metrics, which consume Davis Data Units (DDUs) (Dynatrace classic license) or Metrics powered by Grail (DPS), according to your license model.

The extension runs most SNMP queries every minute. Below is a breakdown of metrics by feature set only including metrics collected once per minute (there are two metrics in the default feature set that are collected at a 30 minute interval):

default: 7 x Check Point Firewall Devices + 3 x Check Point Firewall Interfaces
Check Point Device: 15 x Check Point Firewall Devices
Interfaces: 9 x Check Point Firewall Interfaces

For example, a monitoring configuration with all feature sets enabled, containing 1 Check Point Firewall with 1 Interface, produces 33 metric data points per minute.

Dynatrace Platform Subscription

In the Dynatrace Platform Subscription, metric ingestion consumes Metrics powered by Grail according to the number of ingested metric data points.

To calculate the approximate yearly consumption, apply the following calculation: <metric data points per minute> * 60 minutes * 24 hours * 365 days.

For the example above: 33 * 60 * 24 * 365 = 17,344,800 metric data points per year.

Dynatrace classic license

In the classic licensing model, metric ingestion consumes Davis Data Units (DDUs) at the rate of .001 DDUs per metric data point. Multiply the above formula for annual data points by .001 to estimate annual DDU usage.

For the example above: 33 * 60 * 24 * 365 * 0.001 = 17,344.8 DDUs per year.

The DDU cost above does not include any possible log events or custom events that are triggered by the extension. For more information, see DDU events.

Feature sets

When activating your extension using a monitoring configuration, you can limit monitoring to one of the feature sets. To work properly, the extension has to collect at least one metric after the activation.

In highly segmented networks, feature sets can reflect the segments of your environment. Then, when you create a monitoring configuration, you can select a feature set and a corresponding ActiveGate group that can connect to this particular segment.

All metrics that aren't categorized into any feature set are considered to be the default and are always reported.

A metric inherits the feature set of a subgroup, which in turn inherits the feature set of a group. Also, the feature set defined on the metric level overrides the feature set defined on the subgroup level, which in turn overrides the feature set defined on the group level.

Stack info
Metric nameMetric keyDescription
Physical component statecheckpoint.firewall.component.stateA state metric representing the details of physical components. This is used to collect details about the device stack. Value is always 1; use the dimensions to view details.
Check Point Device
Metric nameMetric keyDescription
Disk percentcheckpoint.firewall.disk.percentPercent of free space
Users connectedcheckpoint.firewall.users.connectedNumber of connected users
Accepted packetscheckpoint.firewall.packets.accepted.countAccepted packets
Dropped packetscheckpoint.firewall.packets.dropped.countDropped packets
Logged packetscheckpoint.firewall.packets.logged.countLogged packets
Rejected packetscheckpoint.firewall.packets.rejected.countRejected packets
Number of connectionscheckpoint.firewall.connectionsNumber of connections
Peak number of connectionscheckpoint.firewall.connections.peakPeak number of connections
Total virtual memorycheckpoint.firewall.memory.total.virtualTotal virtual memory
Active virtual memorycheckpoint.firewall.memory.active.virtualActive virtual memory
Total real memorycheckpoint.firewall.memory.total.realTotal real memory
Active real memorycheckpoint.firewall.memory.active.realActive real memory
Free real memorycheckpoint.firewall.memory.free.realFree real memory
Processor system timecheckpoint.firewall.cpu.time.systemProcessor system time
Processor usagecheckpoint.firewall.cpu.usageProcessor usage
Processor user timecheckpoint.firewall.cpu.time.userProcessor user time
System uptimecheckpoint.firewall.sysuptimeThe system up time since boot, in system ticks (hundredths of a second)
Generic Interfaces
Metric nameMetric keyDescription
—com.dynatrace.extension.network_device.if.bytes_in.count—
—com.dynatrace.extension.network_device.if.bytes_out.count—
—com.dynatrace.extension.network_device.if.lastchange—
default
Metric nameMetric keyDescription
—com.dynatrace.extension.network_device.sysuptime—
—com.dynatrace.extension.network_device.cpu_usage—
—com.dynatrace.extension.network_device.memory_used—
—com.dynatrace.extension.network_device.memory_free—
—com.dynatrace.extension.network_device.if.status—
Advanced interfaces
Metric nameMetric keyDescription
—com.dynatrace.extension.network_device.if.in.errors.count—
—com.dynatrace.extension.network_device.if.in.discards.count—
—com.dynatrace.extension.network_device.if.out.errors.count—
—com.dynatrace.extension.network_device.if.out.discards.count—
—com.dynatrace.extension.network_device.if.in.multicast_pkts.count—
—com.dynatrace.extension.network_device.if.out.multicast_pkts.count—
—com.dynatrace.extension.network_device.if.in.broadcast_pkts.count—
—com.dynatrace.extension.network_device.if.out.broadcast_pkts.count—
—com.dynatrace.extension.network_device.if.in.ucast_pkts.count—
—com.dynatrace.extension.network_device.if.out.ucast_pkts.count—
Entity attributes
Metric nameMetric keyDescription
Device entity attributescheckpoint.firewall.entity_attributesConstant value of 1 used for reporting entity attributes at a lower frequency
Interfaces
Metric nameMetric keyDescription
Bytes incheckpoint.firewall.if.bytes.in.countNumber of octets received on the interface
Packets incheckpoint.firewall.if.packets.in.countNumber of packets received on the interface
Bytes outcheckpoint.firewall.if.bytes.out.countNumber of octets sent on the interface
Packets outcheckpoint.firewall.if.packets.out.countNumber of packets sent on the interface
Errors incheckpoint.firewall.if.errors.in.countNumber of packets with errors received on the interface
Errors outcheckpoint.firewall.if.errors.out.countNumber of packets with errors sent on the interface
Oper statuscheckpoint.firewall.if.status.operCurrent operational state
Admin statuscheckpoint.firewall.if.status.adminDesired state of interface
Speedcheckpoint.firewall.if.speedEstimate of interface's current bandwidth

FAQ

To troubleshoot this extension, use the guides available in the Dynatrace Community, and Dynatrace Documentation.

Hub

Explore in Dynatrace Hub

Monitor Check Point firewall device performance, interface throughput, and cluster health with SNMP metrics, topology, and alerts.

Related topics

  • Dynatrace blog - New SNMP platform extensions provide observability at scale for network devices
Related tags
NetworkSNMPFirewallCheck Point SoftwareInfrastructure Observability