[Home]MyMRTG Page

HauptseiteVerlaufPreferences

How 2 monitor
Checkpoint Firewall-1 with MRTG

Number of sessions during day
Number of connections in the FW1 state table during an average day. Click here to see the full report.
 
Credits
Doing rateup binaries:
Tobias Oetiker <oetiker@ee.ethz.ch>
Doing all the work with me:
Frank Lindemann <hurrz@hurrz.de>

 

 

This side gives a rough description on how to monitor Checkpoint Firewall-1 using MRTG. We are using MRTG running locally on each filter module, so that SNMP is not required. Basically MRTG is used for drawing the graphs only. Maybe in the near future we will use Cricket.

The advantage are:


The shortcomings are: I think the shortcomings are acceptable. Well, you can say that one fine day an intruder might be able to run Perl- scripts on your filter. O.K. ... Right. But, be honest, if a Blackhat is able to penetrate your filter so that he can run scripts on it, it doesen't really matter any more, does it ?
This stuff is heavily tailored for Fireall-1 running on Solaris 6/7 (32 bit). This is before NG has come into beeing. On these machines Checkpoint doesen't scale over multiple CPUs, but Solaris and its drivers do. On multi CPU machines you do not have much loss since MRTG or the rateup binary is always running on an other CPU than the Checkpoint Software.
We are montoring two values only, using scripts feeding them into MRTG: MRTG by itself is made of Perl (the MRTG- Programm) and a tiny binary (rateup) which needs to be compiled. Well, the binaries are sometimes hard to get and difficult to compile if you haven't got a suitable platform handy. I have made a tarball for download (http://www.joerg.cc/downloads/mrtg-271-exec.tar) which should contain everything you need, which is the MRTG- stuff, the rateup binary, mrtg.config and two shell scripts cmd.sh,cmd1.sh feeding MRTG with the above mentioned values.
Additionally you will need to have installed the following packages on Solaris 6/7 . Please note that these are configurations we tried and consider as working. Other package- versions might also be suitable. You can get the packages from www.ibiblio.org/pub/packages/solaris/sparc.

Because of numerous requests I have placed some more recent rateup binaries (MRTG 2.9.27, Solaris 8 and MRTG 2.10.5, Solaris 9) on my server.
MRTG 2.9.27, Solaris 8
MRTG 2.10.5, Solaris 9
 
FeedBack
If you have any questions and comments I would like to hear from you:
<fritsch@joerg.cc>,
or just click here and commentMyMRTG page !
HauptseiteVerlaufPreferences
This page is read-onlyAndere Versionen ansehen
Last edited November 15, 2003 8:12 pm CST (diff)
Search: