sk179926 - Threshold ASG traps send empty "asgTrapChassisID" and "asgTrapBladeID" variables
Threshold ASG traps send empty "asgTrapChassisID" and "asgTrapBladeID" variables
Product: Maestro HyperScale Firewall, Scalable Chassis
Version: R80.20SP (EOS), R80.30SP (EOS), R81 (EOS), R81.10 (EOS), R81.20
Last Modified: 2023-03-07
Symptoms
- Threshold ASG traps send empty "
asgTrapChassisID" and "asgTrapBladeID" variables.
Traffic captures show the empty variable bindings.
| SNMP trap | OID |
| asgTrapChassisId | .1.3.6.1.4.1.2620.1.2001.0.10 |
| asgTrapBladeId | .1.3.6.1.4.1.2620.1.2001.0.11 |
From the traffic capture
E:2620.1.2001.0.10.0=""
E:2620.1.2001.0.11.0=""
E:2620.1.2001.0.12.0="[1_01,hd_usage,/boot,percent]: 98 exceeds maximum threshold of 80 (Alert time: 04-11-2022 10:46)"
E:2620.1.2001.0.13.0=1
- The following OIDs are affected:
| asgTrapConcurrentConnections | Concurrent Connections Total events |
| asgTrapConcurrentConnectionsTotal | Concurrent Connections Peak events |
| asgTrapConnRateTotal | Connection Rate Total events |
| asgTrapConnRate | Connection Rate events |
| asgTrapThroughputTotal | Throughput Total events |
| asgTrapThroughput | Throughput events |
| asgTrapPacketRateTotal | Packet Rate Total events |
| asgTrapPacketRate | Packet Rate events |
| asgCpuCoreUtilTrap | CPU Usage Peak events |
| asgDiskSpaceTrap | Available disk space threshold events |
- The other ASG SNMP traps, such as "
asgBladeStateTrap" create the aforementioned variable bindings correctly.
Cause
The SNMP trap alert is missing the ChassisID and MemberID parameters in the gperfanalyze.tcl script.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R81.20 starting from Take 8
- Jumbo Hotfix Accumulator for R81.10 starting from Take 82
- Jumbo Hotfix Accumulator for R81 starting from Take 79
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2022-09-07
Last Modified: 2023-03-07