Comparing indeni and Check Point’s SmartView Monitor

Notice: This blog post was originally published on Indeni before its acquisition by BlueCat.

The content reflects the expertise and perspectives of the Indeni team at the time of writing. While some references may be outdated, the insights remain valuable. For the latest updates and solutions, explore the rest of our blog

Key Takeaways
  • Check Point SmartView Monitor provides only basic firewall health metrics such as status, resource utilization, traffic counters, VPN status, and NAC status.
  • Many operational issues in Check Point firewalls cannot be detected by SmartView Monitor because it does not deeply analyze configuration, logs, or runtime parameters.
  • Indeni performs advanced checks including certificate authority accessibility, policy installation impact on CPU, kernel and connection table limits, and log file growth rates.
  • Indeni enhances cluster reliability by detecting NIC failures, ClusterXL member state issues, routing table inconsistencies, ARP anomalies, and duplex or speed misconfigurations.
  • Indeni validates and monitors critical dependencies such as DNS and NTP servers, identifying slow responses, resolution failures, or non-operational time sources.
  • Indeni Insight crowdsources operational knowledge from multiple Check Point environments, enabling proactive detection of known failure patterns across all customers.

The summary:

Check Point’s SmartView Monitor is great as a basic tool for identifying the operational health of your firewalls. However, if your network is supporting critical business services and you rely on your firewalls’ uptime to succeed, you need something more capable. indeni provides you with the ability to stay ahead of possible issues in your Check Point firewalls, as well as other devices.

Therefore, if you need in-depth insight into your Check Point firewalls and management servers’ operational health, you need indeni.

The longer version:

From checkpoint.com: “SmartView Monitor is a high-performance network and security analysis system that helps you easily administer your network by establishing work habits based on learned system resource patterns. Based on Check Point’s Security Management Architecture, SmartView Monitor provides a single, central interface for monitoring network activity and performance of Check Point Software Blades.”

If you dig deeper into what SmartView Monitor helps you see, you’ll find:

  • Gateway general health information (up/down, cluster fail over, CPU/memory utilization, operating system in use)
  • Traffic counters
  • Status of VPN tunnels
  • Remote users connected via VPN (such as SecuRemote)
  • Status of Cooperative Enforcement (Check Point’s NAC solution)

This is sufficient if all you are looking for is the basic health of the firewall. The vast majority of issues, however, cannot be uncovered in this way. SmartView Monitor (also known as RTM), wasn’t constructed to dig deep into the operational health of firewalls. In comparison, here’s a partial list of what indeni can help you uncover:

  1. Gateway cannot access certificate authority
  2. Policy installation resulted in high CPU load cluster may failover
  3. Firewall log file increase rate critical – possible connectivity loss to log server
  4. Firewall kernel table limit approaching or reached
  5. ClusterXL member is in a critical state
  6. Cluster member down due to NIC error
  7. Some received packets have been dropped by NIC (SA#24915)
  8. High memory usage (including pin-pointing the cause for the memory usage)
  9. DNS servers configured but responding too slowly
  10. Use of NTP servers configured but not operational
  11. Firewall Connection Table Limit Approaching or Reached
  12. A NIC has failed recently (SA#24915)
  13. RX traffic drastically reduced post fail over possible ARP issue
  14. Two cluster members differ in their routing tables (SA#66322)
  15. DNS server resolution test failed
  16. NAT connections (fwx_alloc) table limit approaching or reached
  17. Errors have been found in packets transmitted by NIC (SA#24915)
  18. ARP table is approaching its limits (SA#25890)
  19. VPN gateway is dropping unexpected packets (SA#22255)
  20. NIC duplex set to half with speed of 10mbps or 100mbps (SA#24967)

The ability of indeni to run such a complicated analysis of the firewalls’ configuration, logs and running parameter, is what allows for these issues to be uncovered. In addition, indeni leverages the world’s knowledge, via indeni Insight. This means that when a given Check Point customer runs into a certain issue and shares it with indeni, all of the other customers benefit.

The bottom line:

Check Point’s SmartView Monitor is great, albeit fairly limited in depth. indeni provides you with far greater insight into the health of your firewalls, and as a result, true proactivity. With indeni, you will solve issues before they even happen.

Try Indeni now, it only takes 45 minutes.


Published in:

Related content

Agentic AI adoption in network observability propels NetOps teams

Network observability is crucial for today’s networks and even more capable with agentic AI, according to new Omdia and BlueCat research.

Read more

Stop the ticket bottleneck: Automate DNS, DHCP, and IPAM with Quick Service

Automated DNS, DHCP, and IPAM (DDI) service delivery enables organizations to replace manual, ticket-based workflows with policy-driven, self-service…

Read more

Stay ahead of network issues with real-time metrics with BlueCat Integrity X

Get real-time DNS, DHCP, and IPAM metrics with BlueCat Integrity X. Detect issues early using native Prometheus telemetry and proactive DDI observability.

Read more

Adding business context to DDI with tagging in BlueCat Integrity X

Add business context to DNS, DHCP, and IPAM with tagging in BlueCat Integrity X. Improve visibility, automation, and governance across complex networks.

Read more

⏳ Cisco Live is almost here. Put BlueCat on your agenda for smarter, more secure networks.