Next-Generation Firewall
Free Health Alerts
Table of Contents
Expand All
|
Collapse All
Next-Generation Firewall Docs
-
-
- Cloud Management of NGFWs
- PAN-OS 10.0 (EoL)
- PAN-OS 10.1
- PAN-OS 10.2
- PAN-OS 11.0
- PAN-OS 11.1 & Later
- PAN-OS 9.1 (EoL)
-
- PAN-OS 10.1
- PAN-OS 10.2
- PAN-OS 11.0
- PAN-OS 11.1 & Later
-
-
- Cloud Management and AIOps for NGFW
- PAN-OS 10.0 (EoL)
- PAN-OS 10.1
- PAN-OS 10.2
- PAN-OS 11.0
- PAN-OS 11.1
- PAN-OS 11.2
- PAN-OS 8.1 (EoL)
- PAN-OS 9.0 (EoL)
- PAN-OS 9.1 (EoL)
Free Health Alerts
The following table identifies the free alerts that AIOps for NGFW and Strata Cloud Manager can raise which are related to the health of your platform.
A Premium license is not required in order for AIOps for NGFW or Strata Cloud Manager to raise these alerts.
Alert
|
Description
|
---|---|
Log Loss due to Log Forwarding Failure (Free alert)
|
The firewall attempts to reliably forward logs to Panorama, log collectors, or the Strata Logging Service. When a forwarded log is successfully received, the firewall will receive an acknowledgment from these destinations. This alert is triggered when the firewall’s ability to track the unacknowledged logs is at capacity. A backlog of too many unacknowledged logs results in log loss.
Class: Health
Category: Logging
|
ACC Query Failure (Free alert)
|
This alert detects if the Application Command Center (ACC) query has failed.
Class: Health
Category: Logging
|
Approaching Max Capacity - EDL Custom Lists (Free alert)
|
The number of EDL Custom List objects is approaching the maximum capacity the firewall can support.
Class: Health
Category: Capacity
|
Approaching Max Capacity - URLs or IPs within EDLs (Free alert)
|
The number of URLs, IPs, or Domains within the configured EDL(s) used in policy on this firewall is approaching the maximum capacity that the firewall can support.
Class: Health
Category: Resource limits
|
Approaching Max Tunnel Throughput (Free alert)
|
The IPsec VPN tunnel usage is close to maximum.
Class: Health
Category: Site-to-Site VPN
|
Card Power Failure (Free alert)
|
A card failure has been detected, suggesting a potential issue with the card or its seating within the chassis.
Class: Health
Category: Hardware
|
Config Memory Usage Approaching Max Limits (Free alert)
|
The firewall's configuration is approaching its maximum memory usage limit. During commits, the firewall's total config memory must accommodate two copies: the current 'in-use' configuration and the new 'to-be-used' configuration. If the allocated memory per configuration exceeds 50%, the firewall reaches capacity, resulting in commit failure.
Class: Health
Category: Resource limits
|
Configuration size reaching device capacity limit (Free alert)
|
The configuration size of this device has reached its capacity limit.
Class: Health
Category: Resource limits
|
Connection Failure to LDAP Server (Free alert)
|
This alert indicates a connection failure between the firewall or Panorama and the LDAP server.
Class: Health
Category: Logging
|
DHCP Client IPv4 address Assignment Failure (Free alert)
|
This alert is triggered when a firewall’s dataplane interface configured as an IPv4 DHCP client either fails to obtain an IP address or has lost its assigned IP address.
Class: Health
Category: Traffic
|
Degraded System Drive (Free alert)
|
A degraded system drive has been identified by monitoring its attributes values.
Class: Health
Category: Hardware
|
Delayed Telemetry (Free alert)
|
The analytics engines have no new telemetry from this NGFW/Panorama.
Class: Health
Category: Telemetry
|
Dropping Logs - Log Forwarding Queue Failure (Free alert)
|
This alert is triggered when a firewall or Panorama's internal log forwarding queue becomes full and starts dropping logs while trying to forward them to an external log destination like a Syslog server or HTTP server. This can occur even if there are no connectivity issues between the firewall or Panorama and the external log server.
Class: Health
Category: Logging
|
Empty Tunnel (Free alert)
|
The IPsec VPN tunnel has no traffic in both ingress and egress.
Class: Health
Category: Site-to-Site VPN
|
FE100 Failure (Free alert)
|
A calibration error has been detected on the FE100 chip in the firewall. This issue usually indicates a hardware failure.
Class: Health
Category: Hardware
|
Fan Issues (Free alert)
|
A fan or fan tray triggered an alarm on the device.
Class: Health
Category: Hardware
|
Fatal Machine Check Failure (Free alert)
|
A Fatal Machine check failure was detected. This issue usually indicates a hardware failure in the CPU.
Class: Health
Category: Hardware
|
Firewall Disconnected from Panorama (Free alert)
|
The connection between Firewall and Panorama has been lost.
Class: Health
Category: System state
|
HA Backup (Free alert)
|
The HA Backup link(s) are not currently configured.
Class: Health
Category: High-Availability
|
HA Peer Connection Status (Free alert)
|
One of the firewalls in the HA pair is in a non-healthy state.
Class: Health
Category: High-Availability
|
HA pair - Oversubscription of resources (Free alert)
|
The active/active HA pair is exceeding 100% resource usage.
Class: Health
Category: High-Availability
|
HW failure - DIMM Error (Free alert)
|
A Dual In-Line Memory Module (DIMM) is a hardware component responsible for storing and accessing data in the firewall's random access memory (RAM). This memory module plays a critical role in the firewall's performance, facilitating rapid processing of network traffic and execution of security tasks. An error related to this component typically indicates a memory failure, where processes encounter issues reaching the specific memory location.
Class: Health
Category: Hardware
|
High Dataplane Processing Latency (Free alert)
|
This alert is triggered when the dataplane processing latency on the firewall exceeds the predefined threshold. Dataplane processing latency refers to the time taken by the firewall to process network traffic and make forwarding decisions.
Class: Health
Category: Resource limits
|
High Disk Space Usage - Pancfg partition (Free alert)
|
The hard disk partition is nearing or at capacity.
Class: Health
Category: Resource limits
|
High Disk Space Usage - Panlogs partition (Free alert)
|
The hard disk partition is nearing or at capacity.
Class: Health
Category: Resource limits
|
High Disk Space Usage - Root partition (Free alert)
|
The hard disk partition is nearing or at capacity.
Class: Health
Category: Resource limits
|
High Processing Activity (Free alert)
|
One or more computing resources are running low on the device.
Class: Health
Category: Resource limits
|
IKEv1 IPsec Tunnel Down - Peer Identification Mismatch (Free alert)
|
This alert triggers when the IKEv1 IPsec tunnel is down due to a Peer Identification mismatch, which is vital for establishing secure communication between peers in an IPsec VPN connection; a discrepancy in Peer Identification between the local and remote ends can prevent the tunnel from establishing or maintaining a connection.
Class: Health
Category: Site-to-Site VPN
|
IKEv2 IPsec Tunnel Down - IPsec Crypto Profile configuration mismatch (Free alert)
|
This alert triggers when the IKEv2 IPsec tunnel is down due to an IPsec Crypto Profile configuration mismatch, which is vital for establishing secure communication between peers in an IPsec VPN connection. A discrepancy in the IPsec Crypto Profile configuration between the local and remote ends can lead to the failure of the Child SA negotiation, thereby preventing the establishment or maintenance of phase 2 of the tunnel.
Class: Health
Category: Site-to-Site VPN
|
IKEv2 IPsec Tunnel Down - Peer Identification Mismatch (Free alert)
|
This alert triggers when the IKEv2 IPsec tunnel is down due to a Peer Identification mismatch, which is vital for establishing secure communication between peers in an IPsec VPN connection. Any discrepancy in Peer Identification between the local and remote ends can prevent the tunnel from establishing or maintaining a connection.
Class: Health
Category: Site-to-Site VPN
|
IPQ Error (Free alert)
|
An IPQ (Ingress Packet Queue) error has been detected on one of the FE100 chips in the firewall. This error usually indicates a reseat is needed, or there is a hardware failure.
Class: Health
Category: Hardware
|
Irregular Input Power (Free alert)
|
Device power levels are outside of the normal range.
Class: Health
Category: Hardware
|
License Expiration (Free alert)
|
One or more of your licenses are nearing or have reached expiration.
Class: Health
Category: PAN-OS and Subscriptions
|
Logging Drive Failure (Free alert)
|
A failed logging drive has been identified through the monitoring of the firewall's disk status.
Class: Health
Category: Hardware
|
MPC Card - CPLD Failure (Free alert)
|
The Management Processor Card (MPC) is an essential component for the PA-5450, providing management, logging, and high availability functions. The MPC card has experienced a failure due to an issue with its component, the Complex Programmable Logic Device (CPLD).
Class: Health
Category: Hardware
|
NGFW/Panorama Management Certificate Expiration (Free alert)
|
This alert detects the expiration of the NGFW/Panorama Management Certificate.
Class: Health
Category: Certificates
|
NPC Card - FE100 Failure (Free alert)
|
Network Processing Cards (NPCs) provide network connectivity and are essential for network traffic processing. An NPC card has experienced an issue with its FE100 component, leading to its failure.
Class: Health
Category: Hardware
|
Non-default Logging level (Free alert)
|
This alert is triggered when the logging level of a service is not set to its default configuration. This alert ensures that services consistently maintain their designated logging settings.
Class: Health
Category: Resource limits
|
Out of Sync Peers - Configuration (Free alert)
|
The system configurations on the high availability peers do not match.
Class: Health
Category: High-Availability
|
Out of Sync Peers - Dynamic Content (Free alert)
|
Dynamic content, such as Antivirus or Applications and Threats, do not match between the high availability peers.
Class: Health
Category: High-Availability
|
Out of Sync Peers - Sessions (Free alert)
|
Sessions are not matching or up to date between the High availability Peers.
Class: Health
Category: High-Availability
|
Out of Sync Peers - Software (Free alert)
|
The PAN-OS software versions on the high availability peers do not match.
Class: Health
Category: High-Availability
|
Outdated Dynamic Content (Free alert)
|
The dynamic content installed on the device is stale when compared to the content that is available on the update server.
Class: Health
Category: Dynamic content
|
PAN-OS End-of-Life (Free alert)
|
Your current version of PAN-OS is no longer supported.
Class: Health
Category: PAN-OS and Subscriptions
|
PAN-OS Known Vulnerability (Free alert)
|
Your current version of PAN-OS has known vulnerabilities.
Class: Health
Category: PAN-OS and Subscriptions
|
PAN-OS Root and Default Certificate Expiration - Scenario 1 (Free alert)
|
The root certificate and the default certificate on the firewall expired.
Class: Health
Category: Certificates
|
PAN-OS Root and Default Certificate Expiration - Scenario 2 (Free alert)
|
The root certificate and the default certificate on the firewall expired.
Class: Health
Category: Certificates
|
PAN-OS integrated User-ID Agent Monitored Server Disconnected (Free alert)
|
This alert is triggered when the server, monitored by the PAN-OS integrated User-ID Agent (Agentless User-ID), loses connection with the firewall. This monitored server is a critical component for mapping user identities to network activities.
Class: Health
Category: Hardware
|
PCI Error (Free alert)
|
A Peripheral Component Interconnect (PCI) is responsible for connecting the Management Plane (MP) to the Control Plane (CP). A certain error related to this component indicates a failure in its functionality.
Class: Health
Category: Hardware
|
Path Monitor Failure - Card (Free alert)
|
A path monitoring failure has been detected on a card located within the firewall's slots.
Class: Health
Category: Hardware
|
Policy Config Memory Usage Approaching Max Limits (Free alert)
|
This alert detects if the policy config memory usage exceeds a critical threshold.
Class: Health
Category: Resource limits
|
Port Failure (Free alert)
|
A failure related to the management physical port or one of the high-availability physical ports has been detected.
Class: Health
Category: Hardware
|
Process Memory Depletion - Configd (Free alert)
|
The device’s management plane processes are depleting its available memory.
Class: Health
Category: Resource limits
|
Process Memory Depletion - Device Server (Free alert)
|
The device’s management plane processes are depleting its available memory.
Class: Health
Category: Resource limits
|
Process Memory Depletion - Log Receiver (Free alert)
|
The device’s management plane processes are depleting its available memory.
Class: Health
Category: Resource limits
|
Process Memory Depletion - Management Server (Free alert)
|
The device’s management plane processes are depleting its available memory.
Class: Health
Category: Resource limits
|
Process Memory Depletion - Report (Free alert)
|
The device’s management plane processes are depleting its available memory.
Class: Health
Category: Resource limits
|
Process Memory Depletion - User Id (Free alert)
|
The device’s management plane processes are depleting its available memory.
Class: Health
Category: Resource limits
|
Reduced Tunnel Throughput (Free alert)
|
The IPsec VPN tunnel usage is below normal usage.
Class: Health
Category: Site-to-Site VPN
|
Redundant Power Supply Failure (Free alert)
|
Power supply redundancy is not attained either because it hasn't been inserted, the power supply has malfunctioned, or complete redundancy hasn't been accomplished.
Class: Health
Category: Hardware
|
SAML SSO authentication failed for User (Free alert)
|
When the Authentication Profile filters specific groups for GlobalProtect or Captive Portal users, or both, authentication failures may occur. Even if users seem to belong to the group listed in the allow list, they still encounter the "user not in allow list" message. Changing the allow list to include "all" groups rather than specific ones enables successful user authentication.
Class: Health
Category: Logging
|
SCP Scheduled Log Export Failure (Free alert)
|
This alert detects if the SCP scheduled log export has failed.
Class: Health
Category: Logging
|
Session Failure (Free alert)
|
Sessions can fail in the firewall, which can result in the increment of various global counters. These global counters indicate the reason that traffic session failed.
Class: Health
Category: Traffic
|
System Drive or Connector fault (Free alert)
|
This alert indicates that the device has experienced a hardware failure in either the drive or the drive connector.
Class: Health
Category: Hardware
|
Terminal Server agent Self-signed Certificate Expiration (Free alert)
|
This alert detects the upcoming expiration of the Terminal Server agent self-signed certificate.
Class: Health
Category: Certificates
|
Thermal Issues (Free alert)
|
Device temperature is outside of the normal range.
Class: Health
Category: Hardware
|
Traffic Latency - Packet Descriptors (on-chip) (Free alert)
|
Packet Descriptor (on-chip) resources are running low on the device.
Class: Health
Category: Flood/DoS
|
Unidirectional Tunnel Traffic (Free alert)
|
The IPsec VPN tunnel has has unidirectional traffic.
Class: Health
Category: Site-to-Site VPN
|
Unsupported Transceiver Used (Free alert)
|
This alert is raised if the part number for any transceiver (SFP, SFP+, QSFP, QSFP+), within a single device, is incompatible with the specifications supported by Palo Alto Networks.
Class: Health
Category: Hardware
|
User authentication unsuccessful - received out-of-band SAML message (Free alert)
|
When the user attempts to log in to GlobalProtect, the Captive Portal, or the Admin UI, if using an Identity Provider (IdP), the IdP sends a SAML Assertion to the PAN-OS device’s Assertion Consumer Service (ACS) URL. Even if the authentication with the IdP is successful, the PAN-OS device must still validate the SAML Assertion to successfully validate the authentication.
This alert is triggered when the PAN-OS device is not expecting a SAML Assertion but receives one, indicating some user’s login attempt was unsuccessful.
Class: Health
Category: Account Monitoring and Control
|
User authentication unsuccessful - “max_clock_skew” Error (Free alert)
|
This alert indicates that the Security Assertion Markup Language (SAML) Identity Provider's authentication message encountered a "max_clock_skew" error due to time discrepancies between the Identity Provider (IdP) and the firewall/Panorama. This issue is often caused by out-of-sync local time or network latency.
Class: Health
Category: Account Monitoring and Control
|
User-ID agent Self-signed Certificate Expiration (Free alert)
|
This alert detects the upcoming expiration of the User-ID agent self-signed certificate. The alert detects if a PAN-OS device has a User-ID policy configured, meets the PAN-OS version requirements per Table 1 of the advisory, and is using a self-signed certificate. It does not apply if custom certificates are in use or User-ID mappings are provided only by an NGFW that serves as a User-ID agent or from GlobalProtect agents.
Class: Health
Category: Certificates
|
Zone Protection profile - Flood Detection (Free alert)
|
Connections established on the zone or the incoming packet rate are excessive or abnormal.
Class: Health
Category: Flood/DoS
|
Zone Protection profile - Threshold Recommendation (Free alert)
|
A zone is missing a Zone Protection profile or the threshold values in a Zone Protection profile need adjustment.
Class: Health
Category: Flood/DoS
|