Forward Traps to an SNMP Manager
Simple Network Management Protocol (SNMP) traps can alert you to system events (failures or changes in hardware or software of Palo Alto Networks firewalls) or to threats (traffic that matches a firewall security rule) that require immediate attention.
- Enable the SNMP manager to interpret the traps
it receives.Load the Supported MIBs for Palo Alto Networks firewalls and, if necessary, compile them. For the specific steps, refer to the documentation of your SNMP manager.
an SNMP Trap server profile.The profile defines how the firewall accesses the SNMP managers (trap servers). You can define up to four SNMP managers for each profile.Optionally, configure separate SNMP Trap server profiles for different log types, severity levels, and WildFire verdicts.
- Log in to the firewall web interface.
- Select DeviceServer ProfilesSNMP Trap.
- Click Add and enter a Name for the profile.
- If the firewall has more than one virtual system (vsys), select the Location (vsys or Shared) where this profile is available.
- Select the SNMP Version and
configure the authentication values as follows. For version details,
- V2c—For each server, click Add and enter the server Name, IP address (SNMP Manager), and Community String. The community string identifies a community of SNMP managers and monitored devices, and serves as a password to authenticate the community members to each other.As a best practice, don’t use the default community string public; it’s well known and therefore not secure.
- V3—For each server, click Add and enter the server Name, IP address (SNMP Manager), SNMP User account (this must match a username defined in the SNMP manager), EngineID used to uniquely identify the firewall (you can leave the field blank to use the firewall serial number), authentication password (Auth Password) used to authenticate to the server, and privacy password (Priv Password) used to encrypt SNMP messages to the server.
- Click OK to save the server profile.
- Configure log forwarding.
- Configure the destinations of Traffic, Threat,
and WildFire traps:
- Create a Log Forwarding profile. For each log type and each severity level or WildFire verdict, select the SNMP Trap server profile.
- Assign the Log Forwarding profile to policy rules and network zones. The rules and zones will trigger trap generation and forwarding.
- Configure the destinations for System, Configuration, User-ID, HIP Match, and Correlation logs. For each log (trap) type and severity level, select the SNMP Trap server profile.
- Click Commit.
- Configure the destinations of Traffic, Threat, and WildFire traps:
- Monitor the traps in an SNMP manager.Refer to the documentation of your SNMP manager.When monitoring traps related to firewall interfaces, you must match the interface indexes in the SNMP manager with interface names in the firewall web interface. For details, see Firewall Interface Identifiers in SNMP Managers and NetFlow Collectors.
Device > Server Profiles > SNMP Trap
Device > Server Profiles > SNMP Trap Simple Network Management Protocol (SNMP) is a standard protocol for monitoring the devices on your network. To alert ...
Monitor Statistics Using SNMP
Monitor Statistics Using SNMP The statistics that a Simple Network Management Protocol (SNMP) manager collects from Palo Alto Networks firewalls can help you gauge the ...
Enable SNMP Monitoring
Enable SNMP Monitoring Device > Setup > Operations Simple Network Management Protocol (SNMP) is a standard protocol for monitoring the devices on your network. Select ...
SNMP Support You can use an SNMP manager to monitor event-driven alerts and operational statistics for the firewall, Panorama, or WF-500 appliance and for the ...
Monitor Panorama and Log Collector Statistics Using SNMP
Monitor Panorama and Log Collector Statistics Using SNMP You can configure an SNMP manager to request information from a Panorama management server and configure Panorama ...
Collector Group Configuration
Collector Group Configuration To configure a Collector Group , click Add and complete the following fields. Collector Group Settings Configured In Description Name Panorama Collector ...
SNMP Monitoring and Traps
SNMP Monitoring and Traps The following topics describe how Palo Alto Networks firewalls, Panorama, and WF-500 appliances implement SNMP, and the procedures to configure SNMP ...
Configure Log Forwarding from Panorama to External Destinations
Configure Log Forwarding from Panorama to External Destinations Panorama enables you to forward logs to external services, including syslog, email, SNMP trap, and HTTP-based services. ...
Selective Log Forwarding Based on Log Attributes
Selective Log Forwarding Based on Log Attributes To maximize the efficiency of your incident response and monitoring operations, you can now create custom log forwarding ...