Monitor Statistics Using SNMP
The statistics that a Simple Network Management Protocol (SNMP) manager collects from Palo Alto Networks firewalls can help you gauge the health of your network (systems and connections), identify resource limitations, and monitor traffic or processing loads. The statistics include information such as interface states (up or down), active user sessions, concurrent sessions, session utilization, temperature, and system uptime.
You can’t configure an SNMP manager to control Palo Alto Networks firewalls (using SET messages), only to collect statistics from them (using GET messages). For details on how SNMP is implemented for Palo Alto Networks firewalls, see SNMP Support.
- Configure the SNMP Manager to get statistics from firewalls.The following steps provide an overview of the tasks you perform on the SNMP manager. For the specific steps, refer to the documentation of your SNMP manager.
- To enable the SNMP manager to interpret firewall statistics, load the Supported MIBs for Palo Alto Networks firewalls and, if necessary, compile them.
- For each firewall that the SNMP manager will monitor, define the connection settings (IP address and port) and authentication settings (SNMPv2c community string or SNMPv3 EngineID/username/password) for the firewall.All Palo Alto Networks firewalls use port 161.The SNMP manager can use the same or different connection and authentication settings for multiple firewalls. The settings must match those you define when you configure SNMP on the firewall (see Step 3). For example, if you use SNMPv2c, the community string you define when configuring the firewall must match the community string you define in the SNMP manager for that firewall.
- Determine the object identifiers (OIDs) of the statistics you want to monitor. For example, to monitor the session utilization percentage of a firewall, a MIB browser shows that this statistic corresponds to OID 188.8.131.52.4.1.254184.108.40.206.3.1.0 in PAN-COMMON-MIB.my. For details, see Use an SNMP Manager to Explore MIBs and Objects.
- Configure the SNMP manager to monitor the desired OIDs.
- Enable SNMP traffic on a firewall interface.This is the interface that will receive statistics requests from the SNMP manager.PAN-OS doesn’t synchronize management (MGT) interface settings for firewalls in a high availability (HA) configuration. You must configure the interface for each HA peer.Perform this step in the firewall web interface.
- To enable SNMP traffic on the MGT interface, select, edit theDeviceSetupInterfacesManagementinterface, selectSNMP, and then clickOKandCommit.
- To enable SNMP traffic on any other interface, create an interface management profile for SNMP services and assign the profile to the interface that will receive the SNMP requests. The interface type must be Layer 3 Ethernet.
- Configure the firewall to respond to statistics requests from an SNMP manager.PAN-OS doesn’t synchronize SNMP response settings for firewalls in a high availability (HA) configuration. You must configure these settings for each HA peer.
- Selectand, in the Miscellaneous section, clickDeviceSetupOperationsSNMP Setup.
- Select the SNMPVersionand configure the authentication values as follows. For version details, see SNMP Support.
- V2c—Enter theSNMP Community String, which identifies a community of SNMP managers and monitored devices, and serves as a password to authenticate the community members to each other.As a best practice, don’t use the default community stringpublic; it’s well known and therefore not secure.
- V3—Create at least one SNMP view group and one user. User accounts and views provide authentication, privacy, and access control when firewalls forward traps and SNMP managers get firewall statistics.
- Views—Each view is a paired OID and bitwise mask: the OID specifies a MIB and the mask (in hexadecimal format) specifies which objects are accessible within (include matching) or outside (exclude matching) that MIB. ClickAddin the first list and enter aNamefor the group of views. For each view in the group, clickAddand configure the viewName,OID, matchingOption(includeorexclude), andMask.
- Users—ClickAddin the second list, enter a username underUsers, select theViewgroup from the drop-down, enter the authentication password (Auth Password) used to authenticate to the SNMP manager, and enter the privacy password (Priv Password) used to encrypt SNMP messages to the SNMP manager.
- Monitor the firewall statistics in an SNMP manager.Refer to the documentation of your SNMP manager for details.When monitoring statistics related to firewall interfaces, you must match the interface indexes in the SNMP manager with interface names in the firewall web interface. For details, see Firewall Interface Identifiers in SNMP Managers and NetFlow Collectors.
Monitor Panorama and Log Collector Statistics Using SNMP
Monitor Panorama and Log Collector Statistics Using SNMP You can configure an SNMP manager to request information from a Panorama management server and configure Panorama ...
SNMP Support You can use an SNMP manager to monitor event-driven alerts and operational statistics for the firewall, Panorama, or WF-500 appliance and for the ...
Enable SNMP Monitoring
Enable SNMP Monitoring Device > Setup > Operations Simple Network Management Protocol (SNMP) is a standard protocol for monitoring the devices on your network. Select ...
Device > Server Profiles > SNMP Trap
Device > Server Profiles > SNMP Trap Simple Network Management Protocol (SNMP) is a standard protocol for monitoring the devices on your network. To alert ...
Forward Traps to an SNMP Manager
Forward Traps to an SNMP Manager Simple Network Management Protocol (SNMP) traps can alert you to system events (failures or changes in hardware or software ...
Use an SNMP Manager to Explore MIBs and Objects
Use an SNMP Manager to Explore MIBs and Objects To use SNMP for monitoring Palo Alto Networks firewalls, Panorama, or WF-500 appliances, you must first ...
SNMP Monitoring and Traps
SNMP Monitoring and Traps The following topics describe how Palo Alto Networks firewalls, Panorama, and WF-500 appliances implement SNMP, and the procedures to configure SNMP ...
Collector Group Configuration
Collector Group Configuration To configure a Collector Group , click Add and complete the following fields. Collector Group Settings Configured In Description Name Panorama Collector ...
Extended SNMP Support
Extended SNMP Support PAN-OS support for Simple Network Management Protocol ( SNMP ) now includes the following features. To access the latest MIBs, refer to ...