Enable SNMP Monitoring
- Device > Setup > Operations
Simple Network Management Protocol (SNMP) is a standard protocol for monitoring the devices on your network. Select Operations to configure the firewall to use the SNMP version that your SNMP manager supports (SNMPv2c or SNMPv3). For a list of the MIBs that you must load into the SNMP manager so it can interpret the statistics it collects from the firewall, see Supported MIBs . To configure the server profile that enables the firewall to communicate with the SNMP trap destinations on your network, see Device > Server Profiles > SNMP Trap. The SNMP MIBs define all SNMP traps that the firewall generates. An SNMP trap identifies an event with a unique Object ID (OID) and the individual fields are defined as a variable binding (varbind) list. Click SNMP Setup and specify the following settings to allow SNMP GET requests from your SNMP manager:
Specify the physical location of the firewall. When a log or trap is generated, this information allows you to identify (in an SNMP manager) the firewall that generated the notification.
Enter the name or email address of the person responsible for maintaining the firewall. This setting is reported in the standard system information MIB.
Use Specific Trap Definitions
This option is selected by default, which means the firewall uses a unique OID for each SNMP trap based on the event type. If you clear this option, every trap will have the same OID.
Select the SNMP version: V2c (default) or V3. Your selection controls the remaining fields that the dialog displays.
For SNMP V2c
SNMP Community String
Enter the community string, which identifies an SNMP community of SNMP managers and monitored devices and also serves as a password to authenticate the community members to each other when they exchange SNMP get (statistics request) and trap messages. The string can have up to 127 characters, accepts all characters, and is case-sensitive.
Don’t use the default community string public. Because SNMP messages contain community strings in clear text, consider the security requirements of your network when defining community membership (administrator access).
For SNMP V3
Name / View
You can assign a group of one or more views to the user of an SNMP manager to control which MIB objects (statistics) the user can get from the firewall. Each view is a paired OID and bitwise mask: the OID specifies a MIB and the mask (in hexadecimal format) specifies which objects are accessible within (include matching) or outside (exclude matching) that MIB.
For example, if the OID is 184.108.40.206, the matching Option is set to include and the Mask is 0xf0, then the objects that the user requests must have OIDs that match the first four nodes (f = 1111) of 220.127.116.11. The objects don’t need to match the remaining nodes. In this example, 18.104.22.168.2 matches the mask and 22.214.171.124.2 doesn’t.
For each group of views, click Add, enter a Name for the group, and then configure the following for each view you Add to the group:
To provide access to all management information, use the top-level OID 126.96.36.199, set the Mask to 0xf0, and set the matching Option to include.
SNMP user accounts provide authentication, privacy, and access control when firewalls forward traps and SNMP managers get firewall statistics. For each user, click Add and configure the following settings:
Monitor Statistics Using SNMP
Monitor Statistics Using SNMP The statistics that a Simple Network Management Protocol (SNMP) manager collects from Palo Alto Networks firewalls can help you gauge the ...
Monitor Panorama and Log Collector Statistics Using SNMP
Monitor Panorama and Log Collector Statistics Using SNMP You can configure an SNMP manager to request information from a Panorama management server and configure Panorama ...
Device > Server Profiles > SNMP Trap
Device > Server Profiles > SNMP Trap Simple Network Management Protocol (SNMP) is a standard protocol for monitoring the devices on your network. To alert ...
Forward Traps to an SNMP Manager
Forward Traps to an SNMP Manager Simple Network Management Protocol (SNMP) traps can alert you to system events (failures or changes in hardware or software ...
SNMP Support You can use an SNMP manager to monitor event-driven alerts and operational statistics for the firewall, Panorama, or WF-500 appliance and for the ...
Collector Group Configuration
Collector Group Configuration To configure a Collector Group , click Add and complete the following fields. Collector Group Settings Configured In Description Name Panorama Collector ...
Use an SNMP Manager to Explore MIBs and Objects
Use an SNMP Manager to Explore MIBs and Objects To use SNMP for monitoring Palo Alto Networks firewalls, Panorama, or WF-500 appliances, you must first ...
LLDP Syslog Messages and SNMP Traps
LLDP Syslog Messages and SNMP Traps The firewall stores LLDP information in MIBs, which an SNMP Manager can monitor. If you want the firewall to ...
Walk a MIB
Walk a MIB If you want to see which SNMP objects (system statistics and traps) are available for monitoring, displaying all the objects of a ...