<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WAN interface connectivity loss logged anywhere? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/wan-interface-connectivity-loss-logged-anywhere/m-p/48448#M35657</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I haven't tried this quite yet but Dead Peer Detection is looking promising.(&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1323"&gt;Dead Peer Detection and Tunnel Monitoring&lt;/A&gt;)&amp;nbsp; It sounds like I can have it monitor an ip address on the other end of the tunnel and then it will write an event to the system log on down events.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;@Mystique - Thanks for the syslog reminder and cautionary note, I have traffic and threat logs being forwarded already but the system syslog settings slipped by me.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 27 Oct 2014 23:46:53 GMT</pubDate>
    <dc:creator>bgirdner</dc:creator>
    <dc:date>2014-10-27T23:46:53Z</dc:date>
    <item>
      <title>WAN interface connectivity loss logged anywhere?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wan-interface-connectivity-loss-logged-anywhere/m-p/48445#M35654</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do the PaloAlto's have any functionality to monitor a wan link or tunnel and create a log entry if the link is down or there is significant packet loss?&amp;nbsp; I am able to see these things through external monitoring tools but it would be nice to have a system log entry or something on the PANs as well.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Oct 2014 22:36:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wan-interface-connectivity-loss-logged-anywhere/m-p/48445#M35654</guid>
      <dc:creator>bgirdner</dc:creator>
      <dc:date>2014-10-27T22:36:18Z</dc:date>
    </item>
    <item>
      <title>Re: WAN interface connectivity loss logged anywhere?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wan-interface-connectivity-loss-logged-anywhere/m-p/48446#M35655</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can use xml api to monitor the tunnel status.&lt;/P&gt;&lt;P&gt;Please refer to below document:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-7378"&gt;How to Monitor VPN state through XML API&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also setup profile for system logs to be forwarded via Email or SNMP Trap by creating log setting profile under Device --&amp;gt; Log setting --&amp;gt; System --&amp;gt; select severity &lt;/P&gt;&lt;P&gt;Whenever a tunnel is down, then system logs are created for the specific tunnel. Please note this could possibly flood your emails if you select forwarding for all types of severity. There is no way to filter the system logs only for tunnels before forwarding via Email or to syslog server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Oct 2014 22:45:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wan-interface-connectivity-loss-logged-anywhere/m-p/48446#M35655</guid>
      <dc:creator>Mystique</dc:creator>
      <dc:date>2014-10-27T22:45:17Z</dc:date>
    </item>
    <item>
      <title>Re: WAN interface connectivity loss logged anywhere?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wan-interface-connectivity-loss-logged-anywhere/m-p/48447#M35656</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bridrner,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For any interface up/down situation firewall creates log in Monitor &amp;gt; System log. Let me know if you have query.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For error firewall do not create any report or log. That should be done via SNMP tool.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Oct 2014 23:12:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wan-interface-connectivity-loss-logged-anywhere/m-p/48447#M35656</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-10-27T23:12:22Z</dc:date>
    </item>
    <item>
      <title>Re: WAN interface connectivity loss logged anywhere?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wan-interface-connectivity-loss-logged-anywhere/m-p/48448#M35657</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I haven't tried this quite yet but Dead Peer Detection is looking promising.(&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1323"&gt;Dead Peer Detection and Tunnel Monitoring&lt;/A&gt;)&amp;nbsp; It sounds like I can have it monitor an ip address on the other end of the tunnel and then it will write an event to the system log on down events.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;@Mystique - Thanks for the syslog reminder and cautionary note, I have traffic and threat logs being forwarded already but the system syslog settings slipped by me.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Oct 2014 23:46:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wan-interface-connectivity-loss-logged-anywhere/m-p/48448#M35657</guid>
      <dc:creator>bgirdner</dc:creator>
      <dc:date>2014-10-27T23:46:53Z</dc:date>
    </item>
    <item>
      <title>Re: WAN interface connectivity loss logged anywhere?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wan-interface-connectivity-loss-logged-anywhere/m-p/48449#M35658</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="2086" data-externalid="" data-presence="null" data-userid="27029" data-username="bgirdner" href="https://live.paloaltonetworks.com/people/bgirdner" style="padding: 0 3px 0 0; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #006595;"&gt;bgirdner&lt;/A&gt;&lt;/STRONG&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is no provision to monitor WAN link but there is tunnel monitoring which can be used to monitor the tunnel status for IPsec VPN. When tunnel monitoring fails, it creates a system logs entry indicating the tunnel as down.&lt;/P&gt;&lt;P&gt;Please take a look at the document below which might be helpful to you:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-7636"&gt;Which Logs are Generated When a Monitor Detects Tunnel is Down/Up?&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1323"&gt;Dead Peer Detection and Tunnel Monitoring&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Oct 2014 00:12:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wan-interface-connectivity-loss-logged-anywhere/m-p/48449#M35658</guid>
      <dc:creator>tshiv</dc:creator>
      <dc:date>2014-10-28T00:12:30Z</dc:date>
    </item>
    <item>
      <title>Re: WAN interface connectivity loss logged anywhere?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wan-interface-connectivity-loss-logged-anywhere/m-p/48450#M35659</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks &lt;A href="https://live.paloaltonetworks.com/u1/10570"&gt;tshiv&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That's pretty much what I was looking for.&amp;nbsp; Between the dead peer detection for tunnel monitoring and the logs already created when ospf routes go down I should, in theory, have PaloAlto logs for pretty much any isp type issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Ben&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Oct 2014 15:14:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wan-interface-connectivity-loss-logged-anywhere/m-p/48450#M35659</guid>
      <dc:creator>bgirdner</dc:creator>
      <dc:date>2014-10-28T15:14:04Z</dc:date>
    </item>
  </channel>
</rss>

