<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Palo alto Interface Monitoring in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interface-monitoring/m-p/137581#M47816</link>
    <description>&lt;P&gt;Hi Team,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way I can Monitor Palo Alto Interfaces directly using SLA.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In case the Interface has no traffic, It will bring itself down.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have already searched two VR PBR stuff. I want to know if there is a way by which we can do tracking on interface.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 16 Jan 2017 05:13:06 GMT</pubDate>
    <dc:creator>yadsingh</dc:creator>
    <dc:date>2017-01-16T05:13:06Z</dc:date>
    <item>
      <title>Palo alto Interface Monitoring</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interface-monitoring/m-p/137581#M47816</link>
      <description>&lt;P&gt;Hi Team,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way I can Monitor Palo Alto Interfaces directly using SLA.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In case the Interface has no traffic, It will bring itself down.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have already searched two VR PBR stuff. I want to know if there is a way by which we can do tracking on interface.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2017 05:13:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interface-monitoring/m-p/137581#M47816</guid>
      <dc:creator>yadsingh</dc:creator>
      <dc:date>2017-01-16T05:13:06Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto Interface Monitoring</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interface-monitoring/m-p/137603#M47822</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can monitor interfaces using SNMP.&lt;/P&gt;
&lt;P&gt;Interface state is controlled by configuration changes and requires a commit to forcibly turn off an interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;could you provide a scenario of what you are trying to accomplish exactly? there may be different methods to accomplish what you want to set up&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2017 10:05:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interface-monitoring/m-p/137603#M47822</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-01-16T10:05:49Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto Interface Monitoring</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interface-monitoring/m-p/137687#M47830</link>
      <description>&lt;P&gt;If this is something that you really need you would need to make ample use of the API to actually get it to work. You could monitor the interfaced with SNMP and then have a script that would run if the interface didn't show any untilization. I really can't think of a scenario where you would really want to do something like this though?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2017 19:58:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interface-monitoring/m-p/137687#M47830</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-01-16T19:58:11Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto Interface Monitoring</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interface-monitoring/m-p/137723#M47836</link>
      <description>&lt;P&gt;Hi Reaper,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First of all, I would like to give you credit of guru as I have learned a lot from your posts and articles!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Second, the secanrio is that my netscreen firewall can have an IP SLA in many flavors implemented on the interfaces.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Example: I have interfaces which do something like link and path monitoring. hence, they will go down in case conditions are met (ping to internet etc).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In Palo Alto only way I see them happening is using PBR and routing or using HA. There is no way I could find that Interfaces themselfs can monitor if cable is disconnected or Internet is not reachable and shut themselfs down and disable routes.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hence, to be sure that my search was correct. Can you confirm.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2017 02:11:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interface-monitoring/m-p/137723#M47836</guid>
      <dc:creator>yadsingh</dc:creator>
      <dc:date>2017-01-17T02:11:41Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto Interface Monitoring</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interface-monitoring/m-p/137724#M47837</link>
      <description>&lt;P&gt;Actually, I come from a different background. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; We used this when Interfaces themself auto disable when conditions are met. By conditions I mean something like link and path monitoring in Palo alto.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Interfaces will disable themself and delete route entry.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not sure if that explains.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2017 02:13:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interface-monitoring/m-p/137724#M47837</guid>
      <dc:creator>yadsingh</dc:creator>
      <dc:date>2017-01-17T02:13:40Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto Interface Monitoring</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interface-monitoring/m-p/137765#M47843</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;first of: thanks for the kudos! much appreciated &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;secondly: ok I see what you're trying to do. we don't have a mechanism to bring an interface down like that, short of it going electrically down, but we do have a mechanism that removes routes when path monitor fails: PBR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you set up your primary route via PBR with a monitor profile set to 'failover', the route will be removed once a remote IP ping fails and then aither the next PBR policy or routing table will be used&lt;/P&gt;
&lt;P&gt;in your routing table you would not include a route to the primary link as this is accomplished by PBR, so as soon as the PBR monitor fails, there is no more route to the primary link until the monitor is reestablished.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pbf monitor disable fail.png"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/2F2A72B3BE70ACC5EBC3E1D7685F5297/responsive_peak/images/image_not_found.png" alt="pbf monitor disable fail.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope this helps ?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2017 09:18:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interface-monitoring/m-p/137765#M47843</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-01-17T09:18:09Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto Interface Monitoring</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interface-monitoring/m-p/137767#M47844</link>
      <description>&lt;P&gt;PA has monitor object which does something similar:&lt;/P&gt;&lt;P&gt;- disables tunnel interface when it's applied on IPSEC tunnel when some destination isn't reachable&lt;/P&gt;&lt;P&gt;- disables PBF route &amp;nbsp;&lt;SPAN&gt;when some destination isn't reachable&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But unfortunatelly it can't be applied to a network interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2017 09:13:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interface-monitoring/m-p/137767#M47844</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2017-01-17T09:13:11Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto Interface Monitoring</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interface-monitoring/m-p/138009#M47880</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;you are awesome.,&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jan 2017 05:47:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-interface-monitoring/m-p/138009#M47880</guid>
      <dc:creator>yadsingh</dc:creator>
      <dc:date>2017-01-18T05:47:11Z</dc:date>
    </item>
  </channel>
</rss>

