Am I missing some way of monitoring VPN connections outside of watching the logs? How about a widget or something?
Solved! Go to Solution.
Take a look at the PAN-TRAPS MIB file. There are a number of IPSec VPN traps that could be used for SNMP-based monitoring. There are also GlobalProtect traps if your questions was actually about monitoring SSL VPN and not IPSec VPN. Download the MIB and open it in a MIB browser to quickly see if any of the available traps will cover what you need.
This is the link to the different MIB versions: https://live.paloaltonetworks.com/community/documentation/content?filterID=content~category[enterpri...
I hope that helps.
- Jared Davis
Thanks for the reply but I was thinking something more along the line of something within the PA GUI on the dashboard tab like most other name brand products have.
It appears that a feature request was filed with Product Management for exactly what interests you. Check with your local systems engineer from Palo Alto Networks. She or he will be able to look into the matter further and let you know whether there are any plans to include such an enhancement in a future release. Ask her or him to search on "IPSec Monitor on Dashboard".
- Jared Davis
In the Network>IPSec Tunnels GUI, you have basic monitoring functionality for the status of each IPSec VPN connection...using those green/red "LEDs". If you need more than that, usually something on that IPSec peer is abnormal, and you have to view the logs anyway to troubleshoot.
From the help section of that page:
Viewing IPSec Tunnel Status on the Firewall
Network > IPSec Tunnels
To view the status of currently defined IPSec VPN tunnels, open the IPSec Tunnels page. The following status information is reported on the page:
Hope that helps...
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!