Hello Palo Alto Community,
I created a few Cacti Templates which allow you to quickly and easily monitor Palo Alto Networks firewalls with SNMP. There are 5 different templates corresponding to the 5 different Firewall families, PA-200, PA-500, PA-20xx, PA-40xx, PA-50xx.
Using these with Cacti (www.cacti.net), these Host templates will monitor the following sets variables, create historical graphs of these variables (example Graphs listed below):
If you know of other OIDs which you feel the broader community would like monitored, I would be happy to add them to the templates.
Once cacti is installed on your favorite OS, you simply connect to the Cacti web interface and import these host templates. Then you can add devices for Cacti to SNMP Poll/Monitor and you have a long term graphical representation of what the firewall is doing, how much traffic it is seeing, how many sessions it is supporting, etc.
Hope these help,
I've built the equivalent of these graphs in Zabbix as well... Zabbix allows you to do some interesting things as well, such as "if the last retrieved uptime raw value is less than 600 seconds, send an alert" (i.e. if the firewall has rebooted in the last ten minutes, throw an alert), or "if the SNMP queried temperature is over X, send an alert"
Unfortunately Zabbix doesn't support SHA/AES for SNMPv3, and the Palo Altos we have don't seem to support MD5/3DES, so I ended up having to use SNMPv2
If anyone's interested I can post them here, or open a new thread
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!