- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
04-16-2019 03:16 AM
Hi All,
Can I monitor my Virtual Systems on Solarwinds - SNMP and Ping? They are configured with shared aggregated interfaces and not indivdual physical interfaces. I am monitoring the device itself but would like visibility of the individual virtual systems.
I read an older post that only physical interfaces could be monitored but not sure if that changed.
Regards
Adrian
04-16-2019 09:06 AM
Hello,
Yes this is possible. I would recommend using snmpv3.
Regards,
04-16-2019 11:46 AM
Hi @a.jones
All accessible OIDs are already available on the management interface - in other words whereever you allow snmp with interface management profiles you can monitor ALL OIDs of the device an all vsys - as long as yoi do not restrict it with snmpv3 permissions/views.
@OtakarKlier why would you recommend snmpv3? What is your use case where you need snmpv3? So far I always used snmpv2 as the access is already restricted on the management interface also with additional firewalls where the mgmt interface is located behind them. And mainly because paloalto only offers snmp read so far I don't see a big advantage of encrypting this huge amount of queries.
04-16-2019 11:51 AM
Hello @Remo ,
snmpv2 is plain text so someone sniffing could scape data to gain insight into the environment. Also customer requirements and/or regulations, some industries require it. But since snmpv3 is secure and encrypted, we are security oriented right ;).
Cheers!
04-16-2019 12:08 PM
@OtakarKlier wrote:Also customer requirements and/or regulations, some industries require it.
Got it. But for other situations I still represwnt the opinion that if an attacker is able so sniff traffic in our firewall management networks then I have a lot bigger problems than someone is able to see what PAN-OS version is installed or how many users are connected with global protect 😜
@OtakarKlier wrote:We are security oriented right ;).
Of course we are 😉
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!