PANOS 7.0 SNMP logical interface counters

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

PANOS 7.0 SNMP logical interface counters

L4 Transporter

I tried the feature and the RX and TX counters are a way off from the physical interface (Tested on 5060 using e1/21 and e1/22 for AE1).   I opened a case with TAC,  and this is the explaination from TAC,

 

For hardware interfaces (ethernet1/21 and ethernet1/22), we only populate ""Physical port counters read from MAC" in the SMNP MIB.

These are MAC counters at the physical interface level.

For logical interfaces (AE1), we only populate "Hardware interface counters read from CPU" in the SNMP MIB.

As we do not actually have a physical interface for AE1, the MAC counters at physical level are not applicable here. We will only look for the Hardware CPU counters here.

Because most of the packets never reach the CPU as they are offloaded, we don't see a significant increment in the Hardware CPU counters.

As the counters on the hardware interfaces and the logical interfaces use different types of counters, it is not appropriate to compare the values on HW interfaces and Logical interfaces.

 

The logical interface counters are currently monitored based on the counters I have mentioned and this is by design.

 

You may need to put in a enhancement request to further enhance this feature.

 

What is the point to add this feature but it can't provide meanful result ?

 

E

2 REPLIES 2

L6 Presenter

I understand the gripe, but can you not get the info you're looking for by looking at the statistics from the po/vPC?

Sorry, I forgot to provide additional details.    The firewall is configured as a Layer 3 with sub interfaces (AE1.x, AE1.y, AE1.z , etc...), each sub interface is part of a vsys/zone.  It is helpful to able to see which sub interface on the AE is the top RX/TX, that helps a lot when you need to troubleshoot high usage, or DDOS.

 

E

  • 2085 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!