Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

PANOS Secure SDWAN Realtime Metrics

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

PANOS Secure SDWAN Realtime Metrics

L2 Linker

I'm doing a Secure SDWAN PoC with a customer this month and they asked if Panorama offered the ability to pull/poll realtime metrics related to SDWAN performance. My first thought is you can pull standard SNMP metrics from any interface including the SDWAN interface. My second thought was using Netflow.

 

But my question would be surrounding pulling SDWAN specific metrics let's say from the Path Monitoring profile.

 

Currently, the customer's MPLS provider gives them statics like Jitter, Latency, etc.., and they would like to do more of an apples-to-apples comparison.

 

The data I need is in the SDWAN plugin itself and is available for export to a report. Just wondering if there are any other ways to get that data out of Panorama that's more "live".

 

Thanks in advance for your thoughts and assistance..

Get out there and do great things!
3 REPLIES 3

L2 Linker

I have the same confusion, but I don't think Paloalto currently has any SNMP interface for SDWAN to get real-time SLA values

L2 Linker

Would a SDWAN report provide the metrics required by the client?  

https://docs.paloaltonetworks.com/sd-wan/3-1/sd-wan-admin/monitoring-and-reporting/generate-an-sd-wa...

Also, is the POC licensed for ADEM?

Douglas Elliott
Security Implementation Engineer
delliott@sayers.com

L4 Transporter

Hello @DanaHawkins ,

 

In the SDWAN plugin, you have the reporting options which gives "near real time" info.
If you want more real time data, you can use the XMLAPI to get the real time statistics on all the firewalls (but that will require someone who can write some code).

 

Also, it may be tough to do a "apple-to-apple" comparison :

MPLS is a more a guaranteed but expensive for multipoint VPN (not really private unless you are having some GET VPN).

PAN-OS Secure SDWAN is a secure (fabric of IPSec tunnels) where you forward application based on your parameters (best link / priority..).

 

Hope that helps.

Olivier

PCSNE - CISSP

Best Effort contributor

Check out our PANCast Channel

Disclaimer : All messages are my personal ones and do not represent my company's view in any way.

  • 2023 Views
  • 3 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!