Skip to main content
Version: NG-2.14

Fortinet Firewall

Introduction

The Fortinet Firewall Monitoring Observability solution aims to provide detailed insights and comprehensive visibility into firewall infrastructure, leveraging the Simple Network Management Protocol (SNMP)

Getting Started

Compatibility

Fortinet Firewall O11ySource supports SNMP versions v1, v2c and v3.

Data Collection Method

vuSmartMaps collects the availability data for Fortinet Firewall O11ySource using an internal data collector and collects data based on the source configuration. NOTE: SNMP Polling O11ySource has to be enabled and configured before enabling Fortinet Firewall O11ySource

Prerequisites

Dependent Configuration

To configure this O11ySource, create a 'credential' of type 'snmp' under the 'Definition' tab.

Inputs for Configuring Data Source

  • Group Name: This field is for grouping devices for SNMP polling, making it easier to manage devices with common characteristics or within the same network segment.
  • No. of Retries: Number of times the system should reattempt polling if the initial attempt fails. Default is set to 7 retries
  • Timeout Duration: Specify how long the system should wait for a response from a device before considering the attempt unsuccessful. Default timeout is 5 seconds
Devices
  • Device IP: Enter the IP address of the device.
  • SNMP Credential: Select the SNMP credential from the dropdown list that corresponds to this device.
  • Vendor: Select the vendor of the device from the dropdown list
  • Model: Select the model of the device from dropdown list.
MIB Groups
  • MIB Group: Select the MIB Group to poll, identifying the MIB OID to collect. Default: 'ALL_SUPPORTED_MIB_GROUPS'.
  • Interval: Specify the polling interval in seconds. Default: 360 seconds

Firewall Requirement

To collect data from this O11ySource, ensure the following ports are opened:

Source IPDestination IPDestination PortProtocolDirection
vuSmartMaps IPIP address of the SNMP device161*UDPOutbound

*Before providing the firewall requirements, please update the port based on the customer environment.

Configuring the Target

Configure SNMP on Fortinet Firewall devices and grant SNMP access permissions to vuSmartMaps designated IP address.

Configuration Steps

  • Enable the Fortinet Firewall O11ySource.
  • Select the Sources tab and press the + button to add a new SNMP device to be monitored.
  • Click on Save to create the instance

Metrics Collected

NameDescriptionData Type
timestampTimestampDateTime64(3)
targetIP of the Target ServerString
hostIP of the HostString
hostnameHostname of the target serverString
tenant_idTenant IdLowCardinality(String)
bu_idBU IdLowCardinality(String)
Data TypeData TypeLowCardinality(String)
TypeType for each dataLowCardinality(String)
DeviceIPDevice IP AddressIPv4
indexIndex used for different partsString
nameName of memoryString
cpu_nameCPU NameLowCardinality(String)
hard_disk_usage_pHard Disk Utilization in percentageFloat64
fghastatsindexHigh Availability Statistics IndexUInt64
fghastatsserialSerial Number of HA cluster memberString
fghastatscpuusageCPU Usgae of HA cluster memberFloat32
fghastatsmemusageMemory Usgae of HA cluster memberFloat32
fghastatsnetusageNetwork usage of HA cluster memberUInt64
fghastatssescountSession count of HA Cluster memberUInt64
fghastatspktcountPacket count of HA Cluster memberUInt64
fghastatspktcount_diffDiff value of Packet count of HA Cluster member with respect to previous iterationUInt64
fghastatsbytecountByte count of HA Cluster memberUInt64
fghastatsbytecount_diffDiff value of Byte count of HA Cluster member with respect to previous iterationUInt64
fghastatsidscountIDS count of HA cluster memberUInt64
fghastatsidscount_diffDiff value of IDS count of HA Cluster member with respect to previous iterationUInt64
fghastatsavcountVA count of HA cluster memberUInt64
fghastatsavcount_diffDiff value of VA count of HA Cluster member with respect to previous iterationUInt64
fghastatshostnameHostname of the HA Cluster memberString
fghastatssyncstatusSync Status of HA Cluster memberInt8
fghastatsglobalchecksumGlobal checksum of HA Cluster MemberString
fghastatsmasterserialSerial Number of HA cluster masterString