Skip to main content
Version: NG-2.14

Palo Alto Firewall

Introduction

The Palo Alto Networks Firewall Monitoring Observability (O11y) solution aims to provide detailed insights and comprehensive visibility into firewall infrastructure, leveraging the Simple Network Management Protocol (SNMP).

Getting Started

Compatibility

PaloAlto Firewall O11ySource supports SNMP versions v1, v2c and v3.

Data Collection Method

vuSmartMaps collects the availability data for PaloAlto Firewall O11ySource using an internal data collector and collects data based on the source configuration. NOTE: SNMP Polling O11ySource has to be enabled and configured before enabling PaloAlto Firewall O11ySource

Prerequisites

Dependent Configuration

To configure this O11ySource, create a 'credential' of type 'snmp' under the 'Definition' tab.

Inputs for Configuring Data Source

  • Group Name: This field is for grouping devices for SNMP polling, making it easier to manage devices with common characteristics or within the same network segment.
  • No. of Retries: Number of times the system should reattempt polling if the initial attempt fails. Default is set to 7 retries
  • Timeout Duration: Specify how long the system should wait for a response from a device before considering the attempt unsuccessful. Default timeout is 5 seconds
Devices
  • Device IP: Enter the IP address of the device.
  • SNMP Credential: Select the SNMP credential from the dropdown list that corresponds to this device.
  • Vendor: Select the vendor of the device from the dropdown list
  • Model: Select the model of the device from dropdown list.
MIB Groups
  • MIB Group: Select the MIB Group to poll, identifying the MIB OID to collect. Default: 'ALL_SUPPORTED_MIB_GROUPS'.
  • Interval: Specify the polling interval in seconds. Default: 360 seconds

Firewall Requirement

To collect data from this O11ySource, ensure the following ports are opened:

Source IPDestination IPDestination PortProtocolDirection
vuSmartMaps IPIP address of the SNMP device161*UDPOutbound

*Before providing the firewall requirements, please update the port based on the customer environment.

Configuring the Target

Configure SNMP on PaloAlto Firewall devices and grant SNMP access permissions to vuSmartMaps designated IP address.

Configuration Steps

  • Enable the PaloAlto Firewall O11ySource.
  • Select the Sources tab and press the + button to add a new SNMP device to be monitored.
  • Click on Save to create the instance

Metrics Collected

NameDescriptionData Type
timestampTimestampDateTime64(3)
targetIP of the Target ServerString
hostIP of the HostString
hostnameHostname of the target serverString
tenant_idTenant IdLowCardinality(String)
bu_idBU IdLowCardinality(String)
Data TypeData TypeLowCardinality(String)
TypeType for each dataLowCardinality(String)
DeviceIPDevice IP AddressIPv4
usedStorage used expressed in Allocation UnitsUInt64
sizeStorage size expressed in Allocation UnitsUInt64
unitIndicates the memory allocation unit. Always indicates bytes for network devicesUInt32
indexCPU IndexString
nameCPU NameString
pansessionNumber of active sessionsUInt32
pan_session_tcpNumber of active TCP sessionsUInt32
pan_session_udpNumber of active UDP sessionsUInt32
pan_session_icmpNumber of active ICMP sessionsUInt32
pansessionutilizationSession UtilizationFloat32
pansyshamodeHigh Availability modeLowCardinality(String)
pansyshapeerstateHigh Availability Peer StateLowCardinality(String)
pansyshastateHigh Availability StateLowCardinality(String)
flow_dos_blk_hw_entriesNumber of entries in DOS hardware Block TableUInt64
flow_dos_blk_num_entriesNumber of entries in DOS Block TableUInt64
flow_dos_blk_sw_entriesNumber of entries in DOS Software Block TableUInt64
flow_dos_drop_ip_blockedPackets Dropped - Flagged for BlockingUInt64
flow_dos_rule_dropPackets Dropped - Rate Limited or IP BlockedUInt64
flow_policy_denySession Setup Denied by policyUInt64