Monitoring IPSec VPN tunnels on Palo Alto 200 firewall device

Yogesh Hasabnis <[email protected]>
Newsgroups gmane.network.mrtg.user
Message-ID <CAOYOSLwwmZg0F6ESaOPvC7PUv-Za+EXLE3swzs3NmPTr0sx8og@mail.gmail.com>
Hi All,

We have a Palo Alto 200 firewall device in our WAN routing setup. Along
with the firewall features it provides, the device is also used to
establish two ipsec-based VPN tunnels (using two different WAN links) to
our HQ office located at a remote location. I have limited access to this
device and all I know about it is it's SNMP read-only community string and
it's IP address. I also know that the interface names for the two tunnels
are tunnel.1 and tunnel.4 and the IP addresses used for the tunnel
interfaces are 10.<a.b>.2 and 10.<c.d>.2 respectively. When I try to create
a cfg file using the
 "/usr/bin/cfgmaker --output=/etc/mrtg/paloalto.cfg --global 'workdir:
/var/www/mrtg' -ifref=eth --global 'options[_]: growright,bits'
--snmp-options=:::::2 <comm_string>@<device_ip> " command on my MRTG host,
the cfg file I get doesn't list out any of the tunnel interfaces.

I also tried using a few other "--ifref=" options mentioned in the cfgmaker
man-page but neither of those options seems to work. I would be thankful if
I get some pointers/suggestions about how I can configure MRTG to monitor
the tunnel interfaces.

Thanks in advance,
Yogesh Hasabnis

_______________________________________________
mrtg mailing list
[email protected]
https://lists.oetiker.ch/cgi-bin/listinfo/mrtg
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.