PDF

Palo Alto Firewall Sensor

Palo Alto Firewall sensor monitors IPSec site-to-site VPN tunnels configured on the Palo Alto device. By default, the sensor alarms when the state of any tunnel becomes non-active. It also allows for the monitoring of specific tunnels.

The sensor gathers traffic metrics for each tunnel. Depending on the system configuration, system-provided metrics are also available for monitoring.

Options

The sensor uses Palo Alto PAN-OS API and needs the correct credentials.

If the sensor is properly configured, you can see detailed information about configured IPSec Site-to-site tunnels on Node Status in node System Views.

Alerts
  • Site-to-Site VPN tunnel is not active
  • Alert on authentication error
  • Alert on connection error
Reports
  • Site-to-Site VPN Report