This template is designed for the effortless deployment of FortiGate monitoring by Zabbix via HTTP and doesn't require any external scripts.
Zabbix version: 7.4 and higher.
This template has been tested on:
Zabbix should be configured according to the instructions in the Templates out of the box section.
System > Admin Profiles > Create New.System > Administrators > Create New > REST API Admin.{$FGATE.API.TOKEN} macro.{$FGATE.API.FQDN} macro value.{$FGATE.SCHEME} macro and 443 into {$FGATE.API.PORT} macro.{$FGATE.API.PORT} macro.NOTE: Starting from template version '7.4-1', the API token is used in the request header. For older template versions (where the API token is passed in the URL query parameter), when using FortiGate v7.4.5+, you must enable the following global setting: Using APIs
For added security, it is strongly recommended to use the latest template version, which passes the API token in the request header instead of the URL parameter.
Please, refer to the vendor documentation about the FortiGate REST API Authentication.
| Name | Description | Default |
|---|---|---|
| {$FGATE.SCHEME} | Request scheme which may be http or https. |
http |
| {$FGATE.API.FQDN} | FortiGate API FQDN/IP (ex. ngfw.example.com). |
|
| {$FGATE.API.TOKEN} | FortiGate API token. |
|
| {$FGATE.API.PORT} | The port of FortiGate API endpoint. |
80 |
| {$FGATE.DATA.TIMEOUT} | Response timeout for an API. |
15s |
| {$FGATE.HTTP.PROXY} | HTTP proxy for API requests. You can specify it using the format [protocol://][username[:password]@]proxy.example.com[:port]. See the documentation at https://www.zabbix.com/documentation/7.4/manual/config/items/itemtypes/http |
|
| {$FIRMWARE.UPDATES.CONTROL} | This macro is used in "New available firmware found" trigger. |
1 |
| {$CPU.UTIL.WARN} | Threshold of CPU utilization for warning trigger in %. |
85 |
| {$CPU.UTIL.CRIT} | Threshold of CPU utilization for critical trigger in %. |
95 |
| {$MEMORY.UTIL.WARN} | Threshold of memory utilization for warning trigger in %. |
80 |
| {$MEMORY.UTIL.CRIT} | Threshold of memory utilization for critical trigger in %. |
90 |
| {$DISK.FREE.WARN} | Threshold of disk free space for warning trigger in %. |
20 |
| {$DISK.FREE.CRIT} | Threshold of disk free space for critical trigger in %. |
10 |
| {$NET.IF.CONTROL} | Macro for operational state of the interface for "Link down" trigger. Can be used with interface name as context. |
1 |
| {$NET.IF.ERRORS.WARN} | Threshold of error packets rate for warning trigger. Can be used with interface name as context. |
2 |
| {$NET.IF.UTIL.MAX} | Threshold of interface bandwidth utilization for warning trigger in %. Can be used with interface name as context. |
95 |
| {$NET.IF.IFDESCR.MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFDESCR.NOT_MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$NET.IF.IFNAME.MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFNAME.NOT_MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$NET.IF.IFTYPE.MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFTYPE.NOT_MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$NET.IF.IFALIAS.MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFALIAS.NOT_MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$NET.IF.IFSTATUS.MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFSTATUS.NOT_MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$FWP.FWACTION.MATCHES} | This macro is used in Firewall policies discovery. Can be overridden on the host or linked template level. |
.* |
| {$FWP.FWACTION.NOT_MATCHES} | This macro is used in Firewall policies discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$FWP.FWTYPE.MATCHES} | This macro is used in Firewall policies discovery. Can be overridden on the host or linked template level. |
.* |
| {$FWP.FWTYPE.NOT_MATCHES} | This macro is used in Firewall policies discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$FWP.FWNAME.MATCHES} | This macro is used in Firewall policies discovery. Can be overridden on the host or linked template level. |
.* |
| {$FWP.FWNAME.NOT_MATCHES} | This macro is used in Firewall policies discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SERVICE.EXPIRY.WARN} | Number of days until the license expires. |
7 |
| {$SERVICE.LICENSE.CONTROL} | This macro is used in Service discovery. Can be used with interface name as context. |
1 |
| {$SERVICE.KEY.MATCHES} | This macro is used in Service discovery. Can be overridden on the host or linked template level. |
.* |
| {$SERVICE.KEY.NOT_MATCHES} | This macro is used in Service discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SERVICE.STATUS.MATCHES} | This macro is used in Service discovery. Can be overridden on the host or linked template level. |
.* |
| {$SERVICE.STATUS.NOT_MATCHES} | This macro is used in Service discovery. Can be overridden on the host or linked template level. |
(no_support|no_license) |
| {$SERVICE.TYPE.MATCHES} | This macro is used in Service discovery. Can be overridden on the host or linked template level. |
.* |
| {$SERVICE.TYPE.NOT_MATCHES} | This macro is used in Service discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.MEMBER.IF.CONTROL} | Macro for the interface state for "Link down" trigger. Can be used with interface name as context. |
1 |
| {$SDWAN.MEMBER.ID.MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.MEMBER.ID.NOT_MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.MEMBER.NAME.MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.MEMBER.NAME.NOT_MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.MEMBER.STATUS.MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.MEMBER.STATUS.NOT_MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.MEMBER.ZONE.MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.MEMBER.ZONE.NOT_MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.HEALTH.IF.CONTROL} | Macro for the interface state for "Link down" trigger. Can be used with interface name as context. |
1 |
| {$SDWAN.HEALTH.ID.MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.HEALTH.ID.NOT_MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.HEALTH.NAME.MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.HEALTH.NAME.NOT_MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.HEALTH.IFNAME.MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.HEALTH.IFNAME.NOT_MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.HEALTH.STATUS.MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.HEALTH.STATUS.NOT_MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.HEALTH.IF.LOSS.WARN} | Threshold of packets loss for warning trigger in %. Can be used with interface name as context. |
20 |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Check port availability | Simple check | net.tcp.service["{$FGATE.SCHEME}","{$FGATE.API.FQDN}","{$FGATE.API.PORT}"] Preprocessing
|
|
| Get system info | Item for gathering device system info from FortiGate API. |
HTTP agent | fgate.system.get_data Preprocessing
|
| Device system info item errors | Item for gathering errors of the device system info. |
Dependent item | fgate.system.data_errors Preprocessing
|
| API availability status | Checking API availability by response. |
Dependent item | fgate.api.status Preprocessing
|
| Get firmware info | Item for gathering device firmware info from FortiGate API. |
HTTP agent | fgate.firmware.get_data Preprocessing
|
| Device firmware info item errors | Item for gathering errors of the device firmware info. |
Dependent item | fgate.firmware.data_errors Preprocessing
|
| Get service licenses | Item for gathering information about service licenses from FortiGate API. |
Script | fgate.service.get_data |
| Service licenses item errors | Item for gathering errors of the service licenses data. |
Dependent item | fgate.service.data_errors Preprocessing
|
| Get resources data | Item for gathering device resource data from FortiGate API. |
Script | fgate.resources.get_data |
| Device resources item errors | Item for gathering errors of the device resources. |
Dependent item | fgate.resources.data_errors Preprocessing
|
| Get interfaces data | Item for gathering network interfaces info from FortiGate API. |
Script | fgate.netif.get_data |
| Device interfaces item errors | Item for gathering errors of network interfaces. |
Dependent item | fgate.netif.data_errors Preprocessing
|
| Get SD-WAN data | Item for gathering SD-WAN information from FortiGate API. |
Script | fgate.sdwan.get_data |
| Get SD-WAN item errors | Item for gathering errors of SD-WAN. |
Dependent item | fgate.sdwan.data_errors Preprocessing
|
| Get firewall data | Item for gathering firewall policies info from FortiGate API. |
Script | fgate.fwp.get_data |
| Firewall data item errors | Item for gathering errors of firewall policies. |
Dependent item | fgate.fwp.data_errors Preprocessing
|
| Available firmware versions | Number of available firmware versions to download. |
Dependent item | fgate.device.firmwares_avail Preprocessing
|
| Device firmware version | Current version of the device firmware. |
Dependent item | fgate.device.firmware Preprocessing
|
| Device model name | The model name of the device. |
Dependent item | fgate.device.model Preprocessing
|
| Device serial number | The device serial number. |
Dependent item | fgate.device.serialnumber Preprocessing
|
| Current VDOM | Name of the current Virtual Domain. |
Dependent item | fgate.device.vdom Preprocessing
|
| System name | The system host name. |
Dependent item | fgate.name Preprocessing
|
| System uptime | The system uptime is calculated on the basis of boot time. |
Dependent item | fgate.uptime Preprocessing
|
| Number of CPUs | Number of processors according to the current license. |
Dependent item | fgate.cpu.num Preprocessing
|
| CPU utilization | CPU utilization, expressed in %. |
Dependent item | fgate.cpu.util Preprocessing
|
| Total memory | Total memory, expressed in bytes. |
Dependent item | fgate.memory.total Preprocessing
|
| Memory utilization | Memory utilization, expressed in %. |
Dependent item | fgate.memory.util Preprocessing
|
| Total disk space | The total space of the current disk, in bytes. |
Dependent item | fgate.fs.total Preprocessing
|
| Used disk space | The used space of the current disk, in bytes. |
Dependent item | fgate.fs.used Preprocessing
|
| Free disk space | The free space of the current disk, in bytes. |
Dependent item | fgate.fs.free Preprocessing
|
| Disk utilization | Disk utilization, expressed in %. |
Dependent item | fgate.fs.util Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| FortiGate: Port {$FGATE.API.PORT} is unavailable | last(/FortiGate by HTTP/net.tcp.service["{$FGATE.SCHEME}","{$FGATE.API.FQDN}","{$FGATE.API.PORT}"])=0 |
Average | Manual close: Yes | |
| FortiGate: There are errors in the 'Get system info' metric | length(last(/FortiGate by HTTP/fgate.system.data_errors))>0 and length(last(/FortiGate by HTTP/fgate.system.data_errors,#1:now-1m))>0 and nodata(/FortiGate by HTTP/fgate.system.data_errors,2m)=0 |
Warning | Depends on:
|
|
| FortiGate: Unexpected response from API | Received an unexpected response from API. It may be unavailable. |
last(/FortiGate by HTTP/fgate.api.status)=0 |
Average | Depends on:
|
| FortiGate: There are errors in the 'Get firmware info' metric | length(last(/FortiGate by HTTP/fgate.firmware.data_errors))>0 and length(last(/FortiGate by HTTP/fgate.firmware.data_errors,#1:now-1m))>0 and nodata(/FortiGate by HTTP/fgate.firmware.data_errors,2m)=0 |
Warning | Depends on:
|
|
| FortiGate: There are errors in the 'Get service licenses' metric | length(last(/FortiGate by HTTP/fgate.service.data_errors))>0 and length(last(/FortiGate by HTTP/fgate.service.data_errors,#1:now-1m))>0 and nodata(/FortiGate by HTTP/fgate.service.data_errors,2m)=0 |
Warning | Depends on:
|
|
| FortiGate: There are errors in the 'Get resources data' metric | length(last(/FortiGate by HTTP/fgate.resources.data_errors))>0 and length(last(/FortiGate by HTTP/fgate.resources.data_errors,#1:now-1m))>0 and nodata(/FortiGate by HTTP/fgate.resources.data_errors,2m)=0 |
Warning | Depends on:
|
|
| FortiGate: There are errors in the 'Get interfaces data' metric | length(last(/FortiGate by HTTP/fgate.netif.data_errors))>0 and length(last(/FortiGate by HTTP/fgate.netif.data_errors,#1:now-1m))>0 and nodata(/FortiGate by HTTP/fgate.netif.data_errors,2m)=0 |
Warning | Depends on:
|
|
| FortiGate: There are errors in the 'Get SD-WAN data' metric | length(last(/FortiGate by HTTP/fgate.sdwan.data_errors))>0 and length(last(/FortiGate by HTTP/fgate.sdwan.data_errors,#1:now-1m))>0 and nodata(/FortiGate by HTTP/fgate.sdwan.data_errors,2m)=0 |
Warning | Depends on:
|
|
| FortiGate: There are errors in the 'Get firewall policies data' metric | length(last(/FortiGate by HTTP/fgate.fwp.data_errors))>0 and length(last(/FortiGate by HTTP/fgate.fwp.data_errors,#1:now-1m))>0 and nodata(/FortiGate by HTTP/fgate.fwp.data_errors,2m)=0 |
Warning | Depends on:
|
|
| FortiGate: New available firmware found | New available firmware versions found to download. |
{$FIRMWARE.UPDATES.CONTROL}=1 and last(/FortiGate by HTTP/fgate.device.firmwares_avail)>0 |
Info | Manual close: Yes |
| FortiGate: Device has been replaced | Device serial number has changed. Acknowledge to close the problem manually. |
last(/FortiGate by HTTP/fgate.device.serialnumber,#1)<>last(/FortiGate by HTTP/fgate.device.serialnumber,#2) and length(last(/FortiGate by HTTP/fgate.device.serialnumber))>0 |
Info | Manual close: Yes |
| FortiGate: System name has changed | The name of the system has changed. Acknowledge to close the problem manually. |
last(/FortiGate by HTTP/fgate.name,#1)<>last(/FortiGate by HTTP/fgate.name,#2) and length(last(/FortiGate by HTTP/fgate.name))>0 |
Info | Manual close: Yes |
| FortiGate: Device has been restarted | Uptime is less than 10 minutes. |
last(/FortiGate by HTTP/fgate.uptime)<10m |
Info | Manual close: Yes |
| FortiGate: CPU utilization is too high | The CPU utilization is too high. The system might be slow to respond. |
min(/FortiGate by HTTP/fgate.cpu.util,5m)>{$CPU.UTIL.CRIT} |
High | |
| FortiGate: CPU utilization is high | The CPU utilization is high. |
min(/FortiGate by HTTP/fgate.cpu.util,5m)>{$CPU.UTIL.WARN} |
Warning | Depends on:
|
| FortiGate: Memory utilization is too high | Free memory size is too low. |
min(/FortiGate by HTTP/fgate.memory.util,5m)>{$MEMORY.UTIL.CRIT} |
High | |
| FortiGate: Memory utilization is high | The system is running out of free memory. |
min(/FortiGate by HTTP/fgate.memory.util,5m)>{$MEMORY.UTIL.WARN} |
Average | Depends on:
|
| FortiGate: Free disk space is too low | Left disk space is too low. |
(100-last(/FortiGate by HTTP/fgate.fs.util))<{$DISK.FREE.CRIT} |
High | |
| FortiGate: Free disk space is low | Left disk space is not enough. |
(100-last(/FortiGate by HTTP/fgate.fs.util))<{$DISK.FREE.WARN} |
Warning | Depends on:
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Firewall policies discovery | Discovery for FortiGate firewall policies. |
Dependent item | fgate.fwp.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| FW Policy [{#FWNAME}]: Get data | Item for gathering data for the {#FWNAME} firewall policy. |
Dependent item | fgate.fwp.get_data[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Active sessions | Number of active sessions covered by this rule. |
Dependent item | fgate.fwp.sessions[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Software processed bytes | Number of bytes processed only by the software firewall. |
Dependent item | fgate.fwp.sw_bytes[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Hardware processed bytes | Number of bytes processed only by the hardware (ASIC) firewall. |
Dependent item | fgate.fwp.hw_bytes[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Total bytes processed | Number of bytes processed by both the software and hardware (ASIC) firewall. |
Dependent item | fgate.fwp.bytes[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Hits into the policy | Number of packets hit into the firewall policy per second. |
Dependent item | fgate.fwp.hits[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Last using time | The time at which the firewall policy was used the last time. |
Dependent item | fgate.fwp.last_used[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Action | The firewall policy action (accept / deny / ipsec). |
Dependent item | fgate.fwp.action[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Status | The firewall policy status. |
Dependent item | fgate.fwp.status[{#FWUUID}] Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Service discovery | Discovery for FortiGate services. |
Dependent item | fgate.service.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Service [{#NAME}]: Get data | Item for gathering data about license for the {#NAME} service. |
Dependent item | fgate.service.get_data["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: License status | Current license status of the {#NAME} service. |
Dependent item | fgate.service.license["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: Service type | Current type of the {#NAME} service. |
Dependent item | fgate.service.type["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: Service version | Current version of the {#NAME} service. |
Dependent item | fgate.service.version["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: Expiration date | Expiration date for the license of the current service. |
Dependent item | fgate.service.expire["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: Last update time | Last update time of the current service. |
Dependent item | fgate.service.update_time["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: Last attempt to update | Last update attempt time of the current service. |
Dependent item | fgate.service.update_attempt["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: Update method | Current update method of the {#NAME} service. |
Dependent item | fgate.service.update_method["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: Update result | Last update result of the {#NAME} service. |
Dependent item | fgate.service.update_result["{#KEY}"] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| FortiGate: Service [{#NAME}]: License status is unsuccessful | This trigger expression works as follows: |
{$SERVICE.LICENSE.CONTROL:"{#KEY}"}=1 and last(/FortiGate by HTTP/fgate.service.license["{#KEY}"])>5 |
Average | Manual close: Yes |
| FortiGate: Service [{#NAME}]: License expires soon | This trigger expression works as follows: |
{$SERVICE.LICENSE.CONTROL:"{#KEY}"}=1 and (last(/FortiGate by HTTP/fgate.service.expire["{#KEY}"]) - now()) / 86400 < {$SERVICE.EXPIRY.WARN:"{#KEY}"} and last(/FortiGate by HTTP/fgate.service.expire["{#KEY}"]) > now() |
Warning | Manual close: Yes |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SD-WAN members discovery | Discovery for FortiGate SD-WAN members. |
Dependent item | fgate.sdwan_member.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SD-WAN [{#ZONE}]:[{#NAME}]: Get data | Item for gathering data about the {#NAME} interface in the {#ZONE} zone. |
Dependent item | fgate.sdwan_member.get_data[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: Member status | Current status of the {#NAME} interface in the {#ZONE} zone. |
Dependent item | fgate.sdwan_member.status[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: Link status | Current link status of the {#NAME} interface in the {#ZONE} zone. |
Dependent item | fgate.sdwan_member.link_status[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: Sessions | Number of active sessions opened through the {#NAME} interface in the {#ZONE} zone. |
Dependent item | fgate.sdwan_member.sessions[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: Bytes sent per second | Bytes sent through the {#NAME} interface in the {#ZONE} zone per second. |
Dependent item | fgate.sdwan_member.tx_bytes[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: Bytes received per second | Bytes received from the {#NAME} interface in the {#ZONE} zone per second. |
Dependent item | fgate.sdwan_member.rx_bytes[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: Output bandwidth | Transmitting bandwidth of the {#NAME} interface in the {#ZONE} zone. |
Dependent item | fgate.sdwan_member.tx_bandwidth[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: Input bandwidth | Receiving bandwidth of the {#NAME} interface in the {#ZONE} zone. |
Dependent item | fgate.sdwan_member.rx_bandwidth[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: State changing time | Last state changing time of the {#NAME} interface in the {#ZONE} zone. |
Dependent item | fgate.service.state_changed[{#ID}] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| FortiGate: SD-WAN [{#ZONE}]:[{#NAME}]: Link down | This trigger expression works as follows: |
{$SDWAN.MEMBER.IF.CONTROL:"{#NAME}"}=1 and last(/FortiGate by HTTP/fgate.sdwan_member.link_status[{#ID}])=1 and (last(/FortiGate by HTTP/fgate.sdwan_member.link_status[{#ID}],#1)<>last(/FortiGate by HTTP/fgate.sdwan_member.link_status[{#ID}],#2)) |
Average | Manual close: Yes |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SD-WAN health-checks discovery | Discovery for FortiGate SD-WAN health-checks. |
Dependent item | fgate.sdwan_health.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SD-WAN [{#NAME}]:[{#IFNAME}]: Get data | Item for gathering data about the {#IFNAME} interface in the {#NAME} health-check. |
Dependent item | fgate.sdwan_health.get_data["{#HID}.{#MID}"] Preprocessing
|
| SD-WAN [{#NAME}]:[{#IFNAME}]: Interface status | Current status of the {#IFNAME} interface in the {#NAME} health-check. |
Dependent item | fgate.sdwan_health.status["{#HID}.{#MID}"] Preprocessing
|
| SD-WAN [{#NAME}]:[{#IFNAME}]: Jitter | Current jitter value for the {#IFNAME} interface in the {#NAME} health-check. |
Dependent item | fgate.sdwan_health.jitter["{#HID}.{#MID}"] Preprocessing
|
| SD-WAN [{#NAME}]:[{#IFNAME}]: Latency | Current latency value for the {#IFNAME} interface in the {#NAME} health-check. |
Dependent item | fgate.sdwan_health.latency["{#HID}.{#MID}"] Preprocessing
|
| SD-WAN [{#NAME}]:[{#IFNAME}]: Packets loss | Percent of lost packets for the {#IFNAME} interface in the {#NAME} health-check. |
Dependent item | fgate.sdwan_health.loss["{#HID}.{#MID}"] Preprocessing
|
| SD-WAN [{#NAME}]:[{#IFNAME}]: Packets sent per second | Number of packets sent through the {#IFNAME} interface in the {#NAME} health-check per second. |
Dependent item | fgate.sdwan_health.sent["{#HID}.{#MID}"] Preprocessing
|
| SD-WAN [{#NAME}]:[{#IFNAME}]: Packets received per second | Number of packets received from the {#IFNAME} interface in the {#NAME} health-check per second. |
Dependent item | fgate.sdwan_health.received["{#HID}.{#MID}"] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| FortiGate: SD-WAN [{#NAME}]:[{#IFNAME}]: Link down | This trigger expression works as follows: |
{$SDWAN.HEALTH.IF.CONTROL:"{#NAME}"}=1 and last(/FortiGate by HTTP/fgate.sdwan_health.status["{#HID}.{#MID}"])=1 and (last(/FortiGate by HTTP/fgate.sdwan_health.status["{#HID}.{#MID}"],#1)<>last(/FortiGate by HTTP/fgate.sdwan_health.status["{#HID}.{#MID}"],#2)) |
Average | Manual close: Yes |
| FortiGate: SD-WAN [{#NAME}]:[{#IFNAME}]: Link state is error | This trigger expression works as follows: |
{$SDWAN.HEALTH.IF.CONTROL:"{#IFNAME}"}=1 and last(/FortiGate by HTTP/fgate.sdwan_health.status["{#HID}.{#MID}"])=2 and (last(/FortiGate by HTTP/fgate.sdwan_health.status["{#HID}.{#MID}"],#1)<>last(/FortiGate by HTTP/fgate.sdwan_health.status["{#HID}.{#MID}"],#2)) |
Average | Manual close: Yes |
| FortiGate: SD-WAN [{#NAME}]:[{#IFNAME}]: High packets loss | High level of packets loss detected. |
min(/FortiGate by HTTP/fgate.sdwan_health.loss["{#HID}.{#MID}"],5m)>{$SDWAN.HEALTH.IF.LOSS.WARN:"{#IFNAME}"} |
Warning |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Network interfaces discovery | Discovery for FortiGate network interfaces. |
Dependent item | fgate.netif.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Interface [{#IFNAME}({#IFALIAS})]: Get data | Item for gathering data for the {#IFKEY} interface. |
Dependent item | fgate.netif.get_data[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Link status | Current link status of the interface. |
Dependent item | fgate.netif.status[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Bits received | The total number of octets received on the interface per second. |
Dependent item | fgate.netif.in[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Inbound packets | The total number of packets received on the interface per second. |
Dependent item | fgate.netif.in_packets[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Bits sent | The total number of octets transmitted out of the interface. |
Dependent item | fgate.netif.out[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Outbound packets | The total number of packets transmitted out of the interface per second. |
Dependent item | fgate.netif.out_packets[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Inbound packets with errors | The total number of errors received. |
Dependent item | fgate.netif.in_errors[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Outbound packets with errors | The total number of errors transmitted. |
Dependent item | fgate.netif.out_errors[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Interface type | Type of the interface. |
Dependent item | fgate.netif.type[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Speed | Speed of the interface. |
Dependent item | fgate.netif.speed[{#IFKEY}] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| FortiGate: Interface [{#IFNAME}({#IFALIAS})]: Link down | This trigger expression works as follows: |
{$NET.IF.CONTROL:"{#IFNAME}"}=1 and last(/FortiGate by HTTP/fgate.netif.status[{#IFKEY}])=1 and (last(/FortiGate by HTTP/fgate.netif.status[{#IFKEY}],#1)<>last(/FortiGate by HTTP/fgate.netif.status[{#IFKEY}],#2)) |
Average | Manual close: Yes |
| FortiGate: Interface [{#IFNAME}({#IFALIAS})]: High bandwidth usage | The utilization of the network interface is close to its estimated maximum bandwidth. |
(avg(/FortiGate by HTTP/fgate.netif.in[{#IFKEY}],15m)>({$NET.IF.UTIL.MAX:"{#IFNAME}"}/100)*last(/FortiGate by HTTP/fgate.netif.speed[{#IFKEY}]) or avg(/FortiGate by HTTP/fgate.netif.out[{#IFKEY}],15m)>({$NET.IF.UTIL.MAX:"{#IFNAME}"}/100)*last(/FortiGate by HTTP/fgate.netif.speed[{#IFKEY}])) and last(/FortiGate by HTTP/fgate.netif.speed[{#IFKEY}])>0 |
Warning | Manual close: Yes Depends on:
|
| FortiGate: Interface [{#IFNAME}({#IFALIAS})]: High error rate | It recovers when it is below 80% of the |
min(/FortiGate by HTTP/fgate.netif.in_errors[{#IFKEY}],5m)>{$NET.IF.ERRORS.WARN:"{#IFKEY}"} or min(/FortiGate by HTTP/fgate.netif.in_errors[{#IFKEY}],5m)>{$NET.IF.ERRORS.WARN:"{#IFKEY}"} |
Warning | Manual close: Yes Depends on:
|
| FortiGate: Interface [{#IFNAME}({#IFALIAS})]: Ethernet has changed to lower speed than it was before | This Ethernet connection has transitioned down from its known maximum speed. This might be a sign of autonegotiation issues. Acknowledge to close the problem manually. |
change(/FortiGate by HTTP/fgate.netif.speed[{#IFKEY}])<0 and last(/FortiGate by HTTP/fgate.netif.speed[{#IFKEY}])>0 and last(/FortiGate by HTTP/fgate.netif.status[{#IFKEY}])<>0 |
Info | Manual close: Yes Depends on:
|
Please report any issues with the template at https://support.zabbix.com
You can also provide feedback, discuss the template, or ask for help at ZABBIX forums
This template is designed for the effortless deployment of FortiGate monitoring by Zabbix via HTTP and doesn't require any external scripts.
Zabbix version: 7.2 and higher.
This template has been tested on:
Zabbix should be configured according to the instructions in the Templates out of the box section.
System > Admin Profiles > Create New.System > Administrators > Create New > REST API Admin.{$FGATE.API.TOKEN} macro.{$FGATE.API.FQDN} macro value.{$FGATE.SCHEME} macro and 443 into {$FGATE.API.PORT} macro.{$FGATE.API.PORT} macro.Please, refer to the vendor documentation about the FortiGate REST API Authentication.
| Name | Description | Default |
|---|---|---|
| {$FGATE.SCHEME} | Request scheme which may be http or https. |
http |
| {$FGATE.API.FQDN} | FortiGate API FQDN/IP (ex. ngfw.example.com). |
|
| {$FGATE.API.TOKEN} | FortiGate API token. |
|
| {$FGATE.API.PORT} | The port of FortiGate API endpoint. |
80 |
| {$FGATE.DATA.TIMEOUT} | Response timeout for an API. |
15s |
| {$FGATE.HTTP.PROXY} | HTTP proxy for API requests. You can specify it using the format [protocol://][username[:password]@]proxy.example.com[:port]. See the documentation at https://www.zabbix.com/documentation/7.2/manual/config/items/itemtypes/http |
|
| {$FIRMWARE.UPDATES.CONTROL} | This macro is used in "New available firmware found" trigger. |
1 |
| {$CPU.UTIL.WARN} | Threshold of CPU utilization for warning trigger in %. |
85 |
| {$CPU.UTIL.CRIT} | Threshold of CPU utilization for critical trigger in %. |
95 |
| {$MEMORY.UTIL.WARN} | Threshold of memory utilization for warning trigger in %. |
80 |
| {$MEMORY.UTIL.CRIT} | Threshold of memory utilization for critical trigger in %. |
90 |
| {$DISK.FREE.WARN} | Threshold of disk free space for warning trigger in %. |
20 |
| {$DISK.FREE.CRIT} | Threshold of disk free space for critical trigger in %. |
10 |
| {$NET.IF.CONTROL} | Macro for operational state of the interface for "Link down" trigger. Can be used with interface name as context. |
1 |
| {$NET.IF.ERRORS.WARN} | Threshold of error packets rate for warning trigger. Can be used with interface name as context. |
2 |
| {$NET.IF.UTIL.MAX} | Threshold of interface bandwidth utilization for warning trigger in %. Can be used with interface name as context. |
95 |
| {$NET.IF.IFDESCR.MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFDESCR.NOT_MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$NET.IF.IFNAME.MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFNAME.NOT_MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$NET.IF.IFTYPE.MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFTYPE.NOT_MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$NET.IF.IFALIAS.MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFALIAS.NOT_MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$NET.IF.IFSTATUS.MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFSTATUS.NOT_MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$FWP.FWACTION.MATCHES} | This macro is used in Firewall policies discovery. Can be overridden on the host or linked template level. |
.* |
| {$FWP.FWACTION.NOT_MATCHES} | This macro is used in Firewall policies discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$FWP.FWTYPE.MATCHES} | This macro is used in Firewall policies discovery. Can be overridden on the host or linked template level. |
.* |
| {$FWP.FWTYPE.NOT_MATCHES} | This macro is used in Firewall policies discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$FWP.FWNAME.MATCHES} | This macro is used in Firewall policies discovery. Can be overridden on the host or linked template level. |
.* |
| {$FWP.FWNAME.NOT_MATCHES} | This macro is used in Firewall policies discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SERVICE.EXPIRY.WARN} | Number of days until the license expires. |
7 |
| {$SERVICE.LICENSE.CONTROL} | This macro is used in Service discovery. Can be used with interface name as context. |
1 |
| {$SERVICE.KEY.MATCHES} | This macro is used in Service discovery. Can be overridden on the host or linked template level. |
.* |
| {$SERVICE.KEY.NOT_MATCHES} | This macro is used in Service discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SERVICE.STATUS.MATCHES} | This macro is used in Service discovery. Can be overridden on the host or linked template level. |
.* |
| {$SERVICE.STATUS.NOT_MATCHES} | This macro is used in Service discovery. Can be overridden on the host or linked template level. |
(no_support|no_license) |
| {$SERVICE.TYPE.MATCHES} | This macro is used in Service discovery. Can be overridden on the host or linked template level. |
.* |
| {$SERVICE.TYPE.NOT_MATCHES} | This macro is used in Service discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.MEMBER.IF.CONTROL} | Macro for the interface state for "Link down" trigger. Can be used with interface name as context. |
1 |
| {$SDWAN.MEMBER.ID.MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.MEMBER.ID.NOT_MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.MEMBER.NAME.MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.MEMBER.NAME.NOT_MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.MEMBER.STATUS.MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.MEMBER.STATUS.NOT_MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.MEMBER.ZONE.MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.MEMBER.ZONE.NOT_MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.HEALTH.IF.CONTROL} | Macro for the interface state for "Link down" trigger. Can be used with interface name as context. |
1 |
| {$SDWAN.HEALTH.ID.MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.HEALTH.ID.NOT_MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.HEALTH.NAME.MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.HEALTH.NAME.NOT_MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.HEALTH.IFNAME.MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.HEALTH.IFNAME.NOT_MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.HEALTH.STATUS.MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.HEALTH.STATUS.NOT_MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.HEALTH.IF.LOSS.WARN} | Threshold of packets loss for warning trigger in %. Can be used with interface name as context. |
20 |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Check port availability | Simple check | net.tcp.service["{$FGATE.SCHEME}","{$FGATE.API.FQDN}","{$FGATE.API.PORT}"] Preprocessing
|
|
| Get system info | Item for gathering device system info from FortiGate API. |
HTTP agent | fgate.system.get_data Preprocessing
|
| Device system info item errors | Item for gathering errors of the device system info. |
Dependent item | fgate.system.data_errors Preprocessing
|
| API availability status | Checking API availability by response. |
Dependent item | fgate.api.status Preprocessing
|
| Get firmware info | Item for gathering device firmware info from FortiGate API. |
HTTP agent | fgate.firmware.get_data Preprocessing
|
| Device firmware info item errors | Item for gathering errors of the device firmware info. |
Dependent item | fgate.firmware.data_errors Preprocessing
|
| Get service licenses | Item for gathering information about service licenses from FortiGate API. |
Script | fgate.service.get_data |
| Service licenses item errors | Item for gathering errors of the service licenses data. |
Dependent item | fgate.service.data_errors Preprocessing
|
| Get resources data | Item for gathering device resource data from FortiGate API. |
Script | fgate.resources.get_data |
| Device resources item errors | Item for gathering errors of the device resources. |
Dependent item | fgate.resources.data_errors Preprocessing
|
| Get interfaces data | Item for gathering network interfaces info from FortiGate API. |
Script | fgate.netif.get_data |
| Device interfaces item errors | Item for gathering errors of network interfaces. |
Dependent item | fgate.netif.data_errors Preprocessing
|
| Get SD-WAN data | Item for gathering SD-WAN information from FortiGate API. |
Script | fgate.sdwan.get_data |
| Get SD-WAN item errors | Item for gathering errors of SD-WAN. |
Dependent item | fgate.sdwan.data_errors Preprocessing
|
| Get firewall data | Item for gathering firewall policies info from FortiGate API. |
Script | fgate.fwp.get_data |
| Firewall data item errors | Item for gathering errors of firewall policies. |
Dependent item | fgate.fwp.data_errors Preprocessing
|
| Available firmware versions | Number of available firmware versions to download. |
Dependent item | fgate.device.firmwares_avail Preprocessing
|
| Device firmware version | Current version of the device firmware. |
Dependent item | fgate.device.firmware Preprocessing
|
| Device model name | The model name of the device. |
Dependent item | fgate.device.model Preprocessing
|
| Device serial number | The device serial number. |
Dependent item | fgate.device.serialnumber Preprocessing
|
| Current VDOM | Name of the current Virtual Domain. |
Dependent item | fgate.device.vdom Preprocessing
|
| System name | The system host name. |
Dependent item | fgate.name Preprocessing
|
| System uptime | The system uptime is calculated on the basis of boot time. |
Dependent item | fgate.uptime Preprocessing
|
| Number of CPUs | Number of processors according to the current license. |
Dependent item | fgate.cpu.num Preprocessing
|
| CPU utilization | CPU utilization, expressed in %. |
Dependent item | fgate.cpu.util Preprocessing
|
| Total memory | Total memory, expressed in bytes. |
Dependent item | fgate.memory.total Preprocessing
|
| Memory utilization | Memory utilization, expressed in %. |
Dependent item | fgate.memory.util Preprocessing
|
| Total disk space | The total space of the current disk, in bytes. |
Dependent item | fgate.fs.total Preprocessing
|
| Used disk space | The used space of the current disk, in bytes. |
Dependent item | fgate.fs.used Preprocessing
|
| Free disk space | The free space of the current disk, in bytes. |
Dependent item | fgate.fs.free Preprocessing
|
| Disk utilization | Disk utilization, expressed in %. |
Dependent item | fgate.fs.util Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| FortiGate: Port {$FGATE.API.PORT} is unavailable | last(/FortiGate by HTTP/net.tcp.service["{$FGATE.SCHEME}","{$FGATE.API.FQDN}","{$FGATE.API.PORT}"])=0 |
Average | Manual close: Yes | |
| FortiGate: There are errors in the 'Get system info' metric | length(last(/FortiGate by HTTP/fgate.system.data_errors))>0 and length(last(/FortiGate by HTTP/fgate.system.data_errors,#1:now-1m))>0 and nodata(/FortiGate by HTTP/fgate.system.data_errors,2m)=0 |
Warning | Depends on:
|
|
| FortiGate: Unexpected response from API | Received an unexpected response from API. It may be unavailable. |
last(/FortiGate by HTTP/fgate.api.status)=0 |
Average | Depends on:
|
| FortiGate: There are errors in the 'Get firmware info' metric | length(last(/FortiGate by HTTP/fgate.firmware.data_errors))>0 and length(last(/FortiGate by HTTP/fgate.firmware.data_errors,#1:now-1m))>0 and nodata(/FortiGate by HTTP/fgate.firmware.data_errors,2m)=0 |
Warning | Depends on:
|
|
| FortiGate: There are errors in the 'Get service licenses' metric | length(last(/FortiGate by HTTP/fgate.service.data_errors))>0 and length(last(/FortiGate by HTTP/fgate.service.data_errors,#1:now-1m))>0 and nodata(/FortiGate by HTTP/fgate.service.data_errors,2m)=0 |
Warning | Depends on:
|
|
| FortiGate: There are errors in the 'Get resources data' metric | length(last(/FortiGate by HTTP/fgate.resources.data_errors))>0 and length(last(/FortiGate by HTTP/fgate.resources.data_errors,#1:now-1m))>0 and nodata(/FortiGate by HTTP/fgate.resources.data_errors,2m)=0 |
Warning | Depends on:
|
|
| FortiGate: There are errors in the 'Get interfaces data' metric | length(last(/FortiGate by HTTP/fgate.netif.data_errors))>0 and length(last(/FortiGate by HTTP/fgate.netif.data_errors,#1:now-1m))>0 and nodata(/FortiGate by HTTP/fgate.netif.data_errors,2m)=0 |
Warning | Depends on:
|
|
| FortiGate: There are errors in the 'Get SD-WAN data' metric | length(last(/FortiGate by HTTP/fgate.sdwan.data_errors))>0 and length(last(/FortiGate by HTTP/fgate.sdwan.data_errors,#1:now-1m))>0 and nodata(/FortiGate by HTTP/fgate.sdwan.data_errors,2m)=0 |
Warning | Depends on:
|
|
| FortiGate: There are errors in the 'Get firewall policies data' metric | length(last(/FortiGate by HTTP/fgate.fwp.data_errors))>0 and length(last(/FortiGate by HTTP/fgate.fwp.data_errors,#1:now-1m))>0 and nodata(/FortiGate by HTTP/fgate.fwp.data_errors,2m)=0 |
Warning | Depends on:
|
|
| FortiGate: New available firmware found | New available firmware versions found to download. |
{$FIRMWARE.UPDATES.CONTROL}=1 and last(/FortiGate by HTTP/fgate.device.firmwares_avail)>0 |
Info | Manual close: Yes |
| FortiGate: Device has been replaced | Device serial number has changed. Acknowledge to close the problem manually. |
last(/FortiGate by HTTP/fgate.device.serialnumber,#1)<>last(/FortiGate by HTTP/fgate.device.serialnumber,#2) and length(last(/FortiGate by HTTP/fgate.device.serialnumber))>0 |
Info | Manual close: Yes |
| FortiGate: System name has changed | The name of the system has changed. Acknowledge to close the problem manually. |
last(/FortiGate by HTTP/fgate.name,#1)<>last(/FortiGate by HTTP/fgate.name,#2) and length(last(/FortiGate by HTTP/fgate.name))>0 |
Info | Manual close: Yes |
| FortiGate: Device has been restarted | Uptime is less than 10 minutes. |
last(/FortiGate by HTTP/fgate.uptime)<10m |
Info | Manual close: Yes |
| FortiGate: CPU utilization is too high | The CPU utilization is too high. The system might be slow to respond. |
min(/FortiGate by HTTP/fgate.cpu.util,5m)>{$CPU.UTIL.CRIT} |
High | |
| FortiGate: CPU utilization is high | The CPU utilization is high. |
min(/FortiGate by HTTP/fgate.cpu.util,5m)>{$CPU.UTIL.WARN} |
Warning | Depends on:
|
| FortiGate: Memory utilization is too high | Free memory size is too low. |
min(/FortiGate by HTTP/fgate.memory.util,5m)>{$MEMORY.UTIL.CRIT} |
High | |
| FortiGate: Memory utilization is high | The system is running out of free memory. |
min(/FortiGate by HTTP/fgate.memory.util,5m)>{$MEMORY.UTIL.WARN} |
Average | Depends on:
|
| FortiGate: Free disk space is too low | Left disk space is too low. |
(100-last(/FortiGate by HTTP/fgate.fs.util))<{$DISK.FREE.CRIT} |
High | |
| FortiGate: Free disk space is low | Left disk space is not enough. |
(100-last(/FortiGate by HTTP/fgate.fs.util))<{$DISK.FREE.WARN} |
Warning | Depends on:
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Firewall policies discovery | Discovery for FortiGate firewall policies. |
Dependent item | fgate.fwp.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| FW Policy [{#FWNAME}]: Get data | Item for gathering data for the {#FWNAME} firewall policy. |
Dependent item | fgate.fwp.get_data[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Active sessions | Number of active sessions covered by this rule. |
Dependent item | fgate.fwp.sessions[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Software processed bytes | Number of bytes processed only by the software firewall. |
Dependent item | fgate.fwp.sw_bytes[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Hardware processed bytes | Number of bytes processed only by the hardware (ASIC) firewall. |
Dependent item | fgate.fwp.hw_bytes[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Total bytes processed | Number of bytes processed by both the software and hardware (ASIC) firewall. |
Dependent item | fgate.fwp.bytes[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Hits into the policy | Number of packets hit into the firewall policy per second. |
Dependent item | fgate.fwp.hits[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Last using time | The time at which the firewall policy was used the last time. |
Dependent item | fgate.fwp.last_used[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Action | The firewall policy action (accept / deny / ipsec). |
Dependent item | fgate.fwp.action[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Status | The firewall policy status. |
Dependent item | fgate.fwp.status[{#FWUUID}] Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Service discovery | Discovery for FortiGate services. |
Dependent item | fgate.service.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Service [{#NAME}]: Get data | Item for gathering data about license for the {#NAME} service. |
Dependent item | fgate.service.get_data["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: License status | Current license status of the {#NAME} service. |
Dependent item | fgate.service.license["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: Service type | Current type of the {#NAME} service. |
Dependent item | fgate.service.type["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: Service version | Current version of the {#NAME} service. |
Dependent item | fgate.service.version["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: Expiration date | Expiration date for the license of the current service. |
Dependent item | fgate.service.expire["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: Last update time | Last update time of the current service. |
Dependent item | fgate.service.update_time["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: Last attempt to update | Last update attempt time of the current service. |
Dependent item | fgate.service.update_attempt["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: Update method | Current update method of the {#NAME} service. |
Dependent item | fgate.service.update_method["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: Update result | Last update result of the {#NAME} service. |
Dependent item | fgate.service.update_result["{#KEY}"] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| FortiGate: Service [{#NAME}]: License status is unsuccessful | This trigger expression works as follows: |
{$SERVICE.LICENSE.CONTROL:"{#KEY}"}=1 and last(/FortiGate by HTTP/fgate.service.license["{#KEY}"])>5 |
Average | Manual close: Yes |
| FortiGate: Service [{#NAME}]: License expires soon | This trigger expression works as follows: |
{$SERVICE.LICENSE.CONTROL:"{#KEY}"}=1 and (last(/FortiGate by HTTP/fgate.service.expire["{#KEY}"]) - now()) / 86400 < {$SERVICE.EXPIRY.WARN:"{#KEY}"} and last(/FortiGate by HTTP/fgate.service.expire["{#KEY}"]) > now() |
Warning | Manual close: Yes |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SD-WAN members discovery | Discovery for FortiGate SD-WAN members. |
Dependent item | fgate.sdwan_member.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SD-WAN [{#ZONE}]:[{#NAME}]: Get data | Item for gathering data about the {#NAME} interface in the {#ZONE} zone. |
Dependent item | fgate.sdwan_member.get_data[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: Member status | Current status of the {#NAME} interface in the {#ZONE} zone. |
Dependent item | fgate.sdwan_member.status[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: Link status | Current link status of the {#NAME} interface in the {#ZONE} zone. |
Dependent item | fgate.sdwan_member.link_status[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: Sessions | Number of active sessions opened through the {#NAME} interface in the {#ZONE} zone. |
Dependent item | fgate.sdwan_member.sessions[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: Bytes sent per second | Bytes sent through the {#NAME} interface in the {#ZONE} zone per second. |
Dependent item | fgate.sdwan_member.tx_bytes[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: Bytes received per second | Bytes received from the {#NAME} interface in the {#ZONE} zone per second. |
Dependent item | fgate.sdwan_member.rx_bytes[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: Output bandwidth | Transmitting bandwidth of the {#NAME} interface in the {#ZONE} zone. |
Dependent item | fgate.sdwan_member.tx_bandwidth[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: Input bandwidth | Receiving bandwidth of the {#NAME} interface in the {#ZONE} zone. |
Dependent item | fgate.sdwan_member.rx_bandwidth[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: State changing time | Last state changing time of the {#NAME} interface in the {#ZONE} zone. |
Dependent item | fgate.service.state_changed[{#ID}] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| FortiGate: SD-WAN [{#ZONE}]:[{#NAME}]: Link down | This trigger expression works as follows: |
{$SDWAN.MEMBER.IF.CONTROL:"{#NAME}"}=1 and last(/FortiGate by HTTP/fgate.sdwan_member.link_status[{#ID}])=1 and (last(/FortiGate by HTTP/fgate.sdwan_member.link_status[{#ID}],#1)<>last(/FortiGate by HTTP/fgate.sdwan_member.link_status[{#ID}],#2)) |
Average | Manual close: Yes |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SD-WAN health-checks discovery | Discovery for FortiGate SD-WAN health-checks. |
Dependent item | fgate.sdwan_health.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SD-WAN [{#NAME}]:[{#IFNAME}]: Get data | Item for gathering data about the {#IFNAME} interface in the {#NAME} health-check. |
Dependent item | fgate.sdwan_health.get_data["{#HID}.{#MID}"] Preprocessing
|
| SD-WAN [{#NAME}]:[{#IFNAME}]: Interface status | Current status of the {#IFNAME} interface in the {#NAME} health-check. |
Dependent item | fgate.sdwan_health.status["{#HID}.{#MID}"] Preprocessing
|
| SD-WAN [{#NAME}]:[{#IFNAME}]: Jitter | Current jitter value for the {#IFNAME} interface in the {#NAME} health-check. |
Dependent item | fgate.sdwan_health.jitter["{#HID}.{#MID}"] Preprocessing
|
| SD-WAN [{#NAME}]:[{#IFNAME}]: Latency | Current latency value for the {#IFNAME} interface in the {#NAME} health-check. |
Dependent item | fgate.sdwan_health.latency["{#HID}.{#MID}"] Preprocessing
|
| SD-WAN [{#NAME}]:[{#IFNAME}]: Packets loss | Percent of lost packets for the {#IFNAME} interface in the {#NAME} health-check. |
Dependent item | fgate.sdwan_health.loss["{#HID}.{#MID}"] Preprocessing
|
| SD-WAN [{#NAME}]:[{#IFNAME}]: Packets sent per second | Number of packets sent through the {#IFNAME} interface in the {#NAME} health-check per second. |
Dependent item | fgate.sdwan_health.sent["{#HID}.{#MID}"] Preprocessing
|
| SD-WAN [{#NAME}]:[{#IFNAME}]: Packets received per second | Number of packets received from the {#IFNAME} interface in the {#NAME} health-check per second. |
Dependent item | fgate.sdwan_health.received["{#HID}.{#MID}"] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| FortiGate: SD-WAN [{#NAME}]:[{#IFNAME}]: Link down | This trigger expression works as follows: |
{$SDWAN.HEALTH.IF.CONTROL:"{#NAME}"}=1 and last(/FortiGate by HTTP/fgate.sdwan_health.status["{#HID}.{#MID}"])=1 and (last(/FortiGate by HTTP/fgate.sdwan_health.status["{#HID}.{#MID}"],#1)<>last(/FortiGate by HTTP/fgate.sdwan_health.status["{#HID}.{#MID}"],#2)) |
Average | Manual close: Yes |
| FortiGate: SD-WAN [{#NAME}]:[{#IFNAME}]: Link state is error | This trigger expression works as follows: |
{$SDWAN.HEALTH.IF.CONTROL:"{#IFNAME}"}=1 and last(/FortiGate by HTTP/fgate.sdwan_health.status["{#HID}.{#MID}"])=2 and (last(/FortiGate by HTTP/fgate.sdwan_health.status["{#HID}.{#MID}"],#1)<>last(/FortiGate by HTTP/fgate.sdwan_health.status["{#HID}.{#MID}"],#2)) |
Average | Manual close: Yes |
| FortiGate: SD-WAN [{#NAME}]:[{#IFNAME}]: High packets loss | High level of packets loss detected. |
min(/FortiGate by HTTP/fgate.sdwan_health.loss["{#HID}.{#MID}"],5m)>{$SDWAN.HEALTH.IF.LOSS.WARN:"{#IFNAME}"} |
Warning |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Network interfaces discovery | Discovery for FortiGate network interfaces. |
Dependent item | fgate.netif.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Interface [{#IFNAME}({#IFALIAS})]: Get data | Item for gathering data for the {#IFKEY} interface. |
Dependent item | fgate.netif.get_data[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Link status | Current link status of the interface. |
Dependent item | fgate.netif.status[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Bits received | The total number of octets received on the interface per second. |
Dependent item | fgate.netif.in[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Inbound packets | The total number of packets received on the interface per second. |
Dependent item | fgate.netif.in_packets[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Bits sent | The total number of octets transmitted out of the interface. |
Dependent item | fgate.netif.out[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Outbound packets | The total number of packets transmitted out of the interface per second. |
Dependent item | fgate.netif.out_packets[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Inbound packets with errors | The total number of errors received. |
Dependent item | fgate.netif.in_errors[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Outbound packets with errors | The total number of errors transmitted. |
Dependent item | fgate.netif.out_errors[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Interface type | Type of the interface. |
Dependent item | fgate.netif.type[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Speed | Speed of the interface. |
Dependent item | fgate.netif.speed[{#IFKEY}] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| FortiGate: Interface [{#IFNAME}({#IFALIAS})]: Link down | This trigger expression works as follows: |
{$NET.IF.CONTROL:"{#IFNAME}"}=1 and last(/FortiGate by HTTP/fgate.netif.status[{#IFKEY}])=1 and (last(/FortiGate by HTTP/fgate.netif.status[{#IFKEY}],#1)<>last(/FortiGate by HTTP/fgate.netif.status[{#IFKEY}],#2)) |
Average | Manual close: Yes |
| FortiGate: Interface [{#IFNAME}({#IFALIAS})]: High bandwidth usage | The utilization of the network interface is close to its estimated maximum bandwidth. |
(avg(/FortiGate by HTTP/fgate.netif.in[{#IFKEY}],15m)>({$NET.IF.UTIL.MAX:"{#IFNAME}"}/100)*last(/FortiGate by HTTP/fgate.netif.speed[{#IFKEY}]) or avg(/FortiGate by HTTP/fgate.netif.out[{#IFKEY}],15m)>({$NET.IF.UTIL.MAX:"{#IFNAME}"}/100)*last(/FortiGate by HTTP/fgate.netif.speed[{#IFKEY}])) and last(/FortiGate by HTTP/fgate.netif.speed[{#IFKEY}])>0 |
Warning | Manual close: Yes Depends on:
|
| FortiGate: Interface [{#IFNAME}({#IFALIAS})]: High error rate | It recovers when it is below 80% of the |
min(/FortiGate by HTTP/fgate.netif.in_errors[{#IFKEY}],5m)>{$NET.IF.ERRORS.WARN:"{#IFKEY}"} or min(/FortiGate by HTTP/fgate.netif.in_errors[{#IFKEY}],5m)>{$NET.IF.ERRORS.WARN:"{#IFKEY}"} |
Warning | Manual close: Yes Depends on:
|
| FortiGate: Interface [{#IFNAME}({#IFALIAS})]: Ethernet has changed to lower speed than it was before | This Ethernet connection has transitioned down from its known maximum speed. This might be a sign of autonegotiation issues. Acknowledge to close the problem manually. |
change(/FortiGate by HTTP/fgate.netif.speed[{#IFKEY}])<0 and last(/FortiGate by HTTP/fgate.netif.speed[{#IFKEY}])>0 and last(/FortiGate by HTTP/fgate.netif.status[{#IFKEY}])<>0 |
Info | Manual close: Yes Depends on:
|
Please report any issues with the template at https://support.zabbix.com
You can also provide feedback, discuss the template, or ask for help at ZABBIX forums
This template is designed for the effortless deployment of FortiGate monitoring by Zabbix via HTTP and doesn't require any external scripts.
Zabbix version: 7.0 and higher.
This template has been tested on:
Zabbix should be configured according to the instructions in the Templates out of the box section.
System > Admin Profiles > Create New.System > Administrators > Create New > REST API Admin.{$FGATE.API.TOKEN} macro.{$FGATE.API.FQDN} macro value.{$FGATE.SCHEME} macro and 443 into {$FGATE.API.PORT} macro.{$FGATE.API.PORT} macro.NOTE: Starting from template version '7.0-2', the API token is used in the request header. For older template versions (where the API token is passed in the URL query parameter), when using FortiGate v7.4.5+, you must enable the following global setting: Using APIs
For added security, it is strongly recommended to use the latest template version, which passes the API token in the request header instead of the URL parameter.
Please, refer to the vendor documentation about the FortiGate REST API Authentication.
| Name | Description | Default |
|---|---|---|
| {$FGATE.SCHEME} | Request scheme which may be http or https. |
http |
| {$FGATE.API.FQDN} | FortiGate API FQDN/IP (ex. ngfw.example.com). |
|
| {$FGATE.API.TOKEN} | FortiGate API token. |
|
| {$FGATE.API.PORT} | The port of FortiGate API endpoint. |
80 |
| {$FGATE.DATA.TIMEOUT} | Response timeout for an API. |
15s |
| {$FGATE.HTTP.PROXY} | HTTP proxy for API requests. You can specify it using the format [protocol://][username[:password]@]proxy.example.com[:port]. See the documentation at https://www.zabbix.com/documentation/7.0/manual/config/items/itemtypes/http |
|
| {$FIRMWARE.UPDATES.CONTROL} | This macro is used in "New available firmware found" trigger. |
1 |
| {$CPU.UTIL.WARN} | Threshold of CPU utilization for warning trigger in %. |
85 |
| {$CPU.UTIL.CRIT} | Threshold of CPU utilization for critical trigger in %. |
95 |
| {$MEMORY.UTIL.WARN} | Threshold of memory utilization for warning trigger in %. |
80 |
| {$MEMORY.UTIL.CRIT} | Threshold of memory utilization for critical trigger in %. |
90 |
| {$DISK.FREE.WARN} | Threshold of disk free space for warning trigger in %. |
20 |
| {$DISK.FREE.CRIT} | Threshold of disk free space for critical trigger in %. |
10 |
| {$NET.IF.CONTROL} | Macro for operational state of the interface for "Link down" trigger. Can be used with interface name as context. |
1 |
| {$NET.IF.ERRORS.WARN} | Threshold of error packets rate for warning trigger. Can be used with interface name as context. |
2 |
| {$NET.IF.UTIL.MAX} | Threshold of interface bandwidth utilization for warning trigger in %. Can be used with interface name as context. |
95 |
| {$NET.IF.IFDESCR.MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFDESCR.NOT_MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$NET.IF.IFNAME.MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFNAME.NOT_MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$NET.IF.IFTYPE.MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFTYPE.NOT_MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$NET.IF.IFALIAS.MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFALIAS.NOT_MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$NET.IF.IFSTATUS.MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFSTATUS.NOT_MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$FWP.FWACTION.MATCHES} | This macro is used in Firewall policies discovery. Can be overridden on the host or linked template level. |
.* |
| {$FWP.FWACTION.NOT_MATCHES} | This macro is used in Firewall policies discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$FWP.FWTYPE.MATCHES} | This macro is used in Firewall policies discovery. Can be overridden on the host or linked template level. |
.* |
| {$FWP.FWTYPE.NOT_MATCHES} | This macro is used in Firewall policies discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$FWP.FWNAME.MATCHES} | This macro is used in Firewall policies discovery. Can be overridden on the host or linked template level. |
.* |
| {$FWP.FWNAME.NOT_MATCHES} | This macro is used in Firewall policies discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SERVICE.EXPIRY.WARN} | Number of days until the license expires. |
7 |
| {$SERVICE.LICENSE.CONTROL} | This macro is used in Service discovery. Can be used with interface name as context. |
1 |
| {$SERVICE.KEY.MATCHES} | This macro is used in Service discovery. Can be overridden on the host or linked template level. |
.* |
| {$SERVICE.KEY.NOT_MATCHES} | This macro is used in Service discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SERVICE.STATUS.MATCHES} | This macro is used in Service discovery. Can be overridden on the host or linked template level. |
.* |
| {$SERVICE.STATUS.NOT_MATCHES} | This macro is used in Service discovery. Can be overridden on the host or linked template level. |
(no_support|no_license) |
| {$SERVICE.TYPE.MATCHES} | This macro is used in Service discovery. Can be overridden on the host or linked template level. |
.* |
| {$SERVICE.TYPE.NOT_MATCHES} | This macro is used in Service discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.MEMBER.IF.CONTROL} | Macro for the interface state for "Link down" trigger. Can be used with interface name as context. |
1 |
| {$SDWAN.MEMBER.ID.MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.MEMBER.ID.NOT_MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.MEMBER.NAME.MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.MEMBER.NAME.NOT_MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.MEMBER.STATUS.MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.MEMBER.STATUS.NOT_MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.MEMBER.ZONE.MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.MEMBER.ZONE.NOT_MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.HEALTH.IF.CONTROL} | Macro for the interface state for "Link down" trigger. Can be used with interface name as context. |
1 |
| {$SDWAN.HEALTH.ID.MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.HEALTH.ID.NOT_MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.HEALTH.NAME.MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.HEALTH.NAME.NOT_MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.HEALTH.IFNAME.MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.HEALTH.IFNAME.NOT_MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.HEALTH.STATUS.MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.HEALTH.STATUS.NOT_MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.HEALTH.IF.LOSS.WARN} | Threshold of packets loss for warning trigger in %. Can be used with interface name as context. |
20 |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Check port availability | Simple check | net.tcp.service["{$FGATE.SCHEME}","{$FGATE.API.FQDN}","{$FGATE.API.PORT}"] Preprocessing
|
|
| Get system info | Item for gathering device system info from FortiGate API. |
HTTP agent | fgate.system.get_data Preprocessing
|
| Device system info item errors | Item for gathering errors of the device system info. |
Dependent item | fgate.system.data_errors Preprocessing
|
| API availability status | Checking API availability by response. |
Dependent item | fgate.api.status Preprocessing
|
| Get firmware info | Item for gathering device firmware info from FortiGate API. |
HTTP agent | fgate.firmware.get_data Preprocessing
|
| Device firmware info item errors | Item for gathering errors of the device firmware info. |
Dependent item | fgate.firmware.data_errors Preprocessing
|
| Get service licenses | Item for gathering information about service licenses from FortiGate API. |
Script | fgate.service.get_data |
| Service licenses item errors | Item for gathering errors of the service licenses data. |
Dependent item | fgate.service.data_errors Preprocessing
|
| Get resources data | Item for gathering device resource data from FortiGate API. |
Script | fgate.resources.get_data |
| Device resources item errors | Item for gathering errors of the device resources. |
Dependent item | fgate.resources.data_errors Preprocessing
|
| Get interfaces data | Item for gathering network interfaces info from FortiGate API. |
Script | fgate.netif.get_data |
| Device interfaces item errors | Item for gathering errors of network interfaces. |
Dependent item | fgate.netif.data_errors Preprocessing
|
| Get SD-WAN data | Item for gathering SD-WAN information from FortiGate API. |
Script | fgate.sdwan.get_data |
| Get SD-WAN item errors | Item for gathering errors of SD-WAN. |
Dependent item | fgate.sdwan.data_errors Preprocessing
|
| Get firewall data | Item for gathering firewall policies info from FortiGate API. |
Script | fgate.fwp.get_data |
| Firewall data item errors | Item for gathering errors of firewall policies. |
Dependent item | fgate.fwp.data_errors Preprocessing
|
| Available firmware versions | Number of available firmware versions to download. |
Dependent item | fgate.device.firmwares_avail Preprocessing
|
| Device firmware version | Current version of the device firmware. |
Dependent item | fgate.device.firmware Preprocessing
|
| Device model name | The model name of the device. |
Dependent item | fgate.device.model Preprocessing
|
| Device serial number | The device serial number. |
Dependent item | fgate.device.serialnumber Preprocessing
|
| Current VDOM | Name of the current Virtual Domain. |
Dependent item | fgate.device.vdom Preprocessing
|
| System name | The system host name. |
Dependent item | fgate.name Preprocessing
|
| System uptime | The system uptime is calculated on the basis of boot time. |
Dependent item | fgate.uptime Preprocessing
|
| Number of CPUs | Number of processors according to the current license. |
Dependent item | fgate.cpu.num Preprocessing
|
| CPU utilization | CPU utilization, expressed in %. |
Dependent item | fgate.cpu.util Preprocessing
|
| Total memory | Total memory, expressed in bytes. |
Dependent item | fgate.memory.total Preprocessing
|
| Memory utilization | Memory utilization, expressed in %. |
Dependent item | fgate.memory.util Preprocessing
|
| Total disk space | The total space of the current disk, in bytes. |
Dependent item | fgate.fs.total Preprocessing
|
| Used disk space | The used space of the current disk, in bytes. |
Dependent item | fgate.fs.used Preprocessing
|
| Free disk space | The free space of the current disk, in bytes. |
Dependent item | fgate.fs.free Preprocessing
|
| Disk utilization | Disk utilization, expressed in %. |
Dependent item | fgate.fs.util Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| FortiGate: Port {$FGATE.API.PORT} is unavailable | last(/FortiGate by HTTP/net.tcp.service["{$FGATE.SCHEME}","{$FGATE.API.FQDN}","{$FGATE.API.PORT}"])=0 |
Average | Manual close: Yes | |
| FortiGate: There are errors in the 'Get system info' metric | length(last(/FortiGate by HTTP/fgate.system.data_errors))>0 and length(last(/FortiGate by HTTP/fgate.system.data_errors,#1:now-1m))>0 and nodata(/FortiGate by HTTP/fgate.system.data_errors,2m)=0 |
Warning | Depends on:
|
|
| FortiGate: Unexpected response from API | Received an unexpected response from API. It may be unavailable. |
last(/FortiGate by HTTP/fgate.api.status)=0 |
Average | Depends on:
|
| FortiGate: There are errors in the 'Get firmware info' metric | length(last(/FortiGate by HTTP/fgate.firmware.data_errors))>0 and length(last(/FortiGate by HTTP/fgate.firmware.data_errors,#1:now-1m))>0 and nodata(/FortiGate by HTTP/fgate.firmware.data_errors,2m)=0 |
Warning | Depends on:
|
|
| FortiGate: There are errors in the 'Get service licenses' metric | length(last(/FortiGate by HTTP/fgate.service.data_errors))>0 and length(last(/FortiGate by HTTP/fgate.service.data_errors,#1:now-1m))>0 and nodata(/FortiGate by HTTP/fgate.service.data_errors,2m)=0 |
Warning | Depends on:
|
|
| FortiGate: There are errors in the 'Get resources data' metric | length(last(/FortiGate by HTTP/fgate.resources.data_errors))>0 and length(last(/FortiGate by HTTP/fgate.resources.data_errors,#1:now-1m))>0 and nodata(/FortiGate by HTTP/fgate.resources.data_errors,2m)=0 |
Warning | Depends on:
|
|
| FortiGate: There are errors in the 'Get interfaces data' metric | length(last(/FortiGate by HTTP/fgate.netif.data_errors))>0 and length(last(/FortiGate by HTTP/fgate.netif.data_errors,#1:now-1m))>0 and nodata(/FortiGate by HTTP/fgate.netif.data_errors,2m)=0 |
Warning | Depends on:
|
|
| FortiGate: There are errors in the 'Get SD-WAN data' metric | length(last(/FortiGate by HTTP/fgate.sdwan.data_errors))>0 and length(last(/FortiGate by HTTP/fgate.sdwan.data_errors,#1:now-1m))>0 and nodata(/FortiGate by HTTP/fgate.sdwan.data_errors,2m)=0 |
Warning | Depends on:
|
|
| FortiGate: There are errors in the 'Get firewall policies data' metric | length(last(/FortiGate by HTTP/fgate.fwp.data_errors))>0 and length(last(/FortiGate by HTTP/fgate.fwp.data_errors,#1:now-1m))>0 and nodata(/FortiGate by HTTP/fgate.fwp.data_errors,2m)=0 |
Warning | Depends on:
|
|
| FortiGate: New available firmware found | New available firmware versions found to download. |
{$FIRMWARE.UPDATES.CONTROL}=1 and last(/FortiGate by HTTP/fgate.device.firmwares_avail)>0 |
Info | Manual close: Yes |
| FortiGate: Device has been replaced | Device serial number has changed. Acknowledge to close the problem manually. |
last(/FortiGate by HTTP/fgate.device.serialnumber,#1)<>last(/FortiGate by HTTP/fgate.device.serialnumber,#2) and length(last(/FortiGate by HTTP/fgate.device.serialnumber))>0 |
Info | Manual close: Yes |
| FortiGate: System name has changed | The name of the system has changed. Acknowledge to close the problem manually. |
last(/FortiGate by HTTP/fgate.name,#1)<>last(/FortiGate by HTTP/fgate.name,#2) and length(last(/FortiGate by HTTP/fgate.name))>0 |
Info | Manual close: Yes |
| FortiGate: Device has been restarted | Uptime is less than 10 minutes. |
last(/FortiGate by HTTP/fgate.uptime)<10m |
Info | Manual close: Yes |
| FortiGate: CPU utilization is too high | The CPU utilization is too high. The system might be slow to respond. |
min(/FortiGate by HTTP/fgate.cpu.util,5m)>{$CPU.UTIL.CRIT} |
High | |
| FortiGate: CPU utilization is high | The CPU utilization is high. |
min(/FortiGate by HTTP/fgate.cpu.util,5m)>{$CPU.UTIL.WARN} |
Warning | Depends on:
|
| FortiGate: Memory utilization is too high | Free memory size is too low. |
min(/FortiGate by HTTP/fgate.memory.util,5m)>{$MEMORY.UTIL.CRIT} |
High | |
| FortiGate: Memory utilization is high | The system is running out of free memory. |
min(/FortiGate by HTTP/fgate.memory.util,5m)>{$MEMORY.UTIL.WARN} |
Average | Depends on:
|
| FortiGate: Free disk space is too low | Left disk space is too low. |
(100-last(/FortiGate by HTTP/fgate.fs.util))<{$DISK.FREE.CRIT} |
High | |
| FortiGate: Free disk space is low | Left disk space is not enough. |
(100-last(/FortiGate by HTTP/fgate.fs.util))<{$DISK.FREE.WARN} |
Warning | Depends on:
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Firewall policies discovery | Discovery for FortiGate firewall policies. |
Dependent item | fgate.fwp.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| FW Policy [{#FWNAME}]: Get data | Item for gathering data for the {#FWNAME} firewall policy. |
Dependent item | fgate.fwp.get_data[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Active sessions | Number of active sessions covered by this rule. |
Dependent item | fgate.fwp.sessions[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Software processed bytes | Number of bytes processed only by the software firewall. |
Dependent item | fgate.fwp.sw_bytes[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Hardware processed bytes | Number of bytes processed only by the hardware (ASIC) firewall. |
Dependent item | fgate.fwp.hw_bytes[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Total bytes processed | Number of bytes processed by both the software and hardware (ASIC) firewall. |
Dependent item | fgate.fwp.bytes[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Hits into the policy | Number of packets hit into the firewall policy per second. |
Dependent item | fgate.fwp.hits[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Last using time | The time at which the firewall policy was used the last time. |
Dependent item | fgate.fwp.last_used[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Action | The firewall policy action (accept / deny / ipsec). |
Dependent item | fgate.fwp.action[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Status | The firewall policy status. |
Dependent item | fgate.fwp.status[{#FWUUID}] Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Service discovery | Discovery for FortiGate services. |
Dependent item | fgate.service.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Service [{#NAME}]: Get data | Item for gathering data about license for the {#NAME} service. |
Dependent item | fgate.service.get_data["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: License status | Current license status of the {#NAME} service. |
Dependent item | fgate.service.license["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: Service type | Current type of the {#NAME} service. |
Dependent item | fgate.service.type["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: Service version | Current version of the {#NAME} service. |
Dependent item | fgate.service.version["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: Expiration date | Expiration date for the license of the current service. |
Dependent item | fgate.service.expire["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: Last update time | Last update time of the current service. |
Dependent item | fgate.service.update_time["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: Last attempt to update | Last update attempt time of the current service. |
Dependent item | fgate.service.update_attempt["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: Update method | Current update method of the {#NAME} service. |
Dependent item | fgate.service.update_method["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: Update result | Last update result of the {#NAME} service. |
Dependent item | fgate.service.update_result["{#KEY}"] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| FortiGate: Service [{#NAME}]: License status is unsuccessful | This trigger expression works as follows: |
{$SERVICE.LICENSE.CONTROL:"{#KEY}"}=1 and last(/FortiGate by HTTP/fgate.service.license["{#KEY}"])>5 |
Average | Manual close: Yes |
| FortiGate: Service [{#NAME}]: License expires soon | This trigger expression works as follows: |
{$SERVICE.LICENSE.CONTROL:"{#KEY}"}=1 and (last(/FortiGate by HTTP/fgate.service.expire["{#KEY}"]) - now()) / 86400 < {$SERVICE.EXPIRY.WARN:"{#KEY}"} and last(/FortiGate by HTTP/fgate.service.expire["{#KEY}"]) > now() |
Warning | Manual close: Yes |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SD-WAN members discovery | Discovery for FortiGate SD-WAN members. |
Dependent item | fgate.sdwan_member.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SD-WAN [{#ZONE}]:[{#NAME}]: Get data | Item for gathering data about the {#NAME} interface in the {#ZONE} zone. |
Dependent item | fgate.sdwan_member.get_data[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: Member status | Current status of the {#NAME} interface in the {#ZONE} zone. |
Dependent item | fgate.sdwan_member.status[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: Link status | Current link status of the {#NAME} interface in the {#ZONE} zone. |
Dependent item | fgate.sdwan_member.link_status[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: Sessions | Number of active sessions opened through the {#NAME} interface in the {#ZONE} zone. |
Dependent item | fgate.sdwan_member.sessions[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: Bytes sent per second | Bytes sent through the {#NAME} interface in the {#ZONE} zone per second. |
Dependent item | fgate.sdwan_member.tx_bytes[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: Bytes received per second | Bytes received from the {#NAME} interface in the {#ZONE} zone per second. |
Dependent item | fgate.sdwan_member.rx_bytes[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: Output bandwidth | Transmitting bandwidth of the {#NAME} interface in the {#ZONE} zone. |
Dependent item | fgate.sdwan_member.tx_bandwidth[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: Input bandwidth | Receiving bandwidth of the {#NAME} interface in the {#ZONE} zone. |
Dependent item | fgate.sdwan_member.rx_bandwidth[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: State changing time | Last state changing time of the {#NAME} interface in the {#ZONE} zone. |
Dependent item | fgate.service.state_changed[{#ID}] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| FortiGate: SD-WAN [{#ZONE}]:[{#NAME}]: Link down | This trigger expression works as follows: |
{$SDWAN.MEMBER.IF.CONTROL:"{#NAME}"}=1 and last(/FortiGate by HTTP/fgate.sdwan_member.link_status[{#ID}])=1 and (last(/FortiGate by HTTP/fgate.sdwan_member.link_status[{#ID}],#1)<>last(/FortiGate by HTTP/fgate.sdwan_member.link_status[{#ID}],#2)) |
Average | Manual close: Yes |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SD-WAN health-checks discovery | Discovery for FortiGate SD-WAN health-checks. |
Dependent item | fgate.sdwan_health.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SD-WAN [{#NAME}]:[{#IFNAME}]: Get data | Item for gathering data about the {#IFNAME} interface in the {#NAME} health-check. |
Dependent item | fgate.sdwan_health.get_data["{#HID}.{#MID}"] Preprocessing
|
| SD-WAN [{#NAME}]:[{#IFNAME}]: Interface status | Current status of the {#IFNAME} interface in the {#NAME} health-check. |
Dependent item | fgate.sdwan_health.status["{#HID}.{#MID}"] Preprocessing
|
| SD-WAN [{#NAME}]:[{#IFNAME}]: Jitter | Current jitter value for the {#IFNAME} interface in the {#NAME} health-check. |
Dependent item | fgate.sdwan_health.jitter["{#HID}.{#MID}"] Preprocessing
|
| SD-WAN [{#NAME}]:[{#IFNAME}]: Latency | Current latency value for the {#IFNAME} interface in the {#NAME} health-check. |
Dependent item | fgate.sdwan_health.latency["{#HID}.{#MID}"] Preprocessing
|
| SD-WAN [{#NAME}]:[{#IFNAME}]: Packets loss | Percent of lost packets for the {#IFNAME} interface in the {#NAME} health-check. |
Dependent item | fgate.sdwan_health.loss["{#HID}.{#MID}"] Preprocessing
|
| SD-WAN [{#NAME}]:[{#IFNAME}]: Packets sent per second | Number of packets sent through the {#IFNAME} interface in the {#NAME} health-check per second. |
Dependent item | fgate.sdwan_health.sent["{#HID}.{#MID}"] Preprocessing
|
| SD-WAN [{#NAME}]:[{#IFNAME}]: Packets received per second | Number of packets received from the {#IFNAME} interface in the {#NAME} health-check per second. |
Dependent item | fgate.sdwan_health.received["{#HID}.{#MID}"] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| FortiGate: SD-WAN [{#NAME}]:[{#IFNAME}]: Link down | This trigger expression works as follows: |
{$SDWAN.HEALTH.IF.CONTROL:"{#NAME}"}=1 and last(/FortiGate by HTTP/fgate.sdwan_health.status["{#HID}.{#MID}"])=1 and (last(/FortiGate by HTTP/fgate.sdwan_health.status["{#HID}.{#MID}"],#1)<>last(/FortiGate by HTTP/fgate.sdwan_health.status["{#HID}.{#MID}"],#2)) |
Average | Manual close: Yes |
| FortiGate: SD-WAN [{#NAME}]:[{#IFNAME}]: Link state is error | This trigger expression works as follows: |
{$SDWAN.HEALTH.IF.CONTROL:"{#IFNAME}"}=1 and last(/FortiGate by HTTP/fgate.sdwan_health.status["{#HID}.{#MID}"])=2 and (last(/FortiGate by HTTP/fgate.sdwan_health.status["{#HID}.{#MID}"],#1)<>last(/FortiGate by HTTP/fgate.sdwan_health.status["{#HID}.{#MID}"],#2)) |
Average | Manual close: Yes |
| FortiGate: SD-WAN [{#NAME}]:[{#IFNAME}]: High packets loss | High level of packets loss detected. |
min(/FortiGate by HTTP/fgate.sdwan_health.loss["{#HID}.{#MID}"],5m)>{$SDWAN.HEALTH.IF.LOSS.WARN:"{#IFNAME}"} |
Warning |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Network interfaces discovery | Discovery for FortiGate network interfaces. |
Dependent item | fgate.netif.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Interface [{#IFNAME}({#IFALIAS})]: Get data | Item for gathering data for the {#IFKEY} interface. |
Dependent item | fgate.netif.get_data[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Link status | Current link status of the interface. |
Dependent item | fgate.netif.status[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Bits received | The total number of octets received on the interface per second. |
Dependent item | fgate.netif.in[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Inbound packets | The total number of packets received on the interface per second. |
Dependent item | fgate.netif.in_packets[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Bits sent | The total number of octets transmitted out of the interface. |
Dependent item | fgate.netif.out[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Outbound packets | The total number of packets transmitted out of the interface per second. |
Dependent item | fgate.netif.out_packets[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Inbound packets with errors | The total number of errors received. |
Dependent item | fgate.netif.in_errors[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Outbound packets with errors | The total number of errors transmitted. |
Dependent item | fgate.netif.out_errors[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Interface type | Type of the interface. |
Dependent item | fgate.netif.type[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Speed | Speed of the interface. |
Dependent item | fgate.netif.speed[{#IFKEY}] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| FortiGate: Interface [{#IFNAME}({#IFALIAS})]: Link down | This trigger expression works as follows: |
{$NET.IF.CONTROL:"{#IFNAME}"}=1 and last(/FortiGate by HTTP/fgate.netif.status[{#IFKEY}])=1 and (last(/FortiGate by HTTP/fgate.netif.status[{#IFKEY}],#1)<>last(/FortiGate by HTTP/fgate.netif.status[{#IFKEY}],#2)) |
Average | Manual close: Yes |
| FortiGate: Interface [{#IFNAME}({#IFALIAS})]: High bandwidth usage | The utilization of the network interface is close to its estimated maximum bandwidth. |
(avg(/FortiGate by HTTP/fgate.netif.in[{#IFKEY}],15m)>({$NET.IF.UTIL.MAX:"{#IFNAME}"}/100)*last(/FortiGate by HTTP/fgate.netif.speed[{#IFKEY}]) or avg(/FortiGate by HTTP/fgate.netif.out[{#IFKEY}],15m)>({$NET.IF.UTIL.MAX:"{#IFNAME}"}/100)*last(/FortiGate by HTTP/fgate.netif.speed[{#IFKEY}])) and last(/FortiGate by HTTP/fgate.netif.speed[{#IFKEY}])>0 |
Warning | Manual close: Yes Depends on:
|
| FortiGate: Interface [{#IFNAME}({#IFALIAS})]: High error rate | It recovers when it is below 80% of the |
min(/FortiGate by HTTP/fgate.netif.in_errors[{#IFKEY}],5m)>{$NET.IF.ERRORS.WARN:"{#IFKEY}"} or min(/FortiGate by HTTP/fgate.netif.in_errors[{#IFKEY}],5m)>{$NET.IF.ERRORS.WARN:"{#IFKEY}"} |
Warning | Manual close: Yes Depends on:
|
| FortiGate: Interface [{#IFNAME}({#IFALIAS})]: Ethernet has changed to lower speed than it was before | This Ethernet connection has transitioned down from its known maximum speed. This might be a sign of autonegotiation issues. Acknowledge to close the problem manually. |
change(/FortiGate by HTTP/fgate.netif.speed[{#IFKEY}])<0 and last(/FortiGate by HTTP/fgate.netif.speed[{#IFKEY}])>0 and last(/FortiGate by HTTP/fgate.netif.status[{#IFKEY}])<>0 |
Info | Manual close: Yes Depends on:
|
Please report any issues with the template at https://support.zabbix.com
You can also provide feedback, discuss the template, or ask for help at ZABBIX forums
This template is designed for the effortless deployment of FortiGate monitoring by Zabbix via HTTP and doesn't require any external scripts.
Zabbix version: 6.4 and higher.
This template has been tested on:
Zabbix should be configured according to the instructions in the Templates out of the box section.
System > Admin Profiles > Create New.System > Administrators > Create New > REST API Admin.{$FGATE.API.TOKEN} macro.{$FGATE.API.FQDN} macro value.{$FGATE.SCHEME} macro and 443 into {$FGATE.API.PORT} macro.{$FGATE.API.PORT} macro.Please, refer to the vendor documentation about the FortiGate REST API Authentication.
| Name | Description | Default |
|---|---|---|
| {$FGATE.SCHEME} | Request scheme which may be http or https. |
http |
| {$FGATE.API.FQDN} | FortiGate API FQDN/IP (ex. ngfw.example.com). |
|
| {$FGATE.API.TOKEN} | FortiGate API token. |
|
| {$FGATE.API.PORT} | The port of FortiGate API endpoint. |
80 |
| {$FGATE.DATA.TIMEOUT} | Response timeout for an API. |
15s |
| {$FGATE.HTTP.PROXY} | HTTP proxy for API requests. You can specify it using the format [protocol://][username[:password]@]proxy.example.com[:port]. See the documentation at https://www.zabbix.com/documentation/6.4/manual/config/items/itemtypes/http |
|
| {$FIRMWARE.UPDATES.CONTROL} | This macro is used in "New available firmware found" trigger. |
1 |
| {$CPU.UTIL.WARN} | Threshold of CPU utilization for warning trigger in %. |
85 |
| {$CPU.UTIL.CRIT} | Threshold of CPU utilization for critical trigger in %. |
95 |
| {$MEMORY.UTIL.WARN} | Threshold of memory utilization for warning trigger in %. |
80 |
| {$MEMORY.UTIL.CRIT} | Threshold of memory utilization for critical trigger in %. |
90 |
| {$DISK.FREE.WARN} | Threshold of disk free space for warning trigger in %. |
20 |
| {$DISK.FREE.CRIT} | Threshold of disk free space for critical trigger in %. |
10 |
| {$NET.IF.CONTROL} | Macro for operational state of the interface for "Link down" trigger. Can be used with interface name as context. |
1 |
| {$NET.IF.ERRORS.WARN} | Threshold of error packets rate for warning trigger. Can be used with interface name as context. |
2 |
| {$NET.IF.UTIL.MAX} | Threshold of interface bandwidth utilization for warning trigger in %. Can be used with interface name as context. |
95 |
| {$NET.IF.IFDESCR.MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFDESCR.NOT_MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$NET.IF.IFNAME.MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFNAME.NOT_MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$NET.IF.IFTYPE.MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFTYPE.NOT_MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$NET.IF.IFALIAS.MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFALIAS.NOT_MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$NET.IF.IFSTATUS.MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFSTATUS.NOT_MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$FWP.FWACTION.MATCHES} | This macro is used in Firewall policies discovery. Can be overridden on the host or linked template level. |
.* |
| {$FWP.FWACTION.NOT_MATCHES} | This macro is used in Firewall policies discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$FWP.FWTYPE.MATCHES} | This macro is used in Firewall policies discovery. Can be overridden on the host or linked template level. |
.* |
| {$FWP.FWTYPE.NOT_MATCHES} | This macro is used in Firewall policies discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$FWP.FWNAME.MATCHES} | This macro is used in Firewall policies discovery. Can be overridden on the host or linked template level. |
.* |
| {$FWP.FWNAME.NOT_MATCHES} | This macro is used in Firewall policies discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SERVICE.EXPIRY.WARN} | Number of days until the license expires. |
7 |
| {$SERVICE.LICENSE.CONTROL} | This macro is used in Service discovery. Can be used with interface name as context. |
1 |
| {$SERVICE.KEY.MATCHES} | This macro is used in Service discovery. Can be overridden on the host or linked template level. |
.* |
| {$SERVICE.KEY.NOT_MATCHES} | This macro is used in Service discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SERVICE.STATUS.MATCHES} | This macro is used in Service discovery. Can be overridden on the host or linked template level. |
.* |
| {$SERVICE.STATUS.NOT_MATCHES} | This macro is used in Service discovery. Can be overridden on the host or linked template level. |
(no_support|no_license) |
| {$SERVICE.TYPE.MATCHES} | This macro is used in Service discovery. Can be overridden on the host or linked template level. |
.* |
| {$SERVICE.TYPE.NOT_MATCHES} | This macro is used in Service discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.MEMBER.IF.CONTROL} | Macro for the interface state for "Link down" trigger. Can be used with interface name as context. |
1 |
| {$SDWAN.MEMBER.ID.MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.MEMBER.ID.NOT_MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.MEMBER.NAME.MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.MEMBER.NAME.NOT_MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.MEMBER.STATUS.MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.MEMBER.STATUS.NOT_MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.MEMBER.ZONE.MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.MEMBER.ZONE.NOT_MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.HEALTH.IF.CONTROL} | Macro for the interface state for "Link down" trigger. Can be used with interface name as context. |
1 |
| {$SDWAN.HEALTH.ID.MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.HEALTH.ID.NOT_MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.HEALTH.NAME.MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.HEALTH.NAME.NOT_MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.HEALTH.IFNAME.MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.HEALTH.IFNAME.NOT_MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.HEALTH.STATUS.MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.HEALTH.STATUS.NOT_MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.HEALTH.IF.LOSS.WARN} | Threshold of packets loss for warning trigger in %. Can be used with interface name as context. |
20 |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| FortiGate: Check port availability | Simple check | net.tcp.service["{$FGATE.SCHEME}","{$FGATE.API.FQDN}","{$FGATE.API.PORT}"] Preprocessing
|
|
| FortiGate: Get system info | Item for gathering device system info from FortiGate API. |
HTTP agent | fgate.system.get_data Preprocessing
|
| FortiGate: Device system info item errors | Item for gathering errors of the device system info. |
Dependent item | fgate.system.data_errors Preprocessing
|
| FortiGate: API availability status | Checking API availability by response. |
Dependent item | fgate.api.status Preprocessing
|
| FortiGate: Get firmware info | Item for gathering device firmware info from FortiGate API. |
HTTP agent | fgate.firmware.get_data Preprocessing
|
| FortiGate: Device firmware info item errors | Item for gathering errors of the device firmware info. |
Dependent item | fgate.firmware.data_errors Preprocessing
|
| FortiGate: Get service licenses | Item for gathering information about service licenses from FortiGate API. |
Script | fgate.service.get_data |
| FortiGate: Service licenses item errors | Item for gathering errors of the service licenses data. |
Dependent item | fgate.service.data_errors Preprocessing
|
| FortiGate: Get resources data | Item for gathering device resource data from FortiGate API. |
Script | fgate.resources.get_data |
| FortiGate: Device resources item errors | Item for gathering errors of the device resources. |
Dependent item | fgate.resources.data_errors Preprocessing
|
| FortiGate: Get interfaces data | Item for gathering network interfaces info from FortiGate API. |
Script | fgate.netif.get_data |
| FortiGate: Device interfaces item errors | Item for gathering errors of network interfaces. |
Dependent item | fgate.netif.data_errors Preprocessing
|
| FortiGate: Get SD-WAN data | Item for gathering SD-WAN information from FortiGate API. |
Script | fgate.sdwan.get_data |
| FortiGate: Get SD-WAN item errors | Item for gathering errors of SD-WAN. |
Dependent item | fgate.sdwan.data_errors Preprocessing
|
| FortiGate: Get firewall data | Item for gathering firewall policies info from FortiGate API. |
Script | fgate.fwp.get_data |
| FortiGate: Firewall data item errors | Item for gathering errors of firewall policies. |
Dependent item | fgate.fwp.data_errors Preprocessing
|
| FortiGate: Available firmware versions | Number of available firmware versions to download. |
Dependent item | fgate.device.firmwares_avail Preprocessing
|
| FortiGate: Device firmware version | Current version of the device firmware. |
Dependent item | fgate.device.firmware Preprocessing
|
| FortiGate: Device model name | The model name of the device. |
Dependent item | fgate.device.model Preprocessing
|
| FortiGate: Device serial number | The device serial number. |
Dependent item | fgate.device.serialnumber Preprocessing
|
| FortiGate: Current VDOM | Name of the current Virtual Domain. |
Dependent item | fgate.device.vdom Preprocessing
|
| FortiGate: System name | The system host name. |
Dependent item | fgate.name Preprocessing
|
| FortiGate: System uptime | The system uptime is calculated on the basis of boot time. |
Dependent item | fgate.uptime Preprocessing
|
| FortiGate: Number of CPUs | Number of processors according to the current license. |
Dependent item | fgate.cpu.num Preprocessing
|
| FortiGate: CPU utilization | CPU utilization, expressed in %. |
Dependent item | fgate.cpu.util Preprocessing
|
| FortiGate: Total memory | Total memory, expressed in bytes. |
Dependent item | fgate.memory.total Preprocessing
|
| FortiGate: Memory utilization | Memory utilization, expressed in %. |
Dependent item | fgate.memory.util Preprocessing
|
| FortiGate: Total disk space | The total space of the current disk, in bytes. |
Dependent item | fgate.fs.total Preprocessing
|
| FortiGate: Used disk space | The used space of the current disk, in bytes. |
Dependent item | fgate.fs.used Preprocessing
|
| FortiGate: Free disk space | The free space of the current disk, in bytes. |
Dependent item | fgate.fs.free Preprocessing
|
| FortiGate: Disk utilization | Disk utilization, expressed in %. |
Dependent item | fgate.fs.util Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| FortiGate: Port {$FGATE.API.PORT} is unavailable | last(/FortiGate by HTTP/net.tcp.service["{$FGATE.SCHEME}","{$FGATE.API.FQDN}","{$FGATE.API.PORT}"])=0 |
Average | Manual close: Yes | |
| FortiGate: There are errors in the 'Get system info' metric | length(last(/FortiGate by HTTP/fgate.system.data_errors))>0 and length(last(/FortiGate by HTTP/fgate.system.data_errors,#1:now-1m))>0 and nodata(/FortiGate by HTTP/fgate.system.data_errors,2m)=0 |
Warning | Depends on:
|
|
| FortiGate: Unexpected response from API | Received an unexpected response from API. It may be unavailable. |
last(/FortiGate by HTTP/fgate.api.status)=0 |
Average | Depends on:
|
| FortiGate: There are errors in the 'Get firmware info' metric | length(last(/FortiGate by HTTP/fgate.firmware.data_errors))>0 and length(last(/FortiGate by HTTP/fgate.firmware.data_errors,#1:now-1m))>0 and nodata(/FortiGate by HTTP/fgate.firmware.data_errors,2m)=0 |
Warning | Depends on:
|
|
| FortiGate: There are errors in the 'Get service licenses' metric | length(last(/FortiGate by HTTP/fgate.service.data_errors))>0 and length(last(/FortiGate by HTTP/fgate.service.data_errors,#1:now-1m))>0 and nodata(/FortiGate by HTTP/fgate.service.data_errors,2m)=0 |
Warning | Depends on:
|
|
| FortiGate: There are errors in the 'Get resources data' metric | length(last(/FortiGate by HTTP/fgate.resources.data_errors))>0 and length(last(/FortiGate by HTTP/fgate.resources.data_errors,#1:now-1m))>0 and nodata(/FortiGate by HTTP/fgate.resources.data_errors,2m)=0 |
Warning | Depends on:
|
|
| FortiGate: There are errors in the 'Get interfaces data' metric | length(last(/FortiGate by HTTP/fgate.netif.data_errors))>0 and length(last(/FortiGate by HTTP/fgate.netif.data_errors,#1:now-1m))>0 and nodata(/FortiGate by HTTP/fgate.netif.data_errors,2m)=0 |
Warning | Depends on:
|
|
| FortiGate: There are errors in the 'Get SD-WAN data' metric | length(last(/FortiGate by HTTP/fgate.sdwan.data_errors))>0 and length(last(/FortiGate by HTTP/fgate.sdwan.data_errors,#1:now-1m))>0 and nodata(/FortiGate by HTTP/fgate.sdwan.data_errors,2m)=0 |
Warning | Depends on:
|
|
| FortiGate: There are errors in the 'Get firewall policies data' metric | length(last(/FortiGate by HTTP/fgate.fwp.data_errors))>0 and length(last(/FortiGate by HTTP/fgate.fwp.data_errors,#1:now-1m))>0 and nodata(/FortiGate by HTTP/fgate.fwp.data_errors,2m)=0 |
Warning | Depends on:
|
|
| FortiGate: New available firmware found | New available firmware versions found to download. |
{$FIRMWARE.UPDATES.CONTROL}=1 and last(/FortiGate by HTTP/fgate.device.firmwares_avail)>0 |
Info | Manual close: Yes |
| FortiGate: Device has been replaced | Device serial number has changed. Acknowledge to close the problem manually. |
last(/FortiGate by HTTP/fgate.device.serialnumber,#1)<>last(/FortiGate by HTTP/fgate.device.serialnumber,#2) and length(last(/FortiGate by HTTP/fgate.device.serialnumber))>0 |
Info | Manual close: Yes |
| FortiGate: System name has changed | The name of the system has changed. Acknowledge to close the problem manually. |
last(/FortiGate by HTTP/fgate.name,#1)<>last(/FortiGate by HTTP/fgate.name,#2) and length(last(/FortiGate by HTTP/fgate.name))>0 |
Info | Manual close: Yes |
| FortiGate: Device has been restarted | Uptime is less than 10 minutes. |
last(/FortiGate by HTTP/fgate.uptime)<10m |
Info | Manual close: Yes |
| FortiGate: CPU utilization is too high | The CPU utilization is too high. The system might be slow to respond. |
min(/FortiGate by HTTP/fgate.cpu.util,5m)>{$CPU.UTIL.CRIT} |
High | |
| FortiGate: CPU utilization is high | The CPU utilization is high. |
min(/FortiGate by HTTP/fgate.cpu.util,5m)>{$CPU.UTIL.WARN} |
Warning | Depends on:
|
| FortiGate: Memory utilization is too high | Free memory size is too low. |
min(/FortiGate by HTTP/fgate.memory.util,5m)>{$MEMORY.UTIL.CRIT} |
High | |
| FortiGate: Memory utilization is high | The system is running out of free memory. |
min(/FortiGate by HTTP/fgate.memory.util,5m)>{$MEMORY.UTIL.WARN} |
Average | Depends on:
|
| FortiGate: Free disk space is too low | Left disk space is too low. |
(100-last(/FortiGate by HTTP/fgate.fs.util))<{$DISK.FREE.CRIT} |
High | |
| FortiGate: Free disk space is low | Left disk space is not enough. |
(100-last(/FortiGate by HTTP/fgate.fs.util))<{$DISK.FREE.WARN} |
Warning | Depends on:
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Firewall policies discovery | Discovery for FortiGate firewall policies. |
Dependent item | fgate.fwp.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| FW Policy [{#FWNAME}]: Get data | Item for gathering data for the {#FWNAME} firewall policy. |
Dependent item | fgate.fwp.get_data[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Active sessions | Number of active sessions covered by this rule. |
Dependent item | fgate.fwp.sessions[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Software processed bytes | Number of bytes processed only by the software firewall. |
Dependent item | fgate.fwp.sw_bytes[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Hardware processed bytes | Number of bytes processed only by the hardware (ASIC) firewall. |
Dependent item | fgate.fwp.hw_bytes[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Total bytes processed | Number of bytes processed by both the software and hardware (ASIC) firewall. |
Dependent item | fgate.fwp.bytes[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Hits into the policy | Number of packets hit into the firewall policy per second. |
Dependent item | fgate.fwp.hits[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Last using time | The time at which the firewall policy was used the last time. |
Dependent item | fgate.fwp.last_used[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Action | The firewall policy action (accept / deny / ipsec). |
Dependent item | fgate.fwp.action[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Status | The firewall policy status. |
Dependent item | fgate.fwp.status[{#FWUUID}] Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Service discovery | Discovery for FortiGate services. |
Dependent item | fgate.service.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Service [{#NAME}]: Get data | Item for gathering data about license for the {#NAME} service. |
Dependent item | fgate.service.get_data["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: License status | Current license status of the {#NAME} service. |
Dependent item | fgate.service.license["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: Service type | Current type of the {#NAME} service. |
Dependent item | fgate.service.type["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: Service version | Current version of the {#NAME} service. |
Dependent item | fgate.service.version["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: Expiration date | Expiration date for the license of the current service. |
Dependent item | fgate.service.expire["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: Last update time | Last update time of the current service. |
Dependent item | fgate.service.update_time["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: Last attempt to update | Last update attempt time of the current service. |
Dependent item | fgate.service.update_attempt["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: Update method | Current update method of the {#NAME} service. |
Dependent item | fgate.service.update_method["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: Update result | Last update result of the {#NAME} service. |
Dependent item | fgate.service.update_result["{#KEY}"] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| Service [{#NAME}]: License status is unsuccessful | This trigger expression works as follows: |
{$SERVICE.LICENSE.CONTROL:"{#KEY}"}=1 and last(/FortiGate by HTTP/fgate.service.license["{#KEY}"])>5 |
Average | Manual close: Yes |
| Service [{#NAME}]: License expires soon | This trigger expression works as follows: |
{$SERVICE.LICENSE.CONTROL:"{#KEY}"}=1 and (last(/FortiGate by HTTP/fgate.service.expire["{#KEY}"]) - now()) / 86400 < {$SERVICE.EXPIRY.WARN:"{#KEY}"} and last(/FortiGate by HTTP/fgate.service.expire["{#KEY}"]) > now() |
Warning | Manual close: Yes |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SD-WAN members discovery | Discovery for FortiGate SD-WAN members. |
Dependent item | fgate.sdwan_member.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SD-WAN [{#ZONE}]:[{#NAME}]: Get data | Item for gathering data about the {#NAME} interface in the {#ZONE} zone. |
Dependent item | fgate.sdwan_member.get_data[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: Member status | Current status of the {#NAME} interface in the {#ZONE} zone. |
Dependent item | fgate.sdwan_member.status[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: Link status | Current link status of the {#NAME} interface in the {#ZONE} zone. |
Dependent item | fgate.sdwan_member.link_status[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: Sessions | Number of active sessions opened through the {#NAME} interface in the {#ZONE} zone. |
Dependent item | fgate.sdwan_member.sessions[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: Bytes sent per second | Bytes sent through the {#NAME} interface in the {#ZONE} zone per second. |
Dependent item | fgate.sdwan_member.tx_bytes[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: Bytes received per second | Bytes received from the {#NAME} interface in the {#ZONE} zone per second. |
Dependent item | fgate.sdwan_member.rx_bytes[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: Output bandwidth | Transmitting bandwidth of the {#NAME} interface in the {#ZONE} zone. |
Dependent item | fgate.sdwan_member.tx_bandwidth[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: Input bandwidth | Receiving bandwidth of the {#NAME} interface in the {#ZONE} zone. |
Dependent item | fgate.sdwan_member.rx_bandwidth[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: State changing time | Last state changing time of the {#NAME} interface in the {#ZONE} zone. |
Dependent item | fgate.service.state_changed[{#ID}] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| SD-WAN [{#ZONE}]:[{#NAME}]: Link down | This trigger expression works as follows: |
{$SDWAN.MEMBER.IF.CONTROL:"{#NAME}"}=1 and last(/FortiGate by HTTP/fgate.sdwan_member.link_status[{#ID}])=1 and (last(/FortiGate by HTTP/fgate.sdwan_member.link_status[{#ID}],#1)<>last(/FortiGate by HTTP/fgate.sdwan_member.link_status[{#ID}],#2)) |
Average | Manual close: Yes |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SD-WAN health-checks discovery | Discovery for FortiGate SD-WAN health-checks. |
Dependent item | fgate.sdwan_health.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SD-WAN [{#NAME}]:[{#IFNAME}]: Get data | Item for gathering data about the {#IFNAME} interface in the {#NAME} health-check. |
Dependent item | fgate.sdwan_health.get_data["{#HID}.{#MID}"] Preprocessing
|
| SD-WAN [{#NAME}]:[{#IFNAME}]: Interface status | Current status of the {#IFNAME} interface in the {#NAME} health-check. |
Dependent item | fgate.sdwan_health.status["{#HID}.{#MID}"] Preprocessing
|
| SD-WAN [{#NAME}]:[{#IFNAME}]: Jitter | Current jitter value for the {#IFNAME} interface in the {#NAME} health-check. |
Dependent item | fgate.sdwan_health.jitter["{#HID}.{#MID}"] Preprocessing
|
| SD-WAN [{#NAME}]:[{#IFNAME}]: Latency | Current latency value for the {#IFNAME} interface in the {#NAME} health-check. |
Dependent item | fgate.sdwan_health.latency["{#HID}.{#MID}"] Preprocessing
|
| SD-WAN [{#NAME}]:[{#IFNAME}]: Packets loss | Percent of lost packets for the {#IFNAME} interface in the {#NAME} health-check. |
Dependent item | fgate.sdwan_health.loss["{#HID}.{#MID}"] Preprocessing
|
| SD-WAN [{#NAME}]:[{#IFNAME}]: Packets sent per second | Number of packets sent through the {#IFNAME} interface in the {#NAME} health-check per second. |
Dependent item | fgate.sdwan_health.sent["{#HID}.{#MID}"] Preprocessing
|
| SD-WAN [{#NAME}]:[{#IFNAME}]: Packets received per second | Number of packets received from the {#IFNAME} interface in the {#NAME} health-check per second. |
Dependent item | fgate.sdwan_health.received["{#HID}.{#MID}"] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| SD-WAN [{#NAME}]:[{#IFNAME}]: Link down | This trigger expression works as follows: |
{$SDWAN.HEALTH.IF.CONTROL:"{#NAME}"}=1 and last(/FortiGate by HTTP/fgate.sdwan_health.status["{#HID}.{#MID}"])=1 and (last(/FortiGate by HTTP/fgate.sdwan_health.status["{#HID}.{#MID}"],#1)<>last(/FortiGate by HTTP/fgate.sdwan_health.status["{#HID}.{#MID}"],#2)) |
Average | Manual close: Yes |
| SD-WAN [{#NAME}]:[{#IFNAME}]: Link state is error | This trigger expression works as follows: |
{$SDWAN.HEALTH.IF.CONTROL:"{#IFNAME}"}=1 and last(/FortiGate by HTTP/fgate.sdwan_health.status["{#HID}.{#MID}"])=2 and (last(/FortiGate by HTTP/fgate.sdwan_health.status["{#HID}.{#MID}"],#1)<>last(/FortiGate by HTTP/fgate.sdwan_health.status["{#HID}.{#MID}"],#2)) |
Average | Manual close: Yes |
| SD-WAN [{#NAME}]:[{#IFNAME}]: High packets loss | High level of packets loss detected. |
min(/FortiGate by HTTP/fgate.sdwan_health.loss["{#HID}.{#MID}"],5m)>{$SDWAN.HEALTH.IF.LOSS.WARN:"{#IFNAME}"} |
Warning |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Network interfaces discovery | Discovery for FortiGate network interfaces. |
Dependent item | fgate.netif.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Interface [{#IFNAME}({#IFALIAS})]: Get data | Item for gathering data for the {#IFKEY} interface. |
Dependent item | fgate.netif.get_data[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Link status | Current link status of the interface. |
Dependent item | fgate.netif.status[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Bits received | The total number of octets received on the interface per second. |
Dependent item | fgate.netif.in[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Inbound packets | The total number of packets received on the interface per second. |
Dependent item | fgate.netif.in_packets[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Bits sent | The total number of octets transmitted out of the interface. |
Dependent item | fgate.netif.out[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Outbound packets | The total number of packets transmitted out of the interface per second. |
Dependent item | fgate.netif.out_packets[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Inbound packets with errors | The total number of errors received. |
Dependent item | fgate.netif.in_errors[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Outbound packets with errors | The total number of errors transmitted. |
Dependent item | fgate.netif.out_errors[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Interface type | Type of the interface. |
Dependent item | fgate.netif.type[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Speed | Speed of the interface. |
Dependent item | fgate.netif.speed[{#IFKEY}] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| Interface [{#IFNAME}({#IFALIAS})]: Link down | This trigger expression works as follows: |
{$NET.IF.CONTROL:"{#IFNAME}"}=1 and last(/FortiGate by HTTP/fgate.netif.status[{#IFKEY}])=1 and (last(/FortiGate by HTTP/fgate.netif.status[{#IFKEY}],#1)<>last(/FortiGate by HTTP/fgate.netif.status[{#IFKEY}],#2)) |
Average | Manual close: Yes |
| Interface [{#IFNAME}({#IFALIAS})]: High bandwidth usage | The utilization of the network interface is close to its estimated maximum bandwidth. |
(avg(/FortiGate by HTTP/fgate.netif.in[{#IFKEY}],15m)>({$NET.IF.UTIL.MAX:"{#IFNAME}"}/100)*last(/FortiGate by HTTP/fgate.netif.speed[{#IFKEY}]) or avg(/FortiGate by HTTP/fgate.netif.out[{#IFKEY}],15m)>({$NET.IF.UTIL.MAX:"{#IFNAME}"}/100)*last(/FortiGate by HTTP/fgate.netif.speed[{#IFKEY}])) and last(/FortiGate by HTTP/fgate.netif.speed[{#IFKEY}])>0 |
Warning | Manual close: Yes Depends on:
|
| Interface [{#IFNAME}({#IFALIAS})]: High error rate | It recovers when it is below 80% of the |
min(/FortiGate by HTTP/fgate.netif.in_errors[{#IFKEY}],5m)>{$NET.IF.ERRORS.WARN:"{#IFKEY}"} or min(/FortiGate by HTTP/fgate.netif.in_errors[{#IFKEY}],5m)>{$NET.IF.ERRORS.WARN:"{#IFKEY}"} |
Warning | Manual close: Yes Depends on:
|
| Interface [{#IFNAME}({#IFALIAS})]: Ethernet has changed to lower speed than it was before | This Ethernet connection has transitioned down from its known maximum speed. This might be a sign of autonegotiation issues. Acknowledge to close the problem manually. |
change(/FortiGate by HTTP/fgate.netif.speed[{#IFKEY}])<0 and last(/FortiGate by HTTP/fgate.netif.speed[{#IFKEY}])>0 and last(/FortiGate by HTTP/fgate.netif.status[{#IFKEY}])<>0 |
Info | Manual close: Yes Depends on:
|
Please report any issues with the template at https://support.zabbix.com
You can also provide feedback, discuss the template, or ask for help at ZABBIX forums
This template is designed for the effortless deployment of FortiGate monitoring by Zabbix via HTTP and doesn't require any external scripts.
Zabbix version: 6.0 and higher.
This template has been tested on:
Zabbix should be configured according to the instructions in the Templates out of the box section.
System > Admin Profiles > Create New.System > Administrators > Create New > REST API Admin.{$FGATE.API.TOKEN} macro.{$FGATE.API.FQDN} macro value.{$FGATE.SCHEME} macro and 443 into {$FGATE.API.PORT} macro.{$FGATE.API.PORT} macro.Please, refer to the vendor documentation about the FortiGate REST API Authentication.
| Name | Description | Default |
|---|---|---|
| {$FGATE.SCHEME} | Request scheme which may be http or https. |
http |
| {$FGATE.API.FQDN} | FortiGate API FQDN/IP (ex. ngfw.example.com). |
|
| {$FGATE.API.TOKEN} | FortiGate API token. |
|
| {$FGATE.API.PORT} | The port of FortiGate API endpoint. |
80 |
| {$FGATE.DATA.TIMEOUT} | Response timeout for an API. |
15s |
| {$FGATE.HTTP.PROXY} | HTTP proxy for API requests. You can specify it using the format [protocol://][username[:password]@]proxy.example.com[:port]. See the documentation at https://www.zabbix.com/documentation/6.0/manual/config/items/itemtypes/http |
|
| {$FIRMWARE.UPDATES.CONTROL} | This macro is used in "New available firmware found" trigger. |
1 |
| {$CPU.UTIL.WARN} | Threshold of CPU utilization for warning trigger in %. |
85 |
| {$CPU.UTIL.CRIT} | Threshold of CPU utilization for critical trigger in %. |
95 |
| {$MEMORY.UTIL.WARN} | Threshold of memory utilization for warning trigger in %. |
80 |
| {$MEMORY.UTIL.CRIT} | Threshold of memory utilization for critical trigger in %. |
90 |
| {$DISK.FREE.WARN} | Threshold of disk free space for warning trigger in %. |
20 |
| {$DISK.FREE.CRIT} | Threshold of disk free space for critical trigger in %. |
10 |
| {$NET.IF.CONTROL} | Macro for operational state of the interface for "Link down" trigger. Can be used with interface name as context. |
1 |
| {$NET.IF.ERRORS.WARN} | Threshold of error packets rate for warning trigger. Can be used with interface name as context. |
2 |
| {$NET.IF.UTIL.MAX} | Threshold of interface bandwidth utilization for warning trigger in %. Can be used with interface name as context. |
95 |
| {$NET.IF.IFDESCR.MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFDESCR.NOT_MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$NET.IF.IFNAME.MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFNAME.NOT_MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$NET.IF.IFTYPE.MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFTYPE.NOT_MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$NET.IF.IFALIAS.MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFALIAS.NOT_MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$NET.IF.IFSTATUS.MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFSTATUS.NOT_MATCHES} | This macro is used in Network interfaces discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$FWP.FWACTION.MATCHES} | This macro is used in Firewall policies discovery. Can be overridden on the host or linked template level. |
.* |
| {$FWP.FWACTION.NOT_MATCHES} | This macro is used in Firewall policies discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$FWP.FWTYPE.MATCHES} | This macro is used in Firewall policies discovery. Can be overridden on the host or linked template level. |
.* |
| {$FWP.FWTYPE.NOT_MATCHES} | This macro is used in Firewall policies discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$FWP.FWNAME.MATCHES} | This macro is used in Firewall policies discovery. Can be overridden on the host or linked template level. |
.* |
| {$FWP.FWNAME.NOT_MATCHES} | This macro is used in Firewall policies discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SERVICE.EXPIRY.WARN} | Number of days until the license expires. |
7 |
| {$SERVICE.LICENSE.CONTROL} | This macro is used in Service discovery. Can be used with interface name as context. |
1 |
| {$SERVICE.KEY.MATCHES} | This macro is used in Service discovery. Can be overridden on the host or linked template level. |
.* |
| {$SERVICE.KEY.NOT_MATCHES} | This macro is used in Service discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SERVICE.STATUS.MATCHES} | This macro is used in Service discovery. Can be overridden on the host or linked template level. |
.* |
| {$SERVICE.STATUS.NOT_MATCHES} | This macro is used in Service discovery. Can be overridden on the host or linked template level. |
(no_support|no_license) |
| {$SERVICE.TYPE.MATCHES} | This macro is used in Service discovery. Can be overridden on the host or linked template level. |
.* |
| {$SERVICE.TYPE.NOT_MATCHES} | This macro is used in Service discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.MEMBER.IF.CONTROL} | Macro for the interface state for "Link down" trigger. Can be used with interface name as context. |
1 |
| {$SDWAN.MEMBER.ID.MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.MEMBER.ID.NOT_MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.MEMBER.NAME.MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.MEMBER.NAME.NOT_MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.MEMBER.STATUS.MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.MEMBER.STATUS.NOT_MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.MEMBER.ZONE.MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.MEMBER.ZONE.NOT_MATCHES} | This macro is used in SD-WAN members discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.HEALTH.IF.CONTROL} | Macro for the interface state for "Link down" trigger. Can be used with interface name as context. |
1 |
| {$SDWAN.HEALTH.ID.MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.HEALTH.ID.NOT_MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.HEALTH.NAME.MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.HEALTH.NAME.NOT_MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.HEALTH.IFNAME.MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.HEALTH.IFNAME.NOT_MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.HEALTH.STATUS.MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.HEALTH.STATUS.NOT_MATCHES} | This macro is used in SD-WAN health-checks discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.HEALTH.IF.LOSS.WARN} | Threshold of packets loss for warning trigger in %. Can be used with interface name as context. |
20 |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| FortiGate: Check port availability | Simple check | net.tcp.service["{$FGATE.SCHEME}","{$FGATE.API.FQDN}","{$FGATE.API.PORT}"] Preprocessing
|
|
| FortiGate: Get system info | Item for gathering device system info from FortiGate API. |
HTTP agent | fgate.system.get_data Preprocessing
|
| FortiGate: Device system info item errors | Item for gathering errors of the device system info. |
Dependent item | fgate.system.data_errors Preprocessing
|
| FortiGate: API availability status | Checking API availability by response. |
Dependent item | fgate.api.status Preprocessing
|
| FortiGate: Get firmware info | Item for gathering device firmware info from FortiGate API. |
HTTP agent | fgate.firmware.get_data Preprocessing
|
| FortiGate: Device firmware info item errors | Item for gathering errors of the device firmware info. |
Dependent item | fgate.firmware.data_errors Preprocessing
|
| FortiGate: Get service licenses | Item for gathering information about service licenses from FortiGate API. |
Script | fgate.service.get_data |
| FortiGate: Service licenses item errors | Item for gathering errors of the service licenses data. |
Dependent item | fgate.service.data_errors Preprocessing
|
| FortiGate: Get resources data | Item for gathering device resource data from FortiGate API. |
Script | fgate.resources.get_data |
| FortiGate: Device resources item errors | Item for gathering errors of the device resources. |
Dependent item | fgate.resources.data_errors Preprocessing
|
| FortiGate: Get interfaces data | Item for gathering network interfaces info from FortiGate API. |
Script | fgate.netif.get_data |
| FortiGate: Device interfaces item errors | Item for gathering errors of network interfaces. |
Dependent item | fgate.netif.data_errors Preprocessing
|
| FortiGate: Get SD-WAN data | Item for gathering SD-WAN information from FortiGate API. |
Script | fgate.sdwan.get_data |
| FortiGate: Get SD-WAN item errors | Item for gathering errors of SD-WAN. |
Dependent item | fgate.sdwan.data_errors Preprocessing
|
| FortiGate: Get firewall data | Item for gathering firewall policies info from FortiGate API. |
Script | fgate.fwp.get_data |
| FortiGate: Firewall data item errors | Item for gathering errors of firewall policies. |
Dependent item | fgate.fwp.data_errors Preprocessing
|
| FortiGate: Available firmware versions | Number of available firmware versions to download. |
Dependent item | fgate.device.firmwares_avail Preprocessing
|
| FortiGate: Device firmware version | Current version of the device firmware. |
Dependent item | fgate.device.firmware Preprocessing
|
| FortiGate: Device model name | The model name of the device. |
Dependent item | fgate.device.model Preprocessing
|
| FortiGate: Device serial number | The device serial number. |
Dependent item | fgate.device.serialnumber Preprocessing
|
| FortiGate: Current VDOM | Name of the current Virtual Domain. |
Dependent item | fgate.device.vdom Preprocessing
|
| FortiGate: System name | The system host name. |
Dependent item | fgate.name Preprocessing
|
| FortiGate: System uptime | The system uptime is calculated on the basis of boot time. |
Dependent item | fgate.uptime Preprocessing
|
| FortiGate: Number of CPUs | Number of processors according to the current license. |
Dependent item | fgate.cpu.num Preprocessing
|
| FortiGate: CPU utilization | CPU utilization, expressed in %. |
Dependent item | fgate.cpu.util Preprocessing
|
| FortiGate: Total memory | Total memory, expressed in bytes. |
Dependent item | fgate.memory.total Preprocessing
|
| FortiGate: Memory utilization | Memory utilization, expressed in %. |
Dependent item | fgate.memory.util Preprocessing
|
| FortiGate: Total disk space | The total space of the current disk, in bytes. |
Dependent item | fgate.fs.total Preprocessing
|
| FortiGate: Used disk space | The used space of the current disk, in bytes. |
Dependent item | fgate.fs.used Preprocessing
|
| FortiGate: Free disk space | The free space of the current disk, in bytes. |
Dependent item | fgate.fs.free Preprocessing
|
| FortiGate: Disk utilization | Disk utilization, expressed in %. |
Dependent item | fgate.fs.util Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| FortiGate: Port {$FGATE.API.PORT} is unavailable | last(/FortiGate by HTTP/net.tcp.service["{$FGATE.SCHEME}","{$FGATE.API.FQDN}","{$FGATE.API.PORT}"])=0 |
Average | Manual close: Yes | |
| FortiGate: There are errors in the 'Get system info' metric | length(last(/FortiGate by HTTP/fgate.system.data_errors))>0 and length(last(/FortiGate by HTTP/fgate.system.data_errors,#1:now-1m))>0 and nodata(/FortiGate by HTTP/fgate.system.data_errors,2m)=0 |
Warning | Depends on:
|
|
| FortiGate: Unexpected response from API | Received an unexpected response from API. It may be unavailable. |
last(/FortiGate by HTTP/fgate.api.status)=0 |
Average | Depends on:
|
| FortiGate: There are errors in the 'Get firmware info' metric | length(last(/FortiGate by HTTP/fgate.firmware.data_errors))>0 and length(last(/FortiGate by HTTP/fgate.firmware.data_errors,#1:now-1m))>0 and nodata(/FortiGate by HTTP/fgate.firmware.data_errors,2m)=0 |
Warning | Depends on:
|
|
| FortiGate: There are errors in the 'Get service licenses' metric | length(last(/FortiGate by HTTP/fgate.service.data_errors))>0 and length(last(/FortiGate by HTTP/fgate.service.data_errors,#1:now-1m))>0 and nodata(/FortiGate by HTTP/fgate.service.data_errors,2m)=0 |
Warning | Depends on:
|
|
| FortiGate: There are errors in the 'Get resources data' metric | length(last(/FortiGate by HTTP/fgate.resources.data_errors))>0 and length(last(/FortiGate by HTTP/fgate.resources.data_errors,#1:now-1m))>0 and nodata(/FortiGate by HTTP/fgate.resources.data_errors,2m)=0 |
Warning | Depends on:
|
|
| FortiGate: There are errors in the 'Get interfaces data' metric | length(last(/FortiGate by HTTP/fgate.netif.data_errors))>0 and length(last(/FortiGate by HTTP/fgate.netif.data_errors,#1:now-1m))>0 and nodata(/FortiGate by HTTP/fgate.netif.data_errors,2m)=0 |
Warning | Depends on:
|
|
| FortiGate: There are errors in the 'Get SD-WAN data' metric | length(last(/FortiGate by HTTP/fgate.sdwan.data_errors))>0 and length(last(/FortiGate by HTTP/fgate.sdwan.data_errors,#1:now-1m))>0 and nodata(/FortiGate by HTTP/fgate.sdwan.data_errors,2m)=0 |
Warning | Depends on:
|
|
| FortiGate: There are errors in the 'Get firewall policies data' metric | length(last(/FortiGate by HTTP/fgate.fwp.data_errors))>0 and length(last(/FortiGate by HTTP/fgate.fwp.data_errors,#1:now-1m))>0 and nodata(/FortiGate by HTTP/fgate.fwp.data_errors,2m)=0 |
Warning | Depends on:
|
|
| FortiGate: New available firmware found | New available firmware versions found to download. |
{$FIRMWARE.UPDATES.CONTROL}=1 and last(/FortiGate by HTTP/fgate.device.firmwares_avail)>0 |
Info | Manual close: Yes |
| FortiGate: Device has been replaced | Device serial number has changed. Acknowledge to close the problem manually. |
last(/FortiGate by HTTP/fgate.device.serialnumber,#1)<>last(/FortiGate by HTTP/fgate.device.serialnumber,#2) and length(last(/FortiGate by HTTP/fgate.device.serialnumber))>0 |
Info | Manual close: Yes |
| FortiGate: System name has changed | The name of the system has changed. Acknowledge to close the problem manually. |
last(/FortiGate by HTTP/fgate.name,#1)<>last(/FortiGate by HTTP/fgate.name,#2) and length(last(/FortiGate by HTTP/fgate.name))>0 |
Info | Manual close: Yes |
| FortiGate: Device has been restarted | Uptime is less than 10 minutes. |
last(/FortiGate by HTTP/fgate.uptime)<10m |
Info | Manual close: Yes |
| FortiGate: CPU utilization is too high | The CPU utilization is too high. The system might be slow to respond. |
min(/FortiGate by HTTP/fgate.cpu.util,5m)>{$CPU.UTIL.CRIT} |
High | |
| FortiGate: CPU utilization is high | The CPU utilization is high. |
min(/FortiGate by HTTP/fgate.cpu.util,5m)>{$CPU.UTIL.WARN} |
Warning | Depends on:
|
| FortiGate: Memory utilization is too high | Free memory size is too low. |
min(/FortiGate by HTTP/fgate.memory.util,5m)>{$MEMORY.UTIL.CRIT} |
High | |
| FortiGate: Memory utilization is high | The system is running out of free memory. |
min(/FortiGate by HTTP/fgate.memory.util,5m)>{$MEMORY.UTIL.WARN} |
Average | Depends on:
|
| FortiGate: Free disk space is too low | Left disk space is too low. |
(100-last(/FortiGate by HTTP/fgate.fs.util))<{$DISK.FREE.CRIT} |
High | |
| FortiGate: Free disk space is low | Left disk space is not enough. |
(100-last(/FortiGate by HTTP/fgate.fs.util))<{$DISK.FREE.WARN} |
Warning | Depends on:
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Firewall policies discovery | Discovery for FortiGate firewall policies. |
Dependent item | fgate.fwp.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| FW Policy [{#FWNAME}]: Get data | Item for gathering data for the {#FWNAME} firewall policy. |
Dependent item | fgate.fwp.get_data[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Active sessions | Number of active sessions covered by this rule. |
Dependent item | fgate.fwp.sessions[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Software processed bytes | Number of bytes processed only by the software firewall. |
Dependent item | fgate.fwp.sw_bytes[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Hardware processed bytes | Number of bytes processed only by the hardware (ASIC) firewall. |
Dependent item | fgate.fwp.hw_bytes[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Total bytes processed | Number of bytes processed by both the software and hardware (ASIC) firewall. |
Dependent item | fgate.fwp.bytes[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Hits into the policy | Number of packets hit into the firewall policy per second. |
Dependent item | fgate.fwp.hits[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Last using time | The time at which the firewall policy was used the last time. |
Dependent item | fgate.fwp.last_used[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Action | The firewall policy action (accept / deny / ipsec). |
Dependent item | fgate.fwp.action[{#FWUUID}] Preprocessing
|
| FW Policy [{#FWNAME}]: Status | The firewall policy status. |
Dependent item | fgate.fwp.status[{#FWUUID}] Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Service discovery | Discovery for FortiGate services. |
Dependent item | fgate.service.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Service [{#NAME}]: Get data | Item for gathering data about license for the {#NAME} service. |
Dependent item | fgate.service.get_data["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: License status | Current license status of the {#NAME} service. |
Dependent item | fgate.service.license["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: Service type | Current type of the {#NAME} service. |
Dependent item | fgate.service.type["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: Service version | Current version of the {#NAME} service. |
Dependent item | fgate.service.version["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: Expiration date | Expiration date for the license of the current service. |
Dependent item | fgate.service.expire["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: Last update time | Last update time of the current service. |
Dependent item | fgate.service.update_time["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: Last attempt to update | Last update attempt time of the current service. |
Dependent item | fgate.service.update_attempt["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: Update method | Current update method of the {#NAME} service. |
Dependent item | fgate.service.update_method["{#KEY}"] Preprocessing
|
| Service [{#NAME}]: Update result | Last update result of the {#NAME} service. |
Dependent item | fgate.service.update_result["{#KEY}"] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| Service [{#NAME}]: License status is unsuccessful | This trigger expression works as follows: |
{$SERVICE.LICENSE.CONTROL:"{#KEY}"}=1 and last(/FortiGate by HTTP/fgate.service.license["{#KEY}"])>5 |
Average | Manual close: Yes |
| Service [{#NAME}]: License expires soon | This trigger expression works as follows: |
{$SERVICE.LICENSE.CONTROL:"{#KEY}"}=1 and (last(/FortiGate by HTTP/fgate.service.expire["{#KEY}"]) - now()) / 86400 < {$SERVICE.EXPIRY.WARN:"{#KEY}"} and last(/FortiGate by HTTP/fgate.service.expire["{#KEY}"]) > now() |
Warning | Manual close: Yes |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SD-WAN members discovery | Discovery for FortiGate SD-WAN members. |
Dependent item | fgate.sdwan_member.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SD-WAN [{#ZONE}]:[{#NAME}]: Get data | Item for gathering data about the {#NAME} interface in the {#ZONE} zone. |
Dependent item | fgate.sdwan_member.get_data[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: Member status | Current status of the {#NAME} interface in the {#ZONE} zone. |
Dependent item | fgate.sdwan_member.status[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: Link status | Current link status of the {#NAME} interface in the {#ZONE} zone. |
Dependent item | fgate.sdwan_member.link_status[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: Sessions | Number of active sessions opened through the {#NAME} interface in the {#ZONE} zone. |
Dependent item | fgate.sdwan_member.sessions[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: Bytes sent per second | Bytes sent through the {#NAME} interface in the {#ZONE} zone per second. |
Dependent item | fgate.sdwan_member.tx_bytes[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: Bytes received per second | Bytes received from the {#NAME} interface in the {#ZONE} zone per second. |
Dependent item | fgate.sdwan_member.rx_bytes[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: Output bandwidth | Transmitting bandwidth of the {#NAME} interface in the {#ZONE} zone. |
Dependent item | fgate.sdwan_member.tx_bandwidth[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: Input bandwidth | Receiving bandwidth of the {#NAME} interface in the {#ZONE} zone. |
Dependent item | fgate.sdwan_member.rx_bandwidth[{#ID}] Preprocessing
|
| SD-WAN [{#ZONE}]:[{#NAME}]: State changing time | Last state changing time of the {#NAME} interface in the {#ZONE} zone. |
Dependent item | fgate.service.state_changed[{#ID}] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| SD-WAN [{#ZONE}]:[{#NAME}]: Link down | This trigger expression works as follows: |
{$SDWAN.MEMBER.IF.CONTROL:"{#NAME}"}=1 and last(/FortiGate by HTTP/fgate.sdwan_member.link_status[{#ID}])=1 and (last(/FortiGate by HTTP/fgate.sdwan_member.link_status[{#ID}],#1)<>last(/FortiGate by HTTP/fgate.sdwan_member.link_status[{#ID}],#2)) |
Average | Manual close: Yes |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SD-WAN health-checks discovery | Discovery for FortiGate SD-WAN health-checks. |
Dependent item | fgate.sdwan_health.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SD-WAN [{#NAME}]:[{#IFNAME}]: Get data | Item for gathering data about the {#IFNAME} interface in the {#NAME} health-check. |
Dependent item | fgate.sdwan_health.get_data["{#HID}.{#MID}"] Preprocessing
|
| SD-WAN [{#NAME}]:[{#IFNAME}]: Interface status | Current status of the {#IFNAME} interface in the {#NAME} health-check. |
Dependent item | fgate.sdwan_health.status["{#HID}.{#MID}"] Preprocessing
|
| SD-WAN [{#NAME}]:[{#IFNAME}]: Jitter | Current jitter value for the {#IFNAME} interface in the {#NAME} health-check. |
Dependent item | fgate.sdwan_health.jitter["{#HID}.{#MID}"] Preprocessing
|
| SD-WAN [{#NAME}]:[{#IFNAME}]: Latency | Current latency value for the {#IFNAME} interface in the {#NAME} health-check. |
Dependent item | fgate.sdwan_health.latency["{#HID}.{#MID}"] Preprocessing
|
| SD-WAN [{#NAME}]:[{#IFNAME}]: Packets loss | Percent of lost packets for the {#IFNAME} interface in the {#NAME} health-check. |
Dependent item | fgate.sdwan_health.loss["{#HID}.{#MID}"] Preprocessing
|
| SD-WAN [{#NAME}]:[{#IFNAME}]: Packets sent per second | Number of packets sent through the {#IFNAME} interface in the {#NAME} health-check per second. |
Dependent item | fgate.sdwan_health.sent["{#HID}.{#MID}"] Preprocessing
|
| SD-WAN [{#NAME}]:[{#IFNAME}]: Packets received per second | Number of packets received from the {#IFNAME} interface in the {#NAME} health-check per second. |
Dependent item | fgate.sdwan_health.received["{#HID}.{#MID}"] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| SD-WAN [{#NAME}]:[{#IFNAME}]: Link down | This trigger expression works as follows: |
{$SDWAN.HEALTH.IF.CONTROL:"{#NAME}"}=1 and last(/FortiGate by HTTP/fgate.sdwan_health.status["{#HID}.{#MID}"])=1 and (last(/FortiGate by HTTP/fgate.sdwan_health.status["{#HID}.{#MID}"],#1)<>last(/FortiGate by HTTP/fgate.sdwan_health.status["{#HID}.{#MID}"],#2)) |
Average | Manual close: Yes |
| SD-WAN [{#NAME}]:[{#IFNAME}]: Link state is error | This trigger expression works as follows: |
{$SDWAN.HEALTH.IF.CONTROL:"{#IFNAME}"}=1 and last(/FortiGate by HTTP/fgate.sdwan_health.status["{#HID}.{#MID}"])=2 and (last(/FortiGate by HTTP/fgate.sdwan_health.status["{#HID}.{#MID}"],#1)<>last(/FortiGate by HTTP/fgate.sdwan_health.status["{#HID}.{#MID}"],#2)) |
Average | Manual close: Yes |
| SD-WAN [{#NAME}]:[{#IFNAME}]: High packets loss | High level of packets loss detected. |
min(/FortiGate by HTTP/fgate.sdwan_health.loss["{#HID}.{#MID}"],5m)>{$SDWAN.HEALTH.IF.LOSS.WARN:"{#IFNAME}"} |
Warning |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Network interfaces discovery | Discovery for FortiGate network interfaces. |
Dependent item | fgate.netif.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Interface [{#IFNAME}({#IFALIAS})]: Get data | Item for gathering data for the {#IFKEY} interface. |
Dependent item | fgate.netif.get_data[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Link status | Current link status of the interface. |
Dependent item | fgate.netif.status[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Bits received | The total number of octets received on the interface per second. |
Dependent item | fgate.netif.in[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Inbound packets | The total number of packets received on the interface per second. |
Dependent item | fgate.netif.in_packets[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Bits sent | The total number of octets transmitted out of the interface. |
Dependent item | fgate.netif.out[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Outbound packets | The total number of packets transmitted out of the interface per second. |
Dependent item | fgate.netif.out_packets[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Inbound packets with errors | The total number of errors received. |
Dependent item | fgate.netif.in_errors[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Outbound packets with errors | The total number of errors transmitted. |
Dependent item | fgate.netif.out_errors[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Interface type | Type of the interface. |
Dependent item | fgate.netif.type[{#IFKEY}] Preprocessing
|
| Interface [{#IFNAME}({#IFALIAS})]: Speed | Speed of the interface. |
Dependent item | fgate.netif.speed[{#IFKEY}] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| Interface [{#IFNAME}({#IFALIAS})]: Link down | This trigger expression works as follows: |
{$NET.IF.CONTROL:"{#IFNAME}"}=1 and last(/FortiGate by HTTP/fgate.netif.status[{#IFKEY}])=1 and (last(/FortiGate by HTTP/fgate.netif.status[{#IFKEY}],#1)<>last(/FortiGate by HTTP/fgate.netif.status[{#IFKEY}],#2)) |
Average | Manual close: Yes |
| Interface [{#IFNAME}({#IFALIAS})]: High bandwidth usage | The utilization of the network interface is close to its estimated maximum bandwidth. |
(avg(/FortiGate by HTTP/fgate.netif.in[{#IFKEY}],15m)>({$NET.IF.UTIL.MAX:"{#IFNAME}"}/100)*last(/FortiGate by HTTP/fgate.netif.speed[{#IFKEY}]) or avg(/FortiGate by HTTP/fgate.netif.out[{#IFKEY}],15m)>({$NET.IF.UTIL.MAX:"{#IFNAME}"}/100)*last(/FortiGate by HTTP/fgate.netif.speed[{#IFKEY}])) and last(/FortiGate by HTTP/fgate.netif.speed[{#IFKEY}])>0 |
Warning | Manual close: Yes Depends on:
|
| Interface [{#IFNAME}({#IFALIAS})]: High error rate | It recovers when it is below 80% of the |
min(/FortiGate by HTTP/fgate.netif.in_errors[{#IFKEY}],5m)>{$NET.IF.ERRORS.WARN:"{#IFKEY}"} or min(/FortiGate by HTTP/fgate.netif.in_errors[{#IFKEY}],5m)>{$NET.IF.ERRORS.WARN:"{#IFKEY}"} |
Warning | Manual close: Yes Depends on:
|
| Interface [{#IFNAME}({#IFALIAS})]: Ethernet has changed to lower speed than it was before | This Ethernet connection has transitioned down from its known maximum speed. This might be a sign of autonegotiation issues. Acknowledge to close the problem manually. |
change(/FortiGate by HTTP/fgate.netif.speed[{#IFKEY}])<0 and last(/FortiGate by HTTP/fgate.netif.speed[{#IFKEY}])>0 and last(/FortiGate by HTTP/fgate.netif.status[{#IFKEY}])<>0 |
Info | Manual close: Yes Depends on:
|
Please report any issues with the template at https://support.zabbix.com
You can also provide feedback, discuss the template, or ask for help at ZABBIX forums
This template is designed for the effortless deployment of FortiGate monitoring by Zabbix via SNMP and doesn't require any external scripts.
Zabbix version: 7.4 and higher.
This template has been tested on:
Zabbix should be configured according to the instructions in the Templates out of the box section.
Refer to the vendor documentation.
| Name | Description | Default |
|---|---|---|
| {$CPU.UTIL.CRIT} | Threshold of CPU utilization for Warning trigger in %. |
90 |
| {$ICMP_LOSS_WARN} | Threshold of ICMP packet loss for Warning trigger in %. |
20 |
| {$ICMP_RESPONSE_TIME_WARN} | Threshold of average ICMP response time for Warning trigger in seconds. |
0.15 |
| {$SNMP.TIMEOUT} | The time interval for SNMP availability trigger. |
5m |
| {$MEMORY.UTIL.MAX} | Threshold of memory utilization for trigger in %. |
90 |
| {$DISK.FREE.WARN} | Threshold of disk free space for Warning trigger in %. |
20 |
| {$DISK.FREE.CRIT} | Threshold of disk free space for Critical trigger in %. |
10 |
| {$VPN.NAME.MATCHES} | Used in VPN tunnel discovery. Can be overridden on the host or linked template level. |
.* |
| {$VPN.NAME.NOT_MATCHES} | Used in VPN tunnel discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$VPN.STATE.CONTROL} | Used in "Tunnel down" trigger. Can be used with interface name as context. |
1 |
| {$HA.MEMBER.SN.MATCHES} | Used in HA member discovery. Can be overridden on the host or linked template level. |
.* |
| {$HA.MEMBER.SN.NOT_MATCHES} | Used in HA member discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$IF.ERRORS.WARN} | Threshold of error packet rate for Warning trigger. Can be used with interface name as context. |
2 |
| {$IF.UTIL.MAX} | Threshold of interface bandwidth utilization for Warning trigger in %. Can be used with interface name as context. |
95 |
| {$IFCONTROL} | Macro for operational state of interface for "Link down" trigger. Can be used with interface name as context. |
1 |
| {$NET.IF.IFADMINSTATUS.MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFADMINSTATUS.NOT_MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
^2$ |
| {$NET.IF.IFDESCR.MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFDESCR.NOT_MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$NET.IF.IFNAME.MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFNAME.NOT_MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
(^[Ll]o[0-9.]*$) |
| {$NET.IF.IFOPERSTATUS.MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFOPERSTATUS.NOT_MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
^6$ |
| {$NET.IF.IFTYPE.MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFTYPE.NOT_MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$NET.IF.IFALIAS.MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFALIAS.NOT_MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.HEALTH.NAME.MATCHES} | Used in SD-WAN health-check discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.HEALTH.NAME.NOT_MATCHES} | Used in SD-WAN health-check discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.HEALTH.IF.CONTROL} | Used in "Health check state is dead" trigger. Can be used with health check name as context. |
1 |
| {$SDWAN.HEALTH.IF.LOSS.WARN} | Threshold of packet loss for Warning trigger in %. Can be used with health check name as context. |
20 |
| {$WC.NAME.MATCHES} | Used in Wireless discovery. Can be overridden on the host or linked template level. |
.* |
| {$WC.NAME.NOT_MATCHES} | Used in Wireless discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$WC.STATE.CONTROL} | Used in "Connection down" trigger. Can be used with interface name as context. |
1 |
| {$WC.UPDATE.CONTROL} | Used in "Receiving firmware update" trigger. Can be used with interface name as context. |
1 |
| {$WC.CPU.UTIL.CRIT} | Threshold of WTP CPU utilization for Warning trigger in %. Can be used with interface name as context. |
90 |
| {$WC.MEMORY.UTIL.MAX} | Threshold of WTP memory utilization for trigger in %. Can be used with interface name as context. |
90 |
| {$VDOM.NAME.MATCHES} | Used in Virtual domain discovery. Can be overridden on the host or linked template level. |
.* |
| {$VDOM.NAME.NOT_MATCHES} | Used in Virtual domain discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Firmware version | MIB: FORTINET-FORTIGATE-MIB Firmware version of the device. |
SNMP agent | system.hw.firmware Preprocessing
|
| Hardware model name | MIB: ENTITY-MIB Model of the device. |
SNMP agent | system.hw.model Preprocessing
|
| Hardware serial number | MIB: ENTITY-MIB Serial number of the device. |
SNMP agent | system.hw.serialnumber Preprocessing
|
| System contact details | MIB: SNMPv2-MIB Name and contact information of the contact person for the node. If not provided, the value is a zero-length string. |
SNMP agent | system.contact[sysContact.0] Preprocessing
|
| System description | MIB: SNMPv2-MIB A textual description of the entity. This value should include the full name and version identification of the system's hardware type, software operating system, and networking software. |
SNMP agent | system.descr[sysDescr.0] Preprocessing
|
| System location | MIB: SNMPv2-MIB Physical location of the node (e.g., |
SNMP agent | system.location[sysLocation.0] Preprocessing
|
| System name | MIB: SNMPv2-MIB An administratively-assigned name for the node (the node's fully-qualified domain name). If not provided, the value is a zero-length string. |
SNMP agent | system.name Preprocessing
|
| System object ID | MIB: SNMPv2-MIB The vendor's authoritative identification of the entity as part of the vendor's SMI enterprises subtree with the prefix 1.3.6.1.4.1 (e.g., a vendor with the identifier 1.3.6.1.4.1.4242 might assign a system object with the OID 1.3.6.1.4.1.4242.1.1). |
SNMP agent | system.objectid[sysObjectID.0] Preprocessing
|
| System uptime | MIB: FORTINET-FORTIGATE-MIB Time since the network management portion of the system was last re-initialized. |
SNMP agent | system.uptime[fgSysUpTime.0] Preprocessing
|
| Number of CPUs | MIB: FORTINET-FORTIGATE-MIB Number of processors. |
SNMP agent | system.cpu.num Preprocessing
|
| CPU utilization | MIB: FORTINET-FORTIGATE-MIB CPU utilization in %. |
SNMP agent | system.cpu.util[fgSysCpuUsage.0] |
| ICMP ping | Host accessibility by ICMP. 0 - ICMP ping failed. 1 - ICMP ping successful. |
Simple check | icmpping |
| ICMP loss | Percentage of lost packets. |
Simple check | icmppingloss |
| ICMP response time | ICMP ping response time (in seconds). |
Simple check | icmppingsec |
| SNMP agent availability | Availability of SNMP checks on the host. The value of this item corresponds to availability icons in the host list. Possible values: 0 - not available 1 - available 2 - unknown |
Zabbix internal | zabbix[host,snmp,available] |
| SNMP walk network interfaces | Used for discovering interfaces from IF-MIB. |
SNMP agent | net.if.walk |
| SNMP walk CPU | Used for discovering CPU from FORTINET-FORTIGATE-MIB. |
SNMP agent | system.cpu.walk |
| SNMP walk VPN tunnels | Used for discovering VPN tunnels from FORTINET-FORTIGATE-MIB. |
SNMP agent | vpn.tunnel.walk |
| SNMP walk HA members | Used for discovering HA members from FORTINET-FORTIGATE-MIB. |
SNMP agent | ha.members.walk |
| SNMP walk SD-WAN health-checks | Used for discovering SD-WAN health-checks from FORTINET-FORTIGATE-MIB. |
SNMP agent | sdwan_health.walk |
| SNMP walk wireless AP | Used for discovering wireless access points from FORTINET-FORTIGATE-MIB. |
SNMP agent | wireless.ap.walk |
| SNMP walk hardware sensors | Used for discovering hardware sensors from FORTINET-FORTIGATE-MIB. |
SNMP agent | hw.sensor.walk |
| SNMP walk virtual domain | Used for discovering virtual domains from FORTINET-FORTIGATE-MIB. |
SNMP agent | vdom.walk |
| Total memory | MIB: FORTINET-FORTIGATE-MIB Total physical memory (RAM) installed. |
SNMP agent | vm.memory.total[fgSysMemCapacity.0] Preprocessing
|
| Memory utilization | Current memory utilization (percentage). |
SNMP agent | vm.memory.util[memoryUsedPercentage.0] |
| Used memory | MIB: FORTINET-FORTIGATE-MIB Physical memory (RAM) used calculated based on memory utilization percentage. |
Calculated | vm.memory.used[fgSysMemUsage.0] |
| Available memory | Total memory available for utilization. |
Calculated | vm.memory.available[fgSysMemFree.0] |
| IPv4 Active sessions | MIB: FORTINET-FORTIGATE-MIB Number of active sessions on the device. |
SNMP agent | net.ipv4.sessions[fgSysSesCount.0] |
| SNMP traps (fallback) | Used for collecting all SNMP traps unmatched by other |
SNMP trap | snmptrap.fallback |
| Total disk space | Total hard disk capacity. |
SNMP agent | vfs.fs.total[fgSysDiskCapacity.0] Preprocessing
|
| Used disk space | Current hard disk usage. |
SNMP agent | vfs.fs.used[fgSysDiskUsage.0] Preprocessing
|
| Free disk space | Free hard disk capacity. |
Calculated | vfs.fs.free |
| Free disk percentage | Free disk space, expressed in %. |
Calculated | vfs.fs.pfree |
| Active IPsec VPN tunnels | MIB: FORTINET-FORTIGATE-MIB Number of IPsec VPN tunnels with at least one SA. |
SNMP agent | vpn.tunnel.active[fgVpnTunnelUpCount.0] Preprocessing
|
| Active SSL VPN users | MIB: FORTINET-FORTIGATE-MIB Current number of users logged in through SSL-VPN tunnels in the virtual domain. |
SNMP agent | vpn.users.count[fgVpnSslStatsLoginUsers.0] Preprocessing
|
| SSL VPN state | MIB: FORTINET-FORTIGATE-MIB Used to determine whether SSL-VPN is enabled on this virtual domain. |
SNMP agent | vpn.ssl.state[fgVpnSslState.0] Preprocessing
|
| Blocked intrusions | MIB: FORTINET-FORTIGATE-MIB Number of intrusions blocked per second. |
SNMP agent | ips.blocked[fgIpsIntrusionsBlocked.0] Preprocessing
|
| Total detected intrusions | MIB: FORTINET-FORTIGATE-MIB Total number of intrusions detected per second. |
SNMP agent | ips.detected.total[fgIpsIntrusionsDetected.0] Preprocessing
|
| Detected critical intrusions | MIB: FORTINET-FORTIGATE-MIB Number of critical severity intrusions detected per second. |
SNMP agent | ips.detected.crit[fgIpsCritSevDetections.0] Preprocessing
|
| Detected high intrusions | MIB: FORTINET-FORTIGATE-MIB Number of high severity intrusions detected per second. |
SNMP agent | ips.detected.high[fgIpsHighSevDetections.0] Preprocessing
|
| Detected medium intrusions | MIB: FORTINET-FORTIGATE-MIB Number of medium severity intrusions detected per second. |
SNMP agent | ips.detected.med[fgIpsMedSevDetections.0] Preprocessing
|
| Detected low intrusions | MIB: FORTINET-FORTIGATE-MIB Number of low severity intrusions detected per second. |
SNMP agent | ips.detected.low[fgIpsLowSevDetections.0] Preprocessing
|
| Detected info intrusions | MIB: FORTINET-FORTIGATE-MIB Number of info severity intrusions detected per second. |
SNMP agent | ips.detected.info[fgIpsInfoSevDetections.0] Preprocessing
|
| Detected anomaly based intrusions | MIB: FORTINET-FORTIGATE-MIB Number of intrusions detected as anomalies per second. |
SNMP agent | ips.detected.anomaly[fgIpsAnomalyDetections.0] Preprocessing
|
| Detected signature based intrusions | MIB: FORTINET-FORTIGATE-MIB Number of intrusions detected by signature per second. |
SNMP agent | ips.detected.sign[fgIpsSignatureDetections.0] Preprocessing
|
| IPS database version | MIB: FORTINET-FORTIGATE-MIB IPS signature database version installed on the device. |
SNMP agent | ips.database.version[fgSysVersionIps.0] Preprocessing
|
| HA mode | MIB: FORTINET-FORTIGATE-MIB High-availability mode (Standalone, A-A or A-P). |
SNMP agent | ha.mode[fgHaSystemMode.0] Preprocessing
|
| HA cluster group ID | MIB: FORTINET-FORTIGATE-MIB HA cluster group ID device is configured for. |
SNMP agent | ha.cluster.group_id[fgHaGroupId.0] Preprocessing
|
| HA cluster group name | MIB: FORTINET-FORTIGATE-MIB HA cluster group name. |
SNMP agent | ha.cluster.group_name[fgHaGroupName.0] Preprocessing
|
| HA cluster priority | MIB: FORTINET-FORTIGATE-MIB HA clustering priority of the device (default = 128). |
SNMP agent | ha.cluster.priority[fgHaPriority.0] Preprocessing
|
| HA cluster primary override | MIB: FORTINET-FORTIGATE-MIB Status of the primary override flag. |
SNMP agent | ha.cluster.override[fgHaOverride.0] Preprocessing
|
| HA config sync | MIB: FORTINET-FORTIGATE-MIB Configuration of an automatic configuration synchronization (enabled or disabled). |
SNMP agent | ha.auto.sync[fgHaAutoSync.0] Preprocessing
|
| HA load-balancing schedule | MIB: FORTINET-FORTIGATE-MIB Load-balancing schedule of cluster (in A-A mode). |
SNMP agent | ha.schedule[fgHaSchedule.0] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| FortiGate: Device has been replaced | Device serial number has changed. Acknowledge to close the problem manually. |
last(/FortiGate by SNMP/system.hw.serialnumber,#1)<>last(/FortiGate by SNMP/system.hw.serialnumber,#2) and length(last(/FortiGate by SNMP/system.hw.serialnumber))>0 |
Info | Manual close: Yes |
| FortiGate: System name has changed | The name of the system has changed. Acknowledge to close the problem manually. |
last(/FortiGate by SNMP/system.name,#1)<>last(/FortiGate by SNMP/system.name,#2) and length(last(/FortiGate by SNMP/system.name))>0 |
Info | Manual close: Yes |
| FortiGate: Device has been restarted | Uptime is less than 10 minutes. |
last(/FortiGate by SNMP/system.uptime[fgSysUpTime.0])<10m |
Info | Manual close: Yes |
| FortiGate: High CPU utilization | The CPU utilization is too high. The system might be slow to respond. |
min(/FortiGate by SNMP/system.cpu.util[fgSysCpuUsage.0],5m)>{$CPU.UTIL.CRIT} |
Warning | |
| FortiGate: Unavailable by ICMP ping | Last three attempts returned timeout. Please check device connectivity. |
max(/FortiGate by SNMP/icmpping,#3)=0 |
High | |
| FortiGate: High ICMP ping loss | ICMP ping loss detected. |
min(/FortiGate by SNMP/icmppingloss,5m)>{$ICMP_LOSS_WARN} and min(/FortiGate by SNMP/icmppingloss,5m)<100 |
Warning | Depends on:
|
| FortiGate: High ICMP ping response time | Average ICMP response time is too high. |
avg(/FortiGate by SNMP/icmppingsec,5m)>{$ICMP_RESPONSE_TIME_WARN} |
Warning | Depends on:
|
| FortiGate: No SNMP data collection | SNMP is not available for polling. Please check device connectivity and SNMP settings. |
max(/FortiGate by SNMP/zabbix[host,snmp,available],{$SNMP.TIMEOUT})=0 |
Warning | Depends on:
|
| FortiGate: High memory utilization | The system is running out of free memory. |
min(/FortiGate by SNMP/vm.memory.util[memoryUsedPercentage.0],5m)>{$MEMORY.UTIL.MAX} |
Average | |
| FortiGate: Free disk space is too low | Available disk space is too low. |
last(/FortiGate by SNMP/vfs.fs.pfree)<{$DISK.FREE.CRIT} |
High | |
| FortiGate: Free disk space is low | Available disk space is not enough. |
last(/FortiGate by SNMP/vfs.fs.pfree)<{$DISK.FREE.WARN} |
Warning | Depends on:
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| CPU discovery | Used for discovering CPUs from FORTINET-FORTIGATE-MIB. |
Dependent item | cpu.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| CPU Core {#CPU.ID}: Average usage over 1min | MIB: FORTINET-FORTIGATE-MIB The processor's CPU usage in %, expressed as an average calculated over the last minute. (Only valid for processor types that support this statistic.) |
Dependent item | system.cpu.usage[fgProcessorUsage.{#SNMPINDEX}] Preprocessing
|
| CPU Core {#CPU.ID}: Average user usage over 1min | MIB: FORTINET-FORTIGATE-MIB The processor's CPU user space usage, expressed as an average calculated over the last minute. (Only valid for processor types that support this statistic.) |
Dependent item | system.cpu.usage[fgProcessorUserUsage.{#SNMPINDEX}] Preprocessing
|
| CPU Core {#CPU.ID}: Average system usage over 1min | MIB: FORTINET-FORTIGATE-MIB The processor's CPU system space usage, expressed as an average calculated over the last minute. (Only valid for processor types that support this statistic.) |
Dependent item | system.cpu.usage[fgProcessorSysUsage.{#SNMPINDEX}] Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| VPN tunnel discovery | Used for discovering VPN tunnels from FORTINET-FORTIGATE-MIB. |
Dependent item | vpn.tunnel.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| VPN {#VPN.NAME}: Tunnel Status | MIB: FORTINET-FORTIGATE-MIB Current status of tunnel (up or down). |
Dependent item | vpn.tunnel.status[fgVpnTunEntStatus.{#SNMPINDEX}] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| FortiGate: VPN {#VPN.NAME}: Tunnel down | This trigger expression works as follows: |
{$VPN.STATE.CONTROL:"{#VPN.NAME}"}=1 and last(/FortiGate by SNMP/vpn.tunnel.status[fgVpnTunEntStatus.{#SNMPINDEX}])=1 and (last(/FortiGate by SNMP/vpn.tunnel.status[fgVpnTunEntStatus.{#SNMPINDEX}],#1)<>last(/FortiGate by SNMP/vpn.tunnel.status[fgVpnTunEntStatus.{#SNMPINDEX}],#2)) |
Average | Manual close: Yes |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Network interface discovery | Used for discovering interfaces from IF-MIB. |
Dependent item | net.if.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Interface {#IFNAME}({#IFALIAS}): Operational status | MIB: IF-MIB The current operational state of the interface. - The - If - If - It should change to - It should remain in the - It should remain in the |
Dependent item | net.if.status[ifOperStatus.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Bits received | MIB: IF-MIB The total number of octets received on the interface, including framing characters. This object is a 64-bit version of Discontinuities in the value of this counter can occur at re-initialization of the management system and at other times as indicated by the value of |
Dependent item | net.if.in[ifHCInOctets.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Bits sent | MIB: IF-MIB The total number of octets transmitted out of the interface, including framing characters. This object is a 64-bit version of Discontinuities in the value of this counter can occur at re-initialization of the management system and at other times as indicated by the value of |
Dependent item | net.if.out[ifHCOutOctets.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Inbound packets with errors | MIB: IF-MIB For packet-oriented interfaces - the number of inbound packets that contained errors preventing them from being deliverable to a higher-layer protocol. For character-oriented or fixed-length interfaces - the number of inbound transmission units that contained errors preventing them from being deliverable to a higher-layer protocol. Discontinuities in the value of this counter can occur at re-initialization of the management system and at other times as indicated by the value of |
Dependent item | net.if.in.errors[ifInErrors.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Outbound packets with errors | MIB: IF-MIB For packet-oriented interfaces - the number of outbound packets that contained errors preventing them from being deliverable to a higher-layer protocol. For character-oriented or fixed-length interfaces - the number of outbound transmission units that contained errors preventing them from being deliverable to a higher-layer protocol. Discontinuities in the value of this counter can occur at re-initialization of the management system and at other times as indicated by the value of |
Dependent item | net.if.out.errors[ifOutErrors.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Outbound packets discarded | MIB: IF-MIB The number of outbound packets which were chosen to be discarded even though no errors had been detected to prevent their being deliverable to a higher-layer protocol. One possible reason for discarding such a packet could be to free up buffer space. Discontinuities in the value of this counter can occur at re-initialization of the management system and at other times as indicated by the value of |
Dependent item | net.if.out.discards[ifOutDiscards.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Inbound packets discarded | MIB: IF-MIB The number of inbound packets which were chosen to be discarded even though no errors had been detected to prevent their being deliverable to a higher-layer protocol. One possible reason for discarding such a packet could be to free up buffer space. Discontinuities in the value of this counter can occur at re-initialization of the management system and at other times as indicated by the value of |
Dependent item | net.if.in.discards[ifInDiscards.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Interface type | MIB: IF-MIB The type of interface. Additional values for |
Dependent item | net.if.type[ifType.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Speed | MIB: IF-MIB An estimate of the interface's current bandwidth in units of 1,000,000 bits per second. If this object reports a value of For interfaces which do not vary in bandwidth or for those where no accurate estimation can be made, this object should contain the nominal bandwidth. For a sub-layer which has no concept of bandwidth, this object should be zero. |
Dependent item | net.if.speed[ifHighSpeed.{#SNMPINDEX}] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| FortiGate: Interface {#IFNAME}({#IFALIAS}): Link down | This trigger expression works as follows: |
{$IFCONTROL:"{#IFNAME}"}=1 and last(/FortiGate by SNMP/net.if.status[ifOperStatus.{#SNMPINDEX}])=2 and (last(/FortiGate by SNMP/net.if.status[ifOperStatus.{#SNMPINDEX}],#1)<>last(/FortiGate by SNMP/net.if.status[ifOperStatus.{#SNMPINDEX}],#2)) |
Average | Manual close: Yes |
| FortiGate: Interface {#IFNAME}({#IFALIAS}): High bandwidth usage | The utilization of the network interface is close to its estimated maximum bandwidth. |
(avg(/FortiGate by SNMP/net.if.in[ifHCInOctets.{#SNMPINDEX}],15m)>({$IF.UTIL.MAX:"{#IFNAME}"}/100)*last(/FortiGate by SNMP/net.if.speed[ifHighSpeed.{#SNMPINDEX}]) or avg(/FortiGate by SNMP/net.if.out[ifHCOutOctets.{#SNMPINDEX}],15m)>({$IF.UTIL.MAX:"{#IFNAME}"}/100)*last(/FortiGate by SNMP/net.if.speed[ifHighSpeed.{#SNMPINDEX}])) and last(/FortiGate by SNMP/net.if.speed[ifHighSpeed.{#SNMPINDEX}])>0 |
Warning | Manual close: Yes Depends on:
|
| FortiGate: Interface {#IFNAME}({#IFALIAS}): High error rate | The trigger recovers when it is below 80% of the |
min(/FortiGate by SNMP/net.if.in.errors[ifInErrors.{#SNMPINDEX}],5m)>{$IF.ERRORS.WARN:"{#IFNAME}"} or min(/FortiGate by SNMP/net.if.out.errors[ifOutErrors.{#SNMPINDEX}],5m)>{$IF.ERRORS.WARN:"{#IFNAME}"} |
Warning | Manual close: Yes Depends on:
|
| FortiGate: Interface {#IFNAME}({#IFALIAS}): Ethernet has changed to lower speed than it was before | This Ethernet connection has transitioned down from its known maximum speed. This might be a sign of autonegotiation issues. Acknowledge to close the problem manually. |
change(/FortiGate by SNMP/net.if.speed[ifHighSpeed.{#SNMPINDEX}])<0 and last(/FortiGate by SNMP/net.if.speed[ifHighSpeed.{#SNMPINDEX}])>0 and ( last(/FortiGate by SNMP/net.if.type[ifType.{#SNMPINDEX}])=6 or last(/FortiGate by SNMP/net.if.type[ifType.{#SNMPINDEX}])=7 or last(/FortiGate by SNMP/net.if.type[ifType.{#SNMPINDEX}])=11 or last(/FortiGate by SNMP/net.if.type[ifType.{#SNMPINDEX}])=62 or last(/FortiGate by SNMP/net.if.type[ifType.{#SNMPINDEX}])=69 or last(/FortiGate by SNMP/net.if.type[ifType.{#SNMPINDEX}])=117 ) and (last(/FortiGate by SNMP/net.if.status[ifOperStatus.{#SNMPINDEX}])<>2) |
Info | Manual close: Yes Depends on:
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| HA member discovery | Used for discovering HA members from FORTINET-FORTIGATE-MIB. |
Dependent item | ha.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| HA {#HA.ID}: Serial number | MIB: FORTINET-FORTIGATE-MIB Serial number of the HA cluster member. |
Dependent item | ha.serialnumber[fgHaStatsSerial.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: CPU usage | MIB: FORTINET-FORTIGATE-MIB CPU usage of the specified cluster member (percentage). |
Dependent item | ha.cpu.usage[fgHaStatsCpuUsage.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Memory usage | MIB: FORTINET-FORTIGATE-MIB Memory usage of the specified cluster member (percentage). |
Dependent item | ha.mem.usage[fgHaStatsMemUsage.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Network bandwidth usage | MIB: FORTINET-FORTIGATE-MIB Network bandwidth usage of the specified cluster member (bps). |
Dependent item | ha.net.usage[fgHaStatsNetUsage.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Session count | MIB: FORTINET-FORTIGATE-MIB Current session count of the specified cluster member. |
Dependent item | ha.session.count[fgHaStatsSesCount.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Packets processed | MIB: FORTINET-FORTIGATE-MIB Number of packets processed by the specified cluster member per second. |
Dependent item | ha.packets.rate[fgHaStatsPktCount.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Bytes processed | MIB: FORTINET-FORTIGATE-MIB Number of bytes processed by the specified cluster member per second. |
Dependent item | ha.bytes.rate[fgHaStatsByteCount.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: IPS events | MIB: FORTINET-FORTIGATE-MIB Number of IDS/IPS events triggered on the specified cluster member per second. |
Dependent item | ha.ips.events[fgHaStatsIdsCount.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Anti-virus events | MIB: FORTINET-FORTIGATE-MIB Number of anti-virus events triggered on the specified cluster member per second. |
Dependent item | ha.av.events[fgHaStatsAvCount.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Hostname | MIB: FORTINET-FORTIGATE-MIB Host name of the specified cluster member. |
Dependent item | ha.hostname[fgHaStatsHostname.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Sync status | MIB: FORTINET-FORTIGATE-MIB Current HA sync status. |
Dependent item | ha.sync.status[fgHaStatsSyncStatus.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Global checksum | MIB: FORTINET-FORTIGATE-MIB Current HA global checksum value. |
Dependent item | ha.checksum.global[fgHaStatsGlobalChecksum.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Primary serial number | MIB: FORTINET-FORTIGATE-MIB Serial number of the primary HA member during the last sync attempt (successful or not). |
Dependent item | ha.primary.serialnumber[fgHaStatsMasterSerial.{#SNMPINDEX}] Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Hardware sensors discovery | Used for discovering hardware sensors from FORTINET-FORTIGATE-MIB. |
Dependent item | hw.sensor.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Sensor {#SENSOR.NAME}: Value | MIB: FORTINET-FORTIGATE-MIB A string representation of the value of the sensor. Because sensors can present data in different formats, string representation is the most general format. Interpretation of the value (units of measure, for example) is dependent on the individual sensor. |
Dependent item | hw.sensor.value[fgHwSensorEntValue.{#SENSOR.ID}] Preprocessing
|
| Sensor {#SENSOR.NAME}: Alarm status | MIB: FORTINET-FORTIGATE-MIB If the sensor has an alarm threshold and has exceeded it, this will indicate its status. Not all sensors have alarms. |
Dependent item | hw.sensor.status[fgHwSensorEntAlarmStatus.{#SENSOR.ID}] Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SoC3 discovery | Used for discovering SoC3 NP6Lite processors from FORTINET-FORTIGATE-MIB. |
Dependent item | soc3.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SoC3 {#CPU.ID}: Packets dropped | MIB: FORTINET-FORTIGATE-MIB The total number of packets dropped by this processor (only valid for processor types that support this statistic). |
Dependent item | soc3.np6lite.pkt.dropped[fgProcessorPktDroppedCount.{#CPU.ID}] Preprocessing
|
| SoC3 {#CPU.ID}: Packets received | MIB: FORTINET-FORTIGATE-MIB The total number of packets received by this processor (only valid for processor types that support this statistic). |
Dependent item | soc3.np6lite.pkt.received[fgProcessorPktRxCount.{#CPU.ID}] Preprocessing
|
| SoC3 {#CPU.ID}: Packets transmitted | MIB: FORTINET-FORTIGATE-MIB The total number of packets transmitted by this processor (only valid for processor types that support this statistic). |
Dependent item | soc3.np6lite.pkt.transmitted[fgProcessorPktRxCount.{#CPU.ID}] Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SD-WAN health-check discovery | Used for discovering SD-WAN health-check from FORTINET-FORTIGATE-MIB. |
Dependent item | sdwan_health.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SD-WAN [{#HNAME}]:[{#IFNAME}]: Health check state | MIB: FORTINET-FORTIGATE-MIB Health check state on a specific member link. |
Dependent item | sdwan_health.state[fgVWLHealthCheckLinkState.{#SNMPINDEX}] Preprocessing
|
| SD-WAN [{#HNAME}]:[{#IFNAME}]: Latency | MIB: FORTINET-FORTIGATE-MIB The average latency of a health check on a specific member link in a float number within the last 30 probes. |
Dependent item | sdwan_health.latency[fgVWLHealthCheckLinkLatency.{#SNMPINDEX}] Preprocessing
|
| SD-WAN [{#HNAME}]:[{#IFNAME}]: Jitter | MIB: FORTINET-FORTIGATE-MIB The average jitter of a health check on a specific member link in a float number within the last 30 probes. |
Dependent item | sdwan_health.jitter[fgVWLHealthCheckLinkJitter.{#SNMPINDEX}] Preprocessing
|
| SD-WAN [{#HNAME}]:[{#IFNAME}]: Packets loss | MIB: FORTINET-FORTIGATE-MIB The packet loss percentage of a health check on a specific member link in a float number within the last 30 probes. |
Dependent item | sdwan_health.loss[fgVWLHealthCheckLinkPacketLoss.{#SNMPINDEX}] Preprocessing
|
| SD-WAN [{#HNAME}]:[{#IFNAME}]: Packets sent per second | MIB: FORTINET-FORTIGATE-MIB Number of packets sent by a health check on a specific member link per second. |
Dependent item | sdwan_health.sent[fgVWLHealthCheckLinkPacketSend.{#SNMPINDEX}] Preprocessing
|
| SD-WAN [{#HNAME}]:[{#IFNAME}]: Packets received per second | MIB: FORTINET-FORTIGATE-MIB Number of packets received by a health check on a specific member link per second. |
Dependent item | sdwan_health.received[fgVWLHealthCheckLinkPacketRecv.{#SNMPINDEX}] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| FortiGate: SD-WAN [{#HNAME}]:[{#IFNAME}]: Health check state is dead | This trigger expression works as follows: |
{$SDWAN.HEALTH.IF.CONTROL:"{#HNAME}"}=1 and last(/FortiGate by SNMP/sdwan_health.state[fgVWLHealthCheckLinkState.{#SNMPINDEX}])=1 and (last(/FortiGate by SNMP/sdwan_health.state[fgVWLHealthCheckLinkState.{#SNMPINDEX}],#1)<>last(/FortiGate by SNMP/sdwan_health.state[fgVWLHealthCheckLinkState.{#SNMPINDEX}],#2)) |
Average | Manual close: Yes |
| FortiGate: SD-WAN [{#HNAME}]:[{#IFNAME}]: High packets loss | High level of packet loss detected. |
min(/FortiGate by SNMP/sdwan_health.loss[fgVWLHealthCheckLinkPacketLoss.{#SNMPINDEX}],5m)>{$SDWAN.HEALTH.IF.LOSS.WARN:"{#HNAME}"} |
Warning |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Wireless discovery | Used for discovering wireless access points from FORTINET-FORTIGATE-MIB. |
Dependent item | wireless.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| WTP {#WC.NAME}: Administrative status | MIB: FORTINET-FORTIGATE-MIB Represents the administrative status of this wireless termination point (WTP). The following enumerated values are supported:
|
Dependent item | wc.admin.status[fgWcWtpConfigWtpAdmin.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Location | MIB: FORTINET-FORTIGATE-MIB Represents the location of this WTP. |
Dependent item | wc.location[fgWcWtpConfigWtpLocation.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Profile name | MIB: FORTINET-FORTIGATE-MIB Represents the profile configured for this WTP. |
Dependent item | wc.profile[fgWcWtpConfigWtpProfile.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Radio enabled | MIB: FORTINET-FORTIGATE-MIB Whether radio is enabled for this WTP. |
Dependent item | wc.radio.enabled[fgWcWtpConfigRadioEnable.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Radio ATPC status | MIB: FORTINET-FORTIGATE-MIB Whether radio automatic TX power control is enabled on this WTP. |
Dependent item | wc.radio.atpc.status[fgWcWtpConfigRadioAutoTxPowerControl.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Radio ATPC low limit | MIB: FORTINET-FORTIGATE-MIB Represents the low limit of radio automatic TX power control configured for this WTP, in dBm. |
Dependent item | wc.radio.atpc.low_limit[fgWcWtpConfigRadioAutoTxPowerLow.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Radio ATPC high limit | MIB: FORTINET-FORTIGATE-MIB Represents the high limit of radio automatic TX power control configured for this WTP, in dBm. |
Dependent item | wc.radio.atpc.high_limit[fgWcWtpConfigRadioAutoTxPowerHigh.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Radio TX power level | MIB: FORTINET-FORTIGATE-MIB Represents the radio TX power setting configured for this WTP, expressed in %. |
Dependent item | wc.radio.power_level[fgWcWtpConfigRadioTxPowerLevel.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Radio band | MIB: FORTINET-FORTIGATE-MIB Represents the radio band configured for this WTP. |
Dependent item | wc.radio.band[fgWcWtpConfigRadioBand.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Background scan | MIB: FORTINET-FORTIGATE-MIB Whether background scan is enabled on this WTP. |
Dependent item | wc.background.scan[fgWcWtpConfigRadioApScan.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: All VAPs selected | MIB: FORTINET-FORTIGATE-MIB Whether all wireless virtual access points (VAP) are selected for this WTP. |
Dependent item | wc.vaps.all[fgWcWtpConfigVapAll.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: VAPs list | MIB: FORTINET-FORTIGATE-MIB Represents a list of wireless virtual access points (VAP) configured for this WTP. |
Dependent item | wc.vaps.list[fgWcWtpConfigVaps.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: IP Address type | MIB: FORTINET-FORTIGATE-MIB Represents the IP address type of a WTP. |
Dependent item | wc.ip.type[fgWcWtpSessionWtpIpAddressType.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: IP Address | MIB: FORTINET-FORTIGATE-MIB Represents the IP address of a WTP that corresponds to the IP address in the IP packet header. |
Dependent item | wc.ip.addr[fgWcWtpSessionWtpIpAddress.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Local IP Address type | MIB: FORTINET-FORTIGATE-MIB Represents the local IP address type of a WTP. |
Dependent item | wc.local_ip.type[fgWcWtpSessionWtpLocalIpAddressType.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Local IP Address | MIB: FORTINET-FORTIGATE-MIB Represents the local IP address of a WTP and models the CAPWAP Local IPv4 Address or CAPWAP Local IPv6 Address fields [RFC5415]. If a Network Address Translation (NAT) device is present between the WTP and access controller (AC), the value of |
Dependent item | wc.local_ip.addr[fgWcWtpSessionWtpLocalIpAddress.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Base MAC Address | MIB: FORTINET-FORTIGATE-MIB Represents the WTP's Base MAC Address, which MAY be assigned to the primary Ethernet interface. The instance of the object corresponds to the Base MAC Address sub-element in the CAPWAP protocol [RFC5415]. |
Dependent item | wc.base.mac[fgWcWtpSessionWtpBaseMacAddress.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Connection status | MIB: FORTINET-FORTIGATE-MIB Represents the connection status of a WTP to the AC. The following enumerated values are supported:
|
Dependent item | wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Uptime | MIB: FORTINET-FORTIGATE-MIB Represents the time since the WTP has booted. |
Dependent item | wc.uptime[fgWcWtpSessionWtpUpTime.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Daemon uptime | MIB: FORTINET-FORTIGATE-MIB Represents the time since the WTP daemon has been started. |
Dependent item | wc.daemon.uptime[fgWcWtpSessionWtpDaemonUpTime.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Session uptime | MIB: FORTINET-FORTIGATE-MIB Represents the time since the WTP has been connected to the AC. |
Dependent item | wc.session.uptime[fgWcWtpSessionWtpSessionUpTime.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Model number | MIB: FORTINET-FORTIGATE-MIB Represents the model number of a WTP. |
Dependent item | wc.model[fgWcWtpSessionWtpModelNumber.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Hardware version | MIB: FORTINET-FORTIGATE-MIB Represents the hardware version of a WTP. |
Dependent item | wc.hardware.version[fgWcWtpSessionWtpHwVersion.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Software version | MIB: FORTINET-FORTIGATE-MIB Represents the software version of a WTP. |
Dependent item | wc.software.version[fgWcWtpSessionWtpSwVersion.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Bootloader version | MIB: FORTINET-FORTIGATE-MIB Represents the boot loader version of a WTP. |
Dependent item | wc.boot.version[fgWcWtpSessionWtpBootVersion.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Region code | MIB: FORTINET-FORTIGATE-MIB Represents the region code programmed for this WTP. |
Dependent item | wc.region_code[fgWcWtpSessionWtpRegionCode.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Connected clients | MIB: FORTINET-FORTIGATE-MIB Represents the number of clients currently connected to this WTP. |
Dependent item | wc.clients.num[fgWcWtpSessionWtpStationCount.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Bits received | MIB: FORTINET-FORTIGATE-MIB Represents the number of bits received by this WTP per second. |
Dependent item | wc.rate.in[fgWcWtpSessionWtpByteRxCount.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Bits sent | MIB: FORTINET-FORTIGATE-MIB Represents the number of bits transmitted by this WTP per second. |
Dependent item | wc.rate.out[fgWcWtpSessionWtpByteTxCount.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: CPU usage | MIB: FORTINET-FORTIGATE-MIB Represents the current CPU usage of a WTP (percentage). |
Dependent item | wc.cpu.usage[fgWcWtpSessionWtpCpuUsage.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Memory usage | MIB: FORTINET-FORTIGATE-MIB Represents the current memory usage of a WTP (percentage). |
Dependent item | wc.mem.usage[fgWcWtpSessionWtpMemoryUsage.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Memory capacity | MIB: FORTINET-FORTIGATE-MIB Represents the total physical memory (RAM) installed. |
Dependent item | wc.mem.size[fgWcWtpSessionWtpMemoryCapacity.{#SNMPINDEX}] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| FortiGate: WTP {#WC.NAME}: Connection is down | This trigger expression works as follows: |
{$WC.STATE.CONTROL:"{#WC.NAME}"}=1 and last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}])=1 and (last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}],#1)<>last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}],#2)) |
High | Manual close: Yes |
| FortiGate: WTP {#WC.NAME}: Receiving firmware update | This trigger expression works as follows: |
{$WC.UPDATE.CONTROL:"{#WC.NAME}"}=1 and last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}])=3 and (last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}],#1)<>last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}],#2)) |
Info | Manual close: Yes |
| FortiGate: WTP {#WC.NAME}: Sending firmware update | This trigger expression works as follows: |
{$WC.UPDATE.CONTROL:"{#WC.NAME}"}=1 and last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}])=4 and (last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}],#1)<>last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}],#2)) |
Info | Manual close: Yes |
| FortiGate: WTP {#WC.NAME}: Session has been restarted | Uptime is less than 10 minutes. |
last(/FortiGate by SNMP/wc.session.uptime[fgWcWtpSessionWtpSessionUpTime.{#SNMPINDEX}])<10m |
Info | Manual close: Yes |
| FortiGate: WTP {#WC.NAME}: High CPU utilization | The CPU utilization is too high. |
min(/FortiGate by SNMP/wc.cpu.usage[fgWcWtpSessionWtpCpuUsage.{#SNMPINDEX}],5m)>{$WC.CPU.UTIL.CRIT:"{#WC.NAME}"} |
Warning | |
| FortiGate: WTP {#WC.NAME}: High memory utilization | The WTP is running out of free memory. |
min(/FortiGate by SNMP/wc.mem.usage[fgWcWtpSessionWtpMemoryUsage.{#SNMPINDEX}],5m)>{$WC.MEMORY.UTIL.MAX:"{#WC.NAME}"} |
Warning |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Virtual domain discovery | Used for discovering virtual domains from FORTINET-FORTIGATE-MIB. |
Dependent item | vdom.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| VDOM {#VDOM.NAME}: Operation mode | MIB: FORTINET-FORTIGATE-MIB Operation mode of the virtual domain (NAT or Transparent). |
Dependent item | vdom.op_mode[fgVdEntOpMode.{#SNMPINDEX}] Preprocessing
|
| VDOM {#VDOM.NAME}: HA member state | MIB: FORTINET-FORTIGATE-MIB HA cluster member state of the virtual domain on this device. |
Dependent item | vdom.ha.state[fgVdEntHaState.{#SNMPINDEX}] Preprocessing
|
| VDOM {#VDOM.NAME}: CPU usage | MIB: FORTINET-FORTIGATE-MIB CPU usage of the virtual domain (percentage). |
Dependent item | vdom.cpu.usage[fgVdEntCpuUsage.{#SNMPINDEX}] Preprocessing
|
| VDOM {#VDOM.NAME}: Memory usage | MIB: FORTINET-FORTIGATE-MIB Memory usage of the virtual domain (percentage). |
Dependent item | vdom.mem.usage[fgVdEntCpuUsage.{#SNMPINDEX}] Preprocessing
|
| VDOM {#VDOM.NAME}: Active sessions | MIB: FORTINET-FORTIGATE-MIB Number of active sessions on the virtual domain. |
Dependent item | vdom.sessions[fgVdEntSesCount.{#SNMPINDEX}] Preprocessing
|
| VDOM {#VDOM.NAME}: Sessions rate | MIB: FORTINET-FORTIGATE-MIB The session setup rate on the virtual domain per second. |
Dependent item | vdom.sessions.rate[fgVdEntSesRate.{#SNMPINDEX}] Preprocessing
|
Please report any issues with the template at https://support.zabbix.com
You can also provide feedback, discuss the template, or ask for help at ZABBIX forums
This template is designed for the effortless deployment of FortiGate monitoring by Zabbix via SNMP and doesn't require any external scripts.
Zabbix version: 7.2 and higher.
This template has been tested on:
Zabbix should be configured according to the instructions in the Templates out of the box section.
Refer to the vendor documentation.
| Name | Description | Default |
|---|---|---|
| {$CPU.UTIL.CRIT} | Threshold of CPU utilization for Warning trigger in %. |
90 |
| {$ICMP_LOSS_WARN} | Threshold of ICMP packet loss for Warning trigger in %. |
20 |
| {$ICMP_RESPONSE_TIME_WARN} | Threshold of average ICMP response time for Warning trigger in seconds. |
0.15 |
| {$SNMP.TIMEOUT} | The time interval for SNMP availability trigger. |
5m |
| {$MEMORY.UTIL.MAX} | Threshold of memory utilization for trigger in %. |
90 |
| {$DISK.FREE.WARN} | Threshold of disk free space for Warning trigger in %. |
20 |
| {$DISK.FREE.CRIT} | Threshold of disk free space for Critical trigger in %. |
10 |
| {$VPN.NAME.MATCHES} | Used in VPN tunnel discovery. Can be overridden on the host or linked template level. |
.* |
| {$VPN.NAME.NOT_MATCHES} | Used in VPN tunnel discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$VPN.STATE.CONTROL} | Used in "Tunnel down" trigger. Can be used with interface name as context. |
1 |
| {$HA.MEMBER.SN.MATCHES} | Used in HA member discovery. Can be overridden on the host or linked template level. |
.* |
| {$HA.MEMBER.SN.NOT_MATCHES} | Used in HA member discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$IF.ERRORS.WARN} | Threshold of error packet rate for Warning trigger. Can be used with interface name as context. |
2 |
| {$IF.UTIL.MAX} | Threshold of interface bandwidth utilization for Warning trigger in %. Can be used with interface name as context. |
95 |
| {$IFCONTROL} | Macro for operational state of interface for "Link down" trigger. Can be used with interface name as context. |
1 |
| {$NET.IF.IFADMINSTATUS.MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFADMINSTATUS.NOT_MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
^2$ |
| {$NET.IF.IFDESCR.MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFDESCR.NOT_MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$NET.IF.IFNAME.MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFNAME.NOT_MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
(^[Ll]o[0-9.]*$) |
| {$NET.IF.IFOPERSTATUS.MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFOPERSTATUS.NOT_MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
^6$ |
| {$NET.IF.IFTYPE.MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFTYPE.NOT_MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$NET.IF.IFALIAS.MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFALIAS.NOT_MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.HEALTH.NAME.MATCHES} | Used in SD-WAN health-check discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.HEALTH.NAME.NOT_MATCHES} | Used in SD-WAN health-check discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.HEALTH.IF.CONTROL} | Used in "Health check state is dead" trigger. Can be used with health check name as context. |
1 |
| {$SDWAN.HEALTH.IF.LOSS.WARN} | Threshold of packet loss for Warning trigger in %. Can be used with health check name as context. |
20 |
| {$WC.NAME.MATCHES} | Used in Wireless discovery. Can be overridden on the host or linked template level. |
.* |
| {$WC.NAME.NOT_MATCHES} | Used in Wireless discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$WC.STATE.CONTROL} | Used in "Connection down" trigger. Can be used with interface name as context. |
1 |
| {$WC.UPDATE.CONTROL} | Used in "Receiving firmware update" trigger. Can be used with interface name as context. |
1 |
| {$WC.CPU.UTIL.CRIT} | Threshold of WTP CPU utilization for Warning trigger in %. Can be used with interface name as context. |
90 |
| {$WC.MEMORY.UTIL.MAX} | Threshold of WTP memory utilization for trigger in %. Can be used with interface name as context. |
90 |
| {$VDOM.NAME.MATCHES} | Used in Virtual domain discovery. Can be overridden on the host or linked template level. |
.* |
| {$VDOM.NAME.NOT_MATCHES} | Used in Virtual domain discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Firmware version | MIB: FORTINET-FORTIGATE-MIB Firmware version of the device. |
SNMP agent | system.hw.firmware Preprocessing
|
| Hardware model name | MIB: ENTITY-MIB Model of the device. |
SNMP agent | system.hw.model Preprocessing
|
| Hardware serial number | MIB: ENTITY-MIB Serial number of the device. |
SNMP agent | system.hw.serialnumber Preprocessing
|
| System contact details | MIB: SNMPv2-MIB Name and contact information of the contact person for the node. If not provided, the value is a zero-length string. |
SNMP agent | system.contact[sysContact.0] Preprocessing
|
| System description | MIB: SNMPv2-MIB A textual description of the entity. This value should include the full name and version identification of the system's hardware type, software operating system, and networking software. |
SNMP agent | system.descr[sysDescr.0] Preprocessing
|
| System location | MIB: SNMPv2-MIB Physical location of the node (e.g., |
SNMP agent | system.location[sysLocation.0] Preprocessing
|
| System name | MIB: SNMPv2-MIB An administratively-assigned name for the node (the node's fully-qualified domain name). If not provided, the value is a zero-length string. |
SNMP agent | system.name Preprocessing
|
| System object ID | MIB: SNMPv2-MIB The vendor's authoritative identification of the entity as part of the vendor's SMI enterprises subtree with the prefix 1.3.6.1.4.1 (e.g., a vendor with the identifier 1.3.6.1.4.1.4242 might assign a system object with the OID 1.3.6.1.4.1.4242.1.1). |
SNMP agent | system.objectid[sysObjectID.0] Preprocessing
|
| System uptime | MIB: FORTINET-FORTIGATE-MIB Time since the network management portion of the system was last re-initialized. |
SNMP agent | system.uptime[fgSysUpTime.0] Preprocessing
|
| Number of CPUs | MIB: FORTINET-FORTIGATE-MIB Number of processors. |
SNMP agent | system.cpu.num Preprocessing
|
| CPU utilization | MIB: FORTINET-FORTIGATE-MIB CPU utilization in %. |
SNMP agent | system.cpu.util[fgSysCpuUsage.0] |
| ICMP ping | Host accessibility by ICMP. 0 - ICMP ping failed. 1 - ICMP ping successful. |
Simple check | icmpping |
| ICMP loss | Percentage of lost packets. |
Simple check | icmppingloss |
| ICMP response time | ICMP ping response time (in seconds). |
Simple check | icmppingsec |
| SNMP agent availability | Availability of SNMP checks on the host. The value of this item corresponds to availability icons in the host list. Possible values: 0 - not available 1 - available 2 - unknown |
Zabbix internal | zabbix[host,snmp,available] |
| SNMP walk network interfaces | Used for discovering interfaces from IF-MIB. |
SNMP agent | net.if.walk |
| SNMP walk CPU | Used for discovering CPU from FORTINET-FORTIGATE-MIB. |
SNMP agent | system.cpu.walk |
| SNMP walk VPN tunnels | Used for discovering VPN tunnels from FORTINET-FORTIGATE-MIB. |
SNMP agent | vpn.tunnel.walk |
| SNMP walk HA members | Used for discovering HA members from FORTINET-FORTIGATE-MIB. |
SNMP agent | ha.members.walk |
| SNMP walk SD-WAN health-checks | Used for discovering SD-WAN health-checks from FORTINET-FORTIGATE-MIB. |
SNMP agent | sdwan_health.walk |
| SNMP walk wireless AP | Used for discovering wireless access points from FORTINET-FORTIGATE-MIB. |
SNMP agent | wireless.ap.walk |
| SNMP walk hardware sensors | Used for discovering hardware sensors from FORTINET-FORTIGATE-MIB. |
SNMP agent | hw.sensor.walk |
| SNMP walk virtual domain | Used for discovering virtual domains from FORTINET-FORTIGATE-MIB. |
SNMP agent | vdom.walk |
| Total memory | MIB: FORTINET-FORTIGATE-MIB Total physical memory (RAM) installed. |
SNMP agent | vm.memory.total[fgSysMemCapacity.0] Preprocessing
|
| Memory utilization | Current memory utilization (percentage). |
SNMP agent | vm.memory.util[memoryUsedPercentage.0] |
| Used memory | MIB: FORTINET-FORTIGATE-MIB Physical memory (RAM) used calculated based on memory utilization percentage. |
Calculated | vm.memory.used[fgSysMemUsage.0] |
| Available memory | Total memory available for utilization. |
Calculated | vm.memory.available[fgSysMemFree.0] |
| IPv4 Active sessions | MIB: FORTINET-FORTIGATE-MIB Number of active sessions on the device. |
SNMP agent | net.ipv4.sessions[fgSysSesCount.0] |
| SNMP traps (fallback) | Used for collecting all SNMP traps unmatched by other |
SNMP trap | snmptrap.fallback |
| Total disk space | Total hard disk capacity. |
SNMP agent | vfs.fs.total[fgSysDiskCapacity.0] Preprocessing
|
| Used disk space | Current hard disk usage. |
SNMP agent | vfs.fs.used[fgSysDiskUsage.0] Preprocessing
|
| Free disk space | Free hard disk capacity. |
Calculated | vfs.fs.free |
| Free disk percentage | Free disk space, expressed in %. |
Calculated | vfs.fs.pfree |
| Active IPsec VPN tunnels | MIB: FORTINET-FORTIGATE-MIB Number of IPsec VPN tunnels with at least one SA. |
SNMP agent | vpn.tunnel.active[fgVpnTunnelUpCount.0] Preprocessing
|
| Active SSL VPN users | MIB: FORTINET-FORTIGATE-MIB Current number of users logged in through SSL-VPN tunnels in the virtual domain. |
SNMP agent | vpn.users.count[fgVpnSslStatsLoginUsers.0] Preprocessing
|
| SSL VPN state | MIB: FORTINET-FORTIGATE-MIB Used to determine whether SSL-VPN is enabled on this virtual domain. |
SNMP agent | vpn.ssl.state[fgVpnSslState.0] Preprocessing
|
| Blocked intrusions | MIB: FORTINET-FORTIGATE-MIB Number of intrusions blocked per second. |
SNMP agent | ips.blocked[fgIpsIntrusionsBlocked.0] Preprocessing
|
| Total detected intrusions | MIB: FORTINET-FORTIGATE-MIB Total number of intrusions detected per second. |
SNMP agent | ips.detected.total[fgIpsIntrusionsDetected.0] Preprocessing
|
| Detected critical intrusions | MIB: FORTINET-FORTIGATE-MIB Number of critical severity intrusions detected per second. |
SNMP agent | ips.detected.crit[fgIpsCritSevDetections.0] Preprocessing
|
| Detected high intrusions | MIB: FORTINET-FORTIGATE-MIB Number of high severity intrusions detected per second. |
SNMP agent | ips.detected.high[fgIpsHighSevDetections.0] Preprocessing
|
| Detected medium intrusions | MIB: FORTINET-FORTIGATE-MIB Number of medium severity intrusions detected per second. |
SNMP agent | ips.detected.med[fgIpsMedSevDetections.0] Preprocessing
|
| Detected low intrusions | MIB: FORTINET-FORTIGATE-MIB Number of low severity intrusions detected per second. |
SNMP agent | ips.detected.low[fgIpsLowSevDetections.0] Preprocessing
|
| Detected info intrusions | MIB: FORTINET-FORTIGATE-MIB Number of info severity intrusions detected per second. |
SNMP agent | ips.detected.info[fgIpsInfoSevDetections.0] Preprocessing
|
| Detected anomaly based intrusions | MIB: FORTINET-FORTIGATE-MIB Number of intrusions detected as anomalies per second. |
SNMP agent | ips.detected.anomaly[fgIpsAnomalyDetections.0] Preprocessing
|
| Detected signature based intrusions | MIB: FORTINET-FORTIGATE-MIB Number of intrusions detected by signature per second. |
SNMP agent | ips.detected.sign[fgIpsSignatureDetections.0] Preprocessing
|
| IPS database version | MIB: FORTINET-FORTIGATE-MIB IPS signature database version installed on the device. |
SNMP agent | ips.database.version[fgSysVersionIps.0] Preprocessing
|
| HA mode | MIB: FORTINET-FORTIGATE-MIB High-availability mode (Standalone, A-A or A-P). |
SNMP agent | ha.mode[fgHaSystemMode.0] Preprocessing
|
| HA cluster group ID | MIB: FORTINET-FORTIGATE-MIB HA cluster group ID device is configured for. |
SNMP agent | ha.cluster.group_id[fgHaGroupId.0] Preprocessing
|
| HA cluster group name | MIB: FORTINET-FORTIGATE-MIB HA cluster group name. |
SNMP agent | ha.cluster.group_name[fgHaGroupName.0] Preprocessing
|
| HA cluster priority | MIB: FORTINET-FORTIGATE-MIB HA clustering priority of the device (default = 128). |
SNMP agent | ha.cluster.priority[fgHaPriority.0] Preprocessing
|
| HA cluster primary override | MIB: FORTINET-FORTIGATE-MIB Status of the primary override flag. |
SNMP agent | ha.cluster.override[fgHaOverride.0] Preprocessing
|
| HA config sync | MIB: FORTINET-FORTIGATE-MIB Configuration of an automatic configuration synchronization (enabled or disabled). |
SNMP agent | ha.auto.sync[fgHaAutoSync.0] Preprocessing
|
| HA load-balancing schedule | MIB: FORTINET-FORTIGATE-MIB Load-balancing schedule of cluster (in A-A mode). |
SNMP agent | ha.schedule[fgHaSchedule.0] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| FortiGate: Device has been replaced | Device serial number has changed. Acknowledge to close the problem manually. |
last(/FortiGate by SNMP/system.hw.serialnumber,#1)<>last(/FortiGate by SNMP/system.hw.serialnumber,#2) and length(last(/FortiGate by SNMP/system.hw.serialnumber))>0 |
Info | Manual close: Yes |
| FortiGate: System name has changed | The name of the system has changed. Acknowledge to close the problem manually. |
last(/FortiGate by SNMP/system.name,#1)<>last(/FortiGate by SNMP/system.name,#2) and length(last(/FortiGate by SNMP/system.name))>0 |
Info | Manual close: Yes |
| FortiGate: Device has been restarted | Uptime is less than 10 minutes. |
last(/FortiGate by SNMP/system.uptime[fgSysUpTime.0])<10m |
Info | Manual close: Yes |
| FortiGate: High CPU utilization | The CPU utilization is too high. The system might be slow to respond. |
min(/FortiGate by SNMP/system.cpu.util[fgSysCpuUsage.0],5m)>{$CPU.UTIL.CRIT} |
Warning | |
| FortiGate: Unavailable by ICMP ping | Last three attempts returned timeout. Please check device connectivity. |
max(/FortiGate by SNMP/icmpping,#3)=0 |
High | |
| FortiGate: High ICMP ping loss | ICMP ping loss detected. |
min(/FortiGate by SNMP/icmppingloss,5m)>{$ICMP_LOSS_WARN} and min(/FortiGate by SNMP/icmppingloss,5m)<100 |
Warning | Depends on:
|
| FortiGate: High ICMP ping response time | Average ICMP response time is too high. |
avg(/FortiGate by SNMP/icmppingsec,5m)>{$ICMP_RESPONSE_TIME_WARN} |
Warning | Depends on:
|
| FortiGate: No SNMP data collection | SNMP is not available for polling. Please check device connectivity and SNMP settings. |
max(/FortiGate by SNMP/zabbix[host,snmp,available],{$SNMP.TIMEOUT})=0 |
Warning | Depends on:
|
| FortiGate: High memory utilization | The system is running out of free memory. |
min(/FortiGate by SNMP/vm.memory.util[memoryUsedPercentage.0],5m)>{$MEMORY.UTIL.MAX} |
Average | |
| FortiGate: Free disk space is too low | Available disk space is too low. |
last(/FortiGate by SNMP/vfs.fs.pfree)<{$DISK.FREE.CRIT} |
High | |
| FortiGate: Free disk space is low | Available disk space is not enough. |
last(/FortiGate by SNMP/vfs.fs.pfree)<{$DISK.FREE.WARN} |
Warning | Depends on:
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| CPU discovery | Used for discovering CPUs from FORTINET-FORTIGATE-MIB. |
Dependent item | cpu.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| CPU Core {#CPU.ID}: Average usage over 1min | MIB: FORTINET-FORTIGATE-MIB The processor's CPU usage in %, expressed as an average calculated over the last minute. (Only valid for processor types that support this statistic.) |
Dependent item | system.cpu.usage[fgProcessorUsage.{#SNMPINDEX}] Preprocessing
|
| CPU Core {#CPU.ID}: Average user usage over 1min | MIB: FORTINET-FORTIGATE-MIB The processor's CPU user space usage, expressed as an average calculated over the last minute. (Only valid for processor types that support this statistic.) |
Dependent item | system.cpu.usage[fgProcessorUserUsage.{#SNMPINDEX}] Preprocessing
|
| CPU Core {#CPU.ID}: Average system usage over 1min | MIB: FORTINET-FORTIGATE-MIB The processor's CPU system space usage, expressed as an average calculated over the last minute. (Only valid for processor types that support this statistic.) |
Dependent item | system.cpu.usage[fgProcessorSysUsage.{#SNMPINDEX}] Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| VPN tunnel discovery | Used for discovering VPN tunnels from FORTINET-FORTIGATE-MIB. |
Dependent item | vpn.tunnel.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| VPN {#VPN.NAME}: Tunnel Status | MIB: FORTINET-FORTIGATE-MIB Current status of tunnel (up or down). |
Dependent item | vpn.tunnel.status[fgVpnTunEntStatus.{#SNMPINDEX}] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| FortiGate: VPN {#VPN.NAME}: Tunnel down | This trigger expression works as follows: |
{$VPN.STATE.CONTROL:"{#VPN.NAME}"}=1 and last(/FortiGate by SNMP/vpn.tunnel.status[fgVpnTunEntStatus.{#SNMPINDEX}])=1 and (last(/FortiGate by SNMP/vpn.tunnel.status[fgVpnTunEntStatus.{#SNMPINDEX}],#1)<>last(/FortiGate by SNMP/vpn.tunnel.status[fgVpnTunEntStatus.{#SNMPINDEX}],#2)) |
Average | Manual close: Yes |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Network interface discovery | Used for discovering interfaces from IF-MIB. |
Dependent item | net.if.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Interface {#IFNAME}({#IFALIAS}): Operational status | MIB: IF-MIB The current operational state of the interface. - The - If - If - It should change to - It should remain in the - It should remain in the |
Dependent item | net.if.status[ifOperStatus.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Bits received | MIB: IF-MIB The total number of octets received on the interface, including framing characters. This object is a 64-bit version of Discontinuities in the value of this counter can occur at re-initialization of the management system and at other times as indicated by the value of |
Dependent item | net.if.in[ifHCInOctets.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Bits sent | MIB: IF-MIB The total number of octets transmitted out of the interface, including framing characters. This object is a 64-bit version of Discontinuities in the value of this counter can occur at re-initialization of the management system and at other times as indicated by the value of |
Dependent item | net.if.out[ifHCOutOctets.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Inbound packets with errors | MIB: IF-MIB For packet-oriented interfaces - the number of inbound packets that contained errors preventing them from being deliverable to a higher-layer protocol. For character-oriented or fixed-length interfaces - the number of inbound transmission units that contained errors preventing them from being deliverable to a higher-layer protocol. Discontinuities in the value of this counter can occur at re-initialization of the management system and at other times as indicated by the value of |
Dependent item | net.if.in.errors[ifInErrors.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Outbound packets with errors | MIB: IF-MIB For packet-oriented interfaces - the number of outbound packets that contained errors preventing them from being deliverable to a higher-layer protocol. For character-oriented or fixed-length interfaces - the number of outbound transmission units that contained errors preventing them from being deliverable to a higher-layer protocol. Discontinuities in the value of this counter can occur at re-initialization of the management system and at other times as indicated by the value of |
Dependent item | net.if.out.errors[ifOutErrors.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Outbound packets discarded | MIB: IF-MIB The number of outbound packets which were chosen to be discarded even though no errors had been detected to prevent their being deliverable to a higher-layer protocol. One possible reason for discarding such a packet could be to free up buffer space. Discontinuities in the value of this counter can occur at re-initialization of the management system and at other times as indicated by the value of |
Dependent item | net.if.out.discards[ifOutDiscards.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Inbound packets discarded | MIB: IF-MIB The number of inbound packets which were chosen to be discarded even though no errors had been detected to prevent their being deliverable to a higher-layer protocol. One possible reason for discarding such a packet could be to free up buffer space. Discontinuities in the value of this counter can occur at re-initialization of the management system and at other times as indicated by the value of |
Dependent item | net.if.in.discards[ifInDiscards.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Interface type | MIB: IF-MIB The type of interface. Additional values for |
Dependent item | net.if.type[ifType.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Speed | MIB: IF-MIB An estimate of the interface's current bandwidth in units of 1,000,000 bits per second. If this object reports a value of For interfaces which do not vary in bandwidth or for those where no accurate estimation can be made, this object should contain the nominal bandwidth. For a sub-layer which has no concept of bandwidth, this object should be zero. |
Dependent item | net.if.speed[ifHighSpeed.{#SNMPINDEX}] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| FortiGate: Interface {#IFNAME}({#IFALIAS}): Link down | This trigger expression works as follows: |
{$IFCONTROL:"{#IFNAME}"}=1 and last(/FortiGate by SNMP/net.if.status[ifOperStatus.{#SNMPINDEX}])=2 and (last(/FortiGate by SNMP/net.if.status[ifOperStatus.{#SNMPINDEX}],#1)<>last(/FortiGate by SNMP/net.if.status[ifOperStatus.{#SNMPINDEX}],#2)) |
Average | Manual close: Yes |
| FortiGate: Interface {#IFNAME}({#IFALIAS}): High bandwidth usage | The utilization of the network interface is close to its estimated maximum bandwidth. |
(avg(/FortiGate by SNMP/net.if.in[ifHCInOctets.{#SNMPINDEX}],15m)>({$IF.UTIL.MAX:"{#IFNAME}"}/100)*last(/FortiGate by SNMP/net.if.speed[ifHighSpeed.{#SNMPINDEX}]) or avg(/FortiGate by SNMP/net.if.out[ifHCOutOctets.{#SNMPINDEX}],15m)>({$IF.UTIL.MAX:"{#IFNAME}"}/100)*last(/FortiGate by SNMP/net.if.speed[ifHighSpeed.{#SNMPINDEX}])) and last(/FortiGate by SNMP/net.if.speed[ifHighSpeed.{#SNMPINDEX}])>0 |
Warning | Manual close: Yes Depends on:
|
| FortiGate: Interface {#IFNAME}({#IFALIAS}): High error rate | The trigger recovers when it is below 80% of the |
min(/FortiGate by SNMP/net.if.in.errors[ifInErrors.{#SNMPINDEX}],5m)>{$IF.ERRORS.WARN:"{#IFNAME}"} or min(/FortiGate by SNMP/net.if.out.errors[ifOutErrors.{#SNMPINDEX}],5m)>{$IF.ERRORS.WARN:"{#IFNAME}"} |
Warning | Manual close: Yes Depends on:
|
| FortiGate: Interface {#IFNAME}({#IFALIAS}): Ethernet has changed to lower speed than it was before | This Ethernet connection has transitioned down from its known maximum speed. This might be a sign of autonegotiation issues. Acknowledge to close the problem manually. |
change(/FortiGate by SNMP/net.if.speed[ifHighSpeed.{#SNMPINDEX}])<0 and last(/FortiGate by SNMP/net.if.speed[ifHighSpeed.{#SNMPINDEX}])>0 and ( last(/FortiGate by SNMP/net.if.type[ifType.{#SNMPINDEX}])=6 or last(/FortiGate by SNMP/net.if.type[ifType.{#SNMPINDEX}])=7 or last(/FortiGate by SNMP/net.if.type[ifType.{#SNMPINDEX}])=11 or last(/FortiGate by SNMP/net.if.type[ifType.{#SNMPINDEX}])=62 or last(/FortiGate by SNMP/net.if.type[ifType.{#SNMPINDEX}])=69 or last(/FortiGate by SNMP/net.if.type[ifType.{#SNMPINDEX}])=117 ) and (last(/FortiGate by SNMP/net.if.status[ifOperStatus.{#SNMPINDEX}])<>2) |
Info | Manual close: Yes Depends on:
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| HA member discovery | Used for discovering HA members from FORTINET-FORTIGATE-MIB. |
Dependent item | ha.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| HA {#HA.ID}: Serial number | MIB: FORTINET-FORTIGATE-MIB Serial number of the HA cluster member. |
Dependent item | ha.serialnumber[fgHaStatsSerial.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: CPU usage | MIB: FORTINET-FORTIGATE-MIB CPU usage of the specified cluster member (percentage). |
Dependent item | ha.cpu.usage[fgHaStatsCpuUsage.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Memory usage | MIB: FORTINET-FORTIGATE-MIB Memory usage of the specified cluster member (percentage). |
Dependent item | ha.mem.usage[fgHaStatsMemUsage.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Network bandwidth usage | MIB: FORTINET-FORTIGATE-MIB Network bandwidth usage of the specified cluster member (bps). |
Dependent item | ha.net.usage[fgHaStatsNetUsage.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Session count | MIB: FORTINET-FORTIGATE-MIB Current session count of the specified cluster member. |
Dependent item | ha.session.count[fgHaStatsSesCount.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Packets processed | MIB: FORTINET-FORTIGATE-MIB Number of packets processed by the specified cluster member per second. |
Dependent item | ha.packets.rate[fgHaStatsPktCount.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Bytes processed | MIB: FORTINET-FORTIGATE-MIB Number of bytes processed by the specified cluster member per second. |
Dependent item | ha.bytes.rate[fgHaStatsByteCount.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: IPS events | MIB: FORTINET-FORTIGATE-MIB Number of IDS/IPS events triggered on the specified cluster member per second. |
Dependent item | ha.ips.events[fgHaStatsIdsCount.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Anti-virus events | MIB: FORTINET-FORTIGATE-MIB Number of anti-virus events triggered on the specified cluster member per second. |
Dependent item | ha.av.events[fgHaStatsAvCount.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Hostname | MIB: FORTINET-FORTIGATE-MIB Host name of the specified cluster member. |
Dependent item | ha.hostname[fgHaStatsHostname.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Sync status | MIB: FORTINET-FORTIGATE-MIB Current HA sync status. |
Dependent item | ha.sync.status[fgHaStatsSyncStatus.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Global checksum | MIB: FORTINET-FORTIGATE-MIB Current HA global checksum value. |
Dependent item | ha.checksum.global[fgHaStatsGlobalChecksum.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Primary serial number | MIB: FORTINET-FORTIGATE-MIB Serial number of the primary HA member during the last sync attempt (successful or not). |
Dependent item | ha.primary.serialnumber[fgHaStatsMasterSerial.{#SNMPINDEX}] Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Hardware sensors discovery | Used for discovering hardware sensors from FORTINET-FORTIGATE-MIB. |
Dependent item | hw.sensor.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Sensor {#SENSOR.NAME}: Value | MIB: FORTINET-FORTIGATE-MIB A string representation of the value of the sensor. Because sensors can present data in different formats, string representation is the most general format. Interpretation of the value (units of measure, for example) is dependent on the individual sensor. |
Dependent item | hw.sensor.value[fgHwSensorEntValue.{#SENSOR.ID}] Preprocessing
|
| Sensor {#SENSOR.NAME}: Alarm status | MIB: FORTINET-FORTIGATE-MIB If the sensor has an alarm threshold and has exceeded it, this will indicate its status. Not all sensors have alarms. |
Dependent item | hw.sensor.status[fgHwSensorEntAlarmStatus.{#SENSOR.ID}] Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SoC3 discovery | Used for discovering SoC3 NP6Lite processors from FORTINET-FORTIGATE-MIB. |
Dependent item | soc3.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SoC3 {#CPU.ID}: Packets dropped | MIB: FORTINET-FORTIGATE-MIB The total number of packets dropped by this processor (only valid for processor types that support this statistic). |
Dependent item | soc3.np6lite.pkt.dropped[fgProcessorPktDroppedCount.{#CPU.ID}] Preprocessing
|
| SoC3 {#CPU.ID}: Packets received | MIB: FORTINET-FORTIGATE-MIB The total number of packets received by this processor (only valid for processor types that support this statistic). |
Dependent item | soc3.np6lite.pkt.received[fgProcessorPktRxCount.{#CPU.ID}] Preprocessing
|
| SoC3 {#CPU.ID}: Packets transmitted | MIB: FORTINET-FORTIGATE-MIB The total number of packets transmitted by this processor (only valid for processor types that support this statistic). |
Dependent item | soc3.np6lite.pkt.transmitted[fgProcessorPktRxCount.{#CPU.ID}] Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SD-WAN health-check discovery | Used for discovering SD-WAN health-check from FORTINET-FORTIGATE-MIB. |
Dependent item | sdwan_health.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SD-WAN [{#HNAME}]:[{#IFNAME}]: Health check state | MIB: FORTINET-FORTIGATE-MIB Health check state on a specific member link. |
Dependent item | sdwan_health.state[fgVWLHealthCheckLinkState.{#SNMPINDEX}] Preprocessing
|
| SD-WAN [{#HNAME}]:[{#IFNAME}]: Latency | MIB: FORTINET-FORTIGATE-MIB The average latency of a health check on a specific member link in a float number within the last 30 probes. |
Dependent item | sdwan_health.latency[fgVWLHealthCheckLinkLatency.{#SNMPINDEX}] Preprocessing
|
| SD-WAN [{#HNAME}]:[{#IFNAME}]: Jitter | MIB: FORTINET-FORTIGATE-MIB The average jitter of a health check on a specific member link in a float number within the last 30 probes. |
Dependent item | sdwan_health.jitter[fgVWLHealthCheckLinkJitter.{#SNMPINDEX}] Preprocessing
|
| SD-WAN [{#HNAME}]:[{#IFNAME}]: Packets loss | MIB: FORTINET-FORTIGATE-MIB The packet loss percentage of a health check on a specific member link in a float number within the last 30 probes. |
Dependent item | sdwan_health.loss[fgVWLHealthCheckLinkPacketLoss.{#SNMPINDEX}] Preprocessing
|
| SD-WAN [{#HNAME}]:[{#IFNAME}]: Packets sent per second | MIB: FORTINET-FORTIGATE-MIB Number of packets sent by a health check on a specific member link per second. |
Dependent item | sdwan_health.sent[fgVWLHealthCheckLinkPacketSend.{#SNMPINDEX}] Preprocessing
|
| SD-WAN [{#HNAME}]:[{#IFNAME}]: Packets received per second | MIB: FORTINET-FORTIGATE-MIB Number of packets received by a health check on a specific member link per second. |
Dependent item | sdwan_health.received[fgVWLHealthCheckLinkPacketRecv.{#SNMPINDEX}] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| FortiGate: SD-WAN [{#HNAME}]:[{#IFNAME}]: Health check state is dead | This trigger expression works as follows: |
{$SDWAN.HEALTH.IF.CONTROL:"{#HNAME}"}=1 and last(/FortiGate by SNMP/sdwan_health.state[fgVWLHealthCheckLinkState.{#SNMPINDEX}])=1 and (last(/FortiGate by SNMP/sdwan_health.state[fgVWLHealthCheckLinkState.{#SNMPINDEX}],#1)<>last(/FortiGate by SNMP/sdwan_health.state[fgVWLHealthCheckLinkState.{#SNMPINDEX}],#2)) |
Average | Manual close: Yes |
| FortiGate: SD-WAN [{#HNAME}]:[{#IFNAME}]: High packets loss | High level of packet loss detected. |
min(/FortiGate by SNMP/sdwan_health.loss[fgVWLHealthCheckLinkPacketLoss.{#SNMPINDEX}],5m)>{$SDWAN.HEALTH.IF.LOSS.WARN:"{#HNAME}"} |
Warning |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Wireless discovery | Used for discovering wireless access points from FORTINET-FORTIGATE-MIB. |
Dependent item | wireless.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| WTP {#WC.NAME}: Administrative status | MIB: FORTINET-FORTIGATE-MIB Represents the administrative status of this wireless termination point (WTP). The following enumerated values are supported:
|
Dependent item | wc.admin.status[fgWcWtpConfigWtpAdmin.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Location | MIB: FORTINET-FORTIGATE-MIB Represents the location of this WTP. |
Dependent item | wc.location[fgWcWtpConfigWtpLocation.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Profile name | MIB: FORTINET-FORTIGATE-MIB Represents the profile configured for this WTP. |
Dependent item | wc.profile[fgWcWtpConfigWtpProfile.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Radio enabled | MIB: FORTINET-FORTIGATE-MIB Whether radio is enabled for this WTP. |
Dependent item | wc.radio.enabled[fgWcWtpConfigRadioEnable.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Radio ATPC status | MIB: FORTINET-FORTIGATE-MIB Whether radio automatic TX power control is enabled on this WTP. |
Dependent item | wc.radio.atpc.status[fgWcWtpConfigRadioAutoTxPowerControl.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Radio ATPC low limit | MIB: FORTINET-FORTIGATE-MIB Represents the low limit of radio automatic TX power control configured for this WTP, in dBm. |
Dependent item | wc.radio.atpc.low_limit[fgWcWtpConfigRadioAutoTxPowerLow.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Radio ATPC high limit | MIB: FORTINET-FORTIGATE-MIB Represents the high limit of radio automatic TX power control configured for this WTP, in dBm. |
Dependent item | wc.radio.atpc.high_limit[fgWcWtpConfigRadioAutoTxPowerHigh.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Radio TX power level | MIB: FORTINET-FORTIGATE-MIB Represents the radio TX power setting configured for this WTP, expressed in %. |
Dependent item | wc.radio.power_level[fgWcWtpConfigRadioTxPowerLevel.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Radio band | MIB: FORTINET-FORTIGATE-MIB Represents the radio band configured for this WTP. |
Dependent item | wc.radio.band[fgWcWtpConfigRadioBand.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Background scan | MIB: FORTINET-FORTIGATE-MIB Whether background scan is enabled on this WTP. |
Dependent item | wc.background.scan[fgWcWtpConfigRadioApScan.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: All VAPs selected | MIB: FORTINET-FORTIGATE-MIB Whether all wireless virtual access points (VAP) are selected for this WTP. |
Dependent item | wc.vaps.all[fgWcWtpConfigVapAll.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: VAPs list | MIB: FORTINET-FORTIGATE-MIB Represents a list of wireless virtual access points (VAP) configured for this WTP. |
Dependent item | wc.vaps.list[fgWcWtpConfigVaps.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: IP Address type | MIB: FORTINET-FORTIGATE-MIB Represents the IP address type of a WTP. |
Dependent item | wc.ip.type[fgWcWtpSessionWtpIpAddressType.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: IP Address | MIB: FORTINET-FORTIGATE-MIB Represents the IP address of a WTP that corresponds to the IP address in the IP packet header. |
Dependent item | wc.ip.addr[fgWcWtpSessionWtpIpAddress.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Local IP Address type | MIB: FORTINET-FORTIGATE-MIB Represents the local IP address type of a WTP. |
Dependent item | wc.local_ip.type[fgWcWtpSessionWtpLocalIpAddressType.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Local IP Address | MIB: FORTINET-FORTIGATE-MIB Represents the local IP address of a WTP and models the CAPWAP Local IPv4 Address or CAPWAP Local IPv6 Address fields [RFC5415]. If a Network Address Translation (NAT) device is present between the WTP and access controller (AC), the value of |
Dependent item | wc.local_ip.addr[fgWcWtpSessionWtpLocalIpAddress.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Base MAC Address | MIB: FORTINET-FORTIGATE-MIB Represents the WTP's Base MAC Address, which MAY be assigned to the primary Ethernet interface. The instance of the object corresponds to the Base MAC Address sub-element in the CAPWAP protocol [RFC5415]. |
Dependent item | wc.base.mac[fgWcWtpSessionWtpBaseMacAddress.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Connection status | MIB: FORTINET-FORTIGATE-MIB Represents the connection status of a WTP to the AC. The following enumerated values are supported:
|
Dependent item | wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Uptime | MIB: FORTINET-FORTIGATE-MIB Represents the time since the WTP has booted. |
Dependent item | wc.uptime[fgWcWtpSessionWtpUpTime.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Daemon uptime | MIB: FORTINET-FORTIGATE-MIB Represents the time since the WTP daemon has been started. |
Dependent item | wc.daemon.uptime[fgWcWtpSessionWtpDaemonUpTime.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Session uptime | MIB: FORTINET-FORTIGATE-MIB Represents the time since the WTP has been connected to the AC. |
Dependent item | wc.session.uptime[fgWcWtpSessionWtpSessionUpTime.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Model number | MIB: FORTINET-FORTIGATE-MIB Represents the model number of a WTP. |
Dependent item | wc.model[fgWcWtpSessionWtpModelNumber.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Hardware version | MIB: FORTINET-FORTIGATE-MIB Represents the hardware version of a WTP. |
Dependent item | wc.hardware.version[fgWcWtpSessionWtpHwVersion.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Software version | MIB: FORTINET-FORTIGATE-MIB Represents the software version of a WTP. |
Dependent item | wc.software.version[fgWcWtpSessionWtpSwVersion.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Bootloader version | MIB: FORTINET-FORTIGATE-MIB Represents the boot loader version of a WTP. |
Dependent item | wc.boot.version[fgWcWtpSessionWtpBootVersion.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Region code | MIB: FORTINET-FORTIGATE-MIB Represents the region code programmed for this WTP. |
Dependent item | wc.region_code[fgWcWtpSessionWtpRegionCode.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Connected clients | MIB: FORTINET-FORTIGATE-MIB Represents the number of clients currently connected to this WTP. |
Dependent item | wc.clients.num[fgWcWtpSessionWtpStationCount.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Bits received | MIB: FORTINET-FORTIGATE-MIB Represents the number of bits received by this WTP per second. |
Dependent item | wc.rate.in[fgWcWtpSessionWtpByteRxCount.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Bits sent | MIB: FORTINET-FORTIGATE-MIB Represents the number of bits transmitted by this WTP per second. |
Dependent item | wc.rate.out[fgWcWtpSessionWtpByteTxCount.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: CPU usage | MIB: FORTINET-FORTIGATE-MIB Represents the current CPU usage of a WTP (percentage). |
Dependent item | wc.cpu.usage[fgWcWtpSessionWtpCpuUsage.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Memory usage | MIB: FORTINET-FORTIGATE-MIB Represents the current memory usage of a WTP (percentage). |
Dependent item | wc.mem.usage[fgWcWtpSessionWtpMemoryUsage.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Memory capacity | MIB: FORTINET-FORTIGATE-MIB Represents the total physical memory (RAM) installed. |
Dependent item | wc.mem.size[fgWcWtpSessionWtpMemoryCapacity.{#SNMPINDEX}] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| FortiGate: WTP {#WC.NAME}: Connection is down | This trigger expression works as follows: |
{$WC.STATE.CONTROL:"{#WC.NAME}"}=1 and last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}])=1 and (last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}],#1)<>last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}],#2)) |
High | Manual close: Yes |
| FortiGate: WTP {#WC.NAME}: Receiving firmware update | This trigger expression works as follows: |
{$WC.UPDATE.CONTROL:"{#WC.NAME}"}=1 and last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}])=3 and (last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}],#1)<>last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}],#2)) |
Info | Manual close: Yes |
| FortiGate: WTP {#WC.NAME}: Sending firmware update | This trigger expression works as follows: |
{$WC.UPDATE.CONTROL:"{#WC.NAME}"}=1 and last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}])=4 and (last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}],#1)<>last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}],#2)) |
Info | Manual close: Yes |
| FortiGate: WTP {#WC.NAME}: Session has been restarted | Uptime is less than 10 minutes. |
last(/FortiGate by SNMP/wc.session.uptime[fgWcWtpSessionWtpSessionUpTime.{#SNMPINDEX}])<10m |
Info | Manual close: Yes |
| FortiGate: WTP {#WC.NAME}: High CPU utilization | The CPU utilization is too high. |
min(/FortiGate by SNMP/wc.cpu.usage[fgWcWtpSessionWtpCpuUsage.{#SNMPINDEX}],5m)>{$WC.CPU.UTIL.CRIT:"{#WC.NAME}"} |
Warning | |
| FortiGate: WTP {#WC.NAME}: High memory utilization | The WTP is running out of free memory. |
min(/FortiGate by SNMP/wc.mem.usage[fgWcWtpSessionWtpMemoryUsage.{#SNMPINDEX}],5m)>{$WC.MEMORY.UTIL.MAX:"{#WC.NAME}"} |
Warning |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Virtual domain discovery | Used for discovering virtual domains from FORTINET-FORTIGATE-MIB. |
Dependent item | vdom.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| VDOM {#VDOM.NAME}: Operation mode | MIB: FORTINET-FORTIGATE-MIB Operation mode of the virtual domain (NAT or Transparent). |
Dependent item | vdom.op_mode[fgVdEntOpMode.{#SNMPINDEX}] Preprocessing
|
| VDOM {#VDOM.NAME}: HA member state | MIB: FORTINET-FORTIGATE-MIB HA cluster member state of the virtual domain on this device. |
Dependent item | vdom.ha.state[fgVdEntHaState.{#SNMPINDEX}] Preprocessing
|
| VDOM {#VDOM.NAME}: CPU usage | MIB: FORTINET-FORTIGATE-MIB CPU usage of the virtual domain (percentage). |
Dependent item | vdom.cpu.usage[fgVdEntCpuUsage.{#SNMPINDEX}] Preprocessing
|
| VDOM {#VDOM.NAME}: Memory usage | MIB: FORTINET-FORTIGATE-MIB Memory usage of the virtual domain (percentage). |
Dependent item | vdom.mem.usage[fgVdEntCpuUsage.{#SNMPINDEX}] Preprocessing
|
| VDOM {#VDOM.NAME}: Active sessions | MIB: FORTINET-FORTIGATE-MIB Number of active sessions on the virtual domain. |
Dependent item | vdom.sessions[fgVdEntSesCount.{#SNMPINDEX}] Preprocessing
|
| VDOM {#VDOM.NAME}: Sessions rate | MIB: FORTINET-FORTIGATE-MIB The session setup rate on the virtual domain per second. |
Dependent item | vdom.sessions.rate[fgVdEntSesRate.{#SNMPINDEX}] Preprocessing
|
Please report any issues with the template at https://support.zabbix.com
You can also provide feedback, discuss the template, or ask for help at ZABBIX forums
This template is designed for the effortless deployment of FortiGate monitoring by Zabbix via SNMP and doesn't require any external scripts.
Zabbix version: 7.0 and higher.
This template has been tested on:
Zabbix should be configured according to the instructions in the Templates out of the box section.
Refer to the vendor documentation.
| Name | Description | Default |
|---|---|---|
| {$CPU.UTIL.CRIT} | Threshold of CPU utilization for Warning trigger in %. |
90 |
| {$ICMP_LOSS_WARN} | Threshold of ICMP packet loss for Warning trigger in %. |
20 |
| {$ICMP_RESPONSE_TIME_WARN} | Threshold of average ICMP response time for Warning trigger in seconds. |
0.15 |
| {$SNMP.TIMEOUT} | The time interval for SNMP availability trigger. |
5m |
| {$MEMORY.UTIL.MAX} | Threshold of memory utilization for trigger in %. |
90 |
| {$DISK.FREE.WARN} | Threshold of disk free space for Warning trigger in %. |
20 |
| {$DISK.FREE.CRIT} | Threshold of disk free space for Critical trigger in %. |
10 |
| {$VPN.NAME.MATCHES} | Used in VPN tunnel discovery. Can be overridden on the host or linked template level. |
.* |
| {$VPN.NAME.NOT_MATCHES} | Used in VPN tunnel discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$VPN.STATE.CONTROL} | Used in "Tunnel down" trigger. Can be used with interface name as context. |
1 |
| {$HA.MEMBER.SN.MATCHES} | Used in HA member discovery. Can be overridden on the host or linked template level. |
.* |
| {$HA.MEMBER.SN.NOT_MATCHES} | Used in HA member discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$IF.ERRORS.WARN} | Threshold of error packet rate for Warning trigger. Can be used with interface name as context. |
2 |
| {$IF.UTIL.MAX} | Threshold of interface bandwidth utilization for Warning trigger in %. Can be used with interface name as context. |
95 |
| {$IFCONTROL} | Macro for operational state of interface for "Link down" trigger. Can be used with interface name as context. |
1 |
| {$NET.IF.IFADMINSTATUS.MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFADMINSTATUS.NOT_MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
^2$ |
| {$NET.IF.IFDESCR.MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFDESCR.NOT_MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$NET.IF.IFNAME.MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFNAME.NOT_MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
(^[Ll]o[0-9.]*$) |
| {$NET.IF.IFOPERSTATUS.MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFOPERSTATUS.NOT_MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
^6$ |
| {$NET.IF.IFTYPE.MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFTYPE.NOT_MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$NET.IF.IFALIAS.MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFALIAS.NOT_MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.HEALTH.NAME.MATCHES} | Used in SD-WAN health-check discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.HEALTH.NAME.NOT_MATCHES} | Used in SD-WAN health-check discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.HEALTH.IF.CONTROL} | Used in "Health check state is dead" trigger. Can be used with health check name as context. |
1 |
| {$SDWAN.HEALTH.IF.LOSS.WARN} | Threshold of packet loss for Warning trigger in %. Can be used with health check name as context. |
20 |
| {$WC.NAME.MATCHES} | Used in Wireless discovery. Can be overridden on the host or linked template level. |
.* |
| {$WC.NAME.NOT_MATCHES} | Used in Wireless discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$WC.STATE.CONTROL} | Used in "Connection down" trigger. Can be used with interface name as context. |
1 |
| {$WC.UPDATE.CONTROL} | Used in "Receiving firmware update" trigger. Can be used with interface name as context. |
1 |
| {$WC.CPU.UTIL.CRIT} | Threshold of WTP CPU utilization for Warning trigger in %. Can be used with interface name as context. |
90 |
| {$WC.MEMORY.UTIL.MAX} | Threshold of WTP memory utilization for trigger in %. Can be used with interface name as context. |
90 |
| {$VDOM.NAME.MATCHES} | Used in Virtual domain discovery. Can be overridden on the host or linked template level. |
.* |
| {$VDOM.NAME.NOT_MATCHES} | Used in Virtual domain discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Firmware version | MIB: FORTINET-FORTIGATE-MIB Firmware version of the device. |
SNMP agent | system.hw.firmware Preprocessing
|
| Hardware model name | MIB: ENTITY-MIB Model of the device. |
SNMP agent | system.hw.model Preprocessing
|
| Hardware serial number | MIB: ENTITY-MIB Serial number of the device. |
SNMP agent | system.hw.serialnumber Preprocessing
|
| System contact details | MIB: SNMPv2-MIB Name and contact information of the contact person for the node. If not provided, the value is a zero-length string. |
SNMP agent | system.contact[sysContact.0] Preprocessing
|
| System description | MIB: SNMPv2-MIB A textual description of the entity. This value should include the full name and version identification of the system's hardware type, software operating system, and networking software. |
SNMP agent | system.descr[sysDescr.0] Preprocessing
|
| System location | MIB: SNMPv2-MIB Physical location of the node (e.g., |
SNMP agent | system.location[sysLocation.0] Preprocessing
|
| System name | MIB: SNMPv2-MIB An administratively-assigned name for the node (the node's fully-qualified domain name). If not provided, the value is a zero-length string. |
SNMP agent | system.name Preprocessing
|
| System object ID | MIB: SNMPv2-MIB The vendor's authoritative identification of the entity as part of the vendor's SMI enterprises subtree with the prefix 1.3.6.1.4.1 (e.g., a vendor with the identifier 1.3.6.1.4.1.4242 might assign a system object with the OID 1.3.6.1.4.1.4242.1.1). |
SNMP agent | system.objectid[sysObjectID.0] Preprocessing
|
| System uptime | MIB: FORTINET-FORTIGATE-MIB Time since the network management portion of the system was last re-initialized. |
SNMP agent | system.uptime[fgSysUpTime.0] Preprocessing
|
| Number of CPUs | MIB: FORTINET-FORTIGATE-MIB Number of processors. |
SNMP agent | system.cpu.num Preprocessing
|
| CPU utilization | MIB: FORTINET-FORTIGATE-MIB CPU utilization in %. |
SNMP agent | system.cpu.util[fgSysCpuUsage.0] |
| ICMP ping | Host accessibility by ICMP. 0 - ICMP ping failed. 1 - ICMP ping successful. |
Simple check | icmpping |
| ICMP loss | Percentage of lost packets. |
Simple check | icmppingloss |
| ICMP response time | ICMP ping response time (in seconds). |
Simple check | icmppingsec |
| SNMP agent availability | Availability of SNMP checks on the host. The value of this item corresponds to availability icons in the host list. Possible values: 0 - not available 1 - available 2 - unknown |
Zabbix internal | zabbix[host,snmp,available] |
| SNMP walk network interfaces | Used for discovering interfaces from IF-MIB. |
SNMP agent | net.if.walk |
| SNMP walk CPU | Used for discovering CPU from FORTINET-FORTIGATE-MIB. |
SNMP agent | system.cpu.walk |
| SNMP walk VPN tunnels | Used for discovering VPN tunnels from FORTINET-FORTIGATE-MIB. |
SNMP agent | vpn.tunnel.walk |
| SNMP walk HA members | Used for discovering HA members from FORTINET-FORTIGATE-MIB. |
SNMP agent | ha.members.walk |
| SNMP walk SD-WAN health-checks | Used for discovering SD-WAN health-checks from FORTINET-FORTIGATE-MIB. |
SNMP agent | sdwan_health.walk |
| SNMP walk wireless AP | Used for discovering wireless access points from FORTINET-FORTIGATE-MIB. |
SNMP agent | wireless.ap.walk |
| SNMP walk hardware sensors | Used for discovering hardware sensors from FORTINET-FORTIGATE-MIB. |
SNMP agent | hw.sensor.walk |
| SNMP walk virtual domain | Used for discovering virtual domains from FORTINET-FORTIGATE-MIB. |
SNMP agent | vdom.walk |
| Total memory | MIB: FORTINET-FORTIGATE-MIB Total physical memory (RAM) installed. |
SNMP agent | vm.memory.total[fgSysMemCapacity.0] Preprocessing
|
| Memory utilization | Current memory utilization (percentage). |
SNMP agent | vm.memory.util[memoryUsedPercentage.0] |
| Used memory | MIB: FORTINET-FORTIGATE-MIB Physical memory (RAM) used calculated based on memory utilization percentage. |
Calculated | vm.memory.used[fgSysMemUsage.0] |
| Available memory | Total memory available for utilization. |
Calculated | vm.memory.available[fgSysMemFree.0] |
| IPv4 Active sessions | MIB: FORTINET-FORTIGATE-MIB Number of active sessions on the device. |
SNMP agent | net.ipv4.sessions[fgSysSesCount.0] |
| SNMP traps (fallback) | Used for collecting all SNMP traps unmatched by other |
SNMP trap | snmptrap.fallback |
| Total disk space | Total hard disk capacity. |
SNMP agent | vfs.fs.total[fgSysDiskCapacity.0] Preprocessing
|
| Used disk space | Current hard disk usage. |
SNMP agent | vfs.fs.used[fgSysDiskUsage.0] Preprocessing
|
| Free disk space | Free hard disk capacity. |
Calculated | vfs.fs.free |
| Free disk percentage | Free disk space, expressed in %. |
Calculated | vfs.fs.pfree |
| Active IPsec VPN tunnels | MIB: FORTINET-FORTIGATE-MIB Number of IPsec VPN tunnels with at least one SA. |
SNMP agent | vpn.tunnel.active[fgVpnTunnelUpCount.0] Preprocessing
|
| Active SSL VPN users | MIB: FORTINET-FORTIGATE-MIB Current number of users logged in through SSL-VPN tunnels in the virtual domain. |
SNMP agent | vpn.users.count[fgVpnSslStatsLoginUsers.0] Preprocessing
|
| SSL VPN state | MIB: FORTINET-FORTIGATE-MIB Used to determine whether SSL-VPN is enabled on this virtual domain. |
SNMP agent | vpn.ssl.state[fgVpnSslState.0] Preprocessing
|
| Blocked intrusions | MIB: FORTINET-FORTIGATE-MIB Number of intrusions blocked per second. |
SNMP agent | ips.blocked[fgIpsIntrusionsBlocked.0] Preprocessing
|
| Total detected intrusions | MIB: FORTINET-FORTIGATE-MIB Total number of intrusions detected per second. |
SNMP agent | ips.detected.total[fgIpsIntrusionsDetected.0] Preprocessing
|
| Detected critical intrusions | MIB: FORTINET-FORTIGATE-MIB Number of critical severity intrusions detected per second. |
SNMP agent | ips.detected.crit[fgIpsCritSevDetections.0] Preprocessing
|
| Detected high intrusions | MIB: FORTINET-FORTIGATE-MIB Number of high severity intrusions detected per second. |
SNMP agent | ips.detected.high[fgIpsHighSevDetections.0] Preprocessing
|
| Detected medium intrusions | MIB: FORTINET-FORTIGATE-MIB Number of medium severity intrusions detected per second. |
SNMP agent | ips.detected.med[fgIpsMedSevDetections.0] Preprocessing
|
| Detected low intrusions | MIB: FORTINET-FORTIGATE-MIB Number of low severity intrusions detected per second. |
SNMP agent | ips.detected.low[fgIpsLowSevDetections.0] Preprocessing
|
| Detected info intrusions | MIB: FORTINET-FORTIGATE-MIB Number of info severity intrusions detected per second. |
SNMP agent | ips.detected.info[fgIpsInfoSevDetections.0] Preprocessing
|
| Detected anomaly based intrusions | MIB: FORTINET-FORTIGATE-MIB Number of intrusions detected as anomalies per second. |
SNMP agent | ips.detected.anomaly[fgIpsAnomalyDetections.0] Preprocessing
|
| Detected signature based intrusions | MIB: FORTINET-FORTIGATE-MIB Number of intrusions detected by signature per second. |
SNMP agent | ips.detected.sign[fgIpsSignatureDetections.0] Preprocessing
|
| IPS database version | MIB: FORTINET-FORTIGATE-MIB IPS signature database version installed on the device. |
SNMP agent | ips.database.version[fgSysVersionIps.0] Preprocessing
|
| HA mode | MIB: FORTINET-FORTIGATE-MIB High-availability mode (Standalone, A-A or A-P). |
SNMP agent | ha.mode[fgHaSystemMode.0] Preprocessing
|
| HA cluster group ID | MIB: FORTINET-FORTIGATE-MIB HA cluster group ID device is configured for. |
SNMP agent | ha.cluster.group_id[fgHaGroupId.0] Preprocessing
|
| HA cluster group name | MIB: FORTINET-FORTIGATE-MIB HA cluster group name. |
SNMP agent | ha.cluster.group_name[fgHaGroupName.0] Preprocessing
|
| HA cluster priority | MIB: FORTINET-FORTIGATE-MIB HA clustering priority of the device (default = 128). |
SNMP agent | ha.cluster.priority[fgHaPriority.0] Preprocessing
|
| HA cluster primary override | MIB: FORTINET-FORTIGATE-MIB Status of the primary override flag. |
SNMP agent | ha.cluster.override[fgHaOverride.0] Preprocessing
|
| HA config sync | MIB: FORTINET-FORTIGATE-MIB Configuration of an automatic configuration synchronization (enabled or disabled). |
SNMP agent | ha.auto.sync[fgHaAutoSync.0] Preprocessing
|
| HA load-balancing schedule | MIB: FORTINET-FORTIGATE-MIB Load-balancing schedule of cluster (in A-A mode). |
SNMP agent | ha.schedule[fgHaSchedule.0] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| FortiGate: Device has been replaced | Device serial number has changed. Acknowledge to close the problem manually. |
last(/FortiGate by SNMP/system.hw.serialnumber,#1)<>last(/FortiGate by SNMP/system.hw.serialnumber,#2) and length(last(/FortiGate by SNMP/system.hw.serialnumber))>0 |
Info | Manual close: Yes |
| FortiGate: System name has changed | The name of the system has changed. Acknowledge to close the problem manually. |
last(/FortiGate by SNMP/system.name,#1)<>last(/FortiGate by SNMP/system.name,#2) and length(last(/FortiGate by SNMP/system.name))>0 |
Info | Manual close: Yes |
| FortiGate: Device has been restarted | Uptime is less than 10 minutes. |
last(/FortiGate by SNMP/system.uptime[fgSysUpTime.0])<10m |
Info | Manual close: Yes |
| FortiGate: High CPU utilization | The CPU utilization is too high. The system might be slow to respond. |
min(/FortiGate by SNMP/system.cpu.util[fgSysCpuUsage.0],5m)>{$CPU.UTIL.CRIT} |
Warning | |
| FortiGate: Unavailable by ICMP ping | Last three attempts returned timeout. Please check device connectivity. |
max(/FortiGate by SNMP/icmpping,#3)=0 |
High | |
| FortiGate: High ICMP ping loss | ICMP ping loss detected. |
min(/FortiGate by SNMP/icmppingloss,5m)>{$ICMP_LOSS_WARN} and min(/FortiGate by SNMP/icmppingloss,5m)<100 |
Warning | Depends on:
|
| FortiGate: High ICMP ping response time | Average ICMP response time is too high. |
avg(/FortiGate by SNMP/icmppingsec,5m)>{$ICMP_RESPONSE_TIME_WARN} |
Warning | Depends on:
|
| FortiGate: No SNMP data collection | SNMP is not available for polling. Please check device connectivity and SNMP settings. |
max(/FortiGate by SNMP/zabbix[host,snmp,available],{$SNMP.TIMEOUT})=0 |
Warning | Depends on:
|
| FortiGate: High memory utilization | The system is running out of free memory. |
min(/FortiGate by SNMP/vm.memory.util[memoryUsedPercentage.0],5m)>{$MEMORY.UTIL.MAX} |
Average | |
| FortiGate: Free disk space is too low | Available disk space is too low. |
last(/FortiGate by SNMP/vfs.fs.pfree)<{$DISK.FREE.CRIT} |
High | |
| FortiGate: Free disk space is low | Available disk space is not enough. |
last(/FortiGate by SNMP/vfs.fs.pfree)<{$DISK.FREE.WARN} |
Warning | Depends on:
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| CPU discovery | Used for discovering CPUs from FORTINET-FORTIGATE-MIB. |
Dependent item | cpu.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| CPU Core {#CPU.ID}: Average usage over 1min | MIB: FORTINET-FORTIGATE-MIB The processor's CPU usage in %, expressed as an average calculated over the last minute. (Only valid for processor types that support this statistic.) |
Dependent item | system.cpu.usage[fgProcessorUsage.{#SNMPINDEX}] Preprocessing
|
| CPU Core {#CPU.ID}: Average user usage over 1min | MIB: FORTINET-FORTIGATE-MIB The processor's CPU user space usage, expressed as an average calculated over the last minute. (Only valid for processor types that support this statistic.) |
Dependent item | system.cpu.usage[fgProcessorUserUsage.{#SNMPINDEX}] Preprocessing
|
| CPU Core {#CPU.ID}: Average system usage over 1min | MIB: FORTINET-FORTIGATE-MIB The processor's CPU system space usage, expressed as an average calculated over the last minute. (Only valid for processor types that support this statistic.) |
Dependent item | system.cpu.usage[fgProcessorSysUsage.{#SNMPINDEX}] Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| VPN tunnel discovery | Used for discovering VPN tunnels from FORTINET-FORTIGATE-MIB. |
Dependent item | vpn.tunnel.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| VPN {#VPN.NAME}: Tunnel Status | MIB: FORTINET-FORTIGATE-MIB Current status of tunnel (up or down). |
Dependent item | vpn.tunnel.status[fgVpnTunEntStatus.{#SNMPINDEX}] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| FortiGate: VPN {#VPN.NAME}: Tunnel down | This trigger expression works as follows: |
{$VPN.STATE.CONTROL:"{#VPN.NAME}"}=1 and last(/FortiGate by SNMP/vpn.tunnel.status[fgVpnTunEntStatus.{#SNMPINDEX}])=1 and (last(/FortiGate by SNMP/vpn.tunnel.status[fgVpnTunEntStatus.{#SNMPINDEX}],#1)<>last(/FortiGate by SNMP/vpn.tunnel.status[fgVpnTunEntStatus.{#SNMPINDEX}],#2)) |
Average | Manual close: Yes |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Network interface discovery | Used for discovering interfaces from IF-MIB. |
Dependent item | net.if.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Interface {#IFNAME}({#IFALIAS}): Operational status | MIB: IF-MIB The current operational state of the interface. - The - If - If - It should change to - It should remain in the - It should remain in the |
Dependent item | net.if.status[ifOperStatus.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Bits received | MIB: IF-MIB The total number of octets received on the interface, including framing characters. This object is a 64-bit version of Discontinuities in the value of this counter can occur at re-initialization of the management system and at other times as indicated by the value of |
Dependent item | net.if.in[ifHCInOctets.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Bits sent | MIB: IF-MIB The total number of octets transmitted out of the interface, including framing characters. This object is a 64-bit version of Discontinuities in the value of this counter can occur at re-initialization of the management system and at other times as indicated by the value of |
Dependent item | net.if.out[ifHCOutOctets.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Inbound packets with errors | MIB: IF-MIB For packet-oriented interfaces - the number of inbound packets that contained errors preventing them from being deliverable to a higher-layer protocol. For character-oriented or fixed-length interfaces - the number of inbound transmission units that contained errors preventing them from being deliverable to a higher-layer protocol. Discontinuities in the value of this counter can occur at re-initialization of the management system and at other times as indicated by the value of |
Dependent item | net.if.in.errors[ifInErrors.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Outbound packets with errors | MIB: IF-MIB For packet-oriented interfaces - the number of outbound packets that contained errors preventing them from being deliverable to a higher-layer protocol. For character-oriented or fixed-length interfaces - the number of outbound transmission units that contained errors preventing them from being deliverable to a higher-layer protocol. Discontinuities in the value of this counter can occur at re-initialization of the management system and at other times as indicated by the value of |
Dependent item | net.if.out.errors[ifOutErrors.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Outbound packets discarded | MIB: IF-MIB The number of outbound packets which were chosen to be discarded even though no errors had been detected to prevent their being deliverable to a higher-layer protocol. One possible reason for discarding such a packet could be to free up buffer space. Discontinuities in the value of this counter can occur at re-initialization of the management system and at other times as indicated by the value of |
Dependent item | net.if.out.discards[ifOutDiscards.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Inbound packets discarded | MIB: IF-MIB The number of inbound packets which were chosen to be discarded even though no errors had been detected to prevent their being deliverable to a higher-layer protocol. One possible reason for discarding such a packet could be to free up buffer space. Discontinuities in the value of this counter can occur at re-initialization of the management system and at other times as indicated by the value of |
Dependent item | net.if.in.discards[ifInDiscards.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Interface type | MIB: IF-MIB The type of interface. Additional values for |
Dependent item | net.if.type[ifType.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Speed | MIB: IF-MIB An estimate of the interface's current bandwidth in units of 1,000,000 bits per second. If this object reports a value of For interfaces which do not vary in bandwidth or for those where no accurate estimation can be made, this object should contain the nominal bandwidth. For a sub-layer which has no concept of bandwidth, this object should be zero. |
Dependent item | net.if.speed[ifHighSpeed.{#SNMPINDEX}] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| FortiGate: Interface {#IFNAME}({#IFALIAS}): Link down | This trigger expression works as follows: |
{$IFCONTROL:"{#IFNAME}"}=1 and last(/FortiGate by SNMP/net.if.status[ifOperStatus.{#SNMPINDEX}])=2 and (last(/FortiGate by SNMP/net.if.status[ifOperStatus.{#SNMPINDEX}],#1)<>last(/FortiGate by SNMP/net.if.status[ifOperStatus.{#SNMPINDEX}],#2)) |
Average | Manual close: Yes |
| FortiGate: Interface {#IFNAME}({#IFALIAS}): High bandwidth usage | The utilization of the network interface is close to its estimated maximum bandwidth. |
(avg(/FortiGate by SNMP/net.if.in[ifHCInOctets.{#SNMPINDEX}],15m)>({$IF.UTIL.MAX:"{#IFNAME}"}/100)*last(/FortiGate by SNMP/net.if.speed[ifHighSpeed.{#SNMPINDEX}]) or avg(/FortiGate by SNMP/net.if.out[ifHCOutOctets.{#SNMPINDEX}],15m)>({$IF.UTIL.MAX:"{#IFNAME}"}/100)*last(/FortiGate by SNMP/net.if.speed[ifHighSpeed.{#SNMPINDEX}])) and last(/FortiGate by SNMP/net.if.speed[ifHighSpeed.{#SNMPINDEX}])>0 |
Warning | Manual close: Yes Depends on:
|
| FortiGate: Interface {#IFNAME}({#IFALIAS}): High error rate | The trigger recovers when it is below 80% of the |
min(/FortiGate by SNMP/net.if.in.errors[ifInErrors.{#SNMPINDEX}],5m)>{$IF.ERRORS.WARN:"{#IFNAME}"} or min(/FortiGate by SNMP/net.if.out.errors[ifOutErrors.{#SNMPINDEX}],5m)>{$IF.ERRORS.WARN:"{#IFNAME}"} |
Warning | Manual close: Yes Depends on:
|
| FortiGate: Interface {#IFNAME}({#IFALIAS}): Ethernet has changed to lower speed than it was before | This Ethernet connection has transitioned down from its known maximum speed. This might be a sign of autonegotiation issues. Acknowledge to close the problem manually. |
change(/FortiGate by SNMP/net.if.speed[ifHighSpeed.{#SNMPINDEX}])<0 and last(/FortiGate by SNMP/net.if.speed[ifHighSpeed.{#SNMPINDEX}])>0 and ( last(/FortiGate by SNMP/net.if.type[ifType.{#SNMPINDEX}])=6 or last(/FortiGate by SNMP/net.if.type[ifType.{#SNMPINDEX}])=7 or last(/FortiGate by SNMP/net.if.type[ifType.{#SNMPINDEX}])=11 or last(/FortiGate by SNMP/net.if.type[ifType.{#SNMPINDEX}])=62 or last(/FortiGate by SNMP/net.if.type[ifType.{#SNMPINDEX}])=69 or last(/FortiGate by SNMP/net.if.type[ifType.{#SNMPINDEX}])=117 ) and (last(/FortiGate by SNMP/net.if.status[ifOperStatus.{#SNMPINDEX}])<>2) |
Info | Manual close: Yes Depends on:
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| HA member discovery | Used for discovering HA members from FORTINET-FORTIGATE-MIB. |
Dependent item | ha.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| HA {#HA.ID}: Serial number | MIB: FORTINET-FORTIGATE-MIB Serial number of the HA cluster member. |
Dependent item | ha.serialnumber[fgHaStatsSerial.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: CPU usage | MIB: FORTINET-FORTIGATE-MIB CPU usage of the specified cluster member (percentage). |
Dependent item | ha.cpu.usage[fgHaStatsCpuUsage.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Memory usage | MIB: FORTINET-FORTIGATE-MIB Memory usage of the specified cluster member (percentage). |
Dependent item | ha.mem.usage[fgHaStatsMemUsage.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Network bandwidth usage | MIB: FORTINET-FORTIGATE-MIB Network bandwidth usage of the specified cluster member (bps). |
Dependent item | ha.net.usage[fgHaStatsNetUsage.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Session count | MIB: FORTINET-FORTIGATE-MIB Current session count of the specified cluster member. |
Dependent item | ha.session.count[fgHaStatsSesCount.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Packets processed | MIB: FORTINET-FORTIGATE-MIB Number of packets processed by the specified cluster member per second. |
Dependent item | ha.packets.rate[fgHaStatsPktCount.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Bytes processed | MIB: FORTINET-FORTIGATE-MIB Number of bytes processed by the specified cluster member per second. |
Dependent item | ha.bytes.rate[fgHaStatsByteCount.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: IPS events | MIB: FORTINET-FORTIGATE-MIB Number of IDS/IPS events triggered on the specified cluster member per second. |
Dependent item | ha.ips.events[fgHaStatsIdsCount.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Anti-virus events | MIB: FORTINET-FORTIGATE-MIB Number of anti-virus events triggered on the specified cluster member per second. |
Dependent item | ha.av.events[fgHaStatsAvCount.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Hostname | MIB: FORTINET-FORTIGATE-MIB Host name of the specified cluster member. |
Dependent item | ha.hostname[fgHaStatsHostname.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Sync status | MIB: FORTINET-FORTIGATE-MIB Current HA sync status. |
Dependent item | ha.sync.status[fgHaStatsSyncStatus.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Global checksum | MIB: FORTINET-FORTIGATE-MIB Current HA global checksum value. |
Dependent item | ha.checksum.global[fgHaStatsGlobalChecksum.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Primary serial number | MIB: FORTINET-FORTIGATE-MIB Serial number of the primary HA member during the last sync attempt (successful or not). |
Dependent item | ha.primary.serialnumber[fgHaStatsMasterSerial.{#SNMPINDEX}] Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Hardware sensors discovery | Used for discovering hardware sensors from FORTINET-FORTIGATE-MIB. |
Dependent item | hw.sensor.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Sensor {#SENSOR.NAME}: Value | MIB: FORTINET-FORTIGATE-MIB A string representation of the value of the sensor. Because sensors can present data in different formats, string representation is the most general format. Interpretation of the value (units of measure, for example) is dependent on the individual sensor. |
Dependent item | hw.sensor.value[fgHwSensorEntValue.{#SENSOR.ID}] Preprocessing
|
| Sensor {#SENSOR.NAME}: Alarm status | MIB: FORTINET-FORTIGATE-MIB If the sensor has an alarm threshold and has exceeded it, this will indicate its status. Not all sensors have alarms. |
Dependent item | hw.sensor.status[fgHwSensorEntAlarmStatus.{#SENSOR.ID}] Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SoC3 discovery | Used for discovering SoC3 NP6Lite processors from FORTINET-FORTIGATE-MIB. |
Dependent item | soc3.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SoC3 {#CPU.ID}: Packets dropped | MIB: FORTINET-FORTIGATE-MIB The total number of packets dropped by this processor (only valid for processor types that support this statistic). |
Dependent item | soc3.np6lite.pkt.dropped[fgProcessorPktDroppedCount.{#CPU.ID}] Preprocessing
|
| SoC3 {#CPU.ID}: Packets received | MIB: FORTINET-FORTIGATE-MIB The total number of packets received by this processor (only valid for processor types that support this statistic). |
Dependent item | soc3.np6lite.pkt.received[fgProcessorPktRxCount.{#CPU.ID}] Preprocessing
|
| SoC3 {#CPU.ID}: Packets transmitted | MIB: FORTINET-FORTIGATE-MIB The total number of packets transmitted by this processor (only valid for processor types that support this statistic). |
Dependent item | soc3.np6lite.pkt.transmitted[fgProcessorPktRxCount.{#CPU.ID}] Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SD-WAN health-check discovery | Used for discovering SD-WAN health-check from FORTINET-FORTIGATE-MIB. |
Dependent item | sdwan_health.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SD-WAN [{#HNAME}]:[{#IFNAME}]: Health check state | MIB: FORTINET-FORTIGATE-MIB Health check state on a specific member link. |
Dependent item | sdwan_health.state[fgVWLHealthCheckLinkState.{#SNMPINDEX}] Preprocessing
|
| SD-WAN [{#HNAME}]:[{#IFNAME}]: Latency | MIB: FORTINET-FORTIGATE-MIB The average latency of a health check on a specific member link in a float number within the last 30 probes. |
Dependent item | sdwan_health.latency[fgVWLHealthCheckLinkLatency.{#SNMPINDEX}] Preprocessing
|
| SD-WAN [{#HNAME}]:[{#IFNAME}]: Jitter | MIB: FORTINET-FORTIGATE-MIB The average jitter of a health check on a specific member link in a float number within the last 30 probes. |
Dependent item | sdwan_health.jitter[fgVWLHealthCheckLinkJitter.{#SNMPINDEX}] Preprocessing
|
| SD-WAN [{#HNAME}]:[{#IFNAME}]: Packets loss | MIB: FORTINET-FORTIGATE-MIB The packet loss percentage of a health check on a specific member link in a float number within the last 30 probes. |
Dependent item | sdwan_health.loss[fgVWLHealthCheckLinkPacketLoss.{#SNMPINDEX}] Preprocessing
|
| SD-WAN [{#HNAME}]:[{#IFNAME}]: Packets sent per second | MIB: FORTINET-FORTIGATE-MIB Number of packets sent by a health check on a specific member link per second. |
Dependent item | sdwan_health.sent[fgVWLHealthCheckLinkPacketSend.{#SNMPINDEX}] Preprocessing
|
| SD-WAN [{#HNAME}]:[{#IFNAME}]: Packets received per second | MIB: FORTINET-FORTIGATE-MIB Number of packets received by a health check on a specific member link per second. |
Dependent item | sdwan_health.received[fgVWLHealthCheckLinkPacketRecv.{#SNMPINDEX}] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| FortiGate: SD-WAN [{#HNAME}]:[{#IFNAME}]: Health check state is dead | This trigger expression works as follows: |
{$SDWAN.HEALTH.IF.CONTROL:"{#HNAME}"}=1 and last(/FortiGate by SNMP/sdwan_health.state[fgVWLHealthCheckLinkState.{#SNMPINDEX}])=1 and (last(/FortiGate by SNMP/sdwan_health.state[fgVWLHealthCheckLinkState.{#SNMPINDEX}],#1)<>last(/FortiGate by SNMP/sdwan_health.state[fgVWLHealthCheckLinkState.{#SNMPINDEX}],#2)) |
Average | Manual close: Yes |
| FortiGate: SD-WAN [{#HNAME}]:[{#IFNAME}]: High packets loss | High level of packet loss detected. |
min(/FortiGate by SNMP/sdwan_health.loss[fgVWLHealthCheckLinkPacketLoss.{#SNMPINDEX}],5m)>{$SDWAN.HEALTH.IF.LOSS.WARN:"{#HNAME}"} |
Warning |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Wireless discovery | Used for discovering wireless access points from FORTINET-FORTIGATE-MIB. |
Dependent item | wireless.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| WTP {#WC.NAME}: Administrative status | MIB: FORTINET-FORTIGATE-MIB Represents the administrative status of this wireless termination point (WTP). The following enumerated values are supported:
|
Dependent item | wc.admin.status[fgWcWtpConfigWtpAdmin.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Location | MIB: FORTINET-FORTIGATE-MIB Represents the location of this WTP. |
Dependent item | wc.location[fgWcWtpConfigWtpLocation.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Profile name | MIB: FORTINET-FORTIGATE-MIB Represents the profile configured for this WTP. |
Dependent item | wc.profile[fgWcWtpConfigWtpProfile.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Radio enabled | MIB: FORTINET-FORTIGATE-MIB Whether radio is enabled for this WTP. |
Dependent item | wc.radio.enabled[fgWcWtpConfigRadioEnable.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Radio ATPC status | MIB: FORTINET-FORTIGATE-MIB Whether radio automatic TX power control is enabled on this WTP. |
Dependent item | wc.radio.atpc.status[fgWcWtpConfigRadioAutoTxPowerControl.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Radio ATPC low limit | MIB: FORTINET-FORTIGATE-MIB Represents the low limit of radio automatic TX power control configured for this WTP, in dBm. |
Dependent item | wc.radio.atpc.low_limit[fgWcWtpConfigRadioAutoTxPowerLow.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Radio ATPC high limit | MIB: FORTINET-FORTIGATE-MIB Represents the high limit of radio automatic TX power control configured for this WTP, in dBm. |
Dependent item | wc.radio.atpc.high_limit[fgWcWtpConfigRadioAutoTxPowerHigh.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Radio TX power level | MIB: FORTINET-FORTIGATE-MIB Represents the radio TX power setting configured for this WTP, expressed in %. |
Dependent item | wc.radio.power_level[fgWcWtpConfigRadioTxPowerLevel.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Radio band | MIB: FORTINET-FORTIGATE-MIB Represents the radio band configured for this WTP. |
Dependent item | wc.radio.band[fgWcWtpConfigRadioBand.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Background scan | MIB: FORTINET-FORTIGATE-MIB Whether background scan is enabled on this WTP. |
Dependent item | wc.background.scan[fgWcWtpConfigRadioApScan.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: All VAPs selected | MIB: FORTINET-FORTIGATE-MIB Whether all wireless virtual access points (VAP) are selected for this WTP. |
Dependent item | wc.vaps.all[fgWcWtpConfigVapAll.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: VAPs list | MIB: FORTINET-FORTIGATE-MIB Represents a list of wireless virtual access points (VAP) configured for this WTP. |
Dependent item | wc.vaps.list[fgWcWtpConfigVaps.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: IP Address type | MIB: FORTINET-FORTIGATE-MIB Represents the IP address type of a WTP. |
Dependent item | wc.ip.type[fgWcWtpSessionWtpIpAddressType.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: IP Address | MIB: FORTINET-FORTIGATE-MIB Represents the IP address of a WTP that corresponds to the IP address in the IP packet header. |
Dependent item | wc.ip.addr[fgWcWtpSessionWtpIpAddress.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Local IP Address type | MIB: FORTINET-FORTIGATE-MIB Represents the local IP address type of a WTP. |
Dependent item | wc.local_ip.type[fgWcWtpSessionWtpLocalIpAddressType.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Local IP Address | MIB: FORTINET-FORTIGATE-MIB Represents the local IP address of a WTP and models the CAPWAP Local IPv4 Address or CAPWAP Local IPv6 Address fields [RFC5415]. If a Network Address Translation (NAT) device is present between the WTP and access controller (AC), the value of |
Dependent item | wc.local_ip.addr[fgWcWtpSessionWtpLocalIpAddress.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Base MAC Address | MIB: FORTINET-FORTIGATE-MIB Represents the WTP's Base MAC Address, which MAY be assigned to the primary Ethernet interface. The instance of the object corresponds to the Base MAC Address sub-element in the CAPWAP protocol [RFC5415]. |
Dependent item | wc.base.mac[fgWcWtpSessionWtpBaseMacAddress.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Connection status | MIB: FORTINET-FORTIGATE-MIB Represents the connection status of a WTP to the AC. The following enumerated values are supported:
|
Dependent item | wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Uptime | MIB: FORTINET-FORTIGATE-MIB Represents the time since the WTP has booted. |
Dependent item | wc.uptime[fgWcWtpSessionWtpUpTime.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Daemon uptime | MIB: FORTINET-FORTIGATE-MIB Represents the time since the WTP daemon has been started. |
Dependent item | wc.daemon.uptime[fgWcWtpSessionWtpDaemonUpTime.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Session uptime | MIB: FORTINET-FORTIGATE-MIB Represents the time since the WTP has been connected to the AC. |
Dependent item | wc.session.uptime[fgWcWtpSessionWtpSessionUpTime.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Model number | MIB: FORTINET-FORTIGATE-MIB Represents the model number of a WTP. |
Dependent item | wc.model[fgWcWtpSessionWtpModelNumber.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Hardware version | MIB: FORTINET-FORTIGATE-MIB Represents the hardware version of a WTP. |
Dependent item | wc.hardware.version[fgWcWtpSessionWtpHwVersion.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Software version | MIB: FORTINET-FORTIGATE-MIB Represents the software version of a WTP. |
Dependent item | wc.software.version[fgWcWtpSessionWtpSwVersion.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Bootloader version | MIB: FORTINET-FORTIGATE-MIB Represents the boot loader version of a WTP. |
Dependent item | wc.boot.version[fgWcWtpSessionWtpBootVersion.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Region code | MIB: FORTINET-FORTIGATE-MIB Represents the region code programmed for this WTP. |
Dependent item | wc.region_code[fgWcWtpSessionWtpRegionCode.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Connected clients | MIB: FORTINET-FORTIGATE-MIB Represents the number of clients currently connected to this WTP. |
Dependent item | wc.clients.num[fgWcWtpSessionWtpStationCount.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Bits received | MIB: FORTINET-FORTIGATE-MIB Represents the number of bits received by this WTP per second. |
Dependent item | wc.rate.in[fgWcWtpSessionWtpByteRxCount.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Bits sent | MIB: FORTINET-FORTIGATE-MIB Represents the number of bits transmitted by this WTP per second. |
Dependent item | wc.rate.out[fgWcWtpSessionWtpByteTxCount.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: CPU usage | MIB: FORTINET-FORTIGATE-MIB Represents the current CPU usage of a WTP (percentage). |
Dependent item | wc.cpu.usage[fgWcWtpSessionWtpCpuUsage.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Memory usage | MIB: FORTINET-FORTIGATE-MIB Represents the current memory usage of a WTP (percentage). |
Dependent item | wc.mem.usage[fgWcWtpSessionWtpMemoryUsage.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Memory capacity | MIB: FORTINET-FORTIGATE-MIB Represents the total physical memory (RAM) installed. |
Dependent item | wc.mem.size[fgWcWtpSessionWtpMemoryCapacity.{#SNMPINDEX}] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| FortiGate: WTP {#WC.NAME}: Connection is down | This trigger expression works as follows: |
{$WC.STATE.CONTROL:"{#WC.NAME}"}=1 and last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}])=1 and (last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}],#1)<>last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}],#2)) |
High | Manual close: Yes |
| FortiGate: WTP {#WC.NAME}: Receiving firmware update | This trigger expression works as follows: |
{$WC.UPDATE.CONTROL:"{#WC.NAME}"}=1 and last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}])=3 and (last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}],#1)<>last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}],#2)) |
Info | Manual close: Yes |
| FortiGate: WTP {#WC.NAME}: Sending firmware update | This trigger expression works as follows: |
{$WC.UPDATE.CONTROL:"{#WC.NAME}"}=1 and last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}])=4 and (last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}],#1)<>last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}],#2)) |
Info | Manual close: Yes |
| FortiGate: WTP {#WC.NAME}: Session has been restarted | Uptime is less than 10 minutes. |
last(/FortiGate by SNMP/wc.session.uptime[fgWcWtpSessionWtpSessionUpTime.{#SNMPINDEX}])<10m |
Info | Manual close: Yes |
| FortiGate: WTP {#WC.NAME}: High CPU utilization | The CPU utilization is too high. |
min(/FortiGate by SNMP/wc.cpu.usage[fgWcWtpSessionWtpCpuUsage.{#SNMPINDEX}],5m)>{$WC.CPU.UTIL.CRIT:"{#WC.NAME}"} |
Warning | |
| FortiGate: WTP {#WC.NAME}: High memory utilization | The WTP is running out of free memory. |
min(/FortiGate by SNMP/wc.mem.usage[fgWcWtpSessionWtpMemoryUsage.{#SNMPINDEX}],5m)>{$WC.MEMORY.UTIL.MAX:"{#WC.NAME}"} |
Warning |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Virtual domain discovery | Used for discovering virtual domains from FORTINET-FORTIGATE-MIB. |
Dependent item | vdom.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| VDOM {#VDOM.NAME}: Operation mode | MIB: FORTINET-FORTIGATE-MIB Operation mode of the virtual domain (NAT or Transparent). |
Dependent item | vdom.op_mode[fgVdEntOpMode.{#SNMPINDEX}] Preprocessing
|
| VDOM {#VDOM.NAME}: HA member state | MIB: FORTINET-FORTIGATE-MIB HA cluster member state of the virtual domain on this device. |
Dependent item | vdom.ha.state[fgVdEntHaState.{#SNMPINDEX}] Preprocessing
|
| VDOM {#VDOM.NAME}: CPU usage | MIB: FORTINET-FORTIGATE-MIB CPU usage of the virtual domain (percentage). |
Dependent item | vdom.cpu.usage[fgVdEntCpuUsage.{#SNMPINDEX}] Preprocessing
|
| VDOM {#VDOM.NAME}: Memory usage | MIB: FORTINET-FORTIGATE-MIB Memory usage of the virtual domain (percentage). |
Dependent item | vdom.mem.usage[fgVdEntCpuUsage.{#SNMPINDEX}] Preprocessing
|
| VDOM {#VDOM.NAME}: Active sessions | MIB: FORTINET-FORTIGATE-MIB Number of active sessions on the virtual domain. |
Dependent item | vdom.sessions[fgVdEntSesCount.{#SNMPINDEX}] Preprocessing
|
| VDOM {#VDOM.NAME}: Sessions rate | MIB: FORTINET-FORTIGATE-MIB The session setup rate on the virtual domain per second. |
Dependent item | vdom.sessions.rate[fgVdEntSesRate.{#SNMPINDEX}] Preprocessing
|
Please report any issues with the template at https://support.zabbix.com
You can also provide feedback, discuss the template, or ask for help at ZABBIX forums
This template is designed for the effortless deployment of FortiGate monitoring by Zabbix via SNMP and doesn't require any external scripts.
Zabbix version: 6.4 and higher.
This template has been tested on:
Zabbix should be configured according to the instructions in the Templates out of the box section.
Refer to the vendor documentation.
| Name | Description | Default |
|---|---|---|
| {$CPU.UTIL.CRIT} | Threshold of CPU utilization for Warning trigger in %. |
90 |
| {$ICMP_LOSS_WARN} | Threshold of ICMP packet loss for Warning trigger in %. |
20 |
| {$ICMP_RESPONSE_TIME_WARN} | Threshold of average ICMP response time for Warning trigger in seconds. |
0.15 |
| {$SNMP.TIMEOUT} | The time interval for SNMP availability trigger. |
5m |
| {$MEMORY.UTIL.MAX} | Threshold of memory utilization for trigger in %. |
90 |
| {$DISK.FREE.WARN} | Threshold of disk free space for Warning trigger in %. |
20 |
| {$DISK.FREE.CRIT} | Threshold of disk free space for Critical trigger in %. |
10 |
| {$VPN.NAME.MATCHES} | Used in VPN tunnel discovery. Can be overridden on the host or linked template level. |
.* |
| {$VPN.NAME.NOT_MATCHES} | Used in VPN tunnel discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$VPN.STATE.CONTROL} | Used in "Tunnel down" trigger. Can be used with interface name as context. |
1 |
| {$HA.MEMBER.SN.MATCHES} | Used in HA member discovery. Can be overridden on the host or linked template level. |
.* |
| {$HA.MEMBER.SN.NOT_MATCHES} | Used in HA member discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$IF.ERRORS.WARN} | Threshold of error packet rate for Warning trigger. Can be used with interface name as context. |
2 |
| {$IF.UTIL.MAX} | Threshold of interface bandwidth utilization for Warning trigger in %. Can be used with interface name as context. |
95 |
| {$IFCONTROL} | Macro for operational state of interface for "Link down" trigger. Can be used with interface name as context. |
1 |
| {$NET.IF.IFADMINSTATUS.MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFADMINSTATUS.NOT_MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
^2$ |
| {$NET.IF.IFDESCR.MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFDESCR.NOT_MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$NET.IF.IFNAME.MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFNAME.NOT_MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
(^[Ll]o[0-9.]*$) |
| {$NET.IF.IFOPERSTATUS.MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFOPERSTATUS.NOT_MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
^6$ |
| {$NET.IF.IFTYPE.MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFTYPE.NOT_MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$NET.IF.IFALIAS.MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFALIAS.NOT_MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.HEALTH.NAME.MATCHES} | Used in SD-WAN health-check discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.HEALTH.NAME.NOT_MATCHES} | Used in SD-WAN health-check discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.HEALTH.IF.CONTROL} | Used in "Health check state is dead" trigger. Can be used with health check name as context. |
1 |
| {$SDWAN.HEALTH.IF.LOSS.WARN} | Threshold of packet loss for Warning trigger in %. Can be used with health check name as context. |
20 |
| {$WC.NAME.MATCHES} | Used in Wireless discovery. Can be overridden on the host or linked template level. |
.* |
| {$WC.NAME.NOT_MATCHES} | Used in Wireless discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$WC.STATE.CONTROL} | Used in "Connection down" trigger. Can be used with interface name as context. |
1 |
| {$WC.UPDATE.CONTROL} | Used in "Receiving firmware update" trigger. Can be used with interface name as context. |
1 |
| {$WC.CPU.UTIL.CRIT} | Threshold of WTP CPU utilization for Warning trigger in %. Can be used with interface name as context. |
90 |
| {$WC.MEMORY.UTIL.MAX} | Threshold of WTP memory utilization for trigger in %. Can be used with interface name as context. |
90 |
| {$VDOM.NAME.MATCHES} | Used in Virtual domain discovery. Can be overridden on the host or linked template level. |
.* |
| {$VDOM.NAME.NOT_MATCHES} | Used in Virtual domain discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| FortiGate: Firmware version | MIB: FORTINET-FORTIGATE-MIB Firmware version of the device. |
SNMP agent | system.hw.firmware Preprocessing
|
| FortiGate: Hardware model name | MIB: ENTITY-MIB Model of the device. |
SNMP agent | system.hw.model Preprocessing
|
| FortiGate: Hardware serial number | MIB: ENTITY-MIB Serial number of the device. |
SNMP agent | system.hw.serialnumber Preprocessing
|
| FortiGate: System contact details | MIB: SNMPv2-MIB Name and contact information of the contact person for the node. If not provided, the value is a zero-length string. |
SNMP agent | system.contact[sysContact.0] Preprocessing
|
| FortiGate: System description | MIB: SNMPv2-MIB A textual description of the entity. This value should include the full name and version identification of the system's hardware type, software operating system, and networking software. |
SNMP agent | system.descr[sysDescr.0] Preprocessing
|
| FortiGate: System location | MIB: SNMPv2-MIB Physical location of the node (e.g., |
SNMP agent | system.location[sysLocation.0] Preprocessing
|
| FortiGate: System name | MIB: SNMPv2-MIB An administratively-assigned name for the node (the node's fully-qualified domain name). If not provided, the value is a zero-length string. |
SNMP agent | system.name Preprocessing
|
| FortiGate: System object ID | MIB: SNMPv2-MIB The vendor's authoritative identification of the entity as part of the vendor's SMI enterprises subtree with the prefix 1.3.6.1.4.1 (e.g., a vendor with the identifier 1.3.6.1.4.1.4242 might assign a system object with the OID 1.3.6.1.4.1.4242.1.1). |
SNMP agent | system.objectid[sysObjectID.0] Preprocessing
|
| FortiGate: System uptime | MIB: FORTINET-FORTIGATE-MIB Time since the network management portion of the system was last re-initialized. |
SNMP agent | system.uptime[fgSysUpTime.0] Preprocessing
|
| FortiGate: Number of CPUs | MIB: FORTINET-FORTIGATE-MIB Number of processors. |
SNMP agent | system.cpu.num Preprocessing
|
| FortiGate: CPU utilization | MIB: FORTINET-FORTIGATE-MIB CPU utilization in %. |
SNMP agent | system.cpu.util[fgSysCpuUsage.0] |
| FortiGate: ICMP ping | Host accessibility by ICMP. 0 - ICMP ping failed. 1 - ICMP ping successful. |
Simple check | icmpping |
| FortiGate: ICMP loss | Percentage of lost packets. |
Simple check | icmppingloss |
| FortiGate: ICMP response time | ICMP ping response time (in seconds). |
Simple check | icmppingsec |
| FortiGate: SNMP agent availability | Availability of SNMP checks on the host. The value of this item corresponds to availability icons in the host list. Possible values: 0 - not available 1 - available 2 - unknown |
Zabbix internal | zabbix[host,snmp,available] |
| FortiGate: SNMP walk network interfaces | Used for discovering interfaces from IF-MIB. |
SNMP agent | net.if.walk |
| FortiGate: SNMP walk CPU | Used for discovering CPU from FORTINET-FORTIGATE-MIB. |
SNMP agent | system.cpu.walk |
| FortiGate: SNMP walk VPN tunnels | Used for discovering VPN tunnels from FORTINET-FORTIGATE-MIB. |
SNMP agent | vpn.tunnel.walk |
| FortiGate: SNMP walk HA members | Used for discovering HA members from FORTINET-FORTIGATE-MIB. |
SNMP agent | ha.members.walk |
| FortiGate: SNMP walk SD-WAN health-checks | Used for discovering SD-WAN health-checks from FORTINET-FORTIGATE-MIB. |
SNMP agent | sdwan_health.walk |
| FortiGate: SNMP walk wireless AP | Used for discovering wireless access points from FORTINET-FORTIGATE-MIB. |
SNMP agent | wireless.ap.walk |
| FortiGate: SNMP walk hardware sensors | Used for discovering hardware sensors from FORTINET-FORTIGATE-MIB. |
SNMP agent | hw.sensor.walk |
| FortiGate: SNMP walk virtual domain | Used for discovering virtual domains from FORTINET-FORTIGATE-MIB. |
SNMP agent | vdom.walk |
| FortiGate: Total memory | MIB: FORTINET-FORTIGATE-MIB Total physical memory (RAM) installed. |
SNMP agent | vm.memory.total[fgSysMemCapacity.0] Preprocessing
|
| FortiGate: Memory utilization | Current memory utilization (percentage). |
SNMP agent | vm.memory.util[memoryUsedPercentage.0] |
| FortiGate: Used memory | MIB: FORTINET-FORTIGATE-MIB Physical memory (RAM) used calculated based on memory utilization percentage. |
Calculated | vm.memory.used[fgSysMemUsage.0] |
| FortiGate: Available memory | Total memory available for utilization. |
Calculated | vm.memory.available[fgSysMemFree.0] |
| FortiGate: IPv4 Active sessions | MIB: FORTINET-FORTIGATE-MIB Number of active sessions on the device. |
SNMP agent | net.ipv4.sessions[fgSysSesCount.0] |
| FortiGate: SNMP traps (fallback) | Used for collecting all SNMP traps unmatched by other |
SNMP trap | snmptrap.fallback |
| FortiGate: Total disk space | Total hard disk capacity. |
SNMP agent | vfs.fs.total[fgSysDiskCapacity.0] Preprocessing
|
| FortiGate: Used disk space | Current hard disk usage. |
SNMP agent | vfs.fs.used[fgSysDiskUsage.0] Preprocessing
|
| FortiGate: Free disk space | Free hard disk capacity. |
Calculated | vfs.fs.free |
| FortiGate: Free disk percentage | Free disk space, expressed in %. |
Calculated | vfs.fs.pfree |
| FortiGate: Active IPsec VPN tunnels | MIB: FORTINET-FORTIGATE-MIB Number of IPsec VPN tunnels with at least one SA. |
SNMP agent | vpn.tunnel.active[fgVpnTunnelUpCount.0] Preprocessing
|
| FortiGate: Active SSL VPN users | MIB: FORTINET-FORTIGATE-MIB Current number of users logged in through SSL-VPN tunnels in the virtual domain. |
SNMP agent | vpn.users.count[fgVpnSslStatsLoginUsers.0] Preprocessing
|
| FortiGate: SSL VPN state | MIB: FORTINET-FORTIGATE-MIB Used to determine whether SSL-VPN is enabled on this virtual domain. |
SNMP agent | vpn.ssl.state[fgVpnSslState.0] Preprocessing
|
| FortiGate: Blocked intrusions | MIB: FORTINET-FORTIGATE-MIB Number of intrusions blocked per second. |
SNMP agent | ips.blocked[fgIpsIntrusionsBlocked.0] Preprocessing
|
| FortiGate: Total detected intrusions | MIB: FORTINET-FORTIGATE-MIB Total number of intrusions detected per second. |
SNMP agent | ips.detected.total[fgIpsIntrusionsDetected.0] Preprocessing
|
| FortiGate: Detected critical intrusions | MIB: FORTINET-FORTIGATE-MIB Number of critical severity intrusions detected per second. |
SNMP agent | ips.detected.crit[fgIpsCritSevDetections.0] Preprocessing
|
| FortiGate: Detected high intrusions | MIB: FORTINET-FORTIGATE-MIB Number of high severity intrusions detected per second. |
SNMP agent | ips.detected.high[fgIpsHighSevDetections.0] Preprocessing
|
| FortiGate: Detected medium intrusions | MIB: FORTINET-FORTIGATE-MIB Number of medium severity intrusions detected per second. |
SNMP agent | ips.detected.med[fgIpsMedSevDetections.0] Preprocessing
|
| FortiGate: Detected low intrusions | MIB: FORTINET-FORTIGATE-MIB Number of low severity intrusions detected per second. |
SNMP agent | ips.detected.low[fgIpsLowSevDetections.0] Preprocessing
|
| FortiGate: Detected info intrusions | MIB: FORTINET-FORTIGATE-MIB Number of info severity intrusions detected per second. |
SNMP agent | ips.detected.info[fgIpsInfoSevDetections.0] Preprocessing
|
| FortiGate: Detected anomaly based intrusions | MIB: FORTINET-FORTIGATE-MIB Number of intrusions detected as anomalies per second. |
SNMP agent | ips.detected.anomaly[fgIpsAnomalyDetections.0] Preprocessing
|
| FortiGate: Detected signature based intrusions | MIB: FORTINET-FORTIGATE-MIB Number of intrusions detected by signature per second. |
SNMP agent | ips.detected.sign[fgIpsSignatureDetections.0] Preprocessing
|
| FortiGate: IPS database version | MIB: FORTINET-FORTIGATE-MIB IPS signature database version installed on the device. |
SNMP agent | ips.database.version[fgSysVersionIps.0] Preprocessing
|
| FortiGate: HA mode | MIB: FORTINET-FORTIGATE-MIB High-availability mode (Standalone, A-A or A-P). |
SNMP agent | ha.mode[fgHaSystemMode.0] Preprocessing
|
| FortiGate: HA cluster group ID | MIB: FORTINET-FORTIGATE-MIB HA cluster group ID device is configured for. |
SNMP agent | ha.cluster.group_id[fgHaGroupId.0] Preprocessing
|
| FortiGate: HA cluster group name | MIB: FORTINET-FORTIGATE-MIB HA cluster group name. |
SNMP agent | ha.cluster.group_name[fgHaGroupName.0] Preprocessing
|
| FortiGate: HA cluster priority | MIB: FORTINET-FORTIGATE-MIB HA clustering priority of the device (default = 128). |
SNMP agent | ha.cluster.priority[fgHaPriority.0] Preprocessing
|
| FortiGate: HA cluster primary override | MIB: FORTINET-FORTIGATE-MIB Status of the primary override flag. |
SNMP agent | ha.cluster.override[fgHaOverride.0] Preprocessing
|
| FortiGate: HA config sync | MIB: FORTINET-FORTIGATE-MIB Configuration of an automatic configuration synchronization (enabled or disabled). |
SNMP agent | ha.auto.sync[fgHaAutoSync.0] Preprocessing
|
| FortiGate: HA load-balancing schedule | MIB: FORTINET-FORTIGATE-MIB Load-balancing schedule of cluster (in A-A mode). |
SNMP agent | ha.schedule[fgHaSchedule.0] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| FortiGate: Device has been replaced | Device serial number has changed. Acknowledge to close the problem manually. |
last(/FortiGate by SNMP/system.hw.serialnumber,#1)<>last(/FortiGate by SNMP/system.hw.serialnumber,#2) and length(last(/FortiGate by SNMP/system.hw.serialnumber))>0 |
Info | Manual close: Yes |
| FortiGate: System name has changed | The name of the system has changed. Acknowledge to close the problem manually. |
last(/FortiGate by SNMP/system.name,#1)<>last(/FortiGate by SNMP/system.name,#2) and length(last(/FortiGate by SNMP/system.name))>0 |
Info | Manual close: Yes |
| FortiGate: Device has been restarted | Uptime is less than 10 minutes. |
last(/FortiGate by SNMP/system.uptime[fgSysUpTime.0])<10m |
Info | Manual close: Yes |
| FortiGate: High CPU utilization | The CPU utilization is too high. The system might be slow to respond. |
min(/FortiGate by SNMP/system.cpu.util[fgSysCpuUsage.0],5m)>{$CPU.UTIL.CRIT} |
Warning | |
| FortiGate: Unavailable by ICMP ping | Last three attempts returned timeout. Please check device connectivity. |
max(/FortiGate by SNMP/icmpping,#3)=0 |
High | |
| FortiGate: High ICMP ping loss | ICMP ping loss detected. |
min(/FortiGate by SNMP/icmppingloss,5m)>{$ICMP_LOSS_WARN} and min(/FortiGate by SNMP/icmppingloss,5m)<100 |
Warning | Depends on:
|
| FortiGate: High ICMP ping response time | Average ICMP response time is too high. |
avg(/FortiGate by SNMP/icmppingsec,5m)>{$ICMP_RESPONSE_TIME_WARN} |
Warning | Depends on:
|
| FortiGate: No SNMP data collection | SNMP is not available for polling. Please check device connectivity and SNMP settings. |
max(/FortiGate by SNMP/zabbix[host,snmp,available],{$SNMP.TIMEOUT})=0 |
Warning | Depends on:
|
| FortiGate: High memory utilization | The system is running out of free memory. |
min(/FortiGate by SNMP/vm.memory.util[memoryUsedPercentage.0],5m)>{$MEMORY.UTIL.MAX} |
Average | |
| FortiGate: Free disk space is too low | Available disk space is too low. |
last(/FortiGate by SNMP/vfs.fs.pfree)<{$DISK.FREE.CRIT} |
High | |
| FortiGate: Free disk space is low | Available disk space is not enough. |
last(/FortiGate by SNMP/vfs.fs.pfree)<{$DISK.FREE.WARN} |
Warning | Depends on:
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| CPU discovery | Used for discovering CPUs from FORTINET-FORTIGATE-MIB. |
Dependent item | cpu.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| CPU Core {#CPU.ID}: Average usage over 1min | MIB: FORTINET-FORTIGATE-MIB The processor's CPU usage in %, expressed as an average calculated over the last minute. (Only valid for processor types that support this statistic.) |
Dependent item | system.cpu.usage[fgProcessorUsage.{#SNMPINDEX}] Preprocessing
|
| CPU Core {#CPU.ID}: Average user usage over 1min | MIB: FORTINET-FORTIGATE-MIB The processor's CPU user space usage, expressed as an average calculated over the last minute. (Only valid for processor types that support this statistic.) |
Dependent item | system.cpu.usage[fgProcessorUserUsage.{#SNMPINDEX}] Preprocessing
|
| CPU Core {#CPU.ID}: Average system usage over 1min | MIB: FORTINET-FORTIGATE-MIB The processor's CPU system space usage, expressed as an average calculated over the last minute. (Only valid for processor types that support this statistic.) |
Dependent item | system.cpu.usage[fgProcessorSysUsage.{#SNMPINDEX}] Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| VPN tunnel discovery | Used for discovering VPN tunnels from FORTINET-FORTIGATE-MIB. |
Dependent item | vpn.tunnel.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| VPN {#VPN.NAME}: Tunnel Status | MIB: FORTINET-FORTIGATE-MIB Current status of tunnel (up or down). |
Dependent item | vpn.tunnel.status[fgVpnTunEntStatus.{#SNMPINDEX}] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| VPN {#VPN.NAME}: Tunnel down | This trigger expression works as follows: |
{$VPN.STATE.CONTROL:"{#VPN.NAME}"}=1 and last(/FortiGate by SNMP/vpn.tunnel.status[fgVpnTunEntStatus.{#SNMPINDEX}])=1 and (last(/FortiGate by SNMP/vpn.tunnel.status[fgVpnTunEntStatus.{#SNMPINDEX}],#1)<>last(/FortiGate by SNMP/vpn.tunnel.status[fgVpnTunEntStatus.{#SNMPINDEX}],#2)) |
Average | Manual close: Yes |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Network interface discovery | Used for discovering interfaces from IF-MIB. |
Dependent item | net.if.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Interface {#IFNAME}({#IFALIAS}): Operational status | MIB: IF-MIB The current operational state of the interface. - The - If - If - It should change to - It should remain in the - It should remain in the |
Dependent item | net.if.status[ifOperStatus.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Bits received | MIB: IF-MIB The total number of octets received on the interface, including framing characters. This object is a 64-bit version of Discontinuities in the value of this counter can occur at re-initialization of the management system and at other times as indicated by the value of |
Dependent item | net.if.in[ifHCInOctets.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Bits sent | MIB: IF-MIB The total number of octets transmitted out of the interface, including framing characters. This object is a 64-bit version of Discontinuities in the value of this counter can occur at re-initialization of the management system and at other times as indicated by the value of |
Dependent item | net.if.out[ifHCOutOctets.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Inbound packets with errors | MIB: IF-MIB For packet-oriented interfaces - the number of inbound packets that contained errors preventing them from being deliverable to a higher-layer protocol. For character-oriented or fixed-length interfaces - the number of inbound transmission units that contained errors preventing them from being deliverable to a higher-layer protocol. Discontinuities in the value of this counter can occur at re-initialization of the management system and at other times as indicated by the value of |
Dependent item | net.if.in.errors[ifInErrors.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Outbound packets with errors | MIB: IF-MIB For packet-oriented interfaces - the number of outbound packets that contained errors preventing them from being deliverable to a higher-layer protocol. For character-oriented or fixed-length interfaces - the number of outbound transmission units that contained errors preventing them from being deliverable to a higher-layer protocol. Discontinuities in the value of this counter can occur at re-initialization of the management system and at other times as indicated by the value of |
Dependent item | net.if.out.errors[ifOutErrors.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Outbound packets discarded | MIB: IF-MIB The number of outbound packets which were chosen to be discarded even though no errors had been detected to prevent their being deliverable to a higher-layer protocol. One possible reason for discarding such a packet could be to free up buffer space. Discontinuities in the value of this counter can occur at re-initialization of the management system and at other times as indicated by the value of |
Dependent item | net.if.out.discards[ifOutDiscards.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Inbound packets discarded | MIB: IF-MIB The number of inbound packets which were chosen to be discarded even though no errors had been detected to prevent their being deliverable to a higher-layer protocol. One possible reason for discarding such a packet could be to free up buffer space. Discontinuities in the value of this counter can occur at re-initialization of the management system and at other times as indicated by the value of |
Dependent item | net.if.in.discards[ifInDiscards.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Interface type | MIB: IF-MIB The type of interface. Additional values for |
Dependent item | net.if.type[ifType.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Speed | MIB: IF-MIB An estimate of the interface's current bandwidth in units of 1,000,000 bits per second. If this object reports a value of For interfaces which do not vary in bandwidth or for those where no accurate estimation can be made, this object should contain the nominal bandwidth. For a sub-layer which has no concept of bandwidth, this object should be zero. |
Dependent item | net.if.speed[ifHighSpeed.{#SNMPINDEX}] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| Interface {#IFNAME}({#IFALIAS}): Link down | This trigger expression works as follows: |
{$IFCONTROL:"{#IFNAME}"}=1 and last(/FortiGate by SNMP/net.if.status[ifOperStatus.{#SNMPINDEX}])=2 and (last(/FortiGate by SNMP/net.if.status[ifOperStatus.{#SNMPINDEX}],#1)<>last(/FortiGate by SNMP/net.if.status[ifOperStatus.{#SNMPINDEX}],#2)) |
Average | Manual close: Yes |
| Interface {#IFNAME}({#IFALIAS}): High bandwidth usage | The utilization of the network interface is close to its estimated maximum bandwidth. |
(avg(/FortiGate by SNMP/net.if.in[ifHCInOctets.{#SNMPINDEX}],15m)>({$IF.UTIL.MAX:"{#IFNAME}"}/100)*last(/FortiGate by SNMP/net.if.speed[ifHighSpeed.{#SNMPINDEX}]) or avg(/FortiGate by SNMP/net.if.out[ifHCOutOctets.{#SNMPINDEX}],15m)>({$IF.UTIL.MAX:"{#IFNAME}"}/100)*last(/FortiGate by SNMP/net.if.speed[ifHighSpeed.{#SNMPINDEX}])) and last(/FortiGate by SNMP/net.if.speed[ifHighSpeed.{#SNMPINDEX}])>0 |
Warning | Manual close: Yes Depends on:
|
| Interface {#IFNAME}({#IFALIAS}): High error rate | The trigger recovers when it is below 80% of the |
min(/FortiGate by SNMP/net.if.in.errors[ifInErrors.{#SNMPINDEX}],5m)>{$IF.ERRORS.WARN:"{#IFNAME}"} or min(/FortiGate by SNMP/net.if.out.errors[ifOutErrors.{#SNMPINDEX}],5m)>{$IF.ERRORS.WARN:"{#IFNAME}"} |
Warning | Manual close: Yes Depends on:
|
| Interface {#IFNAME}({#IFALIAS}): Ethernet has changed to lower speed than it was before | This Ethernet connection has transitioned down from its known maximum speed. This might be a sign of autonegotiation issues. Acknowledge to close the problem manually. |
change(/FortiGate by SNMP/net.if.speed[ifHighSpeed.{#SNMPINDEX}])<0 and last(/FortiGate by SNMP/net.if.speed[ifHighSpeed.{#SNMPINDEX}])>0 and ( last(/FortiGate by SNMP/net.if.type[ifType.{#SNMPINDEX}])=6 or last(/FortiGate by SNMP/net.if.type[ifType.{#SNMPINDEX}])=7 or last(/FortiGate by SNMP/net.if.type[ifType.{#SNMPINDEX}])=11 or last(/FortiGate by SNMP/net.if.type[ifType.{#SNMPINDEX}])=62 or last(/FortiGate by SNMP/net.if.type[ifType.{#SNMPINDEX}])=69 or last(/FortiGate by SNMP/net.if.type[ifType.{#SNMPINDEX}])=117 ) and (last(/FortiGate by SNMP/net.if.status[ifOperStatus.{#SNMPINDEX}])<>2) |
Info | Manual close: Yes Depends on:
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| HA member discovery | Used for discovering HA members from FORTINET-FORTIGATE-MIB. |
Dependent item | ha.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| HA {#HA.ID}: Serial number | MIB: FORTINET-FORTIGATE-MIB Serial number of the HA cluster member. |
Dependent item | ha.serialnumber[fgHaStatsSerial.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: CPU usage | MIB: FORTINET-FORTIGATE-MIB CPU usage of the specified cluster member (percentage). |
Dependent item | ha.cpu.usage[fgHaStatsCpuUsage.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Memory usage | MIB: FORTINET-FORTIGATE-MIB Memory usage of the specified cluster member (percentage). |
Dependent item | ha.mem.usage[fgHaStatsMemUsage.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Network bandwidth usage | MIB: FORTINET-FORTIGATE-MIB Network bandwidth usage of the specified cluster member (bps). |
Dependent item | ha.net.usage[fgHaStatsNetUsage.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Session count | MIB: FORTINET-FORTIGATE-MIB Current session count of the specified cluster member. |
Dependent item | ha.session.count[fgHaStatsSesCount.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Packets processed | MIB: FORTINET-FORTIGATE-MIB Number of packets processed by the specified cluster member per second. |
Dependent item | ha.packets.rate[fgHaStatsPktCount.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Bytes processed | MIB: FORTINET-FORTIGATE-MIB Number of bytes processed by the specified cluster member per second. |
Dependent item | ha.bytes.rate[fgHaStatsByteCount.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: IPS events | MIB: FORTINET-FORTIGATE-MIB Number of IDS/IPS events triggered on the specified cluster member per second. |
Dependent item | ha.ips.events[fgHaStatsIdsCount.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Anti-virus events | MIB: FORTINET-FORTIGATE-MIB Number of anti-virus events triggered on the specified cluster member per second. |
Dependent item | ha.av.events[fgHaStatsAvCount.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Hostname | MIB: FORTINET-FORTIGATE-MIB Host name of the specified cluster member. |
Dependent item | ha.hostname[fgHaStatsHostname.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Sync status | MIB: FORTINET-FORTIGATE-MIB Current HA sync status. |
Dependent item | ha.sync.status[fgHaStatsSyncStatus.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Global checksum | MIB: FORTINET-FORTIGATE-MIB Current HA global checksum value. |
Dependent item | ha.checksum.global[fgHaStatsGlobalChecksum.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Primary serial number | MIB: FORTINET-FORTIGATE-MIB Serial number of the primary HA member during the last sync attempt (successful or not). |
Dependent item | ha.primary.serialnumber[fgHaStatsMasterSerial.{#SNMPINDEX}] Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Hardware sensors discovery | Used for discovering hardware sensors from FORTINET-FORTIGATE-MIB. |
Dependent item | hw.sensor.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Sensor {#SENSOR.NAME}: Value | MIB: FORTINET-FORTIGATE-MIB A string representation of the value of the sensor. Because sensors can present data in different formats, string representation is the most general format. Interpretation of the value (units of measure, for example) is dependent on the individual sensor. |
Dependent item | hw.sensor.value[fgHwSensorEntValue.{#SENSOR.ID}] Preprocessing
|
| Sensor {#SENSOR.NAME}: Alarm status | MIB: FORTINET-FORTIGATE-MIB If the sensor has an alarm threshold and has exceeded it, this will indicate its status. Not all sensors have alarms. |
Dependent item | hw.sensor.status[fgHwSensorEntAlarmStatus.{#SENSOR.ID}] Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SoC3 discovery | Used for discovering SoC3 NP6Lite processors from FORTINET-FORTIGATE-MIB. |
Dependent item | soc3.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SoC3 {#CPU.ID}: Packets dropped | MIB: FORTINET-FORTIGATE-MIB The total number of packets dropped by this processor (only valid for processor types that support this statistic). |
Dependent item | soc3.np6lite.pkt.dropped[fgProcessorPktDroppedCount.{#CPU.ID}] Preprocessing
|
| SoC3 {#CPU.ID}: Packets received | MIB: FORTINET-FORTIGATE-MIB The total number of packets received by this processor (only valid for processor types that support this statistic). |
Dependent item | soc3.np6lite.pkt.received[fgProcessorPktRxCount.{#CPU.ID}] Preprocessing
|
| SoC3 {#CPU.ID}: Packets transmitted | MIB: FORTINET-FORTIGATE-MIB The total number of packets transmitted by this processor (only valid for processor types that support this statistic). |
Dependent item | soc3.np6lite.pkt.transmitted[fgProcessorPktRxCount.{#CPU.ID}] Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SD-WAN health-check discovery | Used for discovering SD-WAN health-check from FORTINET-FORTIGATE-MIB. |
Dependent item | sdwan_health.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SD-WAN [{#HNAME}]:[{#IFNAME}]: Health check state | MIB: FORTINET-FORTIGATE-MIB Health check state on a specific member link. |
Dependent item | sdwan_health.state[fgVWLHealthCheckLinkState.{#SNMPINDEX}] Preprocessing
|
| SD-WAN [{#HNAME}]:[{#IFNAME}]: Latency | MIB: FORTINET-FORTIGATE-MIB The average latency of a health check on a specific member link in a float number within the last 30 probes. |
Dependent item | sdwan_health.latency[fgVWLHealthCheckLinkLatency.{#SNMPINDEX}] Preprocessing
|
| SD-WAN [{#HNAME}]:[{#IFNAME}]: Jitter | MIB: FORTINET-FORTIGATE-MIB The average jitter of a health check on a specific member link in a float number within the last 30 probes. |
Dependent item | sdwan_health.jitter[fgVWLHealthCheckLinkJitter.{#SNMPINDEX}] Preprocessing
|
| SD-WAN [{#HNAME}]:[{#IFNAME}]: Packets loss | MIB: FORTINET-FORTIGATE-MIB The packet loss percentage of a health check on a specific member link in a float number within the last 30 probes. |
Dependent item | sdwan_health.loss[fgVWLHealthCheckLinkPacketLoss.{#SNMPINDEX}] Preprocessing
|
| SD-WAN [{#HNAME}]:[{#IFNAME}]: Packets sent per second | MIB: FORTINET-FORTIGATE-MIB Number of packets sent by a health check on a specific member link per second. |
Dependent item | sdwan_health.sent[fgVWLHealthCheckLinkPacketSend.{#SNMPINDEX}] Preprocessing
|
| SD-WAN [{#HNAME}]:[{#IFNAME}]: Packets received per second | MIB: FORTINET-FORTIGATE-MIB Number of packets received by a health check on a specific member link per second. |
Dependent item | sdwan_health.received[fgVWLHealthCheckLinkPacketRecv.{#SNMPINDEX}] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| SD-WAN [{#HNAME}]:[{#IFNAME}]: Health check state is dead | This trigger expression works as follows: |
{$SDWAN.HEALTH.IF.CONTROL:"{#HNAME}"}=1 and last(/FortiGate by SNMP/sdwan_health.state[fgVWLHealthCheckLinkState.{#SNMPINDEX}])=1 and (last(/FortiGate by SNMP/sdwan_health.state[fgVWLHealthCheckLinkState.{#SNMPINDEX}],#1)<>last(/FortiGate by SNMP/sdwan_health.state[fgVWLHealthCheckLinkState.{#SNMPINDEX}],#2)) |
Average | Manual close: Yes |
| SD-WAN [{#HNAME}]:[{#IFNAME}]: High packets loss | High level of packet loss detected. |
min(/FortiGate by SNMP/sdwan_health.loss[fgVWLHealthCheckLinkPacketLoss.{#SNMPINDEX}],5m)>{$SDWAN.HEALTH.IF.LOSS.WARN:"{#HNAME}"} |
Warning |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Wireless discovery | Used for discovering wireless access points from FORTINET-FORTIGATE-MIB. |
Dependent item | wireless.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| WTP {#WC.NAME}: Administrative status | MIB: FORTINET-FORTIGATE-MIB Represents the administrative status of this wireless termination point (WTP). The following enumerated values are supported:
|
Dependent item | wc.admin.status[fgWcWtpConfigWtpAdmin.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Location | MIB: FORTINET-FORTIGATE-MIB Represents the location of this WTP. |
Dependent item | wc.location[fgWcWtpConfigWtpLocation.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Profile name | MIB: FORTINET-FORTIGATE-MIB Represents the profile configured for this WTP. |
Dependent item | wc.profile[fgWcWtpConfigWtpProfile.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Radio enabled | MIB: FORTINET-FORTIGATE-MIB Whether radio is enabled for this WTP. |
Dependent item | wc.radio.enabled[fgWcWtpConfigRadioEnable.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Radio ATPC status | MIB: FORTINET-FORTIGATE-MIB Whether radio automatic TX power control is enabled on this WTP. |
Dependent item | wc.radio.atpc.status[fgWcWtpConfigRadioAutoTxPowerControl.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Radio ATPC low limit | MIB: FORTINET-FORTIGATE-MIB Represents the low limit of radio automatic TX power control configured for this WTP, in dBm. |
Dependent item | wc.radio.atpc.low_limit[fgWcWtpConfigRadioAutoTxPowerLow.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Radio ATPC high limit | MIB: FORTINET-FORTIGATE-MIB Represents the high limit of radio automatic TX power control configured for this WTP, in dBm. |
Dependent item | wc.radio.atpc.high_limit[fgWcWtpConfigRadioAutoTxPowerHigh.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Radio TX power level | MIB: FORTINET-FORTIGATE-MIB Represents the radio TX power setting configured for this WTP, expressed in %. |
Dependent item | wc.radio.power_level[fgWcWtpConfigRadioTxPowerLevel.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Radio band | MIB: FORTINET-FORTIGATE-MIB Represents the radio band configured for this WTP. |
Dependent item | wc.radio.band[fgWcWtpConfigRadioBand.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Background scan | MIB: FORTINET-FORTIGATE-MIB Whether background scan is enabled on this WTP. |
Dependent item | wc.background.scan[fgWcWtpConfigRadioApScan.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: All VAPs selected | MIB: FORTINET-FORTIGATE-MIB Whether all wireless virtual access points (VAP) are selected for this WTP. |
Dependent item | wc.vaps.all[fgWcWtpConfigVapAll.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: VAPs list | MIB: FORTINET-FORTIGATE-MIB Represents a list of wireless virtual access points (VAP) configured for this WTP. |
Dependent item | wc.vaps.list[fgWcWtpConfigVaps.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: IP Address type | MIB: FORTINET-FORTIGATE-MIB Represents the IP address type of a WTP. |
Dependent item | wc.ip.type[fgWcWtpSessionWtpIpAddressType.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: IP Address | MIB: FORTINET-FORTIGATE-MIB Represents the IP address of a WTP that corresponds to the IP address in the IP packet header. |
Dependent item | wc.ip.addr[fgWcWtpSessionWtpIpAddress.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Local IP Address type | MIB: FORTINET-FORTIGATE-MIB Represents the local IP address type of a WTP. |
Dependent item | wc.local_ip.type[fgWcWtpSessionWtpLocalIpAddressType.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Local IP Address | MIB: FORTINET-FORTIGATE-MIB Represents the local IP address of a WTP and models the CAPWAP Local IPv4 Address or CAPWAP Local IPv6 Address fields [RFC5415]. If a Network Address Translation (NAT) device is present between the WTP and access controller (AC), the value of |
Dependent item | wc.local_ip.addr[fgWcWtpSessionWtpLocalIpAddress.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Base MAC Address | MIB: FORTINET-FORTIGATE-MIB Represents the WTP's Base MAC Address, which MAY be assigned to the primary Ethernet interface. The instance of the object corresponds to the Base MAC Address sub-element in the CAPWAP protocol [RFC5415]. |
Dependent item | wc.base.mac[fgWcWtpSessionWtpBaseMacAddress.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Connection status | MIB: FORTINET-FORTIGATE-MIB Represents the connection status of a WTP to the AC. The following enumerated values are supported:
|
Dependent item | wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Uptime | MIB: FORTINET-FORTIGATE-MIB Represents the time since the WTP has booted. |
Dependent item | wc.uptime[fgWcWtpSessionWtpUpTime.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Daemon uptime | MIB: FORTINET-FORTIGATE-MIB Represents the time since the WTP daemon has been started. |
Dependent item | wc.daemon.uptime[fgWcWtpSessionWtpDaemonUpTime.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Session uptime | MIB: FORTINET-FORTIGATE-MIB Represents the time since the WTP has been connected to the AC. |
Dependent item | wc.session.uptime[fgWcWtpSessionWtpSessionUpTime.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Model number | MIB: FORTINET-FORTIGATE-MIB Represents the model number of a WTP. |
Dependent item | wc.model[fgWcWtpSessionWtpModelNumber.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Hardware version | MIB: FORTINET-FORTIGATE-MIB Represents the hardware version of a WTP. |
Dependent item | wc.hardware.version[fgWcWtpSessionWtpHwVersion.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Software version | MIB: FORTINET-FORTIGATE-MIB Represents the software version of a WTP. |
Dependent item | wc.software.version[fgWcWtpSessionWtpSwVersion.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Bootloader version | MIB: FORTINET-FORTIGATE-MIB Represents the boot loader version of a WTP. |
Dependent item | wc.boot.version[fgWcWtpSessionWtpBootVersion.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Region code | MIB: FORTINET-FORTIGATE-MIB Represents the region code programmed for this WTP. |
Dependent item | wc.region_code[fgWcWtpSessionWtpRegionCode.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Connected clients | MIB: FORTINET-FORTIGATE-MIB Represents the number of clients currently connected to this WTP. |
Dependent item | wc.clients.num[fgWcWtpSessionWtpStationCount.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Bits received | MIB: FORTINET-FORTIGATE-MIB Represents the number of bits received by this WTP per second. |
Dependent item | wc.rate.in[fgWcWtpSessionWtpByteRxCount.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Bits sent | MIB: FORTINET-FORTIGATE-MIB Represents the number of bits transmitted by this WTP per second. |
Dependent item | wc.rate.out[fgWcWtpSessionWtpByteTxCount.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: CPU usage | MIB: FORTINET-FORTIGATE-MIB Represents the current CPU usage of a WTP (percentage). |
Dependent item | wc.cpu.usage[fgWcWtpSessionWtpCpuUsage.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Memory usage | MIB: FORTINET-FORTIGATE-MIB Represents the current memory usage of a WTP (percentage). |
Dependent item | wc.mem.usage[fgWcWtpSessionWtpMemoryUsage.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Memory capacity | MIB: FORTINET-FORTIGATE-MIB Represents the total physical memory (RAM) installed. |
Dependent item | wc.mem.size[fgWcWtpSessionWtpMemoryCapacity.{#SNMPINDEX}] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| WTP {#WC.NAME}: Connection is down | This trigger expression works as follows: |
{$WC.STATE.CONTROL:"{#WC.NAME}"}=1 and last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}])=1 and (last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}],#1)<>last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}],#2)) |
High | Manual close: Yes |
| WTP {#WC.NAME}: Receiving firmware update | This trigger expression works as follows: |
{$WC.UPDATE.CONTROL:"{#WC.NAME}"}=1 and last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}])=3 and (last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}],#1)<>last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}],#2)) |
Info | Manual close: Yes |
| WTP {#WC.NAME}: Sending firmware update | This trigger expression works as follows: |
{$WC.UPDATE.CONTROL:"{#WC.NAME}"}=1 and last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}])=4 and (last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}],#1)<>last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}],#2)) |
Info | Manual close: Yes |
| WTP {#WC.NAME}: Session has been restarted | Uptime is less than 10 minutes. |
last(/FortiGate by SNMP/wc.session.uptime[fgWcWtpSessionWtpSessionUpTime.{#SNMPINDEX}])<10m |
Info | Manual close: Yes |
| WTP {#WC.NAME}: High CPU utilization | The CPU utilization is too high. |
min(/FortiGate by SNMP/wc.cpu.usage[fgWcWtpSessionWtpCpuUsage.{#SNMPINDEX}],5m)>{$WC.CPU.UTIL.CRIT:"{#WC.NAME}"} |
Warning | |
| WTP {#WC.NAME}: High memory utilization | The WTP is running out of free memory. |
min(/FortiGate by SNMP/wc.mem.usage[fgWcWtpSessionWtpMemoryUsage.{#SNMPINDEX}],5m)>{$WC.MEMORY.UTIL.MAX:"{#WC.NAME}"} |
Warning |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Virtual domain discovery | Used for discovering virtual domains from FORTINET-FORTIGATE-MIB. |
Dependent item | vdom.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| VDOM {#VDOM.NAME}: Operation mode | MIB: FORTINET-FORTIGATE-MIB Operation mode of the virtual domain (NAT or Transparent). |
Dependent item | vdom.op_mode[fgVdEntOpMode.{#SNMPINDEX}] Preprocessing
|
| VDOM {#VDOM.NAME}: HA member state | MIB: FORTINET-FORTIGATE-MIB HA cluster member state of the virtual domain on this device. |
Dependent item | vdom.ha.state[fgVdEntHaState.{#SNMPINDEX}] Preprocessing
|
| VDOM {#VDOM.NAME}: CPU usage | MIB: FORTINET-FORTIGATE-MIB CPU usage of the virtual domain (percentage). |
Dependent item | vdom.cpu.usage[fgVdEntCpuUsage.{#SNMPINDEX}] Preprocessing
|
| VDOM {#VDOM.NAME}: Memory usage | MIB: FORTINET-FORTIGATE-MIB Memory usage of the virtual domain (percentage). |
Dependent item | vdom.mem.usage[fgVdEntCpuUsage.{#SNMPINDEX}] Preprocessing
|
| VDOM {#VDOM.NAME}: Active sessions | MIB: FORTINET-FORTIGATE-MIB Number of active sessions on the virtual domain. |
Dependent item | vdom.sessions[fgVdEntSesCount.{#SNMPINDEX}] Preprocessing
|
| VDOM {#VDOM.NAME}: Sessions rate | MIB: FORTINET-FORTIGATE-MIB The session setup rate on the virtual domain per second. |
Dependent item | vdom.sessions.rate[fgVdEntSesRate.{#SNMPINDEX}] Preprocessing
|
Please report any issues with the template at https://support.zabbix.com
You can also provide feedback, discuss the template, or ask for help at ZABBIX forums
This template is designed for the effortless deployment of FortiGate monitoring by Zabbix via SNMP and doesn't require any external scripts.
Zabbix version: 6.0 and higher.
This template has been tested on:
Zabbix should be configured according to the instructions in the Templates out of the box section.
Refer to the vendor documentation.
| Name | Description | Default |
|---|---|---|
| {$CPU.UTIL.CRIT} | Threshold of CPU utilization for Warning trigger in %. |
90 |
| {$ICMP_LOSS_WARN} | Threshold of ICMP packet loss for Warning trigger in %. |
20 |
| {$ICMP_RESPONSE_TIME_WARN} | Threshold of average ICMP response time for Warning trigger in seconds. |
0.15 |
| {$SNMP.TIMEOUT} | The time interval for SNMP availability trigger. |
5m |
| {$MEMORY.UTIL.MAX} | Threshold of memory utilization for trigger in %. |
90 |
| {$DISK.FREE.WARN} | Threshold of disk free space for Warning trigger in %. |
20 |
| {$DISK.FREE.CRIT} | Threshold of disk free space for Critical trigger in %. |
10 |
| {$VPN.NAME.MATCHES} | Used in VPN tunnel discovery. Can be overridden on the host or linked template level. |
.* |
| {$VPN.NAME.NOT_MATCHES} | Used in VPN tunnel discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$VPN.STATE.CONTROL} | Used in "Tunnel down" trigger. Can be used with interface name as context. |
1 |
| {$HA.MEMBER.SN.MATCHES} | Used in HA member discovery. Can be overridden on the host or linked template level. |
.* |
| {$HA.MEMBER.SN.NOT_MATCHES} | Used in HA member discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$IF.ERRORS.WARN} | Threshold of error packet rate for Warning trigger. Can be used with interface name as context. |
2 |
| {$IF.UTIL.MAX} | Threshold of interface bandwidth utilization for Warning trigger in %. Can be used with interface name as context. |
95 |
| {$IFCONTROL} | Macro for operational state of interface for "Link down" trigger. Can be used with interface name as context. |
1 |
| {$NET.IF.IFADMINSTATUS.MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFADMINSTATUS.NOT_MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
^2$ |
| {$NET.IF.IFDESCR.MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFDESCR.NOT_MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$NET.IF.IFNAME.MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFNAME.NOT_MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
(^[Ll]o[0-9.]*$) |
| {$NET.IF.IFOPERSTATUS.MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFOPERSTATUS.NOT_MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
^6$ |
| {$NET.IF.IFTYPE.MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFTYPE.NOT_MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$NET.IF.IFALIAS.MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
.* |
| {$NET.IF.IFALIAS.NOT_MATCHES} | Used in Network interface discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.HEALTH.NAME.MATCHES} | Used in SD-WAN health-check discovery. Can be overridden on the host or linked template level. |
.* |
| {$SDWAN.HEALTH.NAME.NOT_MATCHES} | Used in SD-WAN health-check discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$SDWAN.HEALTH.IF.CONTROL} | Used in "Health check state is dead" trigger. Can be used with health check name as context. |
1 |
| {$SDWAN.HEALTH.IF.LOSS.WARN} | Threshold of packet loss for Warning trigger in %. Can be used with health check name as context. |
20 |
| {$WC.NAME.MATCHES} | Used in Wireless discovery. Can be overridden on the host or linked template level. |
.* |
| {$WC.NAME.NOT_MATCHES} | Used in Wireless discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| {$WC.STATE.CONTROL} | Used in "Connection down" trigger. Can be used with interface name as context. |
1 |
| {$WC.UPDATE.CONTROL} | Used in "Receiving firmware update" trigger. Can be used with interface name as context. |
1 |
| {$WC.CPU.UTIL.CRIT} | Threshold of WTP CPU utilization for Warning trigger in %. Can be used with interface name as context. |
90 |
| {$WC.MEMORY.UTIL.MAX} | Threshold of WTP memory utilization for trigger in %. Can be used with interface name as context. |
90 |
| {$VDOM.NAME.MATCHES} | Used in Virtual domain discovery. Can be overridden on the host or linked template level. |
.* |
| {$VDOM.NAME.NOT_MATCHES} | Used in Virtual domain discovery. Can be overridden on the host or linked template level. |
CHANGE_IF_NEEDED |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| FortiGate: Firmware version | MIB: FORTINET-FORTIGATE-MIB Firmware version of the device. |
SNMP agent | system.hw.firmware Preprocessing
|
| FortiGate: Hardware model name | MIB: ENTITY-MIB Model of the device. |
SNMP agent | system.hw.model Preprocessing
|
| FortiGate: Hardware serial number | MIB: ENTITY-MIB Serial number of the device. |
SNMP agent | system.hw.serialnumber Preprocessing
|
| FortiGate: System contact details | MIB: SNMPv2-MIB Name and contact information of the contact person for the node. If not provided, the value is a zero-length string. |
SNMP agent | system.contact[sysContact.0] Preprocessing
|
| FortiGate: System description | MIB: SNMPv2-MIB A textual description of the entity. This value should include the full name and version identification of the system's hardware type, software operating system, and networking software. |
SNMP agent | system.descr[sysDescr.0] Preprocessing
|
| FortiGate: System location | MIB: SNMPv2-MIB Physical location of the node (e.g., |
SNMP agent | system.location[sysLocation.0] Preprocessing
|
| FortiGate: System name | MIB: SNMPv2-MIB An administratively-assigned name for the node (the node's fully-qualified domain name). If not provided, the value is a zero-length string. |
SNMP agent | system.name Preprocessing
|
| FortiGate: System object ID | MIB: SNMPv2-MIB The vendor's authoritative identification of the entity as part of the vendor's SMI enterprises subtree with the prefix 1.3.6.1.4.1 (e.g., a vendor with the identifier 1.3.6.1.4.1.4242 might assign a system object with the OID 1.3.6.1.4.1.4242.1.1). |
SNMP agent | system.objectid[sysObjectID.0] Preprocessing
|
| FortiGate: System uptime | MIB: FORTINET-FORTIGATE-MIB Time since the network management portion of the system was last re-initialized. |
SNMP agent | system.uptime[fgSysUpTime.0] Preprocessing
|
| FortiGate: Number of CPUs | MIB: FORTINET-FORTIGATE-MIB Number of processors. |
SNMP agent | system.cpu.num Preprocessing
|
| FortiGate: CPU utilization | MIB: FORTINET-FORTIGATE-MIB CPU utilization in %. |
SNMP agent | system.cpu.util[fgSysCpuUsage.0] |
| FortiGate: ICMP ping | Host accessibility by ICMP. 0 - ICMP ping failed. 1 - ICMP ping successful. |
Simple check | icmpping |
| FortiGate: ICMP loss | Percentage of lost packets. |
Simple check | icmppingloss |
| FortiGate: ICMP response time | ICMP ping response time (in seconds). |
Simple check | icmppingsec |
| FortiGate: SNMP agent availability | Availability of SNMP checks on the host. The value of this item corresponds to availability icons in the host list. Possible values: 0 - not available 1 - available 2 - unknown |
Zabbix internal | zabbix[host,snmp,available] |
| FortiGate: Total memory | MIB: FORTINET-FORTIGATE-MIB Total physical memory (RAM) installed. |
SNMP agent | vm.memory.total[fgSysMemCapacity.0] Preprocessing
|
| FortiGate: Memory utilization | Current memory utilization (percentage). |
SNMP agent | vm.memory.util[memoryUsedPercentage.0] |
| FortiGate: Used memory | MIB: FORTINET-FORTIGATE-MIB Physical memory (RAM) used calculated based on memory utilization percentage. |
Calculated | vm.memory.used[fgSysMemUsage.0] |
| FortiGate: Available memory | Total memory available for utilization. |
Calculated | vm.memory.available[fgSysMemFree.0] |
| FortiGate: IPv4 Active sessions | MIB: FORTINET-FORTIGATE-MIB Number of active sessions on the device. |
SNMP agent | net.ipv4.sessions[fgSysSesCount.0] |
| FortiGate: SNMP traps (fallback) | Used for collecting all SNMP traps unmatched by other |
SNMP trap | snmptrap.fallback |
| FortiGate: Total disk space | Total hard disk capacity. |
SNMP agent | vfs.fs.total[fgSysDiskCapacity.0] Preprocessing
|
| FortiGate: Used disk space | Current hard disk usage. |
SNMP agent | vfs.fs.used[fgSysDiskUsage.0] Preprocessing
|
| FortiGate: Free disk space | Free hard disk capacity. |
Calculated | vfs.fs.free |
| FortiGate: Free disk percentage | Free disk space, expressed in %. |
Calculated | vfs.fs.pfree |
| FortiGate: Active IPsec VPN tunnels | MIB: FORTINET-FORTIGATE-MIB Number of IPsec VPN tunnels with at least one SA. |
SNMP agent | vpn.tunnel.active[fgVpnTunnelUpCount.0] Preprocessing
|
| FortiGate: Active SSL VPN users | MIB: FORTINET-FORTIGATE-MIB Current number of users logged in through SSL-VPN tunnels in the virtual domain. |
SNMP agent | vpn.users.count[fgVpnSslStatsLoginUsers.0] Preprocessing
|
| FortiGate: SSL VPN state | MIB: FORTINET-FORTIGATE-MIB Used to determine whether SSL-VPN is enabled on this virtual domain. |
SNMP agent | vpn.ssl.state[fgVpnSslState.0] Preprocessing
|
| FortiGate: Blocked intrusions | MIB: FORTINET-FORTIGATE-MIB Number of intrusions blocked per second. |
SNMP agent | ips.blocked[fgIpsIntrusionsBlocked.0] Preprocessing
|
| FortiGate: Total detected intrusions | MIB: FORTINET-FORTIGATE-MIB Total number of intrusions detected per second. |
SNMP agent | ips.detected.total[fgIpsIntrusionsDetected.0] Preprocessing
|
| FortiGate: Detected critical intrusions | MIB: FORTINET-FORTIGATE-MIB Number of critical severity intrusions detected per second. |
SNMP agent | ips.detected.crit[fgIpsCritSevDetections.0] Preprocessing
|
| FortiGate: Detected high intrusions | MIB: FORTINET-FORTIGATE-MIB Number of high severity intrusions detected per second. |
SNMP agent | ips.detected.high[fgIpsHighSevDetections.0] Preprocessing
|
| FortiGate: Detected medium intrusions | MIB: FORTINET-FORTIGATE-MIB Number of medium severity intrusions detected per second. |
SNMP agent | ips.detected.med[fgIpsMedSevDetections.0] Preprocessing
|
| FortiGate: Detected low intrusions | MIB: FORTINET-FORTIGATE-MIB Number of low severity intrusions detected per second. |
SNMP agent | ips.detected.low[fgIpsLowSevDetections.0] Preprocessing
|
| FortiGate: Detected info intrusions | MIB: FORTINET-FORTIGATE-MIB Number of info severity intrusions detected per second. |
SNMP agent | ips.detected.info[fgIpsInfoSevDetections.0] Preprocessing
|
| FortiGate: Detected anomaly based intrusions | MIB: FORTINET-FORTIGATE-MIB Number of intrusions detected as anomalies per second. |
SNMP agent | ips.detected.anomaly[fgIpsAnomalyDetections.0] Preprocessing
|
| FortiGate: Detected signature based intrusions | MIB: FORTINET-FORTIGATE-MIB Number of intrusions detected by signature per second. |
SNMP agent | ips.detected.sign[fgIpsSignatureDetections.0] Preprocessing
|
| FortiGate: IPS database version | MIB: FORTINET-FORTIGATE-MIB IPS signature database version installed on the device. |
SNMP agent | ips.database.version[fgSysVersionIps.0] Preprocessing
|
| FortiGate: HA mode | MIB: FORTINET-FORTIGATE-MIB High-availability mode (Standalone, A-A or A-P). |
SNMP agent | ha.mode[fgHaSystemMode.0] Preprocessing
|
| FortiGate: HA cluster group ID | MIB: FORTINET-FORTIGATE-MIB HA cluster group ID device is configured for. |
SNMP agent | ha.cluster.group_id[fgHaGroupId.0] Preprocessing
|
| FortiGate: HA cluster group name | MIB: FORTINET-FORTIGATE-MIB HA cluster group name. |
SNMP agent | ha.cluster.group_name[fgHaGroupName.0] Preprocessing
|
| FortiGate: HA cluster priority | MIB: FORTINET-FORTIGATE-MIB HA clustering priority of the device (default = 128). |
SNMP agent | ha.cluster.priority[fgHaPriority.0] Preprocessing
|
| FortiGate: HA cluster primary override | MIB: FORTINET-FORTIGATE-MIB Status of the primary override flag. |
SNMP agent | ha.cluster.override[fgHaOverride.0] Preprocessing
|
| FortiGate: HA config sync | MIB: FORTINET-FORTIGATE-MIB Configuration of an automatic configuration synchronization (enabled or disabled). |
SNMP agent | ha.auto.sync[fgHaAutoSync.0] Preprocessing
|
| FortiGate: HA load-balancing schedule | MIB: FORTINET-FORTIGATE-MIB Load-balancing schedule of cluster (in A-A mode). |
SNMP agent | ha.schedule[fgHaSchedule.0] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| FortiGate: Device has been replaced | Device serial number has changed. Acknowledge to close the problem manually. |
last(/FortiGate by SNMP/system.hw.serialnumber,#1)<>last(/FortiGate by SNMP/system.hw.serialnumber,#2) and length(last(/FortiGate by SNMP/system.hw.serialnumber))>0 |
Info | Manual close: Yes |
| FortiGate: System name has changed | The name of the system has changed. Acknowledge to close the problem manually. |
last(/FortiGate by SNMP/system.name,#1)<>last(/FortiGate by SNMP/system.name,#2) and length(last(/FortiGate by SNMP/system.name))>0 |
Info | Manual close: Yes |
| FortiGate: Device has been restarted | Uptime is less than 10 minutes. |
last(/FortiGate by SNMP/system.uptime[fgSysUpTime.0])<10m |
Info | Manual close: Yes |
| FortiGate: High CPU utilization | The CPU utilization is too high. The system might be slow to respond. |
min(/FortiGate by SNMP/system.cpu.util[fgSysCpuUsage.0],5m)>{$CPU.UTIL.CRIT} |
Warning | |
| FortiGate: Unavailable by ICMP ping | Last three attempts returned timeout. Please check device connectivity. |
max(/FortiGate by SNMP/icmpping,#3)=0 |
High | |
| FortiGate: High ICMP ping loss | ICMP ping loss detected. |
min(/FortiGate by SNMP/icmppingloss,5m)>{$ICMP_LOSS_WARN} and min(/FortiGate by SNMP/icmppingloss,5m)<100 |
Warning | Depends on:
|
| FortiGate: High ICMP ping response time | Average ICMP response time is too high. |
avg(/FortiGate by SNMP/icmppingsec,5m)>{$ICMP_RESPONSE_TIME_WARN} |
Warning | Depends on:
|
| FortiGate: No SNMP data collection | SNMP is not available for polling. Please check device connectivity and SNMP settings. |
max(/FortiGate by SNMP/zabbix[host,snmp,available],{$SNMP.TIMEOUT})=0 |
Warning | Depends on:
|
| FortiGate: High memory utilization | The system is running out of free memory. |
min(/FortiGate by SNMP/vm.memory.util[memoryUsedPercentage.0],5m)>{$MEMORY.UTIL.MAX} |
Average | |
| FortiGate: Free disk space is too low | Available disk space is too low. |
last(/FortiGate by SNMP/vfs.fs.pfree)<{$DISK.FREE.CRIT} |
High | |
| FortiGate: Free disk space is low | Available disk space is not enough. |
last(/FortiGate by SNMP/vfs.fs.pfree)<{$DISK.FREE.WARN} |
Warning | Depends on:
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| CPU discovery | Used for discovering CPUs from FORTINET-FORTIGATE-MIB. |
SNMP agent | cpu.discovery |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| CPU Core {#CPU.ID}: Average usage over 1min | MIB: FORTINET-FORTIGATE-MIB The processor's CPU usage in %, expressed as an average calculated over the last minute. (Only valid for processor types that support this statistic.) |
SNMP agent | system.cpu.usage[fgProcessorUsage.{#SNMPINDEX}] |
| CPU Core {#CPU.ID}: Average user usage over 1min | MIB: FORTINET-FORTIGATE-MIB The processor's CPU user space usage, expressed as an average calculated over the last minute. (Only valid for processor types that support this statistic.) |
SNMP agent | system.cpu.usage[fgProcessorUserUsage.{#SNMPINDEX}] |
| CPU Core {#CPU.ID}: Average system usage over 1min | MIB: FORTINET-FORTIGATE-MIB The processor's CPU system space usage, expressed as an average calculated over the last minute. (Only valid for processor types that support this statistic.) |
SNMP agent | system.cpu.usage[fgProcessorSysUsage.{#SNMPINDEX}] |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| VPN tunnel discovery | Used for discovering VPN tunnels from FORTINET-FORTIGATE-MIB. |
SNMP agent | vpn.tunnel.discovery |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| VPN {#VPN.NAME}: Tunnel Status | MIB: FORTINET-FORTIGATE-MIB Current status of tunnel (up or down). |
SNMP agent | vpn.tunnel.status[fgVpnTunEntStatus.{#SNMPINDEX}] |
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| VPN {#VPN.NAME}: Tunnel down | This trigger expression works as follows: |
{$VPN.STATE.CONTROL:"{#VPN.NAME}"}=1 and last(/FortiGate by SNMP/vpn.tunnel.status[fgVpnTunEntStatus.{#SNMPINDEX}])=1 and (last(/FortiGate by SNMP/vpn.tunnel.status[fgVpnTunEntStatus.{#SNMPINDEX}],#1)<>last(/FortiGate by SNMP/vpn.tunnel.status[fgVpnTunEntStatus.{#SNMPINDEX}],#2)) |
Average | Manual close: Yes |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Network interface discovery | Used for discovering interfaces from IF-MIB. |
SNMP agent | net.if.discovery Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Interface {#IFNAME}({#IFALIAS}): Operational status | MIB: IF-MIB The current operational state of the interface. - The - If - If - It should change to - It should remain in the - It should remain in the |
SNMP agent | net.if.status[ifOperStatus.{#SNMPINDEX}] |
| Interface {#IFNAME}({#IFALIAS}): Bits received | MIB: IF-MIB The total number of octets received on the interface, including framing characters. This object is a 64-bit version of Discontinuities in the value of this counter can occur at re-initialization of the management system and at other times as indicated by the value of |
SNMP agent | net.if.in[ifHCInOctets.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Bits sent | MIB: IF-MIB The total number of octets transmitted out of the interface, including framing characters. This object is a 64-bit version of Discontinuities in the value of this counter can occur at re-initialization of the management system and at other times as indicated by the value of |
SNMP agent | net.if.out[ifHCOutOctets.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Inbound packets with errors | MIB: IF-MIB For packet-oriented interfaces - the number of inbound packets that contained errors preventing them from being deliverable to a higher-layer protocol. For character-oriented or fixed-length interfaces - the number of inbound transmission units that contained errors preventing them from being deliverable to a higher-layer protocol. Discontinuities in the value of this counter can occur at re-initialization of the management system and at other times as indicated by the value of |
SNMP agent | net.if.in.errors[ifInErrors.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Outbound packets with errors | MIB: IF-MIB For packet-oriented interfaces - the number of outbound packets that contained errors preventing them from being deliverable to a higher-layer protocol. For character-oriented or fixed-length interfaces - the number of outbound transmission units that contained errors preventing them from being deliverable to a higher-layer protocol. Discontinuities in the value of this counter can occur at re-initialization of the management system and at other times as indicated by the value of |
SNMP agent | net.if.out.errors[ifOutErrors.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Outbound packets discarded | MIB: IF-MIB The number of outbound packets which were chosen to be discarded even though no errors had been detected to prevent their being deliverable to a higher-layer protocol. One possible reason for discarding such a packet could be to free up buffer space. Discontinuities in the value of this counter can occur at re-initialization of the management system and at other times as indicated by the value of |
SNMP agent | net.if.out.discards[ifOutDiscards.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Inbound packets discarded | MIB: IF-MIB The number of inbound packets which were chosen to be discarded even though no errors had been detected to prevent their being deliverable to a higher-layer protocol. One possible reason for discarding such a packet could be to free up buffer space. Discontinuities in the value of this counter can occur at re-initialization of the management system and at other times as indicated by the value of |
SNMP agent | net.if.in.discards[ifInDiscards.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Interface type | MIB: IF-MIB The type of interface. Additional values for |
SNMP agent | net.if.type[ifType.{#SNMPINDEX}] Preprocessing
|
| Interface {#IFNAME}({#IFALIAS}): Speed | MIB: IF-MIB An estimate of the interface's current bandwidth in units of 1,000,000 bits per second. If this object reports a value of For interfaces which do not vary in bandwidth or for those where no accurate estimation can be made, this object should contain the nominal bandwidth. For a sub-layer which has no concept of bandwidth, this object should be zero. |
SNMP agent | net.if.speed[ifHighSpeed.{#SNMPINDEX}] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| Interface {#IFNAME}({#IFALIAS}): Link down | This trigger expression works as follows: |
{$IFCONTROL:"{#IFNAME}"}=1 and last(/FortiGate by SNMP/net.if.status[ifOperStatus.{#SNMPINDEX}])=2 and (last(/FortiGate by SNMP/net.if.status[ifOperStatus.{#SNMPINDEX}],#1)<>last(/FortiGate by SNMP/net.if.status[ifOperStatus.{#SNMPINDEX}],#2)) |
Average | Manual close: Yes |
| Interface {#IFNAME}({#IFALIAS}): High bandwidth usage | The utilization of the network interface is close to its estimated maximum bandwidth. |
(avg(/FortiGate by SNMP/net.if.in[ifHCInOctets.{#SNMPINDEX}],15m)>({$IF.UTIL.MAX:"{#IFNAME}"}/100)*last(/FortiGate by SNMP/net.if.speed[ifHighSpeed.{#SNMPINDEX}]) or avg(/FortiGate by SNMP/net.if.out[ifHCOutOctets.{#SNMPINDEX}],15m)>({$IF.UTIL.MAX:"{#IFNAME}"}/100)*last(/FortiGate by SNMP/net.if.speed[ifHighSpeed.{#SNMPINDEX}])) and last(/FortiGate by SNMP/net.if.speed[ifHighSpeed.{#SNMPINDEX}])>0 |
Warning | Manual close: Yes Depends on:
|
| Interface {#IFNAME}({#IFALIAS}): High error rate | The trigger recovers when it is below 80% of the |
min(/FortiGate by SNMP/net.if.in.errors[ifInErrors.{#SNMPINDEX}],5m)>{$IF.ERRORS.WARN:"{#IFNAME}"} or min(/FortiGate by SNMP/net.if.out.errors[ifOutErrors.{#SNMPINDEX}],5m)>{$IF.ERRORS.WARN:"{#IFNAME}"} |
Warning | Manual close: Yes Depends on:
|
| Interface {#IFNAME}({#IFALIAS}): Ethernet has changed to lower speed than it was before | This Ethernet connection has transitioned down from its known maximum speed. This might be a sign of autonegotiation issues. Acknowledge to close the problem manually. |
change(/FortiGate by SNMP/net.if.speed[ifHighSpeed.{#SNMPINDEX}])<0 and last(/FortiGate by SNMP/net.if.speed[ifHighSpeed.{#SNMPINDEX}])>0 and ( last(/FortiGate by SNMP/net.if.type[ifType.{#SNMPINDEX}])=6 or last(/FortiGate by SNMP/net.if.type[ifType.{#SNMPINDEX}])=7 or last(/FortiGate by SNMP/net.if.type[ifType.{#SNMPINDEX}])=11 or last(/FortiGate by SNMP/net.if.type[ifType.{#SNMPINDEX}])=62 or last(/FortiGate by SNMP/net.if.type[ifType.{#SNMPINDEX}])=69 or last(/FortiGate by SNMP/net.if.type[ifType.{#SNMPINDEX}])=117 ) and (last(/FortiGate by SNMP/net.if.status[ifOperStatus.{#SNMPINDEX}])<>2) |
Info | Manual close: Yes Depends on:
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| HA member discovery | Used for discovering HA members from FORTINET-FORTIGATE-MIB. |
SNMP agent | ha.discovery |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| HA {#HA.ID}: Serial number | MIB: FORTINET-FORTIGATE-MIB Serial number of the HA cluster member. |
SNMP agent | ha.serialnumber[fgHaStatsSerial.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: CPU usage | MIB: FORTINET-FORTIGATE-MIB CPU usage of the specified cluster member (percentage). |
SNMP agent | ha.cpu.usage[fgHaStatsCpuUsage.{#SNMPINDEX}] |
| HA {#HA.ID}: Memory usage | MIB: FORTINET-FORTIGATE-MIB Memory usage of the specified cluster member (percentage). |
SNMP agent | ha.mem.usage[fgHaStatsMemUsage.{#SNMPINDEX}] |
| HA {#HA.ID}: Network bandwidth usage | MIB: FORTINET-FORTIGATE-MIB Network bandwidth usage of the specified cluster member (bps). |
SNMP agent | ha.net.usage[fgHaStatsNetUsage.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Session count | MIB: FORTINET-FORTIGATE-MIB Current session count of the specified cluster member. |
SNMP agent | ha.session.count[fgHaStatsSesCount.{#SNMPINDEX}] |
| HA {#HA.ID}: Packets processed | MIB: FORTINET-FORTIGATE-MIB Number of packets processed by the specified cluster member per second. |
SNMP agent | ha.packets.rate[fgHaStatsPktCount.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Bytes processed | MIB: FORTINET-FORTIGATE-MIB Number of bytes processed by the specified cluster member per second. |
SNMP agent | ha.bytes.rate[fgHaStatsByteCount.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: IPS events | MIB: FORTINET-FORTIGATE-MIB Number of IDS/IPS events triggered on the specified cluster member per second. |
SNMP agent | ha.ips.events[fgHaStatsIdsCount.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Anti-virus events | MIB: FORTINET-FORTIGATE-MIB Number of anti-virus events triggered on the specified cluster member per second. |
SNMP agent | ha.av.events[fgHaStatsAvCount.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Hostname | MIB: FORTINET-FORTIGATE-MIB Host name of the specified cluster member. |
SNMP agent | ha.hostname[fgHaStatsHostname.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Sync status | MIB: FORTINET-FORTIGATE-MIB Current HA sync status. |
SNMP agent | ha.sync.status[fgHaStatsSyncStatus.{#SNMPINDEX}] |
| HA {#HA.ID}: Global checksum | MIB: FORTINET-FORTIGATE-MIB Current HA global checksum value. |
SNMP agent | ha.checksum.global[fgHaStatsGlobalChecksum.{#SNMPINDEX}] Preprocessing
|
| HA {#HA.ID}: Primary serial number | MIB: FORTINET-FORTIGATE-MIB Serial number of the primary HA member during the last sync attempt (successful or not). |
SNMP agent | ha.primary.serialnumber[fgHaStatsMasterSerial.{#SNMPINDEX}] Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Hardware sensors discovery | Used for discovering hardware sensors from FORTINET-FORTIGATE-MIB. |
SNMP agent | hw.sensor.discovery |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Sensor {#SENSOR.NAME}: Value | MIB: FORTINET-FORTIGATE-MIB A string representation of the value of the sensor. Because sensors can present data in different formats, string representation is the most general format. Interpretation of the value (units of measure, for example) is dependent on the individual sensor. |
SNMP agent | hw.sensor.value[fgHwSensorEntValue.{#SENSOR.ID}] Preprocessing
|
| Sensor {#SENSOR.NAME}: Alarm status | MIB: FORTINET-FORTIGATE-MIB If the sensor has an alarm threshold and has exceeded it, this will indicate its status. Not all sensors have alarms. |
SNMP agent | hw.sensor.status[fgHwSensorEntAlarmStatus.{#SENSOR.ID}] |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SoC3 discovery | Used for discovering SoC3 NP6Lite processors from FORTINET-FORTIGATE-MIB. |
SNMP agent | soc3.discovery |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SoC3 {#CPU.ID}: Packets dropped | MIB: FORTINET-FORTIGATE-MIB The total number of packets dropped by this processor (only valid for processor types that support this statistic). |
SNMP agent | soc3.np6lite.pkt.dropped[fgProcessorPktDroppedCount.{#CPU.ID}] Preprocessing
|
| SoC3 {#CPU.ID}: Packets received | MIB: FORTINET-FORTIGATE-MIB The total number of packets received by this processor (only valid for processor types that support this statistic). |
SNMP agent | soc3.np6lite.pkt.received[fgProcessorPktRxCount.{#CPU.ID}] Preprocessing
|
| SoC3 {#CPU.ID}: Packets transmitted | MIB: FORTINET-FORTIGATE-MIB The total number of packets transmitted by this processor (only valid for processor types that support this statistic). |
SNMP agent | soc3.np6lite.pkt.transmitted[fgProcessorPktRxCount.{#CPU.ID}] Preprocessing
|
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SD-WAN health-check discovery | Used for discovering SD-WAN health-check from FORTINET-FORTIGATE-MIB. |
SNMP agent | sdwan_health.discovery |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| SD-WAN [{#HNAME}]:[{#IFNAME}]: Health check state | MIB: FORTINET-FORTIGATE-MIB Health check state on a specific member link. |
SNMP agent | sdwan_health.state[fgVWLHealthCheckLinkState.{#SNMPINDEX}] |
| SD-WAN [{#HNAME}]:[{#IFNAME}]: Latency | MIB: FORTINET-FORTIGATE-MIB The average latency of a health check on a specific member link in a float number within the last 30 probes. |
SNMP agent | sdwan_health.latency[fgVWLHealthCheckLinkLatency.{#SNMPINDEX}] |
| SD-WAN [{#HNAME}]:[{#IFNAME}]: Jitter | MIB: FORTINET-FORTIGATE-MIB The average jitter of a health check on a specific member link in a float number within the last 30 probes. |
SNMP agent | sdwan_health.jitter[fgVWLHealthCheckLinkJitter.{#SNMPINDEX}] |
| SD-WAN [{#HNAME}]:[{#IFNAME}]: Packets loss | MIB: FORTINET-FORTIGATE-MIB The packet loss percentage of a health check on a specific member link in a float number within the last 30 probes. |
SNMP agent | sdwan_health.loss[fgVWLHealthCheckLinkPacketLoss.{#SNMPINDEX}] |
| SD-WAN [{#HNAME}]:[{#IFNAME}]: Packets sent per second | MIB: FORTINET-FORTIGATE-MIB Number of packets sent by a health check on a specific member link per second. |
SNMP agent | sdwan_health.sent[fgVWLHealthCheckLinkPacketSend.{#SNMPINDEX}] Preprocessing
|
| SD-WAN [{#HNAME}]:[{#IFNAME}]: Packets received per second | MIB: FORTINET-FORTIGATE-MIB Number of packets received by a health check on a specific member link per second. |
SNMP agent | sdwan_health.received[fgVWLHealthCheckLinkPacketRecv.{#SNMPINDEX}] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| SD-WAN [{#HNAME}]:[{#IFNAME}]: Health check state is dead | This trigger expression works as follows: |
{$SDWAN.HEALTH.IF.CONTROL:"{#HNAME}"}=1 and last(/FortiGate by SNMP/sdwan_health.state[fgVWLHealthCheckLinkState.{#SNMPINDEX}])=1 and (last(/FortiGate by SNMP/sdwan_health.state[fgVWLHealthCheckLinkState.{#SNMPINDEX}],#1)<>last(/FortiGate by SNMP/sdwan_health.state[fgVWLHealthCheckLinkState.{#SNMPINDEX}],#2)) |
Average | Manual close: Yes |
| SD-WAN [{#HNAME}]:[{#IFNAME}]: High packets loss | High level of packet loss detected. |
min(/FortiGate by SNMP/sdwan_health.loss[fgVWLHealthCheckLinkPacketLoss.{#SNMPINDEX}],5m)>{$SDWAN.HEALTH.IF.LOSS.WARN:"{#HNAME}"} |
Warning |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Wireless discovery | Used for discovering wireless access points from FORTINET-FORTIGATE-MIB. |
SNMP agent | wireless.discovery |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| WTP {#WC.NAME}: Administrative status | MIB: FORTINET-FORTIGATE-MIB Represents the administrative status of this wireless termination point (WTP). The following enumerated values are supported:
|
SNMP agent | wc.admin.status[fgWcWtpConfigWtpAdmin.{#SNMPINDEX}] |
| WTP {#WC.NAME}: Location | MIB: FORTINET-FORTIGATE-MIB Represents the location of this WTP. |
SNMP agent | wc.location[fgWcWtpConfigWtpLocation.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Profile name | MIB: FORTINET-FORTIGATE-MIB Represents the profile configured for this WTP. |
SNMP agent | wc.profile[fgWcWtpConfigWtpProfile.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Radio enabled | MIB: FORTINET-FORTIGATE-MIB Whether radio is enabled for this WTP. |
SNMP agent | wc.radio.enabled[fgWcWtpConfigRadioEnable.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Radio ATPC status | MIB: FORTINET-FORTIGATE-MIB Whether radio automatic TX power control is enabled on this WTP. |
SNMP agent | wc.radio.atpc.status[fgWcWtpConfigRadioAutoTxPowerControl.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Radio ATPC low limit | MIB: FORTINET-FORTIGATE-MIB Represents the low limit of radio automatic TX power control configured for this WTP, in dBm. |
SNMP agent | wc.radio.atpc.low_limit[fgWcWtpConfigRadioAutoTxPowerLow.{#SNMPINDEX}] |
| WTP {#WC.NAME}: Radio ATPC high limit | MIB: FORTINET-FORTIGATE-MIB Represents the high limit of radio automatic TX power control configured for this WTP, in dBm. |
SNMP agent | wc.radio.atpc.high_limit[fgWcWtpConfigRadioAutoTxPowerHigh.{#SNMPINDEX}] |
| WTP {#WC.NAME}: Radio TX power level | MIB: FORTINET-FORTIGATE-MIB Represents the radio TX power setting configured for this WTP, expressed in %. |
SNMP agent | wc.radio.power_level[fgWcWtpConfigRadioTxPowerLevel.{#SNMPINDEX}] |
| WTP {#WC.NAME}: Radio band | MIB: FORTINET-FORTIGATE-MIB Represents the radio band configured for this WTP. |
SNMP agent | wc.radio.band[fgWcWtpConfigRadioBand.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Background scan | MIB: FORTINET-FORTIGATE-MIB Whether background scan is enabled on this WTP. |
SNMP agent | wc.background.scan[fgWcWtpConfigRadioApScan.{#SNMPINDEX}] |
| WTP {#WC.NAME}: All VAPs selected | MIB: FORTINET-FORTIGATE-MIB Whether all wireless virtual access points (VAP) are selected for this WTP. |
SNMP agent | wc.vaps.all[fgWcWtpConfigVapAll.{#SNMPINDEX}] |
| WTP {#WC.NAME}: VAPs list | MIB: FORTINET-FORTIGATE-MIB Represents a list of wireless virtual access points (VAP) configured for this WTP. |
SNMP agent | wc.vaps.list[fgWcWtpConfigVaps.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: IP Address type | MIB: FORTINET-FORTIGATE-MIB Represents the IP address type of a WTP. |
SNMP agent | wc.ip.type[fgWcWtpSessionWtpIpAddressType.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: IP Address | MIB: FORTINET-FORTIGATE-MIB Represents the IP address of a WTP that corresponds to the IP address in the IP packet header. |
SNMP agent | wc.ip.addr[fgWcWtpSessionWtpIpAddress.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Local IP Address type | MIB: FORTINET-FORTIGATE-MIB Represents the local IP address type of a WTP. |
SNMP agent | wc.local_ip.type[fgWcWtpSessionWtpLocalIpAddressType.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Local IP Address | MIB: FORTINET-FORTIGATE-MIB Represents the local IP address of a WTP and models the CAPWAP Local IPv4 Address or CAPWAP Local IPv6 Address fields [RFC5415]. If a Network Address Translation (NAT) device is present between the WTP and access controller (AC), the value of |
SNMP agent | wc.local_ip.addr[fgWcWtpSessionWtpLocalIpAddress.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Base MAC Address | MIB: FORTINET-FORTIGATE-MIB Represents the WTP's Base MAC Address, which MAY be assigned to the primary Ethernet interface. The instance of the object corresponds to the Base MAC Address sub-element in the CAPWAP protocol [RFC5415]. |
SNMP agent | wc.base.mac[fgWcWtpSessionWtpBaseMacAddress.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Connection status | MIB: FORTINET-FORTIGATE-MIB Represents the connection status of a WTP to the AC. The following enumerated values are supported:
|
SNMP agent | wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}] |
| WTP {#WC.NAME}: Uptime | MIB: FORTINET-FORTIGATE-MIB Represents the time since the WTP has booted. |
SNMP agent | wc.uptime[fgWcWtpSessionWtpUpTime.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Daemon uptime | MIB: FORTINET-FORTIGATE-MIB Represents the time since the WTP daemon has been started. |
SNMP agent | wc.daemon.uptime[fgWcWtpSessionWtpDaemonUpTime.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Session uptime | MIB: FORTINET-FORTIGATE-MIB Represents the time since the WTP has been connected to the AC. |
SNMP agent | wc.session.uptime[fgWcWtpSessionWtpSessionUpTime.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Model number | MIB: FORTINET-FORTIGATE-MIB Represents the model number of a WTP. |
SNMP agent | wc.model[fgWcWtpSessionWtpModelNumber.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Hardware version | MIB: FORTINET-FORTIGATE-MIB Represents the hardware version of a WTP. |
SNMP agent | wc.hardware.version[fgWcWtpSessionWtpHwVersion.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Software version | MIB: FORTINET-FORTIGATE-MIB Represents the software version of a WTP. |
SNMP agent | wc.software.version[fgWcWtpSessionWtpSwVersion.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Bootloader version | MIB: FORTINET-FORTIGATE-MIB Represents the boot loader version of a WTP. |
SNMP agent | wc.boot.version[fgWcWtpSessionWtpBootVersion.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Region code | MIB: FORTINET-FORTIGATE-MIB Represents the region code programmed for this WTP. |
SNMP agent | wc.region_code[fgWcWtpSessionWtpRegionCode.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Connected clients | MIB: FORTINET-FORTIGATE-MIB Represents the number of clients currently connected to this WTP. |
SNMP agent | wc.clients.num[fgWcWtpSessionWtpStationCount.{#SNMPINDEX}] |
| WTP {#WC.NAME}: Bits received | MIB: FORTINET-FORTIGATE-MIB Represents the number of bits received by this WTP per second. |
SNMP agent | wc.rate.in[fgWcWtpSessionWtpByteRxCount.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: Bits sent | MIB: FORTINET-FORTIGATE-MIB Represents the number of bits transmitted by this WTP per second. |
SNMP agent | wc.rate.out[fgWcWtpSessionWtpByteTxCount.{#SNMPINDEX}] Preprocessing
|
| WTP {#WC.NAME}: CPU usage | MIB: FORTINET-FORTIGATE-MIB Represents the current CPU usage of a WTP (percentage). |
SNMP agent | wc.cpu.usage[fgWcWtpSessionWtpCpuUsage.{#SNMPINDEX}] |
| WTP {#WC.NAME}: Memory usage | MIB: FORTINET-FORTIGATE-MIB Represents the current memory usage of a WTP (percentage). |
SNMP agent | wc.mem.usage[fgWcWtpSessionWtpMemoryUsage.{#SNMPINDEX}] |
| WTP {#WC.NAME}: Memory capacity | MIB: FORTINET-FORTIGATE-MIB Represents the total physical memory (RAM) installed. |
SNMP agent | wc.mem.size[fgWcWtpSessionWtpMemoryCapacity.{#SNMPINDEX}] Preprocessing
|
| Name | Description | Expression | Severity | Dependencies and additional info |
|---|---|---|---|---|
| WTP {#WC.NAME}: Connection is down | This trigger expression works as follows: |
{$WC.STATE.CONTROL:"{#WC.NAME}"}=1 and last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}])=1 and (last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}],#1)<>last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}],#2)) |
High | Manual close: Yes |
| WTP {#WC.NAME}: Receiving firmware update | This trigger expression works as follows: |
{$WC.UPDATE.CONTROL:"{#WC.NAME}"}=1 and last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}])=3 and (last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}],#1)<>last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}],#2)) |
Info | Manual close: Yes |
| WTP {#WC.NAME}: Sending firmware update | This trigger expression works as follows: |
{$WC.UPDATE.CONTROL:"{#WC.NAME}"}=1 and last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}])=4 and (last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}],#1)<>last(/FortiGate by SNMP/wc.conn.status[fgWcWtpSessionConnectionState.{#SNMPINDEX}],#2)) |
Info | Manual close: Yes |
| WTP {#WC.NAME}: Session has been restarted | Uptime is less than 10 minutes. |
last(/FortiGate by SNMP/wc.session.uptime[fgWcWtpSessionWtpSessionUpTime.{#SNMPINDEX}])<10m |
Info | Manual close: Yes |
| WTP {#WC.NAME}: High CPU utilization | The CPU utilization is too high. |
min(/FortiGate by SNMP/wc.cpu.usage[fgWcWtpSessionWtpCpuUsage.{#SNMPINDEX}],5m)>{$WC.CPU.UTIL.CRIT:"{#WC.NAME}"} |
Warning | |
| WTP {#WC.NAME}: High memory utilization | The WTP is running out of free memory. |
min(/FortiGate by SNMP/wc.mem.usage[fgWcWtpSessionWtpMemoryUsage.{#SNMPINDEX}],5m)>{$WC.MEMORY.UTIL.MAX:"{#WC.NAME}"} |
Warning |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| Virtual domain discovery | Used for discovering virtual domains from FORTINET-FORTIGATE-MIB. |
SNMP agent | vdom.discovery |
| Name | Description | Type | Key and additional info |
|---|---|---|---|
| VDOM {#VDOM.NAME}: Operation mode | MIB: FORTINET-FORTIGATE-MIB Operation mode of the virtual domain (NAT or Transparent). |
SNMP agent | vdom.op_mode[fgVdEntOpMode.{#SNMPINDEX}] |
| VDOM {#VDOM.NAME}: HA member state | MIB: FORTINET-FORTIGATE-MIB HA cluster member state of the virtual domain on this device. |
SNMP agent | vdom.ha.state[fgVdEntHaState.{#SNMPINDEX}] |
| VDOM {#VDOM.NAME}: CPU usage | MIB: FORTINET-FORTIGATE-MIB CPU usage of the virtual domain (percentage). |
SNMP agent | vdom.cpu.usage[fgVdEntCpuUsage.{#SNMPINDEX}] |
| VDOM {#VDOM.NAME}: Memory usage | MIB: FORTINET-FORTIGATE-MIB Memory usage of the virtual domain (percentage). |
SNMP agent | vdom.mem.usage[fgVdEntCpuUsage.{#SNMPINDEX}] |
| VDOM {#VDOM.NAME}: Active sessions | MIB: FORTINET-FORTIGATE-MIB Number of active sessions on the virtual domain. |
SNMP agent | vdom.sessions[fgVdEntSesCount.{#SNMPINDEX}] |
| VDOM {#VDOM.NAME}: Sessions rate | MIB: FORTINET-FORTIGATE-MIB The session setup rate on the virtual domain per second. |
SNMP agent | vdom.sessions.rate[fgVdEntSesRate.{#SNMPINDEX}] |
Please report any issues with the template at https://support.zabbix.com
You can also provide feedback, discuss the template, or ask for help at ZABBIX forums
| Link | Source | Compatibility | Type, Technology | Created Updated | Rating |
|---|---|---|---|---|---|
| Fortimail 60D template_fortinet_fortimail |
GitHub Community Templates |
5.0+ |
| ||
| SNMP Fortinet - Antivirus and WebFilter Updated: 2021-04-19 -> Support for monitoring the WebFilter feature.Template for monitoring Antivirus and Web Filter features in FORTIGATE equipment based on FORTINET-FORTIGATE-MIB.WEBFILTER:7 Item prototypes0 Trigger prototypesANTIVIRUS:18 Item prototypes0 Trigger prototypesFeel free to make sugges template_snmp_fortinet-antivirus_and_webfilter |
GitHub Community Templates |
5.0+ |
| ||
| SNMP Fortigate Wifi Access Points Template to monitor Fortinet APs. Forti AP is monitored through FortiGate, so you need to apply this template to the Fortigate device.Originally based on template: "Fortigate SNMP SSLVPN/FortiAP Manged by Fortigate WiFi Controller template" created by Vadim Portnoy. Source: https://share.zabbix.com/network\_devices/fortigate/fortigate-snmp-sslvpn-fortiap-manged-by-fortigate-wifi-controller-templateMy ... template_snmp_fortigate_wifi_access_point |
GitHub Community Templates |
5.0+ |
| ||
| SNMP FortiSwitch Devices This is a template created starting from Andrea Durante´s Fortigate SNMP template, but with modified OIDs from the MIB of the FortiSwitch 124E-PoE device.Serial No., OS version,% CPU,% RAM, disk (total and used), interface data (link and speed).Graphs for % CPU, % RAM, disk use and network traffic. template_fortiswitch_124e-poe |
GitHub Community Templates |
5.0+ |
| ||
| Module Interfaces SNMPv2 Hello, I created this template that contains the verification of all interfaces of fortinet equipmentIncludingCPU%Memory%Vpn discoveryHA monitoringEquipment UptimeNumber of ConnectionsTraffic Internet Inbound and OutboundSerial Number (Included in host screens)Firmware version (Included in host screens)In ... template_fortinet_all_discovery |
GitHub Community Templates |
5.0+ |
| ||
| SNMP Fortinet Devices v2019 Up to date of Andrea Durante´s excellent template.Monitors: Serial N., OS version, Connection num, CPU%, RAM%, Disk (Total and Used), Interface data (link and speed).Graph for everything. template_fortigate_snmp_v2019 |
GitHub Community Templates |
5.0+ |
| ||
| SNMP Fortinet Devices This is a template created starting from the Leonardo Nascimento da Silva, but modified in English.Serial N., OS version, Connection num, CPU%, RAM%, Disk (Total and Used), Interface data (link and speed)Graph for everything.01 Aug 2017 - Added UPTIME and a trigger for Reboot check template_fortigate_snmp |
GitHub Community Templates |
5.0+ |
| ||
| Fortigate HA Sync Fortigate HA SyncItensHa Group NameHa System ModeHa Stats Sync StatusHa Auto SyncTriggersHA - {HOST.NAME} - UnSynchronizedHA Auto Sync- {HOST.NAME} - DisableTesteFortigate 100E / Fortigate 60E / Fortigate 30EFirmware6.2/ 6.1 template_fortigate_ha_status |
GitHub Community Templates |
5.0+ |
| ||
| FGT-INTERFACES DISCOVERY Monitoramento de Appliance Fortigate homologado nos modelos "100D - 200B - 60C - 30D",(CPU(%), Interfaces (bit/s), Memoria(%), Nº. Serial, Uptime, Modelo, Uso em Disco).Template pensado para ser usado em conjunto com o Grafana. template_fortigate_100d-200b-60c-30d |
GitHub Community Templates |
5.0+ |
| ||
| Fortigate 100D Customized Template based on the original made by Leonardo Nascimento da Silva. Added LLD for Hostname, CPU, Memory and Serial Number.Also added HA Status and basic SNMP info (Contact, Name, Uptime).Tested with Fortigate 100D on Zabbix 3.4.6BTW, I had to create some Value Mappings as follows:Fortigate ... template_fortigate_100d |
GitHub Community Templates |
5.0+ |
| ||
| SNMP FortiAnalyzer Hi,This is my first attempt to create a template for the FortiAnalyzer appliance. In the future, I will update with more items and triggers.I test on Zabbix 4.4, but I believe it must be compatible with other recent versions.I used the MIB to extract the OID. Search the Fortinet website for the MIB: ... template_fortianalyzer |
GitHub Community Templates |
5.0+ |
|