Ad Widget

Collapse

Monitoring of IPSEC Tunnels via SNMP

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Saaggs
    Junior Member
    • Dec 2022
    • 12

    #1

    Monitoring of IPSEC Tunnels via SNMP

    Good morning,

    I am trying to monitor IPSEC Tunnel via SNMP get on a fortigate. Zabbix does an SNMP GET every 1 minute, if the value is 1 tunnel is down, if the value is 2 tunnel is UP.
    My goal is to create a problem only if the last 5 values are at 1 (to avoid false positive). I have tried multiple things and searched multiple posts but it doesn't seem to work for me. Here is the configuration I've already tried :

    min(/FIREWALLS-FORTIGATE-VPN/fgVpnTunEntStatus[{#SNMPINDEX}],#5)=1 : For some reason, this create a problem instantly when a 1 is received
    last(/FIREWALLS-FORTIGATE-VPN/fgVpnTunEntStatus[{#SNMPINDEX}],#5)=1 : Doesn't always work, I've read the documentation about this function but I do not fully understand what it does.
    min(/FIREWALLS-FORTIGATE-VPN/fgVpnTunEntStatus[{#SNMPINDEX}],#5:now-6m)=1 : I thought this meant trigger only if 5 data is 1 in a 6min intervale but even if I only receive one this opens a problem but 6 minutes after receiving it. I've tried the same thing with the last function.

    I've seen some trigger expression in the forums like these posts :
    https://www.zabbix.com/forum/zabbix-...values-trigger
    https://www.zabbix.com/forum/zabbix-...are-equal-to-1


    But these posts are old and the trigger are not written in the same way as in 6.x it seems.

    I am new to zabbix and still trying to understand some of the features, any help/documentation would be much appreciated !
    I am using Discovery item/trigger and zabbix 6.0.12

    Wish you all a happy new year!
  • Markku
    Senior Member
    Zabbix Certified SpecialistZabbix Certified ProfessionalZabbix Certified Expert
    • Sep 2018
    • 1782

    #2
    max(xxxxx,#5) = 1

    will trigger if the last 5 values have been at most 1 (= no values of 2 have been received).

    Markku

    Comment

    • Saaggs
      Junior Member
      • Dec 2022
      • 12

      #3
      Hello Markku,

      Sorry for the late reply. Thank you so much ! It works.

      Regards,

      Comment

      • Ebsys
        Junior Member
        • Oct 2023
        • 22

        #4
        Hello Saaggs, how did you monitor your VPN at first using SNMP?, I am trying to monitor my ipsec tunnels too.

        Thanks

        Comment

        • Saaggs
          Junior Member
          • Dec 2022
          • 12

          #5
          Hi,
          I used the script mib2zabbix to create a template with a discovery for the OIDs of IPSEC tunnels. I then created a trigger if the IPSEC tunnel was down for more than 5 minutes.
          Hope that helps

          Comment

          • hannah131517
            Junior Member
            • Nov 2024
            • 3

            #6
            Hello, may i know if you also monitor all devices to another location connected via firewall? I'm facing issue with all the switches in other location. We have two data centers to monitor. The primary data center, where Zabbix is installed, is being monitored properly. However, the switches in the second data center are experiencing SNMP data collection errors. So i want to know if do i need to do extra steps in my 2nd location so it will send data to my Zabbix

            Comment

            Working...