Hi Zabbix Community,
we are currently redesigning parts of our monitoring environment and I would like to hear how others handle the following situation and what is considered best practice in Zabbix.
We are running Zabbix 7.4 with a central Zabbix server and multiple active proxies, usually one proxy per customer/site.
Most customer hosts are assigned to their local Zabbix proxy because the proxy has access to the internal network.
However, for many hosts we also need checks from an external perspective, ideally directly from the central Zabbix server.
Two typical examples: Example 1 – Firewall
The firewall host is monitored by the customer's Zabbix proxy.
Internal checks:
These checks should obviously be performed by the customer's proxy.
At the same time, we would like to monitor the public WAN IP from outside, for example:
This check should be performed by the central Zabbix server, because we want to know whether the customer's Internet connection/public IP is reachable from outside.
If the firewall host is assigned to the customer's proxy, icmpping is also executed by that proxy, which does not give us the external perspective we need. Example 2 – Linux web server
A Linux VM is monitored internally using the Zabbix agent / active checks through the customer proxy.
For the same server/application we also want to monitor:
These checks should be performed externally by the central Zabbix server.
Again, because the host is assigned to the customer proxy, HTTP/Web checks are normally executed by that proxy.
What we would ideally like
Conceptually, we would like something like this:
Host: CUSTOMER-WEB01
Monitored internally by: CUSTOMER-PROXY
Agent / SNMP / internal checks
-> CUSTOMER-PROXY
URL / SSL / public ICMP checks
-> ZABBIX-SERVER
In other words, selecting the execution location per item, item type, template or check rather than only per host.
As far as I understand, Zabbix currently assigns the monitoring responsibility at host level, so there is no native "execute this item on the server instead of the assigned proxy" option. Solutions we are currently considering
1. Separate logical hosts
For example:
CUSTOMER-FW01
monitored by CUSTOMER-PROXY
SNMP / internal monitoring
CUSTOMER-FW01-EXTERNAL
monitored by ZABBIX-SERVER
public ICMP monitoring
and:
CUSTOMER-WEB01
monitored by CUSTOMER-PROXY
OS / agent monitoring
CUSTOMER-WEB01-WEB
monitored by ZABBIX-SERVER
HTTPS / certificate / external availability
This seems to be the most native Zabbix solution, but it creates additional hosts representing the same physical system/service.
2. Central custom collector + trapper items
Another option would be to keep everything on the original host and run a central script/service on the Zabbix server.
The collector would perform the external checks and push the results back into trapper items on the original host.
This keeps all data/problems on one host, but obviously requires custom logic outside the normal Zabbix item execution model. Existing feature requests
I also found several existing feature requests that seem to describe almost exactly this use case:
As far as I can see, these requests are still unresolved.
Questions
How do you handle this in larger Zabbix environments?
Is using separate logical hosts for the different monitoring perspectives still the recommended/best-practice approach?
For example:
FW01
FW01-External
WEB01
WEB01-External
Or is there a newer/native way in Zabbix 7.4 to execute selected checks on the Zabbix server while the host itself is monitored by a proxy?
Is there any way to select a Zabbix proxy/server per item, template, Web Scenario or similar?
For people using separate hosts: how do you organize them so that problems, dashboards, tags and services still clearly show that both hosts belong to the same physical device or service?
And finally, with Zabbix 8.0 LTS approaching:
Are there any plans in Zabbix 8.0, or in a later release, to support selecting the monitoring location (Zabbix server / proxy / proxy group) on item level rather than only on host level?
If not, are the feature requests mentioned above still considered the intended direction for solving this limitation, or is there another architectural approach planned for Zabbix 8?
I found some older discussions where using two host configurations (internal/external) was suggested, but I would be interested to know whether this is still how people solve this today, especially in larger environments with many customer proxies.
Thanks!
we are currently redesigning parts of our monitoring environment and I would like to hear how others handle the following situation and what is considered best practice in Zabbix.
We are running Zabbix 7.4 with a central Zabbix server and multiple active proxies, usually one proxy per customer/site.
Most customer hosts are assigned to their local Zabbix proxy because the proxy has access to the internal network.
However, for many hosts we also need checks from an external perspective, ideally directly from the central Zabbix server.
Two typical examples: Example 1 – Firewall
The firewall host is monitored by the customer's Zabbix proxy.
Internal checks:
- SNMP
- interfaces
- CPU/memory
- VPN status
- other firewall-specific metrics
These checks should obviously be performed by the customer's proxy.
At the same time, we would like to monitor the public WAN IP from outside, for example:
- ICMP availability
- packet loss
- response time
This check should be performed by the central Zabbix server, because we want to know whether the customer's Internet connection/public IP is reachable from outside.
If the firewall host is assigned to the customer's proxy, icmpping is also executed by that proxy, which does not give us the external perspective we need. Example 2 – Linux web server
A Linux VM is monitored internally using the Zabbix agent / active checks through the customer proxy.
For the same server/application we also want to monitor:
- public HTTPS URL availability
- HTTP response
- SSL certificate
- response time
These checks should be performed externally by the central Zabbix server.
Again, because the host is assigned to the customer proxy, HTTP/Web checks are normally executed by that proxy.
What we would ideally like
Conceptually, we would like something like this:
Host: CUSTOMER-WEB01
Monitored internally by: CUSTOMER-PROXY
Agent / SNMP / internal checks
-> CUSTOMER-PROXY
URL / SSL / public ICMP checks
-> ZABBIX-SERVER
In other words, selecting the execution location per item, item type, template or check rather than only per host.
As far as I understand, Zabbix currently assigns the monitoring responsibility at host level, so there is no native "execute this item on the server instead of the assigned proxy" option. Solutions we are currently considering
1. Separate logical hosts
For example:
CUSTOMER-FW01
monitored by CUSTOMER-PROXY
SNMP / internal monitoring
CUSTOMER-FW01-EXTERNAL
monitored by ZABBIX-SERVER
public ICMP monitoring
and:
CUSTOMER-WEB01
monitored by CUSTOMER-PROXY
OS / agent monitoring
CUSTOMER-WEB01-WEB
monitored by ZABBIX-SERVER
HTTPS / certificate / external availability
This seems to be the most native Zabbix solution, but it creates additional hosts representing the same physical system/service.
2. Central custom collector + trapper items
Another option would be to keep everything on the original host and run a central script/service on the Zabbix server.
The collector would perform the external checks and push the results back into trapper items on the original host.
This keeps all data/problems on one host, but obviously requires custom logic outside the normal Zabbix item execution model. Existing feature requests
I also found several existing feature requests that seem to describe almost exactly this use case:
- ZBXNEXT-5772 – Allow set "Monitored by proxy" per Item
- ZBXNEXT-4531 – Proxy: ability to configure items to be monitored out of proxy (directly by Zabbix Server)
- ZBXNEXT-8201 – Checkbox to poll item from the server instead of the proxy
- ZBXNEXT-2282 – Monitoring Host Items by different proxies
As far as I can see, these requests are still unresolved.
Questions
How do you handle this in larger Zabbix environments?
Is using separate logical hosts for the different monitoring perspectives still the recommended/best-practice approach?
For example:
FW01
FW01-External
WEB01
WEB01-External
Or is there a newer/native way in Zabbix 7.4 to execute selected checks on the Zabbix server while the host itself is monitored by a proxy?
Is there any way to select a Zabbix proxy/server per item, template, Web Scenario or similar?
For people using separate hosts: how do you organize them so that problems, dashboards, tags and services still clearly show that both hosts belong to the same physical device or service?
And finally, with Zabbix 8.0 LTS approaching:
Are there any plans in Zabbix 8.0, or in a later release, to support selecting the monitoring location (Zabbix server / proxy / proxy group) on item level rather than only on host level?
If not, are the feature requests mentioned above still considered the intended direction for solving this limitation, or is there another architectural approach planned for Zabbix 8?
I found some older discussions where using two host configurations (internal/external) was suggested, but I would be interested to know whether this is still how people solve this today, especially in larger environments with many customer proxies.
Thanks!
Comment