Ad Widget

Collapse

Zabbix Agent behind Firewall/Overloading NAT

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Stefan_x96
    Junior Member
    • Apr 2019
    • 10

    #1

    Zabbix Agent behind Firewall/Overloading NAT

    Hello, I have a scenario where:
    Zabbix Server have ip of 1.1.1.1 And I am trying to monitor Network that has public ip of: 2.2.2.2 and local network 172.16.0.0 where Zabbix agent is installed on 172.16.0.10.

    I am trying to monitor agent but am Having issues.
    Steps taken are:
    Duplicated Linux Server template and changed copy to Active agent,
    Setup agent with Server Ip 1.1.1.1 , psk...
    Setup host on a server with 2.2.2.2, psk..
    setup active template.
    Turned off the firewall on the agent, access lists enabled ports 10051 and 10050 in any direction on the firewall. ( Firewall is pf sense).

    No matter what I do I am not getting communication. Any help is welcome
  • mauro
    Member
    • Jan 2017
    • 94

    #2
    The original template have a lint to Template App Zabbix Agent.
    This template is not for active agent (only passive): you need also clone this template, and change every item (and discovery item...) to "Active", then link it to the "Active agent template".

    Comment

    • Stefan_x96
      Junior Member
      • Apr 2019
      • 10

      #3
      Originally posted by mauro
      The original template have a lint to Template App Zabbix Agent.
      This template is not for active agent (only passive): you need also clone this template, and change every item (and discovery item...) to "Active", then link it to the "Active agent template".
      Thank you for your answer mauro but I did that, I even tried with simple check, its failing somewhere but I have no idea where.
      Is my IP configuration correct, I need to put IP of the agents gateway?

      Comment

      • mauro
        Member
        • Jan 2017
        • 94

        #4
        what do you mean?
        the agent must be able to "reach" the zabbix server.
        therefore the traffic must be able to exit (port 10051), and yes, you must (at the operating system level) set the gateway if it is not possible to reach the server otherwise (e.g. routing in gw/fw).
        however I repeat: check the items well even at the discovery level in the template, you have to set them all. I had initially missed it.

        Comment

        • kloczek
          Senior Member
          • Jun 2006
          • 1771

          #5
          Originally posted by mauro
          The original template have a lint to Template App Zabbix Agent.
          This template is not for active agent (only passive): you need also clone this template, and change every item (and discovery item...) to "Active", then link it to the "Active agent template".
          Just in case .. example active agent monitoring template is possibe to find here:
          http://uk.linkedin.com/pub/tomasz-k%...zko/6/940/430/
          https://kloczek.wordpress.com/
          zapish - Zabbix API SHell binding https://github.com/kloczek/zapish
          My zabbix templates https://github.com/kloczek/zabbix-templates

          Comment

          Working...