Skip to main content
Version: NG-2.16

Fortinet Firewall

Introduction

The Fortinet Firewall Monitoring Observability solution aims to provide detailed insights and comprehensive visibility into firewall infrastructure, leveraging the Simple Network Management Protocol (SNMP)

Getting Started

Compatibility

Fortinet Firewall O11ySource supports SNMP versions v1, v2c and v3.

Data Collection Method

vuSmartMaps collects the availability data for Fortinet Firewall O11ySource using an internal data collector and collects data based on the source configuration. NOTE: SNMP Polling O11ySource has to be enabled and configured before enabling Fortinet Firewall O11ySource

Prerequisites

Dependent Configuration

To configure this O11ySource, create a 'credential' of type 'snmp' under the 'Definition' tab.

Inputs for Configuring Data Source

  • Group Name: This field is for grouping devices for SNMP polling, making it easier to manage devices with common characteristics or within the same network segment.
  • No. of Retries: Number of times the system should reattempt polling if the initial attempt fails. Default is set to 7 retries
  • Timeout Duration: Specify how long the system should wait for a response from a device before considering the attempt unsuccessful. Default timeout is 5 seconds
  • Devices: Enter the Fortinet firewall device details.
  • Device IP: Enter the IP address of the device.
  • SNMP Credential: Select the SNMP credential from the dropdown list that corresponds to this device.
  • Vendor: Select the vendor of the device from the dropdown list
  • Model: Select the model of the device from dropdown list.
  • MIB Groups: Configure the MIB groups and polling intervals.
  • MIB Group: Select the MIB Group to poll, identifying the MIB OID to collect. Default: 'ALL_SUPPORTED_MIB_GROUPS'.
  • Interval: Specify the polling interval in seconds. Default: 360 seconds

Firewall Requirement

To collect data from this O11ySource, ensure the following ports are opened:

Source IPDestination IPDestination PortProtocolDirection
vuSmartMaps IPIP address of the SNMP device161*UDPOutbound

*Before providing the firewall requirements, please update the port based on the customer environment.

Configuring the Target

Configure SNMP on Fortinet Firewall devices and grant SNMP access permissions to vuSmartMaps designated IP address.

Configuration Steps

  • Enable the Fortinet Firewall O11ySource.
  • Select the Sources tab and press the + button to add a new SNMP device to be monitored.
  • Click on Save to create the instance

Metrics Collected

NameDescriptionData Type
Data Collection TimeWhen this information was collected from the firewall.DateTime64(3)
Monitored Firewall AddressIP address or network name of the firewall being monitored.String
Monitoring ServerServer that collected this firewall information.String
Firewall NameName of the Fortinet firewall.String
Customer IDID of the customer that owns the firewall.LowCardinality(String)
Business Unit IDID of the team or business unit responsible for the firewall.LowCardinality(String)
Data GroupMain group this firewall information belongs to.LowCardinality(String)
Information TypeType of firewall information shown in this row.LowCardinality(String)
Firewall IP AddressIP address used to connect to the firewall.IPv4
Component NumberNumber used to identify a firewall part or cluster member.String
Component NameName of the firewall part being monitored.String
Processor NameName of the firewall processor being monitored.LowCardinality(String)
Disk Space Used (%)Percentage of firewall disk space currently being used.Float64
Cluster Member NumberUnique number that identifies this firewall in the HA cluster.UInt64
Cluster Member Serial NumberSerial number of this firewall in the HA cluster.String
Cluster Member CPU Used (%)Percentage of CPU currently used by this firewall in the HA cluster.Float32
Cluster Member Memory Used (%)Percentage of memory currently used by this firewall in the HA cluster.Float32
Cluster Member Network UsageNetwork bandwidth currently used by this firewall in the HA cluster, measured in kilobits per second (kbps).UInt64
Cluster Member Active ConnectionsCurrent number of network sessions handled by this firewall in the HA cluster.UInt64
Cluster Member Total PacketsTotal number of packets processed by this firewall since it started.UInt64
Cluster Member New PacketsNumber of packets processed since the previous data collection.UInt64
Cluster Member Total DataTotal number of bytes processed by this firewall since it started.UInt64
Cluster Member New DataNumber of bytes processed since the previous data collection.UInt64
Cluster Member Total Threat AlertsTotal number of IDS/IPS security events triggered on this firewall since it started.UInt64
Cluster Member New Threat AlertsNumber of new IDS/IPS security events since the previous data collection.UInt64
Cluster Member Total Virus AlertsTotal number of antivirus events triggered on this firewall since it started.UInt64
Cluster Member New Virus AlertsNumber of new antivirus events since the previous data collection.UInt64
Cluster Member NameHost name of this firewall in the HA cluster.String
Cluster Sync StatusCurrent HA synchronization status: 0 means not synchronized and 1 means synchronized.Int8
Cluster Settings Check ValueCurrent global checksum used to compare HA configuration data across cluster members.String
Primary Firewall Serial NumberSerial number of the primary firewall during the most recent synchronization attempt, whether it succeeded or failed.String
Automatic Cluster SyncShows whether automatic configuration synchronization is enabled or disabled for the HA cluster.UInt32
Cluster Operating ModeHA mode used by the firewall: standalone, active-active, or active-passive.UInt32