Fortinet Firewall
Introduction
The Fortinet Firewall Monitoring Observability solution aims to provide detailed insights and comprehensive visibility into firewall infrastructure, leveraging the Simple Network Management Protocol (SNMP)
Getting Started
Compatibility
Fortinet Firewall O11ySource supports SNMP versions v1, v2c and v3.
Data Collection Method
vuSmartMaps collects the availability data for Fortinet Firewall O11ySource using an internal data collector and collects data based on the source configuration. NOTE: SNMP Polling O11ySource has to be enabled and configured before enabling Fortinet Firewall O11ySource
Prerequisites
Dependent Configuration
To configure this O11ySource, create a 'credential' of type 'snmp' under the 'Definition' tab.
Inputs for Configuring Data Source
- Group Name: This field is for grouping devices for SNMP polling, making it easier to manage devices with common characteristics or within the same network segment.
- No. of Retries: Number of times the system should reattempt polling if the initial attempt fails. Default is set to 7 retries
- Timeout Duration: Specify how long the system should wait for a response from a device before considering the attempt unsuccessful. Default timeout is 5 seconds
- Devices: Enter the Fortinet firewall device details.
- Device IP: Enter the IP address of the device.
- SNMP Credential: Select the SNMP credential from the dropdown list that corresponds to this device.
- Vendor: Select the vendor of the device from the dropdown list
- Model: Select the model of the device from dropdown list.
- MIB Groups: Configure the MIB groups and polling intervals.
- MIB Group: Select the MIB Group to poll, identifying the MIB OID to collect. Default: 'ALL_SUPPORTED_MIB_GROUPS'.
- Interval: Specify the polling interval in seconds. Default: 360 seconds
Firewall Requirement
To collect data from this O11ySource, ensure the following ports are opened:
| Source IP | Destination IP | Destination Port | Protocol | Direction |
|---|---|---|---|---|
| vuSmartMaps IP | IP address of the SNMP device | 161* | UDP | Outbound |
*Before providing the firewall requirements, please update the port based on the customer environment.
Configuring the Target
Configure SNMP on Fortinet Firewall devices and grant SNMP access permissions to vuSmartMaps designated IP address.
Configuration Steps
- Enable the Fortinet Firewall O11ySource.
- Select the Sources tab and press the
+button to add a new SNMP device to be monitored. - Click on
Saveto create the instance
Metrics Collected
| Name | Description | Data Type |
|---|---|---|
| Data Collection Time | When this information was collected from the firewall. | DateTime64(3) |
| Monitored Firewall Address | IP address or network name of the firewall being monitored. | String |
| Monitoring Server | Server that collected this firewall information. | String |
| Firewall Name | Name of the Fortinet firewall. | String |
| Customer ID | ID of the customer that owns the firewall. | LowCardinality(String) |
| Business Unit ID | ID of the team or business unit responsible for the firewall. | LowCardinality(String) |
| Data Group | Main group this firewall information belongs to. | LowCardinality(String) |
| Information Type | Type of firewall information shown in this row. | LowCardinality(String) |
| Firewall IP Address | IP address used to connect to the firewall. | IPv4 |
| Component Number | Number used to identify a firewall part or cluster member. | String |
| Component Name | Name of the firewall part being monitored. | String |
| Processor Name | Name of the firewall processor being monitored. | LowCardinality(String) |
| Disk Space Used (%) | Percentage of firewall disk space currently being used. | Float64 |
| Cluster Member Number | Unique number that identifies this firewall in the HA cluster. | UInt64 |
| Cluster Member Serial Number | Serial number of this firewall in the HA cluster. | String |
| Cluster Member CPU Used (%) | Percentage of CPU currently used by this firewall in the HA cluster. | Float32 |
| Cluster Member Memory Used (%) | Percentage of memory currently used by this firewall in the HA cluster. | Float32 |
| Cluster Member Network Usage | Network bandwidth currently used by this firewall in the HA cluster, measured in kilobits per second (kbps). | UInt64 |
| Cluster Member Active Connections | Current number of network sessions handled by this firewall in the HA cluster. | UInt64 |
| Cluster Member Total Packets | Total number of packets processed by this firewall since it started. | UInt64 |
| Cluster Member New Packets | Number of packets processed since the previous data collection. | UInt64 |
| Cluster Member Total Data | Total number of bytes processed by this firewall since it started. | UInt64 |
| Cluster Member New Data | Number of bytes processed since the previous data collection. | UInt64 |
| Cluster Member Total Threat Alerts | Total number of IDS/IPS security events triggered on this firewall since it started. | UInt64 |
| Cluster Member New Threat Alerts | Number of new IDS/IPS security events since the previous data collection. | UInt64 |
| Cluster Member Total Virus Alerts | Total number of antivirus events triggered on this firewall since it started. | UInt64 |
| Cluster Member New Virus Alerts | Number of new antivirus events since the previous data collection. | UInt64 |
| Cluster Member Name | Host name of this firewall in the HA cluster. | String |
| Cluster Sync Status | Current HA synchronization status: 0 means not synchronized and 1 means synchronized. | Int8 |
| Cluster Settings Check Value | Current global checksum used to compare HA configuration data across cluster members. | String |
| Primary Firewall Serial Number | Serial number of the primary firewall during the most recent synchronization attempt, whether it succeeded or failed. | String |
| Automatic Cluster Sync | Shows whether automatic configuration synchronization is enabled or disabled for the HA cluster. | UInt32 |
| Cluster Operating Mode | HA mode used by the firewall: standalone, active-active, or active-passive. | UInt32 |
