Cacti Monitor Firewall Port Traffice

Post support questions that directly relate to Linux/Unix operating systems.

Moderators: Developers, Moderators

Post Reply
ahtshun83
Cacti User
Posts: 95
Joined: Wed Feb 25, 2009 12:23 am

Cacti Monitor Firewall Port Traffice

Post by ahtshun83 »

hi all,

I'm using Cacti 0.8.7d ....i would like to monitor Fortinet Firewall..i want to monitor a specify port for the traffic out and in..

anyone can assist me? Can i use the default template in Cacti?

thank you
engeishi
Cacti User
Posts: 75
Joined: Sun Aug 23, 2009 12:03 pm
Location: Tokyo, Japan

Post by engeishi »

Let us know WHAT is your problem.
Fortinet Firewall support SNMP, so you can use built in DATA Query "SNMP - Interface Statistics" to monitor your device traffic.
ahtshun83
Cacti User
Posts: 95
Joined: Wed Feb 25, 2009 12:23 am

Post by ahtshun83 »

can the template monitor a specify port?

My fortinet gots 6 LAN ports....i just need to monitor port 1 for example..
engeishi
Cacti User
Posts: 75
Joined: Sun Aug 23, 2009 12:03 pm
Location: Tokyo, Japan

Post by engeishi »

YES. Just try it! To see is to believe.
ahtshun83
Cacti User
Posts: 95
Joined: Wed Feb 25, 2009 12:23 am

Post by ahtshun83 »

engeishi wrote:YES. Just try it! To see is to believe.
Hi,

I have enabled snmp on my fortinet firewall 310b..i created a new device in cacti to monitor however,i received an error "SNMP error"

I have allowed from dmz(cacti) to any interface with SNMP and ICMP services.

do i need to allow dmz to firewall IP?

pls assist!
User avatar
gandalf
Developer
Posts: 22383
Joined: Thu Dec 02, 2004 2:46 am
Location: Muenster, Germany
Contact:

Post by gandalf »

Please see 2nd link of my sig for debugging. The firewall must pass cacti snmp requests, that's for sure
Reinhard
ahtshun83
Cacti User
Posts: 95
Joined: Wed Feb 25, 2009 12:23 am

Post by ahtshun83 »

gandalf wrote:Please see 2nd link of my sig for debugging. The firewall must pass cacti snmp requests, that's for sure
Reinhard
hi reinhard,

how do i debug whether my firewall pass the snmp request?
User avatar
TheWitness
Developer
Posts: 17004
Joined: Tue May 14, 2002 5:08 pm
Location: MI, USA
Contact:

Post by TheWitness »

From the Cacti box.

Code: Select all

snmpwalk -c <your_community> -v 1 (or 2c) <your_host> .1.3
Post output.

TheWitness
True understanding begins only when we realize how little we truly understand...

Life is an adventure, let yours begin with Cacti!

Author of dozens of Cacti plugins and customization's. Advocate of LAMP, MariaDB, IBM Spectrum LSF and the world of batch. Creator of IBM Spectrum RTM, author of quite a bit of unpublished work and most of Cacti's bugs.
_________________
Official Cacti Documentation
GitHub Repository with Supported Plugins
Percona Device Packages (no support)
Interesting Device Packages


For those wondering, I'm still here, but lost in the shadows. Yearning for less bugs. Who want's a Cacti 1.3/2.0? Streams anyone?
ahtshun83
Cacti User
Posts: 95
Joined: Wed Feb 25, 2009 12:23 am

Post by ahtshun83 »

TheWitness wrote:From the Cacti box.

Code: Select all

snmpwalk -c <your_community> -v 1 (or 2c) <your_host> .1.3
Post output.

TheWitness
i got the output " Timeout: No response from <my host> .

i able to ping from my cacti to the firewall device..

pls assist.
User avatar
gandalf
Developer
Posts: 22383
Joined: Thu Dec 02, 2004 2:46 am
Location: Muenster, Germany
Contact:

Post by gandalf »

Then it is very likely, that <my host> does not respond to snmp either
- because SNMP is not enabled or
- because SNMP packets are dropped
Please verify <my host>. As long as SNMP via cli fails, Cacti will fail as well
Reinhard
xminos
Cacti User
Posts: 63
Joined: Wed Apr 26, 2006 8:10 am

Post by xminos »

My advice.. return the fortinet and buy a real firewall such as a juniper 8)

But since you've already bought it SNMP must be configured as an allowed service on that interface (and policy if you're going THROUGH the firewall first)

You also need to permit the subnet to be able to manage the device. SNMP is considered management traffic on most firewalls (vs ICMP).

If this were a netscreen I could tell you with ease how to configure this stuff.. but since its a fortinet perhaps you can take some of that $$ you saved and call their tech support :wink:
mcutting
Cacti Guru User
Posts: 1884
Joined: Mon Oct 16, 2006 5:57 am
Location: United Kingdom
Contact:

Post by mcutting »

i hope you won't be offended, but I saw this:
http://docs.google.com/gview?a=v&q=cach ... xRCH1_kQVA
Cacti Version 0.8.8b
Cacti OS Ubuntu LTS
RRDTool Version RRDTool 1.4.7
Poller Information
Type SPINE 0.8.8b
Post Reply

Who is online

Users browsing this forum: No registered users and 1 guest