<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Sophos XG Monitoring HA</title><link>https://community.sophos.com/sophos-xg-firewall/f/discussions/135501/sophos-xg-monitoring-ha</link><description>Hello Sophos and Community, 
 
 this topic seems to be an problem for a long time and i have tried to figure out how but i just seems, that there is no way. 
 We are using the Sophos XG Web API which is for at least some part documented ( https://docs</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Sophos XG Monitoring HA</title><link>https://community.sophos.com/thread/501054?ContentTypeID=1</link><pubDate>Thu, 21 Jul 2022 12:42:13 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:a169e260-8bd1-4e99-8695-8cf7a66491d7</guid><dc:creator>LuCar Toni</dc:creator><description>&lt;p&gt;Did you or somebody eventually cleared the alert? Because the alert should be generated on those dates as you can see.&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sophos XG Monitoring HA</title><link>https://community.sophos.com/thread/501038?ContentTypeID=1</link><pubDate>Thu, 21 Jul 2022 09:19:58 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:e1fe0b5e-8546-4dfd-a7ec-0c2ee93c99a6</guid><dc:creator>Michael Schneider</dc:creator><description>&lt;p&gt;I checked the central the approach, but i am &amp;quot;stucked&amp;quot;.&lt;/p&gt;
&lt;p&gt;We have a faulty HA Status in Central, which is actually shown in the firewall status:&lt;/p&gt;
&lt;p&gt;&lt;img src="/resized-image/__size/1280x960/__key/communityserver-discussions-components-files/126/pastedimage1658394943983v1.png" alt=" " /&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;I crawled through all central events on this specific customer as a test but could not find any &amp;quot;fail&amp;quot; event.&lt;/p&gt;
&lt;p&gt;There are not that much firewall events and i found those 4:&lt;/p&gt;
&lt;p&gt;&lt;img src="/resized-image/__size/1280x960/__key/communityserver-discussions-components-files/126/pastedimage1658395007475v2.png" alt=" " /&gt;&lt;/p&gt;
&lt;p&gt;But they explicitly said the HA Status is not impared, which could be happen on a failover or firmware update or just a reboot. It is a warning, which at least for me says: everything is, but one note is rebooting or do i missunderstand? And it seems to happen 4 times with a recover after that, i found the recover events, but not for every date:&lt;/p&gt;
&lt;p&gt;&lt;img src="/resized-image/__size/1280x960/__key/communityserver-discussions-components-files/126/pastedimage1658395142392v3.png" alt=" " /&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Seems to be No Recover Event for Juli 16. and Juli 20. But two 2 the 27. Mai.&lt;/p&gt;
&lt;p&gt;Do you have any more details about the event you mean?&lt;/p&gt;
&lt;p&gt;Thank you.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sophos XG Monitoring HA</title><link>https://community.sophos.com/thread/501035?ContentTypeID=1</link><pubDate>Thu, 21 Jul 2022 08:58:26 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:260a0a6d-254d-4256-aa71-b187c87cb60d</guid><dc:creator>Michael Schneider</dc:creator><description>&lt;p&gt;I don&amp;#39;t know :)&amp;nbsp;&lt;br /&gt;There is just no option:&lt;br /&gt;&lt;img src="/resized-image/__size/1280x960/__key/communityserver-discussions-components-files/126/pastedimage1658393903857v1.png" alt=" " /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sophos XG Monitoring HA</title><link>https://community.sophos.com/thread/501033?ContentTypeID=1</link><pubDate>Thu, 21 Jul 2022 08:47:57 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:2288420e-25dc-408f-9bcc-e898cc083370</guid><dc:creator>JasP</dc:creator><description>&lt;p&gt;Why is it that you can&amp;#39;t add a &amp;quot;Local service ACL exception rule&amp;quot; for SNMP? You can add one for just about any service that you may want to access via the WAN connection but not SNMP&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sophos XG Monitoring HA</title><link>https://community.sophos.com/thread/501015?ContentTypeID=1</link><pubDate>Thu, 21 Jul 2022 07:02:47 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:33c41955-a8fd-4933-9f9c-1ecc9d84b13a</guid><dc:creator>Michael Schneider</dc:creator><description>&lt;p&gt;I did not say that there is bug. But there are alot and just wrong documentation.&lt;br /&gt;Something like this, just as one of alot examples:&lt;br /&gt;&lt;img src="/resized-image/__size/1280x960/__key/communityserver-discussions-components-files/126/pastedimage1658386877599v1.png" alt=" " /&gt;&lt;/p&gt;
&lt;p&gt;I read &amp;quot;Datatype&amp;quot; is INTEGER. Expecting a Number with Range of 0 - 2 as explained in the Note.&lt;/p&gt;
&lt;p&gt;The Actual Result is a String containing Enable, Disable&amp;nbsp;&lt;span class="emoticon" data-url="https://community.sophos.com/cfs-file/__key/system/emoji/1f600.svg" title="Grinning"&gt;&amp;#x1f600;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;You just can&amp;#39;t trust the api documentation &lt;span class="emoticon" data-url="https://community.sophos.com/cfs-file/__key/system/emoji/1f642.svg" title="Slight smile"&gt;&amp;#x1f642;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sophos XG Monitoring HA</title><link>https://community.sophos.com/thread/501011?ContentTypeID=1</link><pubDate>Thu, 21 Jul 2022 06:50:24 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:08c2e71c-e2b8-40c0-979f-28ff50dbdd91</guid><dc:creator>LuCar Toni</dc:creator><description>&lt;p&gt;I do not see the bug in your initial post. Because the API is a configuration API, not a status API. This means, you do not have access to some of those live events and status updates of certain parts of the hardware.&lt;/p&gt;
&lt;p&gt;Nevertheless, Central API will be extended by firewall API. There &amp;quot;should&amp;quot; be a HA flag in Central as well.&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sophos XG Monitoring HA</title><link>https://community.sophos.com/thread/501003?ContentTypeID=1</link><pubDate>Thu, 21 Jul 2022 06:19:21 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:ed1ed9e5-4867-4585-b1e3-c4af96bba45f</guid><dc:creator>Michael Schneider</dc:creator><description>&lt;p&gt;Hey Lucar, i will give that a shot aswell. The i am really hoping that at some point you can actually do and monitor xg&amp;#39;s via central api.&amp;nbsp;&lt;br /&gt;Thanks for the the idea. I do not like the concept of monitoring a log insteaed of of the actual current status, but i guess it is better than nothing.&lt;br /&gt;I just don&amp;#39;t understand why the sophos xg web api is lacking alot of features and there are a lot of bugs ;) Would be nice to have a single source of monitoring :)&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sophos XG Monitoring HA</title><link>https://community.sophos.com/thread/500962?ContentTypeID=1</link><pubDate>Wed, 20 Jul 2022 15:55:51 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:1e918bef-7a78-4538-943d-93fd142f9dd5</guid><dc:creator>LuCar Toni</dc:creator><description>&lt;p&gt;I would recommend to use Central for this.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Central will generate an alert specifically for degraded HA State. So you can monitor via API this particular Alert.&lt;/p&gt;
&lt;p&gt;If the alert comes up, you can call for next steps.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;See:&amp;nbsp;&lt;a href="https://developer.sophos.com/"&gt;https://developer.sophos.com/&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sophos XG Monitoring HA</title><link>https://community.sophos.com/thread/500940?ContentTypeID=1</link><pubDate>Wed, 20 Jul 2022 11:46:04 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:937de647-103e-4b5f-9f5b-aac39d8dd851</guid><dc:creator>Michael Schneider</dc:creator><description>&lt;p&gt;Thanks :) I don&amp;#39;t see the HAState metioned above until now but sophos already did &amp;quot;kill this&amp;quot; idea.&lt;br /&gt;I need a WAN side Monitoring and we disable anything on the WAN Zone. But setup a LocalACL Rule for our IP Only with https and userportal. But for whatever reason you cannot enable SNMP in a Local ACL Rule :)&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sophos XG Monitoring HA</title><link>https://community.sophos.com/thread/500937?ContentTypeID=1</link><pubDate>Wed, 20 Jul 2022 11:40:42 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:f6da1db0-e2a0-4502-870d-5b02e4d396bd</guid><dc:creator>Vivek Jagad</dc:creator><description>&lt;p&gt;Hello&amp;nbsp;&lt;a href="/members/michael-schneider"&gt;Michael Schneider&lt;/a&gt;,&lt;br /&gt;&lt;br /&gt;Here are the useful links below:&lt;br /&gt;&amp;gt;&amp;nbsp;&lt;a href="https://www.sophos.com/en-us/medialibrary/PDFs/documentation/SophosFirewall/Other-documents/SOPHOS-MIB.txt?la=en"&gt;https://www.sophos.com/en-us/medialibrary/PDFs/documentation/SophosFirewall/Other-documents/SOPHOS-MIB.txt?la=en&lt;/a&gt;&lt;br /&gt;&amp;gt;&amp;nbsp;&lt;a href="https://docs.sophos.com/nsg/sophos-firewall/18.5/Help/en-us/webhelp/onlinehelp/AdministratorHelp/Administration/SNMP/index.html#snmpv3-users-and-traps"&gt;https://docs.sophos.com/nsg/sophos-firewall/18.5/Help/en-us/webhelp/onlinehelp/AdministratorHelp/Administration/SNMP/index.html#snmpv3-users-and-traps&lt;br /&gt;&lt;/a&gt;&amp;gt;&amp;nbsp;&lt;a href="http://www.net-snmp.org/docs/mibs/index.html"&gt;http://www.net-snmp.org/docs/mibs/index.html&lt;/a&gt;&lt;br /&gt;&amp;gt;&amp;nbsp;&lt;a href="https://docs.sophos.com/nsg/sophos-firewall/17.5/Help/en-us/webhelp/onlinehelp/nsg/sfos/concepts/SNMP.html"&gt;https://docs.sophos.com/nsg/sophos-firewall/17.5/Help/en-us/webhelp/onlinehelp/nsg/sfos/concepts/SNMP.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sophos XG Monitoring HA</title><link>https://community.sophos.com/thread/500936?ContentTypeID=1</link><pubDate>Wed, 20 Jul 2022 11:32:20 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:e34eccfe-3560-4e56-8e59-7bee751a5012</guid><dc:creator>Michael Schneider</dc:creator><description>&lt;p&gt;Hi Vishai,&lt;/p&gt;
&lt;p&gt;I will give that a shot, but the hole point of me using the webapi is that i can query it via WAN which i can&amp;#39;t or well i would not love to do with snmp &lt;span class="emoticon" data-url="https://community.sophos.com/cfs-file/__key/system/emoji/1f642.svg" title="Slight smile"&gt;&amp;#x1f642;&lt;/span&gt; Dou you got any details oids for this ?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sophos XG Monitoring HA</title><link>https://community.sophos.com/thread/500935?ContentTypeID=1</link><pubDate>Wed, 20 Jul 2022 11:30:43 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:cc06b562-9686-4e04-a937-b872b3148c41</guid><dc:creator>Michael Schneider</dc:creator><description>&lt;p&gt;Hell Bharat, thank you for your time and answer. I do not actually see a way to automate this in a good way.&lt;br /&gt;I would like to activly pull a status from the device and not monitor some logs which might have a occurance of &amp;quot;xyz&amp;quot;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sophos XG Monitoring HA</title><link>https://community.sophos.com/thread/500933?ContentTypeID=1</link><pubDate>Wed, 20 Jul 2022 11:22:57 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:e6d113bc-84e5-4ab2-a352-5860b10e0da4</guid><dc:creator>Vishal_R</dc:creator><description>&lt;p&gt;Hi &lt;a href="/members/michael-schneider"&gt;Michael Schneider&lt;/a&gt;&amp;nbsp;Thank you for the detailed information. How about managing HA status alerts via SNMP? In SNMP we have HA state MIB and that will help you on your actual requirement of &amp;quot;Monitoring HA status&amp;quot;.&lt;br /&gt;&lt;br /&gt;HaState ::= TEXTUAL-CONVENTION&lt;br /&gt; STATUS current&lt;br /&gt; DESCRIPTION &amp;quot;enumerated type for HA State&amp;quot;&lt;br /&gt; SYNTAX INTEGER {&lt;br /&gt; notapplicable ( 0 ),&lt;br /&gt; auxiliary ( 1 ),&lt;br /&gt; standAlone ( 2 ),&lt;br /&gt; primary ( 3 ),&lt;br /&gt; faulty ( 4 ),&lt;br /&gt; ready ( 5 )&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sophos XG Monitoring HA</title><link>https://community.sophos.com/thread/500928?ContentTypeID=1</link><pubDate>Wed, 20 Jul 2022 10:52:52 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:e9224ef9-7c8d-47dd-a6f1-3d391cdbaf20</guid><dc:creator>Bharat J</dc:creator><description>&lt;p&gt;Hi&amp;nbsp;&lt;a href="/members/michael-schneider"&gt;Michael Schneider&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Thank you for reaching out to the community,&amp;nbsp;please verify the logs for below command to identity the issue :&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Connect to the Sophos Firewall console by using one of the following methods:
&lt;ul&gt;
&lt;li&gt;Connect by using a Secure Shell (SSH) such as PuTTY:&amp;nbsp;&lt;a href="https://support.sophos.com/support/s/article/KB-000038697"&gt;Sophos Firewall: SSH to the firewall using PuTTY utility&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Open the Console from Sophos Firewall&amp;#39;s&amp;nbsp;GUI by going to&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;b&gt;Admin&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&amp;gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;b&gt;Console&lt;/b&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Sign in and select&amp;nbsp;&lt;b&gt;5. Device Management&lt;/b&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&amp;gt;&amp;nbsp;&lt;b&gt;3. Advanced Shell&lt;/b&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span&gt;cat /log/msync.log | grep &amp;ldquo;ha:&amp;rdquo;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;code&gt;cat /log/applog.log | grep &amp;ldquo;ha:&lt;/code&gt;&amp;rdquo;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Thanks and Regards&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>