Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Monitoring SOPHOS XG with ZABBIX

Hello,

I monitor SOPHOS XG through ZABBIX and recently I noticed that I am not receiving HA status, we use the firewall in version 18, and this collection worked. After updating to version 19 the collection stopped.

Does anyone have an idea how to resolve this?



This thread was automatically locked due to age.
Parents Reply
  • 1. go to "configuration"

    2. go to "host"
    3. select your XG firewall
    4. click on "items"
    5. I clone one items (which item exactly to clone, I do not remember, but I do not think matter that much)
    6. then on the cloned item screen, you will see OID field, look at the beginning of this thread, Richard gave out OID # that will work, copy and paste his #,
    then that is.
    I hope the above will help. Sorry, It has been a while, I forgot exactly what I did, but if you have problem to follow my step, maybe you can google "zabbix snmp create a new item", I remembered that was how I got some of help.
Children

  • My dear, I tried to do it here and it didn't work, we have a lot of Sophos in version 19.5. We downloaded the default template and adjusted it as you went through and it didn't work.

  • 1. for the host, template = Sophos XG FW 18 SNMPV2 (should be one of zabbix template, I am using zabbix 6.0)

    2. in XG, I think you need to turn on snmp, and set community "public" and allow zabbix server to communication with XG.

    3. after you create a host, in configuration, click on "item", then clone one existing item, then modify OIDs number and rename it, you will find those info in this topic but earlier day.

    I have to tell you, even i used zabbix template, but most of items not working anyway, but I only care and monitor followings:

    1. cpu

    2. mem

    3 ping

    4 deviceHAstatus (which you need to create an item your own, see above)

    5. interface traffic

    hope will help you

  • thank you very much for your help , we managed to get all the MIB information.

    We would like an alternative regarding the collection of events IPS, AV-Detec, Botnet that are not provided by SNMP, do we have any alternative for this?

    how could collect the security information in zabbix that snmp doesn't provide? would we have any alternative API integration or security alert email collection?

  • Hi, Ronaldo de Moura;

    I only use Zabbix to monitor my XG is up or down, I am not collecting anything else.

    For event detecting alert, I assume XG will be able to send out alert email. I have not yet look into that yet.

    Sorry, not much I can help here. Good luck.