Hello,
I need to detect when VPN Ipsec tunnels goes up or down. I had a Fortigate 200D and the Fortinet Support told me this:
OID 1.3.6.1.4.1.12356.101.1.1402.6.302 is a nonstandard trap and maps to the following:
1.3.6.1.4.1.12356.101.1.1402.6.302 - .1. is the MIB for the Fortigate .1402 is the model which is the FG140 .6 is the MIBOject fgMgmt .302 is the trapprefix for fgTrapVpnTunDown fgTrapVpnTunDown NOTIFICATION-TYPE OBJECTS { fnSysSerial, sysName, fgVpnTrapLocalGateway, fgVpnTrapRemoteGateway, fgVpnTrapPhase1Name } STATUS current DESCRIPTION "The specified VPN tunnel has been brought down." ::= { fgTrapPrefix 302 }
1.3.6.1.4.1.12356.101.2.0.301 - Indicates that the specified VPN tunnel has been brought up.
in PRTG I created a SNMP Trap sensor, I put in Include Filter = bindings[1.3.6.1.4.1.12356.101.12.3.4.0] AND spectrap[301-302]
and when vpn tunnel goes UP or DOWN log this:
SpecTrap 302=vpn down 05.09.2017 11:42:15 11.71.132.1 xx.xx.xx.xx SNMPv2-SMI::enterprises.12356.101.1.2005 SNMPv2-SMI::enterprises.12356.100.1.1.1.0 = FG200D_serialnumber RFC1213-MIB::sysName.0 = FG200D-FW SNMPv2-SMI::enterprises.12356.101.12.3.2.0 = xx.xx.xx.xx (fortigate external ip) SNMPv2-SMI::enterprises.12356.101.12.3.3.0 = xx.xx.xx.xx (remote vpn client ip) SNMPv2-SMI::enterprises.12356.101.12.3.4.0 = VPNxxxxx_0 (tunnel name)
So, I need to get an email notificación when each tunnel up or down with all this info:
SMI::enterprises.12356.100.1.1.1.0 = FG200D_serialnumber RFC1213-MIB::sysName.0 = FG200D-FW SNMPv2-SMI::enterprises.12356.101.12.3.2.0 = xx.xx.xx.xx (fortigate external ip) SNMPv2-SMI::enterprises.12356.101.12.3.3.0 = xx.xx.xx.xx (remote vpn client ip) SNMPv2-SMI::enterprises.12356.101.12.3.4.0 = VPNxxxxx_0 (tunnel name)
Add comment