Performance monitors that help in VPN Monitoring in OpManager

OpManager allows you to monitor the critical metrics in your network and helps in maintaining the integrity of the VPN connection. There are approximately 1000 firewall templates with built-in performance metrics shipped with OpManager. Apart from those templates, listed below are a list of VPN specific performance monitors that can be associated with the device. You can also create custom monitors as per your requirements. You can find these performance monitors under Settings -> Monitoring -> Performance Monitors.

Vendor NameMonitor NameProtocolOIDDescription
CiscoTunnel In-OctetSNMP.1.3.6.1.4.1.9.9.171.1.2.3.1.19Monitors the VPN Tunnel In-Octet
CiscoTunnel Out-OctetSNMP.1.3.6.1.4.1.9.9.171.1.2.3.1.27Monitors the VPN Tunnel Out-Octet
CiscoTunnel In-PacketsSNMP.1.3.6.1.4.1.9.9.171.1.2.3.1.20Monitors the VPN Tunnel In-Packets
CiscoTunnel Out-PacketsSNMP.1.3.6.1.4.1.9.9.171.1.2.3.1.28Monitors the VPN Tunnel Out-Packets
CiscoTunnel In-Drop PacketsSNMP.1.3.6.1.4.1.9.9.171.1.2.3.1.21Monitors the VPN Tunnel In-Drop Packets
CiscoTunnel Out-Drop PacketsSNMP.1.3.6.1.4.1.9.9.171.1.2.3.1.29Monitors the VPN Tunnel Out-Drop Packets
CiscoTotal Clientless only WEB VPN sessionsSNMP(.1.3.6.1.4.1.9.9.392.1.3.38.0-.1.3.6.1.4.1.9.9.392.1.3.35.0)Total Clientless only WEB VPN Sessions
CiscoActive Web VPN sessionsSNMP.1.3.6.1.4.1.9.9.392.1.3.38.0The number of currently active Webvpn sessions.
CiscoPeak concurrent Webvpn sessionsSNMP.1.3.6.1.4.1.9.9.392.1.3.40.0The number of peak concurrent Webvpn sessions since system up.
Palo Alto NetworksGP Gateway UtilizationSNMP.1.3.6.1.4.1.25461.2.1.2.5.1.1.0Monitors the active GlobalProtect tunnels on a gateway and measures tunnel utilization. Use this metric if you use this VM-Series firewall as a VPN gateway to secure remote users.
Palo Alto NetworksGP Active TunnelsSNMP.1.3.6.1.4.1.25461.2.1.2.5.1.3.0Monitors the number of active GlobalProtect sessions on a firewall deployed as a GlobalProtect gateway. Use this metric if you use this VM-Series firewall as a VPN gateway to secure remote users. Check the datasheet for the maximum number of active tunnels supported for your firewall model.
CheckPointConnected usersSNMP.1.3.6.1.4.1.2620.1.9.5.0Number of users who are connected to AMON (Application monitor) via VPN tunnel
CheckPointVPN Decryption errorsSNMP.1.3.6.1.4.1.2620.1.2.4.2.2Monitors the VPN Decryption errors
CheckPointVPN peer tunnel stateSNMP.1.3.6.1.4.1.2620.500.9002.1.3To check the VPN Tunnels status (can also use 1.3.6.1.4.1.2620.500.9003.1.3). Append the instance (ipaddress) obtained from .1.3.6.1.4.1.2620.500.9002.1.1 to get values. Need to add in graphoidcolumninfo table. active(3), destroy(4), idle(129), phase1(130), down(131), init(132)
FortigateVPN SSL Tunnel UptimeSNMP.1.3.6.1.4.1.12356.101.12.2.4.1.6.1Monitors the Up time of SSL VPN tunnels (in secs) from the time of VPN reboot.
FortigateActive SSL VPN UsersSNMP.1.3.6.1.4.1.12356.101.12.2.3.1.2.1The current number of users logged in through SSL-VPN tunnels in the virtual domain
BarracudaVPN Tunnels countSNMP.1.3.6.1.4.1.10704.1.11Number of live client-to-site VPN tunnels
BarracudaVPN Tunnel statusSNMP.1.3.6.1.4.1.10704.1.6.1.2Monitors the VPN tunnel status
TopsecVPN-ConnectionsSNMP.1.3.6.1.4.1.14331.5.5.1.4.9.0VPN-Connections of TopSec Firewall
ZyXELVPN BandwidthSNMP.1.3.6.1.4.1.890.1.6.22.2.1.0Monitors the VPN Bandwidth

More about VPN monitoring in OpManager.