The market is full of tools that just monitor your Palo Alto Network Firewalls. What about a platform that can go in depth and analyze, configure and give remediation steps 24/7/365? Enter indeni, a proactive platform built with predictive analysis approach for IT teams looking to not just monitor, but to optimize and build (HA) high availability networks.

Dynamic Knowledge for Palo Alto Networks:

  • Guarantee PAN FW cluster configurations are done correctly (ie: matching routing tables)
  • Optimize firewall performance (tracking CPU, number of connections, dropped packets on ports)
  • Monitor logs to prevent loss.

Keep the Clocks in Sync

You’ve gone through the trouble of configuring the use of NTP on all of your Palo Alto firewalls. It worked at the time you’ve configured it. Then, months later, while troubleshooting an issue you realize the clock is no longer set correctly. Someone must have made a change to the network that broke it.

indeni constantly tests the current NTP configurations on a gateway. If NTP fails consistently for 24 hours we alert. The reason for the 24 hour threshold is to avoid alerting for any maintenance being done on your NTP server.

Commands used: show ntp

Identify Configs Not Following Best Practices

DOC-5389 shows that a certain configuration is not recommended. The best way for you to know that is have indeni watch your configurations and compare them to the best (and worst) practices as dictated by Palo Alto Networks.

Commands used: all the show commands and several others. Data sources: live.paloaltonetworks.com

Identify failed jobs and why

Many tasks conducted on PAN-OS occur in the scope of jobs. indeni tracks the jobs, identifies failures and points you to the specific DOC file on live.paloaltonetworks.com that would help you solve the job failure. For example, DOC-7890.

Commands used: show jobs Data sources: live.paloaltonetworks.com

Know if FQDN’s Are not Resolving Correctly

If you are using fully qualified domain names (FQDNs) in your firewall configuration, you may want to know if they get resolved correctly to IP addresses. Any failures can result in traffic loss or outages. indeni will alert you when a certain FQDN cannot be resolved to an IP address.

Commands used: request system fqdn show

Identify issues before your users

  1. ALERT OF THE WEEK: GROUP ID CONFLICT DETECTED
  2. ALERT OF THE WEEK: FIREWALL IN MAINTENANCE MODE
  3. PULLING LOGS FROM PALO ALTO NETWORKS FIREWALLS: DIGGING DEEP
  4. ALERT OF THE WEEK: JOB(S) STUCK IN PENDING
  5. ALERT OF THE WEEK: RX TRAFFIC DRASTICALLY REDUCED POST FAIL OVER, POSSIBLE ARP ISSUE

 


Ready to get started?

Create a healthy network in minutes. Click here to begin your 15 day trial for Palo Alto Networks.

Free Trial