Firewall appliance monitoring is still in its early stages. We plan to continuously improve it by adding support for more firewall platforms and vendors, along with additional monitoring capabilities.
Any feedback is greatly appreciated.
Supported models
- Cisco ASA 5500 Series
- Cisco ASA 5500-X Series
- Cisco Firepower 1000 Series (FPR1010, FPR1120, FPR1140, FPR1150, ...)
- Cisco Firepower 2100 Series
- Cisco Firepower 4100 Series
- Cisco Firepower 9300 Series
- Cisco Secure Firewall appliances
- Firepower Threat Defense (FTD) deployments
Supported technology
- Port-Channel
- VLAN
- Physical ports
- HA interface (Active/Standby failover)
Monitored metrics
Interface metrics
- Data throughput [MB/sec, Mbit/sec]
- Link utilization [%]
- Packets throughput [packet/sec]
- Error packets [packet/sec]
- Discarded packets [packet/sec]
System metrics
- CPU usage [%]
- Memory usage [%]
Firewall metrics
- Active connections
- Connection rate [conn/sec]
- Max connections
- Half-open connections
- NAT translations
- Packets dropped [packet/sec]
- Firewall drops [packet/sec]
NAT metrics
- Active NAT translations
- NAT translation misses [/sec]
VPN metrics
- IPsec tunnels active
- IKE phase-1 tunnels active
- VPN sessions (AnyConnect / Remote Access)
- SSL users
- IPsec RX/TX throughput [Mbit/sec]
- IKE RX/TX throughput [Mbit/sec]
HA metrics (collected if available)
- HA role status (Active / Standby)
BGP metrics (collected if available)
- BGP peer status (up/down) per peer
- BGP updates in/out [/sec]
- BGP session established time [sec]
QoS metrics (collected if available)
- Per class-map traffic in/out [bytes/sec]
- Per class-map drops [bytes/sec]
Additional features
- Display comprehensive configuration data
- Healthcheck (HW or logical issues on ports or switches)
- Historical reporting
- Alerting: performance metrics
- Alerting: HW issues