firewall interface showing administratively down

This support forum board is for support questions relating to Nagios XI, our flagship commercial network monitoring solution.
Locked
progressive.nagiosXI
Posts: 277
Joined: Mon Jul 31, 2017 5:54 am

firewall interface showing administratively down

Post by progressive.nagiosXI »

Hi team,

firewall showing administratively down in nagios from many days ,but as per client Port is up and working fine.

we are also not able to scan these interfaces via Nagios switch wizard.

Snmpwalk command output also show interface administratively down ,but as per client Internet links connected with this ports and ports are acually in UP state.
Please help how to resolve this

We also check as per below link :- Network > Interface > select problem Interface > found Link State set to Auto
https://knowledgebase.paloaltonetworks. ... 000ClZQCA0

Firewall Description :-

Code: Select all

Palo Alto Networks PA-3000 series firewall, sw version 9.0.6, hw version: 1.1
Thanks
You do not have the required permissions to view the files attached to this post.
User avatar
tgriep
Madmin
Posts: 9190
Joined: Thu Oct 30, 2014 9:02 am

Re: firewall interface showing administratively down

Post by tgriep »

You said that the Network Switch / Router wizard cannot connect to the Firewall.
Do you know if the community string was changed if using snmp version 2 or if it using snmp version 3, was any of the protocols changed or the username and password?

The snmpwalk shows that it is administratively down which matches the Nagios status.
Are the other interfaces showing the correct status when you ran the snmpwalk?

Is there a chance you can run the snmpwalk command and post or PM me the output so I can see all of the output to troubleshoot the issue?

One thing to try, have the administrators of the firewall set the link state to up and see if that resolves the issue.
Maybe the status needs to be reset on the device.
Be sure to check out our Knowledgebase for helpful articles and solutions!
progressive.nagiosXI
Posts: 277
Joined: Mon Jul 31, 2017 5:54 am

Re: firewall interface showing administratively down

Post by progressive.nagiosXI »

Hi

other interface in nagiosxi showing UP/Ok state as per client.

only interface showing admin down in Nagiosxi are in UP state as per client.

Please find attachment.

Thanks
You do not have the required permissions to view the files attached to this post.
User avatar
tgriep
Madmin
Posts: 9190
Joined: Thu Oct 30, 2014 9:02 am

Re: firewall interface showing administratively down

Post by tgriep »

The snmpwalk is showing that most of the ports are administratively down.
I suspect that the counter needs to be reset in the Palo Alto device.
Try changing the ports configuration from Auto to On and see if that resets the counter.

I found this on Palo Alto's site for the Decated-HA ports and their statuses.
https://knowledgebase.paloaltonetworks. ... 000Cm7ACAS

You said earlier, you cannot scan the device, what sort of error are to seeing?

Does the username or password have and special characters in it?
If so, what are they?

What version of Nagios XI are you running?

Also, do the following in the XI interface to make sure the Network Switch / Router Wizard is up to date.
To do that, go to the Admin > Manage Config Wizards menu.
Click on the Check for Updates button to update the list and install the updates for the wizard.
If the Wizard was updated, try running it again to see if the XI server can connect to the device.
This won't fix the administratively down issue as it looks like the issue is on the Palo Alto device, but is may allow you to connect to it again.
Be sure to check out our Knowledgebase for helpful articles and solutions!
Locked