LM with CLoudgenic (Palo Alto Prisma SD-WAN) API support?
Recently started our journey with LM and we use Cloudgenix as our SD-WAN. We set up the NetScan using the Cloudgenix Groovy script provided by LM Support, but seems to only discover 240 devices of our 268, and after the scan runs, only minimal data is discovered on the ION's which then show dead.
Is anyone successfully using the Cloudgenix NetScan successfully?
Nick_Ellson
Posted 4 years ago·Last reply 3 years ago
19 comments
Nick_Ellson
OP3 years agoAh well.. we have another road block in our success path. As Cloudgenix Customer #1 (were using them before they came out of beta) we are established in their hood.cloudgenix.com portal structure. Can't make use of the Palo Alto SASE API until all our data is copied over to Palo Servers in May 2023...
LM User
·3 years agoYep, was just talking with one of my noc guys who said, "LogicMonitor found another one we didn't even know about"
Nick_Ellson
OP3 years agoGotta say, after 3 years of nearly NO monitoring.. having over 1,000 instances of stuff per device LM looks at is a dream... Turned over so many rocks it feels like I ran through a quarry of shale with bare feet..
Nick_Ellson
OP3 years agoI can imagine as a Monitoring solution for multiple tenancy that things are bit more dicey. Worst case for my crew is we mess up an escalation chain and we get 100's of tickets instead of 10. Fortunately the ticketing system has bulk delete ?
LM User
·3 years agoHa, we've already gone to production and the only time things are clean are the first 59 seconds after i onboard a customer's devices.
Nick_Ellson
OP3 years agoWe are still in our Pro Services engagement for turn up, so I am addeding and deleting things daily to figure out what might break next ? It's a sea of red triangles man, a sea of them.
LM User
·3 years agoMust be nice not to
when you make a change in your portal.
Nick_Ellson
OP3 years agoAs this is a "monitoring" solution, testing stuff in Prod is perfectly fine with us at Columbia. LM hasn't gone Prod yet in our environment either, so no harm in a few thousand accidental alerts ?
Nick_Ellson
OP3 years agoSame.. haven't had an ION in our lab portal is years.. will see if Palo will issue some eval's for VM's perhaps..
LM User
·3 years agoYeah, sandbox portal doesn't have customer devices in it, so no dice for mine.
Patrick Rouse
·3 years agoHi, @Nick Ellsonand @Stuart Weenig. I just sent you both instructions/requirements for configuring your sandbox portal for Prisma SD-WAN LogicModule R&D. Please reply to the email I sent you with any questions you might have, or send me a meeting invitation if you'd like to have a discussion.
Thanks so much.
Nick_Ellson
OP3 years agoTo add some context to what we have achieved with other integrations with Cloudgenix in the past:
The Topology API contains the necessary information at a site level to show all of the VPN Fabric connections and their status. When posting for a particular Site ID, you obtain a list of several "Types" of topology. For making Topology maps for use in mapping your SD-WAN, you look for the type "vpn". This will give you source and destination nodes to make pretty maps of the underlaying fabric from spokes to hubs, or spokes to spokes.
But for connectivity validation, using the status of the type: "internet-stub" you get a better idea of your ISP's validity at each location that goes beyond just Link Up/Down on any particular ION's interface. It is a direct representation of the SWI's ability to connect to the portal itself and is also used by Cloudgenix for use in making pathing decisions. This is what the Topo_App from ebob9 in github is doing to provide this data via synthetic web transactions so that basic monitoring tools like Thousand Eyes or Solarwinds can monitor this data.
Having LM do this directly via the portal API is a great advantage to us as it eliminates the middleware portion of our current monitoring.
LM User
·3 years agoSure, I'm in.
Nick_Ellson
OP3 years agoYou know I love me some R&D. Sign me up.
Patrick Rouse
·3 years agoThanks @Nick Ellsonand @Stuart Weenig. For awareness, we've recently published this public support article and are actively developing against Palo Alto Networks' Unified SASE SD-WAN API. Additionally, in release 177 we released updated Isilon LogicModules that explicitly exclude Cloudgenix ION OIDs from the AppliesTo logic, as previously the Isilon DataSources were getting applied to some CloudGenix ION devices and causing excessive Isilon DataSources Instances for CloudGenix devices.
https://www.logicmonitor.com/support/palo-alto-prisma-sd-wan-monitoring
If you would like to participate in the R&D of the next set of Palo Alto Prisma SD-WAN LogicModules, please feel free to reach out directly to me or to your Customer Success Manager, as this work is active and "aims" to conclude in December.
For those that might not want to click on URLs, attached is the current summary. As we update Palo Alto Prisma SD-WAN and CloudGenix ION monitoring support we'll update this page. However, currently we provide monitoring support for the following ION Series:
Nick_Ellson
OP4 years agoIn this case I do need LM to fix their integration. I have written quite a bit to the Cloudgenix API, used it to get all my controller interfaces to feed to the SNMP scanner, and discovered the issue where my controllers use DHCP so they tend to move around. This was why I needed the integration.
I'll update as LM Devs update me.
LM User
·4 years agoIt's a solvable problem. I wouldn't wait on LM to fix it though. Dig into the cloudgenix api to see if you can get the data.
Nick_Ellson
OP4 years agoHey Stuart,
Yeah, in our case we have an ION 2K at 268 retail installations where the controller port is DHCP so that we can easily crash cart the store if the manager moves a cable direct to the ISP Modem. So we need that as DHCP. Having LM be able to parse the portal to not only get ION information, but direct SWI status from the portal via our local collector was one of the reasons we chose LM over Solar Winds. But looks like it's currently busted with a few other customers in line with us, so yay, we are not alone! ?
LM User
·4 years agoWe are monitoring ion 9000's, but we didn't use netscan since we're just monitoring the devices using a local collector and had all the IP addresses.