Uploaded image for project: 'Observium'
  1. Observium
  2. OBS-4419

Sophos Firewall ipsec Interface shows other firewalls connected

Details

    • Improvement
    • Resolution: Fixed
    • Minor
    • None
    • Professional Edition
    • Default
    • None

    Description

      Hello.

      My Observium shows me the ipsec interfaces of all monitored firewalls in the ports tab, no matter if there is a site-to-site VPN or not.

      Is this behavior intended like this?

       

      Best regards

      Thomas

      Attachments

        Activity

          [OBS-4419] Sophos Firewall ipsec Interface shows other firewalls connected

          Ohh, that was incorrect fix

          Correctly fixed in r12553.

          landy Mike Stupalov added a comment - Ohh, that was incorrect fix Correctly fixed in r12553.

          sure.

          thomasschreiner Thomas Schreiner added a comment - sure.

          Hrm, can you make new screenshot?

          landy Mike Stupalov added a comment - Hrm, can you make new screenshot?

          Hello Mike.

          Thank you. The self assigned IP of the interface is now no more shown. But the ipsec interfaces on the right side of al other firewalls are still visible.

           

           

          thomasschreiner Thomas Schreiner added a comment - Hello Mike. Thank you. The self assigned IP of the interface is now no more shown. But the ipsec interfaces on the right side of al other firewalls are still visible.    

          Improved in r12545.

          landy Mike Stupalov added a comment - Improved in r12545.

          Just main reason for show this links is "same" IPv4 net, but as I see net is '/32'.. I will improve this.

          landy Mike Stupalov added a comment - Just main reason for show this links is "same" IPv4 net, but as I see net is '/32'.. I will improve this.

          Yes, but I can't even configure this IP.

          As far as I know IPSec Tunnels don't even have an IP

          169.254 (self assigned IP space) must be some kind of a dummy address.

          thomasschreiner Thomas Schreiner added a comment - Yes, but I can't even configure this IP. As far as I know IPSec Tunnels don't even have an IP 169.254 (self assigned IP space) must be some kind of a dummy address.

          all of your ipsec0 interfaces have same IP (169.254.234.5)?

          landy Mike Stupalov added a comment - all of your ipsec0 interfaces have same IP (169.254.234.5)?

          General questions and device support can be discussed in our Discord channel, click here to join.


          Please make and attach additional information about the device:

          • full snmp dump from device:

            snmpwalk -v2c -c <community> -t 3 -Cc --hexOutputLength=0 -ObentxU <hostname> .1 > myagent.snmpwalk
            snmpwalk -v2c -c <community> -t 3 -Cc --hexOutputLength=0 -ObentxU <hostname> .1.3.6.1.4.1 >> myagent.snmpwalk

            If device not support SNMP version 2c, replace -v2c with -v1.

          • If you have problems with discovery or poller processes, please do and attach these debugs:

            ./discovery.php -d -h <device>
            ./poller.php -d -h <device>

          • additionally attach device and/or vendor specific MIB files

          This comment is added automatically.

          bot Observium Bot added a comment - General questions and device support can be discussed in our Discord channel, click here to join . Please make and attach additional information about the device: full snmp dump from device: snmpwalk -v2c -c <community> -t 3 -Cc --hexOutputLength=0 -ObentxU <hostname> .1 > myagent.snmpwalk snmpwalk -v2c -c <community> -t 3 -Cc --hexOutputLength=0 -ObentxU <hostname> .1.3.6.1.4.1 >> myagent.snmpwalk If device not support SNMP version 2c, replace -v2c with -v1. If you have problems with discovery or poller processes, please do and attach these debugs: ./discovery.php -d -h <device> ./poller.php -d -h <device> additionally attach device and/or vendor specific MIB files This comment is added automatically.

          People

            landy Mike Stupalov
            thomasschreiner Thomas Schreiner
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: