title: Palo Alto: IPSec Tunnels (XML API)
agents: palo_alto_api
catalog: hw/network/palo_alto
license: GPLv3
distribution: kuhn-ruess
description:
 This check monitors the IPSec tunnels of a Palo Alto Networks firewall.

 The special agent {agent_palo_alto_api} lists the IPSec security associations
 through the PAN-OS XML API ({show vpn ipsec-sa}) and, unless disabled, fetches
 the negotiated cipher of each tunnel. The service reports the tunnel state, the
 peer address and the cipher, together with the local address, tunnel and outer
 interface, tunnel monitoring and gateway id as details.

 The service is {OK} while the tunnel state is {active}. Any other state is
 reported with the configurable monitoring state (default {CRIT}).

item:
 The name of the IPSec security association as returned by the firewall
 (usually {tunnel-name:proxy-id}).

discovery:
 One service is created for each IPSec security association.
