{
  "checks": [
    {
      "name": "Ping",
      "auto_add": true,
      "check_mode": "passive",
      "check_type": "ping",
      "parameters": {},
      "sort_order": 0,
      "value_type": "duration",
      "description": "",
      "check_config": {},
      "is_telemetry": false,
      "interpretation": null,
      "threshold_crit": null,
      "threshold_warn": null,
      "interval_seconds": 60,
      "threshold_direction": "upper",
      "is_reachability_hint": true,
      "confirmation_attempts": 1,
      "confirmation_interval_seconds": 10
    },
    {
      "name": "Uptime",
      "auto_add": true,
      "check_mode": "passive",
      "check_type": "snmp",
      "parameters": {
        "oid": "1.3.6.1.2.1.1.3.0",
        "unit": "ticks"
      },
      "sort_order": 1,
      "value_type": "gauge",
      "description": "",
      "check_config": {
        "oid": "1.3.6.1.2.1.1.3.0",
        "unit": "ticks"
      },
      "is_telemetry": false,
      "interpretation": null,
      "threshold_crit": null,
      "threshold_warn": null,
      "interval_seconds": 300,
      "threshold_direction": "upper",
      "is_reachability_hint": false,
      "confirmation_attempts": 1,
      "confirmation_interval_seconds": 10
    },
    {
      "name": "Device Snapshot (firewall)",
      "auto_add": true,
      "check_mode": "passive",
      "check_type": "snmp_table",
      "parameters": null,
      "sort_order": 5,
      "value_type": "gauge",
      "description": "",
      "check_config": {
        "snapshot_type": "firewall"
      },
      "is_telemetry": false,
      "interpretation": null,
      "threshold_crit": null,
      "threshold_warn": null,
      "interval_seconds": 300,
      "threshold_direction": "upper",
      "is_reachability_hint": false,
      "confirmation_attempts": 1,
      "confirmation_interval_seconds": 10
    },
    {
      "name": "HTTPS Mgmt",
      "auto_add": false,
      "check_mode": "passive",
      "check_type": "port",
      "parameters": {
        "port": 443
      },
      "sort_order": 6,
      "value_type": "status",
      "description": "SonicWall-Verwaltungs-UI (443). Nur aktivieren, wenn die Mgmt-UI vom Collector aus erreichbar ist.",
      "check_config": {
        "port": 443
      },
      "is_telemetry": false,
      "interpretation": null,
      "threshold_crit": null,
      "threshold_warn": null,
      "interval_seconds": 60,
      "threshold_direction": "upper",
      "is_reachability_hint": false,
      "confirmation_attempts": 1,
      "confirmation_interval_seconds": 10
    },
    {
      "name": "SonicWall — DPI-SSL Verbindungen",
      "auto_add": true,
      "check_mode": "passive",
      "check_type": "snmp",
      "parameters": null,
      "sort_order": 100,
      "value_type": "gauge",
      "description": "Aktuelle DPI-SSL-Verbindungen (.8741.1.3.5.1.0; Maximum liegt auf .3.0 — auf der TZ-470 z.B. 35000). Nur aktivieren, wenn DPI-SSL lizenziert/aktiv ist, sonst dauerhaft 0. Das Firewall-Panel zeigt DPI-SSL automatisch, sobald Verbindungen laufen.",
      "check_config": {
        "oid": "1.3.6.1.4.1.8741.1.3.5.1.0",
        "unit": "conns"
      },
      "is_telemetry": false,
      "interpretation": null,
      "threshold_crit": null,
      "threshold_warn": null,
      "interval_seconds": 60,
      "threshold_direction": "upper",
      "is_reachability_hint": false,
      "confirmation_attempts": 1,
      "confirmation_interval_seconds": 10
    },
    {
      "name": "SonicWall — RAM-Auslastung (Gen7)",
      "auto_add": true,
      "check_mode": "passive",
      "check_type": "snmp",
      "parameters": null,
      "sort_order": 100,
      "value_type": "gauge",
      "description": "RAM-Auslastung auf SonicOS 7.x — OID .8741.1.3.1.4.0 laut offizieller SonicWall-KB (240716040427050), gegen Gen7 (TZ-470) verifiziert.",
      "check_config": {
        "oid": "1.3.6.1.4.1.8741.1.3.1.4.0",
        "unit": "%"
      },
      "is_telemetry": false,
      "interpretation": null,
      "threshold_crit": 95.0,
      "threshold_warn": 85.0,
      "interval_seconds": 60,
      "threshold_direction": "upper",
      "is_reachability_hint": false,
      "confirmation_attempts": 1,
      "confirmation_interval_seconds": 10
    },
    {
      "name": "SonicWall — VPN-Tunnel-Wächter",
      "auto_add": false,
      "check_mode": "passive",
      "check_type": "snmp_row_watch",
      "parameters": null,
      "sort_order": 100,
      "value_type": "gauge",
      "description": "Überwacht EINEN bestimmten VPN-Tunnel: pro wichtigem Tunnel einmal hinzufügen und in der Konfiguration unter „Name des Eintrags\" den Policy-Namen eintragen (exakt wie in SonicOS, z.B. „VPN_Standort_X\"). Verschwindet der Tunnel aus der SA-Tabelle (= abgebaut), wird der Check CRITICAL. Ohne eingetragenen Namen bleibt er UNKNOWN.",
      "check_config": {
        "walk_oid": "1.3.6.1.4.1.8741.1.3.2.1.1.1.1",
        "label_match": "",
        "label_column_oid": "1.3.6.1.4.1.8741.1.3.2.1.1.1.14"
      },
      "is_telemetry": false,
      "interpretation": null,
      "threshold_crit": null,
      "threshold_warn": null,
      "interval_seconds": 60,
      "threshold_direction": "upper",
      "is_reachability_hint": false,
      "confirmation_attempts": 1,
      "confirmation_interval_seconds": 10
    },
    {
      "name": "SonicWall — CPU-Auslastung",
      "auto_add": true,
      "check_mode": "passive",
      "check_type": "snmp",
      "parameters": null,
      "sort_order": 1000,
      "value_type": "gauge",
      "description": "CPU-Auslastung über die sonicwallMulticoreUtilizationTable (.8741.1.3.1.8) — gemeldet wird der HEISSESTE Kern (Single-Core-Hotpath drosselt zuerst). Gegen TZ-470/SonicOS 7.3 verifiziert; der frühere Skalar sonicCurrentCPUUtil (.1.3.1.3.0) zeigt nur die Management-Plane.",
      "check_config": {
        "unit": "%",
        "walk_oid": "1.3.6.1.4.1.8741.1.3.1.8.1.2",
        "aggregate": "max",
        "label_column_oid": "1.3.6.1.4.1.8741.1.3.1.8.1.1"
      },
      "is_telemetry": false,
      "interpretation": null,
      "threshold_crit": 95.0,
      "threshold_warn": 80.0,
      "interval_seconds": 60,
      "threshold_direction": "upper",
      "is_reachability_hint": false,
      "confirmation_attempts": 1,
      "confirmation_interval_seconds": 10
    },
    {
      "name": "SonicWall — Aktive Verbindungen",
      "auto_add": true,
      "check_mode": "passive",
      "check_type": "snmp",
      "parameters": null,
      "sort_order": 1002,
      "value_type": "gauge",
      "description": "sonicCurrentConnCacheEntries — aktuelle Verbindungen in der Conn-Cache.",
      "check_config": {
        "oid": "1.3.6.1.4.1.8741.1.3.1.2.0",
        "unit": "conns"
      },
      "is_telemetry": false,
      "interpretation": null,
      "threshold_crit": null,
      "threshold_warn": null,
      "interval_seconds": 60,
      "threshold_direction": "upper",
      "is_reachability_hint": false,
      "confirmation_attempts": 1,
      "confirmation_interval_seconds": 10
    },
    {
      "name": "SonicWall — Aktive VPN-Tunnel",
      "auto_add": true,
      "check_mode": "passive",
      "check_type": "snmp",
      "parameters": null,
      "sort_order": 1003,
      "value_type": "gauge",
      "description": "Zählt aufgebaute Site-to-Site-Tunnel (eindeutige Policy-Namen in der sonicSAStatTable — die Tabelle enthält NUR aktive SAs, eine OperStatus-Spalte existiert nicht; abgebaute Tunnel verschwinden). 0 Tunnel = OK. Für \"Tunnel X muss stehen\": unteren Schwellwert auf die erwartete Mindestanzahl setzen (Richtung ist vorkonfiguriert \"lower\").",
      "check_config": {
        "unit": "Tunnel",
        "walk_oid": "1.3.6.1.4.1.8741.1.3.2.1.1.1.1",
        "aggregate": "count",
        "distinct_label": true,
        "label_column_oid": "1.3.6.1.4.1.8741.1.3.2.1.1.1.14"
      },
      "is_telemetry": false,
      "interpretation": null,
      "threshold_crit": null,
      "threshold_warn": null,
      "interval_seconds": 60,
      "threshold_direction": "lower",
      "is_reachability_hint": false,
      "confirmation_attempts": 1,
      "confirmation_interval_seconds": 10
    },
    {
      "name": "SonicWall — Verbindungs-Auslastung",
      "auto_add": true,
      "check_mode": "passive",
      "check_type": "snmp",
      "parameters": null,
      "sort_order": 1010,
      "value_type": "percent",
      "description": "Auslastung des Verbindungs-Caches in Prozent (aktuelle / maximale Verbindungen, .8741.1.3.1.2 gegen .1). Auf großen Boxen der frühste Sättigungs-Indikator.",
      "check_config": {
        "unit": "%",
        "walk_oid": "1.3.6.1.4.1.8741.1.3.1.2",
        "aggregate": "max",
        "total_walk_oid": "1.3.6.1.4.1.8741.1.3.1.1"
      },
      "is_telemetry": false,
      "interpretation": null,
      "threshold_crit": 95.0,
      "threshold_warn": 80.0,
      "interval_seconds": 60,
      "threshold_direction": "upper",
      "is_reachability_hint": false,
      "confirmation_attempts": 1,
      "confirmation_interval_seconds": 10
    },
    {
      "name": "SonicWall HA — Failover-Wächter (aktive Seriennummer)",
      "auto_add": true,
      "check_mode": "passive",
      "check_type": "snmp_string",
      "parameters": null,
      "sort_order": 1020,
      "value_type": "status",
      "description": "Seriennummer der gerade AKTIVEN Einheit (.8741.2.1.1.2.0) — der von SonicWall empfohlene Weg, HA-Failover per SNMP zu erkennen (die HA-Trap-OIDs sind nicht pollbar). Einrichtung: nach dem Anlegen die value_map mit den eigenen Seriennummern füllen, z. B. {\"<Serial-Primary>\": \"OK\", \"<Serial-Secondary>\": \"WARNING\"} — ein Failover wird dann sofort WARNING. Ohne value_map reiner Anzeige-Check.",
      "check_config": {
        "oid": "1.3.6.1.4.1.8741.2.1.1.2.0"
      },
      "is_telemetry": false,
      "interpretation": null,
      "threshold_crit": null,
      "threshold_warn": null,
      "interval_seconds": 60,
      "threshold_direction": "upper",
      "is_reachability_hint": false,
      "confirmation_attempts": 1,
      "confirmation_interval_seconds": 10
    },
    {
      "name": "SonicWall HA — Mitglieds-Status (Beta)",
      "auto_add": false,
      "check_mode": "passive",
      "check_type": "snmp_string",
      "parameters": null,
      "sort_order": 1021,
      "value_type": "status",
      "description": "⚠️ BETA/unverifiziert: HA-Mitglieds-Status (.8741.1.8.1.2.0) aus Community-Monitoring-Templates (Zabbix). Auf Geräten ohne HA bzw. je nach Firmware kann die OID leer sein (Check bleibt UNKNOWN — dann deaktivieren und Feedback im Community-Hub hinterlassen, gern mit dem Roh-Wert eures HA-Paars).",
      "check_config": {
        "oid": "1.3.6.1.4.1.8741.1.8.1.2.0"
      },
      "is_telemetry": false,
      "interpretation": null,
      "threshold_crit": null,
      "threshold_warn": null,
      "interval_seconds": 120,
      "threshold_direction": "upper",
      "is_reachability_hint": false,
      "confirmation_attempts": 1,
      "confirmation_interval_seconds": 10
    },
    {
      "name": "SonicWall HA — Sync-Status (Beta)",
      "auto_add": false,
      "check_mode": "passive",
      "check_type": "snmp_string",
      "parameters": null,
      "sort_order": 1022,
      "value_type": "status",
      "description": "⚠️ BETA/unverifiziert: HA-Synchronisations-Status (.8741.1.8.1.4.0) aus Community-Monitoring-Templates (Zabbix). Auf Geräten ohne HA bzw. je nach Firmware kann die OID leer sein (UNKNOWN → deaktivieren + Feedback im Hub).",
      "check_config": {
        "oid": "1.3.6.1.4.1.8741.1.8.1.4.0"
      },
      "is_telemetry": false,
      "interpretation": null,
      "threshold_crit": null,
      "threshold_warn": null,
      "interval_seconds": 120,
      "threshold_direction": "upper",
      "is_reachability_hint": false,
      "confirmation_attempts": 1,
      "confirmation_interval_seconds": 10
    },
    {
      "name": "SonicWall — Hardware-Sensoren (Beta)",
      "auto_add": false,
      "check_mode": "passive",
      "check_type": "snmp_table_state",
      "parameters": null,
      "sort_order": 1023,
      "value_type": "gauge",
      "description": "⚠️ BETA/unverifiziert: Sensor-Tabelle .8741.1.7.1 (Name/Typ/Status/Wert — Lüfter, Temperatur, Spannung) aus Community-Templates. Die TZ-Serie liefert diese Tabelle NICHT (dort leer/UNKNOWN); auf NSa-Geräten bitte testen. Unbekannte Status-Codes erscheinen als WARNING — Roh-Werte gern als Hub-Feedback melden.",
      "check_config": {
        "walk_oid": "1.3.6.1.4.1.8741.1.7.1.3",
        "ok_values": [
          1
        ],
        "state_labels": {
          "1": "ok"
        },
        "label_column_oid": "1.3.6.1.4.1.8741.1.7.1.1"
      },
      "is_telemetry": false,
      "interpretation": null,
      "threshold_crit": null,
      "threshold_warn": null,
      "interval_seconds": 120,
      "threshold_direction": "upper",
      "is_reachability_hint": false,
      "confirmation_attempts": 1,
      "confirmation_interval_seconds": 10
    }
  ],
  "profile": {
    "icon": "shield",
    "name": "SonicWall NSa (HA) — Beta",
    "tags": [
      "sonicwall",
      "snmp",
      "firewall",
      "vpn",
      "ha",
      "nsa",
      "beta"
    ],
    "vendor": "sonicwall",
    "category": "firewall",
    "os_family": null,
    "description": "SonicWall NSa 2700 und größer (SonicOS Gen7): alle Checks des Basis-Profils (CPU je Kern, RAM, Verbindungen, VPN-Tunnel, DPI-SSL) plus HA-Überwachung (Failover-Wächter über die Seriennummer der aktiven Einheit + HA-Status-OIDs) und Hardware-Sensoren. ⚠️ BETA: Dieses Profil ist gegen eine TZ-470 (gleiche Gen7-MIB-Welt) verifiziert, aber noch NICHT gegen eine echte NSa mit HA-Paar. Feedback über den Community-Hub ist willkommen.",
    "ip_required": true,
    "port_layout": null,
    "visual_type": "firewall_panel",
    "snmp_enabled": true,
    "agent_capable": false,
    "sysoid_patterns": null,
    "sysdescr_patterns": [
      "NSa",
      "NSA"
    ]
  },
  "scripts": [],
  "schema_version": 1
}