From 321bed23b5b7741564a04b4ffa52bef017271a7a Mon Sep 17 00:00:00 2001 From: cgagnaire Date: Wed, 18 Apr 2018 22:23:53 +0200 Subject: [PATCH] Enhance juniper ssg plugin (#959) Closes https://github.com/centreon/centreon-plugins/issues/891 * enhance juniper ssg plugin * fix key loop and hash init --- .../common/screenos/snmp/mode/listvpn.pm | 138 +++++++++++ .../common/screenos/snmp/mode/vpnstatus.pm | 223 ++++++++++++++++++ .../common/screenos/snmp/mode/vpnusage.pm | 152 ++++++++++++ network/juniper/ssg/snmp/plugin.pm | 9 +- 4 files changed, 519 insertions(+), 3 deletions(-) create mode 100644 network/juniper/common/screenos/snmp/mode/listvpn.pm create mode 100644 network/juniper/common/screenos/snmp/mode/vpnstatus.pm create mode 100644 network/juniper/common/screenos/snmp/mode/vpnusage.pm diff --git a/network/juniper/common/screenos/snmp/mode/listvpn.pm b/network/juniper/common/screenos/snmp/mode/listvpn.pm new file mode 100644 index 000000000..51cf2738b --- /dev/null +++ b/network/juniper/common/screenos/snmp/mode/listvpn.pm @@ -0,0 +1,138 @@ +# +# Copyright 2018 Centreon (http://www.centreon.com/) +# +# Centreon is a full-fledged industry-strength solution that meets +# the needs in IT infrastructure and application monitoring for +# service performance. +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. +# + +package network::juniper::common::screenos::snmp::mode::listvpn; + +use base qw(centreon::plugins::mode); + +use strict; +use warnings; + +sub new { + my ($class, %options) = @_; + my $self = $class->SUPER::new(package => __PACKAGE__, %options); + bless $self, $class; + + $self->{version} = '1.0'; + $options{options}->add_options(arguments => + { + "filter-name:s" => { name => 'filter_name' }, + }); + $self->{vpn} = {}; + + return $self; +} + +sub check_options { + my ($self, %options) = @_; + $self->SUPER::init(%options); +} + +my %map_state = (0 => 'inactive', 1 => 'active'); + +my $mapping = { + nsVpnMonVpnName => { oid => '.1.3.6.1.4.1.3224.4.1.1.1.4' }, + nsVpnMonP1State => { oid => '.1.3.6.1.4.1.3224.4.1.1.1.21', map => \%map_state }, + nsVpnMonP2State => { oid => '.1.3.6.1.4.1.3224.4.1.1.1.23', map => \%map_state }, +}; + +sub manage_selection { + my ($self, %options) = @_; + + my $snmp_result = $options{snmp}->get_multiple_table(oids => [ + { oid => $mapping->{nsVpnMonVpnName}->{oid} }, + { oid => $mapping->{nsVpnMonP1State}->{oid} }, + { oid => $mapping->{nsVpnMonP2State}->{oid} } + ], + return_type => 1, nothing_quit => 1); + foreach my $oid (keys %{$snmp_result}) { + next if ($oid !~ /^$mapping->{nsVpnMonVpnName}->{oid}\.(.*)$/); + my $instance = $1; + my $result = $options{snmp}->map_instance(mapping => $mapping, results => $snmp_result, instance => $instance); + + $result->{nsVpnMonVpnName} =~ s/\\//g; + if (defined($self->{option_results}->{filter_name}) && $self->{option_results}->{filter_name} ne '' && + $result->{nsVpnMonVpnName} !~ /$self->{option_results}->{filter_name}/) { + $self->{output}->output_add(long_msg => "skipping '" . $result->{nsVpnMonVpnName} . "': no matching filter.", debug => 1); + next; + } + + $self->{vpn}->{$instance} = { + name => $result->{nsVpnMonVpnName}, + p1state => $result->{nsVpnMonP1State}, + p2state => $result->{nsVpnMonP2State} + }; + } +} + +sub run { + my ($self, %options) = @_; + + $self->manage_selection(%options); + foreach my $instance (sort keys %{$self->{vpn}}) { + $self->{output}->output_add(long_msg => '[name = ' . $self->{vpn}->{$instance}->{name} . + "] [p1state = " . $self->{vpn}->{$instance}->{p1state} . + "] [p2state = " . $self->{vpn}->{$instance}->{p2state} . ']' + ); + } + + $self->{output}->output_add(severity => 'OK', + short_msg => 'List VPN:'); + $self->{output}->display(nolabel => 1, force_ignore_perfdata => 1, force_long_output => 1); + $self->{output}->exit(); +} + +sub disco_format { + my ($self, %options) = @_; + + $self->{output}->add_disco_format(elements => ['name', 'p1state', 'p2state']); +} + +sub disco_show { + my ($self, %options) = @_; + + $self->manage_selection(%options); + foreach my $instance (sort keys %{$self->{vpn}}) { + $self->{output}->add_disco_entry( + name => $self->{vpn}->{$instance}->{name}, + p1state => $self->{vpn}->{$instance}->{p1state}, + p2state => $self->{vpn}->{$instance}->{p2state} + ); + } +} + +1; + +__END__ + +=head1 MODE + +List VPN. + +=over 8 + +=item B<--filter-name> + +Filter by VPN (can be a regexp). + +=back + +=cut + diff --git a/network/juniper/common/screenos/snmp/mode/vpnstatus.pm b/network/juniper/common/screenos/snmp/mode/vpnstatus.pm new file mode 100644 index 000000000..d4228bcec --- /dev/null +++ b/network/juniper/common/screenos/snmp/mode/vpnstatus.pm @@ -0,0 +1,223 @@ +# +# Copyright 2018 Centreon (http://www.centreon.com/) +# +# Centreon is a full-fledged industry-strength solution that meets +# the needs in IT infrastructure and application monitoring for +# service performance. +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. +# + +package network::juniper::common::screenos::snmp::mode::vpnstatus; + +use base qw(centreon::plugins::templates::counter); + +use strict; +use warnings; + +my $instance_mode; + +sub custom_status_threshold { + my ($self, %options) = @_; + my $status = 'ok'; + my $message; + + eval { + local $SIG{__WARN__} = sub { $message = $_[0]; }; + local $SIG{__DIE__} = sub { $message = $_[0]; }; + + if (defined($instance_mode->{option_results}->{critical_status}) && $instance_mode->{option_results}->{critical_status} ne '' && + eval "$instance_mode->{option_results}->{critical_status}") { + $status = 'critical'; + } elsif (defined($instance_mode->{option_results}->{warning_status}) && $instance_mode->{option_results}->{warning_status} ne '' && + eval "$instance_mode->{option_results}->{warning_status}") { + $status = 'warning'; + } + }; + if (defined($message)) { + $self->{output}->output_add(long_msg => 'filter status issue: ' . $message); + } + + return $status; +} + +sub custom_status_output { + my ($self, %options) = @_; + + my $msg = "Phase 1 state is '" . $self->{result_values}->{p1state} . "', Phase 2 state is '" . $self->{result_values}->{p2state}; + return $msg; +} + +sub custom_status_calc { + my ($self, %options) = @_; + + $self->{result_values}->{p1state} = $options{new_datas}->{$self->{instance} . '_p1state'}; + $self->{result_values}->{p2state} = $options{new_datas}->{$self->{instance} . '_p2state'}; + $self->{result_values}->{display} = $options{new_datas}->{$self->{instance} . '_display'}; + return 0; +} + +sub custom_update_output { + my ($self, %options) = @_; + + my $msg = sprintf("Update time: %s", + $self->{result_values}->{update_time_absolute} != 0 ? centreon::plugins::misc::change_seconds(value => $self->{result_values}->{update_time_absolute}) : 0); + return $msg; +} + +sub prefix_vpn_output { + my ($self, %options) = @_; + + return "VPN '" . $options{instance_value}->{display} . "' "; +} + +sub set_counters { + my ($self, %options) = @_; + + $self->{maps_counters_type} = [ + { name => 'vpn', type => 1, cb_prefix_output => 'prefix_vpn_output', message_multiple => 'All VPN are ok' } + ]; + + $self->{maps_counters}->{vpn} = [ + { label => 'status', threshold => 0, set => { + key_values => [ { name => 'p1state' }, { name => 'p2state' }, { name => 'display' } ], + closure_custom_calc => $self->can('custom_status_calc'), + closure_custom_output => $self->can('custom_status_output'), + closure_custom_perfdata => sub { return 0; }, + closure_custom_threshold_check => $self->can('custom_status_threshold'), + } + }, + { label => 'update-time', set => { + key_values => [ { name => 'update_time'}, { name => 'display' } ], + closure_custom_output => $self->can('custom_update_output'), + perfdatas => [ + { label => 'update_time', value => 'update_time_absolute', template => '%d', + min => 0, unit => 's', label_extra_instance => 1, instance_use => 'display_absolute' }, + ], + } + }, + ]; +} + +sub new { + my ($class, %options) = @_; + my $self = $class->SUPER::new(package => __PACKAGE__, %options); + bless $self, $class; + + $self->{version} = '1.0'; + $options{options}->add_options(arguments => + { + "filter-name:s" => { name => 'filter_name' }, + "warning-status:s" => { name => 'warning_status', default => '' }, + "critical-status:s" => { name => 'critical_status', default => '%{p1state} eq "inactive" || %{p2state} eq "inactive"' }, + }); + + return $self; +} + +sub check_options { + my ($self, %options) = @_; + $self->SUPER::check_options(%options); + + $instance_mode = $self; + $self->change_macros(); +} + +sub change_macros { + my ($self, %options) = @_; + + foreach (('warning_status', 'critical_status')) { + if (defined($self->{option_results}->{$_})) { + $self->{option_results}->{$_} =~ s/%\{(.*?)\}/\$self->{result_values}->{$1}/g; + } + } +} + +my %map_state = (0 => 'inactive', 1 => 'active'); + +my $mapping = { + nsVpnMonVpnName => { oid => '.1.3.6.1.4.1.3224.4.1.1.1.4' }, + nsVpnMonP1State => { oid => '.1.3.6.1.4.1.3224.4.1.1.1.21', map => \%map_state }, + nsVpnMonP2State => { oid => '.1.3.6.1.4.1.3224.4.1.1.1.23', map => \%map_state }, + nsVpnMonUpdateTime => { oid => '.1.3.6.1.4.1.3224.4.1.1.1.40' }, +}; + +sub manage_selection { + my ($self, %options) = @_; + + $self->{vpn} = {}; + my $snmp_result = $options{snmp}->get_multiple_table(oids => [ + { oid => $mapping->{nsVpnMonVpnName}->{oid} }, + { oid => $mapping->{nsVpnMonP1State}->{oid} }, + { oid => $mapping->{nsVpnMonP2State}->{oid} }, + { oid => $mapping->{nsVpnMonUpdateTime}->{oid} }, + ], nothing_quit => 1, return_type => 1); + + foreach my $oid (keys %{$snmp_result}) { + next if ($oid !~ /^$mapping->{nsVpnMonVpnName}->{oid}\.(.*)$/); + my $instance = $1; + my $result = $options{snmp}->map_instance(mapping => $mapping, results => $snmp_result, instance => $instance); + + if (defined($self->{option_results}->{filter_name}) && $self->{option_results}->{filter_name} ne '' && + $result->{nsVpnMonVpnName} !~ /$self->{option_results}->{filter_name}/) { + $self->{output}->output_add(long_msg => "skipping '" . $result->{nsVpnMonVpnName} . "': no matching filter.", debug => 1); + next; + } + + $self->{vpn}->{$instance} = { display => $result->{nsVpnMonVpnName}, + p1state => $result->{nsVpnMonP1State}, + p2state => $result->{nsVpnMonP2State}, + update_time => $result->{nsVpnMonUpdateTime} / 100 }; + } + + if (scalar(keys %{$self->{vpn}}) <= 0) { + $self->{output}->add_option_msg(short_msg => "No vpn found."); + $self->{output}->option_exit(); + } +} + +1; + +__END__ + +=head1 MODE + +Check Juniper VPN status (NETSCREEN-VPN-MON-MIB). + +=over 8 + +=item B<--filter-name> + +Filter VPN name (can be a regexp). + +=item B<--warning-status> + +Set warning threshold for status. +Can used special variables like: %{p1state}, %{p2state} + +=item B<--critical-status> + +Set critical threshold for status (Default: '%{p1state} eq "inactive" || %{p2state} eq "inactive"'). +Can used special variables like: %{p1state}, %{p2state} + +=item B<--warning-update-time> + +Threshold warning for update time (in secondes). + +=item B<--critical-update-time> + +Threshold critical for update time (in secondes). + +=back + +=cut diff --git a/network/juniper/common/screenos/snmp/mode/vpnusage.pm b/network/juniper/common/screenos/snmp/mode/vpnusage.pm new file mode 100644 index 000000000..52187e5cc --- /dev/null +++ b/network/juniper/common/screenos/snmp/mode/vpnusage.pm @@ -0,0 +1,152 @@ +# +# Copyright 2018 Centreon (http://www.centreon.com/) +# +# Centreon is a full-fledged industry-strength solution that meets +# the needs in IT infrastructure and application monitoring for +# service performance. +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. +# + +package network::juniper::common::screenos::snmp::mode::vpnusage; + +use base qw(centreon::plugins::templates::counter); + +use strict; +use warnings; +use Digest::MD5 qw(md5_hex); + +sub prefix_vpn_output { + my ($self, %options) = @_; + + return "VPN '" . $options{instance_value}->{display} . "' "; +} + +sub set_counters { + my ($self, %options) = @_; + + $self->{maps_counters_type} = [ + { name => 'vpn', type => 1, cb_prefix_output => 'prefix_vpn_output', message_multiple => 'All VPN are ok' } + ]; + + $self->{maps_counters}->{vpn} = [ + { label => 'traffic-in', set => { + key_values => [ { name => 'traffic_in', diff => 1 }, { name => 'display' } ], + output_template => 'Traffic In: %s %s/s', + per_second => 1, output_change_bytes => 2, + perfdatas => [ + { label => 'traffic_in', value => 'traffic_in_absolute', template => '%s', + min => 0, unit => 'b/s', label_extra_instance => 1, instance_use => 'display_absolute' }, + ], + } + }, + { label => 'traffic-out', set => { + key_values => [ { name => 'traffic_out', diff => 1 }, { name => 'display' } ], + output_template => 'Traffic Out: %s %s/s', + per_second => 1, output_change_bytes => 2, + perfdatas => [ + { label => 'traffic_out', value => 'traffic_out_absolute', template => '%s', + min => 0, unit => 'b/s', label_extra_instance => 1, instance_use => 'display_absolute' }, + ], + } + }, + ]; +} + +sub new { + my ($class, %options) = @_; + my $self = $class->SUPER::new(package => __PACKAGE__, %options, statefile => 1); + bless $self, $class; + + $self->{version} = '1.0'; + $options{options}->add_options(arguments => + { + "filter-name:s" => { name => 'filter_name' }, + }); + + return $self; +} + +sub check_options { + my ($self, %options) = @_; + $self->SUPER::check_options(%options); +} + +my $mapping = { + nsVpnMonVpnName => { oid => '.1.3.6.1.4.1.3224.4.1.1.1.4' }, + nsVpnMonBytesIn => { oid => '.1.3.6.1.4.1.3224.4.1.1.1.35' }, + nsVpnMonBytesOut => { oid => '.1.3.6.1.4.1.3224.4.1.1.1.36' }, +}; + +sub manage_selection { + my ($self, %options) = @_; + + $self->{vpn} = {}; + my $snmp_result = $options{snmp}->get_multiple_table(oids => [ + { oid => $mapping->{nsVpnMonVpnName}->{oid} }, + { oid => $mapping->{nsVpnMonBytesIn}->{oid} }, + { oid => $mapping->{nsVpnMonBytesOut}->{oid} }, + ], nothing_quit => 1, return_type => 1); + + foreach my $oid (keys %{$snmp_result}) { + next if ($oid !~ /^$mapping->{nsVpnMonVpnName}->{oid}\.(.*)$/); + my $instance = $1; + my $result = $options{snmp}->map_instance(mapping => $mapping, results => $snmp_result, instance => $instance); + + if (defined($self->{option_results}->{filter_name}) && $self->{option_results}->{filter_name} ne '' && + $result->{nsVpnMonVpnName} !~ /$self->{option_results}->{filter_name}/) { + $self->{output}->output_add(long_msg => "skipping '" . $result->{nsVpnMonVpnName} . "': no matching filter.", debug => 1); + next; + } + + $self->{vpn}->{$instance} = { display => $result->{nsVpnMonVpnName}, + traffic_in => $result->{nsVpnMonBytesIn}, + traffic_out => $result->{nsVpnMonBytesOut} }; + } + + if (scalar(keys %{$self->{vpn}}) <= 0) { + $self->{output}->add_option_msg(short_msg => "No vpn found."); + $self->{output}->option_exit(); + } + + $self->{cache_name} = "juniper_ssg_" . $options{snmp}->get_hostname() . '_' . $options{snmp}->get_port() . '_' . $self->{mode} . '_' . + (defined($self->{option_results}->{filter_name}) ? md5_hex($self->{option_results}->{filter_name}) : md5_hex('all')); +} + +1; + +__END__ + +=head1 MODE + +Check Juniper VPN usage (NETSCREEN-VPN-MON-MIB). + +=over 8 + +=item B<--filter-name> + +Filter VPN name (can be a regexp). + +=item B<--warning-*> + +Threshold warning. +Can be: 'traffic-in', 'traffic-out'. + +=item B<--critical-*> + +Threshold critical. +Can be: 'traffic-in', 'traffic-out'. + +=back + +=cut diff --git a/network/juniper/ssg/snmp/plugin.pm b/network/juniper/ssg/snmp/plugin.pm index 460b41dbc..74b3189fe 100644 --- a/network/juniper/ssg/snmp/plugin.pm +++ b/network/juniper/ssg/snmp/plugin.pm @@ -32,11 +32,14 @@ sub new { $self->{version} = '1.0'; %{$self->{modes}} = ( 'cpu' => 'network::juniper::common::screenos::snmp::mode::cpu', + 'hardware' => 'network::juniper::common::screenos::snmp::mode::hardware', + 'interfaces' => 'snmp_standard::mode::interfaces', + 'list-interfaces' => 'snmp_standard::mode::listinterfaces', + 'list-vpn' => 'network::juniper::common::screenos::snmp::mode::listvpn', 'memory' => 'network::juniper::common::screenos::snmp::mode::memory', 'sessions' => 'network::juniper::common::screenos::snmp::mode::sessions', - 'hardware' => 'network::juniper::common::screenos::snmp::mode::hardware', - 'interfaces' => 'snmp_standard::mode::interfaces', - 'list-interfaces' => 'snmp_standard::mode::listinterfaces', + 'vpn-status' => 'network::juniper::common::screenos::snmp::mode::vpnstatus', + 'vpn-usage' => 'network::juniper::common::screenos::snmp::mode::vpnusage', ); return $self;