Probes | PRTG Manual

PRTG Manual: Probes

On the Probes tab, you can define settings for probe connections if you use remote probes.

i_podIf 15 minutes (900) seconds have passed since your last credential-based login and you open a setup page from a different setup page, PRTG asks you to enter your credentials again for security reasons. A dialog box appears. Enter your Login Name and Password and click OK to continue.

i_round_blueThis documentation refers to an administrator that accesses the PRTG web interface on a master node. Other user accounts, interfaces, or failover nodes might not have all of the options in the way described here. In a cluster, note that failover nodes are read-only by default.

In this section:

Probe Connection Settings

Probe Connection Settings

Probe Connection Settings

Setting

Description

Probe Connection IP Addresses

Define how the PRTG core server handles incoming connections from probes:

  • Local probe only, 127.0.0.1: Only accept local probe connections. The PRTG core server does not allow the use of remote probes.

i_prtgThis is the default setting in PRTG Network Monitor.

  • All IP addresses available on this computer: Accept incoming connections from remote probes, no matter on which IP address of the PRTG core server they come in.
    i_podThis is the default setting in PRTG Hosted Monitor.
  • Specify IP addresses: Accept incoming connections from remote probes only on the selected IP address(es) of the PRTG core server. In the list, enable the checkbox in front of the desired IP addresses to select an IP address.

i_round_blueYou can also change this setting in the PRTG Administration Tool on PRTG Core Server Systems.

i_round_redIf you change this setting, PRTG needs to restart the PRTG core server to apply your changes. After you click Save, a dialog box appears that asks you to confirm the restart. Click OK to trigger the restart. During the restart, all users of the PRTG web interface, the PRTG app for desktop, or the PRTG Apps for Mobile Network Monitoring are disconnected and reconnected.

i_podThis option is not available in PRTG Hosted Monitor.

Allow IP Addresses

Enter a list of remote probe IP addresses or Domain Name System (DNS) names that you want to allow to connect to the PRTG core server. Enter one IP address or DNS name per line. The following options are also possible:

  • [Empty]: An empty field does not allow any remote probes (only the local probe). Enter IP addresses or DNS names to allow remote probe connections.
    i_round_blueWe recommend that you use IP addresses instead of DNS names because DNS name resolution might be cached.
  • any: Enter the word any to automatically allow all remote probe connections.
    i_round_blueThis is the default setting when you install a classic remote probe from the device tree. We recommend that you enter the IP addresses specific to your remote probes.
    i_round_blueWe recommend that you only use this option in intranets in PRTG Network Monitor, not in PRTG Hosted Monitor.

i_round_bluePRTG always automatically allows the local probe (127.0.0.1). PRTG checks the list of allowed IP addresses before it checks the list of denied IP addresses.

i_round_blueIf the IP address of a remote probe regularly changes (for example, because of an internet provider that dynamically assigns IP addresses), enter the potential IP address range for the remote probe or use any.

i_square_cyanYou can use the PRTG syntax for IP address ranges. For more information, see section Define IP Address Ranges.

i_round_blueThis setting does not affect multi-platform probe connections.

Deny IP Addresses

Enter a list of remote probe IP addresses or DNS names that you do not want to allow to connect to the PRTG core server. Enter one IP address or DNS name per line.

i_round_blueYou can use Deny IP Addresses to explicitly deny connections from remote probes that you do not want to include in your setup either at all or for a certain time. You can also use it to allow access to an IP address range under Allow IP Addresses, but to deny access to a single IP address from the IP address range.

i_square_cyanYou can use the PRTG syntax for IP address ranges. For more information, see section Define IP Address Ranges.

i_round_blueIf you deny the IP address or DNS name of a remote probe, you must restart the PRTG core server to apply your changes.

i_round_blueWe recommend that you use IP addresses rather than DNS names because DNS name resolution might be cached.

i_round_blueThis setting does not affect multi-platform probe connections.

Deny GIDs

Enter a list of global IDs (GID). Enter one GID per line. PRTG denies access to matching GIDs.

i_round_blueIf you remove a remote probe from the device tree or if you deny a remote probe after installation, PRTG automatically adds its GID to this list. The remote probe is no longer able to connect. Denying GIDs is more precise than denying IP addresses, where other remote probes at the same location could also be excluded.

i_round_blueA GID is the ID that PRTG attributes to every probe that you include in your monitoring.

Classic Probe Settings

Classic Probe Settings

Classic Probe Settings

Setting

Description

Access Keys

Enter a list of access keys for remote probe connections. Enter one access key per line.

i_round_blueEvery remote probe that wants to connect to this PRTG installation must use one of these keys.

i_square_cyanFor more information on how to set an access key for a classic remote probe, see section PRTG Administration Tool.

i_square_cyanFor more information on how to set an access key for a multi-platform probe, see the manual: Multi-Platform Probe for PRTG.

Connection Security

Specify the security level that the PRTG web server accepts for connections to and from the PRTG core server:

  • High security (TLS 1.3, TLS 1.2): Only accept high security connections from probes.
  • Default security (TLS 1.3, TLS 1.2) (recommended): Only accept high security connections from probes.
  • Weakened security (TLS 1.3, TLS 1.2, TLS 1.1, TLS 1.0): Additionally accept TLS 1.1-secured and TLS 1.0-secured connections from probes.
    i_round_blueIf you have probes that do not support -secured or TLS 1.2-secured connections because you updated from an older PRTG version, you can use this setting to connect to and to update older probes. After the update, we recommend that you change this setting to High security (TLS 1.3, TLS 1.2) or Default security (TLS 1.3, TLS 1.2) (recommended).

i_round_blueIf you set a registry key in previous PRTG versions to override the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) version and cipher suites of PRTG web server connections or probe connections, High security (TLS 1.3, TLS 1.2) overrides the registry setting and only TLS 1.3 and TLS 1.2 are allowed. If you select Default security (TLS 1.3, TLS 1.2) (recommended), the registry value overrides this setting and the connection security that you defined in the registry applies.

i_round_redIf you change this setting, PRTG needs to restart the PRTG core server to apply your changes. After you click Save, a dialog box appears that asks you to confirm the restart. Click OK to trigger the restart. During the restart, all users of the PRTG web interface, the PRTG app for desktop, or the PRTG Apps for Mobile Network Monitoring are disconnected and reconnected.

i_podThis option is not available in PRTG Hosted Monitor.

i_round_blueThis setting does not affect multi-platform probe connections.

NATS Connection Settings

NATS Connection Settings

NATS Connection Settings

Setting

Description

NATS Connections

Define if you want to allow NATS connections to the PRTG core server:

  • Do not allow NATS connections (default): Multi-platform probes cannot connect to the PRTG core server. You cannot monitor with multi-platform probes if you select this option.
  • Allow connection via integrated NATS server (recommended): Use the integrated NATS server to connect to multi-platform probes.
  • Allow connection via remote NATS server: Use a NATS server on a different system to connect to multi-platform probes.

i_round_bluePRTG automatically creates a Multi-Platform Probe Connection Health (Autonomous) sensor on your PRTG core server when you enable NATS connections.

i_square_cyanFor more information about the multi-platform probe, see the manual: Multi-Platform Probe for PRTG.

i_round_redIf you change this setting, PRTG needs to restart the PRTG core server to apply your changes. After you click Save, a dialog box appears that asks you to confirm the restart. Click OK to trigger the restart. During the restart, all users of the PRTG web interface, the PRTG app for desktop, or the PRTG Apps for Mobile Network Monitoring are disconnected and reconnected.

NATS Server Access Identifiers

This setting is only visible if you select Allow connection via integrated NATS server (recommended) above.

Enter a list of access identifiers. An access identifier consists of a tenant ID and an NKey. Use the format tenant ID:access identifier. Each multi-platform probe that you install has a unique access identifier to connect to the NATS server. Enter one access identifier per line.

i_round_blueFor security reasons, we recommend that you use a unique tenant ID for each network section or organization. A tenant ID can be a maximum length of 36 characters and supports alphanumeric characters, underscores, and hyphens.

i_round_blueYou can add comments to help identify the access identifier in the format access identifier; comment.

NATS Connection Security

This setting is only visible if you select Allow connection via remote NATS server above.

Define the connection security level between the PRTG core server and the NATS server.

  • TLS (default): Select Transport Layer Security (TLS) for an encrypted communication channel to the NATS server. This configures the NATS connection to use the tls:// schema.
  • Unsecure (not recommended): All data sent between the PRTG core server and the NATS server, including passwords and other sensitive information, will be transmitted in plain text. The NATS connection will use the unencrypted nats:// schema.

NATS Server Host

This setting is only visible if you select Allow connection via remote NATS server above.

Enter the hostname and the port of the NATS server. An encrypted NATS server connection follows the format hostname:port. The default host is localhost:23561.

i_round_blueEnter the hostname as a fully qualified domain address name (FQDN) of the system that runs the NATS server.

i_round_blueThe default port for this connection is 23561. The NATS server supports port numbers 1-65535.

NATS Authentication

This setting is only visible if you select Allow connection via remote NATS server above.

Select how you want to authenticate against the NATS server:

  • User name and password (default): Use the NATS user name and password that you defined when you configured your NATS server.
  • NKey: Use the NKey seed that matches the user seed configured in your NATS server.
  • NATS credentials: Use your NATS credentials from the NATS credentials file.

NATS User Name

This setting is only visible if you select User name and password (default) above.

Enter the user name for authentication against the NATS server.

NATS Password

This setting is only visible if you select User name and password (default) above.

Enter the password for authentication against the NATS server.

NATS NKey

This setting is only visible if you select NKey above.

Enter the NKey seed for authentication against the NATS server. The NKey seed is prefixed with an S, for example, SUACSSL3UAHUDXKFSNVUZRF5UHPMWZ6BFDTJ7M6.

NATS Credentials

This setting is only visible if you select NATS credentials above.

Enter the NATS credentials in the NATS credentials file format to authenticate against the NATS server. The NATS credentials file includes the NATS user JWT and user NKey seed in the following format:

-----BEGIN NATS USER JWT-----
eyJ0eXAiOiJqd3QiLCJhbGciOiJlZDI1NTE5In0
------END NATS USER JWT------
 
-----BEGIN USER NKEY SEED-----
SUACSSL3UAHUDXKFSNVUZRF5UHPMWZ6BFDTJ7M6
------END USER NKEY SEED------

i_round_redEnter the NATS credentials with all headers and footers in the file.

i_round_blueWe recommend that you copy and paste it to avoid typing errors.

NATS Server Certificate Authority Handling

This setting is only visible if you select TLS (default) above.

Define the CA root certificate that signed the TLS server certificate that you used to set up the NATS server:

  • Use system certificate store (default): Find the CA root certificate from your system's certificate store.
  • Specify a certificate authority root certificate: Define a CA root certificate file.

CA Root Certificate

This setting is only visible if you select Specify a certificate authority root certificate above.

Select a CA root certificate. The CA root certificate you select must be the one that signed the TLS server certificate that your NATS server uses.

i_round_redThe certificate must be in the /cert folder in the PRTG program directory and must be in the PEM format.

Connection Log Level

This setting is only visible if you allow connections to a NATS server.

Define the log severity level of the multi-platform probe connection that will appear in the log file:

  • Error: Log critical events.
  • Warning: Log unexpected events that might result in future errors.
  • Info (default): Log events that are significant to the normal operation of the the probe adapter.
  • Debug: Log detailed events that occur during the operation of the probe adapter. Useful for identifying issues.
  • Trace: Log all events of the probe adapter.

i_round_blueThe log level decreases in severity, with Error being the highest severity and Trace being the lowest. The log file will record all logs pertaining to the selected log severity level and all higher severity levels. For example, if you select Info (default), the log file will contain logs identified as Info, Warning, and Error. If you select Debug, the log file will contain logs identified as Error, Warning, Info, and Debug.

i_round_blueYou can find the log files in the PRTG data directory: C:\ProgramData\Paessler\PRTG Network Monitor\Logs\probeadapter.

i_round_redWe recommend that you only set your level to Debug or Trace when you are troubleshooting your setup due to the large amount of logs the probe adapter generates. Treat log files created at these log levels as confidential as some logs may contain sensitive information.

More

i_square_blueKNOWLEDGE BASE

How can I create a TLS certificate?

i_square_blueOTHER MANUALS

Multi-Platform Probe for PRTG (PDF)

Others

There are some settings that you must define in the PRTG Administration Tool. For more information, see sections: