{"id":4683,"date":"2025-11-01T17:39:21","date_gmt":"2025-11-01T17:39:21","guid":{"rendered":"https:\/\/geekmungus.co.uk\/?p=4683"},"modified":"2025-11-01T17:39:22","modified_gmt":"2025-11-01T17:39:22","slug":"palo-alto-firewall-obtain-api-key","status":"publish","type":"post","link":"https:\/\/geekmungus.co.uk\/?p=4683","title":{"rendered":"Palo Alto Firewall &#8211; Obtain API Key"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">There is an available Palo Alto firewall NagiosXI check which utilises the REST API to obtain state information from the firewall, this includes things such as PSU and FAN health. The plugin uses an API Key to allow access but to ensure you only allow the minimal privileges&#8217; to get the information you need please use the below procedure.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"check_paloaltoNagiosXIMonitoringofPaloAltoFirewallviaRESTAPI-CreatetheRole\">Create the Role<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">You only need to perform this on one Firewall in the cluster (these users are replicated automatically), you also need to complete this with the local &#8220;admin&#8221; user, you can&#8217;t use your normal administrative credentials these don&#8217;t seem to see the full set of options needed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Click Device\u2192Admin Roles, then click &#8220;Add&#8221;.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Create a Role called &#8220;monitoring&#8221; with a description, then set the following options for each tab:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Web UI = All disabled.<\/li>\n\n\n\n<li>XML API = Enable &#8220;Operational Requests&#8221; then disable all other options.<\/li>\n\n\n\n<li>Command Line = None (should be set to &#8220;None&#8221;).<\/li>\n\n\n\n<li>REST API = All disabled.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The role is now ready for use.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"check_paloaltoNagiosXIMonitoringofPaloAltoFirewallviaRESTAPI-CreatetheUser\">Create the User<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Click Device\u2192Administrators, then click &#8220;Add&#8221;.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Complete the user configuration as shown below, ensure you set the &#8220;Administrator Type&#8221; to &#8220;Role Based&#8221; and select the role you just created!<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"654\" height=\"323\" src=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/11\/image-1.png\" alt=\"\" class=\"wp-image-4684\" srcset=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/11\/image-1.png 654w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/11\/image-1-300x148.png 300w\" sizes=\"auto, (max-width: 654px) 100vw, 654px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Make a note of these credentials in the department keysafe.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"check_paloaltoNagiosXIMonitoringofPaloAltoFirewallviaRESTAPI-ObtaintheAPIKey\">Obtain the API Key<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Now you have a username and password with the correct role on the Palo Alto Firewall, you need to generate a key.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Open a web browser to the following URL, you need to substitute in the FQDN, Username and Password accordingly:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>https:\/\/firewall1.domain.com\/api?type=keygen&amp;user=monitoring&amp;password=&lt;password here><\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">You should get a response as follows, which shows the API key, so take a copy of this.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"945\" height=\"220\" src=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/11\/image-2.png\" alt=\"\" class=\"wp-image-4685\" srcset=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/11\/image-2.png 945w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/11\/image-2-300x70.png 300w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/11\/image-2-768x179.png 768w\" sizes=\"auto, (max-width: 945px) 100vw, 945px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">You now have the API Key (or Token as they call it) you can use in the check.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"check_paloaltoNagiosXIMonitoringofPaloAltoFirewallviaRESTAPI-AdditionalInformation\">Additional Information<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/nagios-check-paloalto.readthedocs.io\/en\/latest\/configuration.html#token\">https:\/\/nagios-check-paloalto.readthedocs.io\/en\/latest\/configuration.html#token<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/pypi.org\/project\/check_paloalto\/\">https:\/\/pypi.org\/project\/check_paloalto\/<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>There is an available Palo Alto firewall NagiosXI check which utilises the REST API to obtain state information from the firewall, this includes things such as PSU and FAN health. The plugin uses an API Key to allow access but to ensure you only allow the minimal privileges&#8217; to get the information you need please &#8230; <a title=\"Palo Alto Firewall &#8211; Obtain API Key\" class=\"read-more\" href=\"https:\/\/geekmungus.co.uk\/?p=4683\" aria-label=\"Read more about Palo Alto Firewall &#8211; Obtain API Key\">Read more<\/a><\/p>\n","protected":false},"author":4,"featured_media":4299,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[],"class_list":["post-4683","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-palo-alto-firewall"],"_links":{"self":[{"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/4683","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4683"}],"version-history":[{"count":1,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/4683\/revisions"}],"predecessor-version":[{"id":4686,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/4683\/revisions\/4686"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/media\/4299"}],"wp:attachment":[{"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4683"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4683"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4683"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}