VCF VPN Insight: Overview

Version: 2026.1.0.0

This page is the technical reference for VCF VPN Insight. Everything described here appears in Aria Operations once an adapter instance has been configured and a collection has completed. The first supported vendor is F5 BIG-IP APM SSL VPN; the object model is shared across vendors and carries no vendor names.

Dashboards

All dashboards are shipped inside the Management Pack, are placed in a dedicated folder named after the product, and are installed automatically with the adapter content. They are vendor-neutral: the same dashboards serve every supported VPN vendor, because they are built on the shared object model, not on vendor-specific keys.

VPN Overview

The VPN Overview dashboard is the entry point for the SSL VPN estate:

  • VPN Clusters and VPN Devices: a resource list of the clusters and their member devices, coloured by the health badge and showing availability.
  • VPN Alerts: the active alert list scoped to the objects produced by VCF VPN Insight.
  • Cluster scores: cluster_load and standby_members for the selected cluster.
  • Object relationship: a topology widget that shows how clusters, devices, gateways and the objects beneath them connect.

VPN Health

The VPN Health dashboard is a fast, whole-pack status check:

  • VPN Devices: a heatmap coloured by health, so a degrading device stands out immediately.
  • Active alert list: the alerts raised against the adapter, with severity.
  • Availability and scoreboard tiles: how many devices and gateways were collected in the last cycle.

VPN Sessions

The VPN Sessions dashboard answers who is connected and how the address pools are coping:

  • VPN Gateways: active_sessions and peak_sessions per gateway over time.
  • VPN Sessions: a table of session objects with user, source address, state and duration.
  • VPN Lease Pools: utilization, used_addresses and free_addresses per pool.
  • Overflow tile: sessions_overflow, the sessions above the per-cycle object cap, so a truncated list is never mistaken for a short one.

VPN Device Status

The VPN Device Status dashboard shows the base layer of each polled device:

  • Scoreboards and line charts per device: availability, cpu_usage, memory_usage, disk_usage and device_load.
  • Device table: failover_state, sync_state, software_version and device_type.

VPN Certificates

The VPN Certificates dashboard is the certificate renewal view:

  • Certificate table: days_until_expiration, issuer and expiration_date per certificate.
  • Bar chart: certificates sorted by days to expiry, ascending, so the nearest expiry is first.
  • Alert list: the certificate-expiry alerts.

Custom Groups

Custom Group NameDescription
VPN WorldA single container group that aggregates every object produced by VCF VPN Insight, across all vendors and all nine object kinds.
VPN ClustersVPN Devices grouped by their parent VPN Cluster. A backstop for the read-only case where the device group cannot be read and the cluster is synthesized.
VPN Devices by TypeVPN Devices filtered on the top-level device_type property: standalone or cluster member.
VPN Devices by VendorVPN Devices filtered on the top-level vendor property: F5 or Palo Alto.

Collected objects

Relationships

Object relationships

The topology is rebuilt on every collection cycle. The hierarchy is:

  • The adapter instance is the root of the hierarchy and the single API entry point. It parents the cluster.
  • VPN Cluster is the HA group or device group. It parents every VPN Device, both the polled member and its peers.
  • VPN Device is one BIG-IP member. It parents the network ports, the VPN gateways, the security policies, the virtual servers and the SSL certificates.
  • VPN Gateway terminates SSL VPN sessions. It parents the sessions and the lease pools that its clients use.
  • A VPN Session or a VPN Lease Pool that cannot be resolved to a gateway is attached to its device instead, so it stays visible rather than being orphaned.
  • A VMware VirtualMachine is an external parent of VPN Device, joined on the management address.
  • A phpIPAM IP Address is an external parent of VPN Cluster, VPN Device and VPN Port, matched on the bare management_ip property.

Relationships are never declared in the adapter schema; they are added at collection time and cleared and rebuilt each cycle, so a relationship removed at the source disappears downstream.

VPN Cluster

The HA group or device group. When the read-only account cannot read the F5 Device Group, the cluster is synthesized from the device member list, so the object always exists.

Identifiers: adapter_host, cluster_key.

Data NameTypeDescription
availabilitymetric1 when the cluster was collected, 0 when it was expected but unreachable.
management_ippropertyManagement address of the cluster (active member).
vendorpropertyF5.
modelpropertyAPM SSL VPN.
identity|namepropertyCluster name.
identity|cluster_typepropertyDevice-group type, or synthesized / standalone.
identity|cluster_ippropertyCluster management address.
identity|ha_modepropertystandalone, active/standby or active/active.
status|cluster_statusmetric1 when at least one member is reachable, otherwise 0.
status|failover_statepropertyAggregate member state: active, standby, mixed or offline.
status|sync_statepropertySynchronization state; present only when the account may read it.
status|member_countmetricNumber of members in the group.
status|standby_membersmetricNumber of members in standby.
capacity|cluster_loadmetricAverage device load of the polled members.

VPN Device

One BIG-IP in the HA group. The polled member carries the full system metrics; peer members carry properties and availability only, because their system is never read.

Identifiers: adapter_host, device_key.

Data NameTypeDescription
availabilitymetric1 when the device is present and reachable, 0 when it is offline.
management_ippropertyDevice management address.
vendorpropertyF5.
modelpropertyAPM SSL VPN.
device_typepropertystandalone or cluster member.
identity|namepropertyDevice name, the HA identity.
identity|hostnamepropertyConfigured hostname.
identity|hardware_modelpropertyHardware model.
identity|platformpropertyHardware platform.
identity|serial_numberpropertyChassis serial number.
identity|software_versionpropertyTMOS version and build.
status|failover_statepropertyactive, standby or offline.
status|sync_statepropertySynchronization state, when readable.
status|device_statuspropertyProvisioned modules of the polled device.
system|cpu_usagemetricCPU utilization.
system|memory_usagemetricMemory utilization, computed from used and total.
system|disk_usagemetricDisk utilization, computed from used and total.
system|disk_freemetricFree disk space.
system|disk_totalmetricTotal disk space.
system|disk_usedmetricUsed disk space.
system|memory_freemetricFree memory.
system|memory_totalmetricTotal memory.
system|memory_usedmetricUsed memory.
system|device_loadmetricSystem load.

VPN Port

One network interface of the polled device.

Identifiers: adapter_host, device_key, port_key.

Data NameTypeDescription
availabilitymetric1 when the interface is present and operational, 0 when it is down.
management_ippropertyPort IPv4 address, or the device management address when the port has no layer-3 address.
vendor / modelpropertyF5 / APM SSL VPN.
identity|namepropertyInterface name.
identity|typepropertyInterface type.
identity|enabledpropertyAdministrative enabled flag.
identity|speedpropertyNegotiated media speed.
identity|mtupropertyInterface MTU.
identity|uidpropertyInterface UID.
identity|commentspropertyInterface comment.
addressing|ipv4_addresspropertyIPv4 address.
addressing|ipv4_mask_lengthpropertyIPv4 mask length.
addressing|ipv6_addresspropertyIPv6 address.
addressing|ipv6_mask_lengthpropertyIPv6 mask length.
addressing|ipv6_link_localpropertyIPv6 link-local address.
addressing|ipv6_autoconfigpropertyIPv6 autoconfiguration state.
status|admin_statusmetricAdministrative state, 1 for up.
status|operational_statusmetricOperational state, 1 for up.
traffic|throughput_inmetricInbound rate derived from the cumulative bit counter.
traffic|throughput_outmetricOutbound rate derived from the cumulative bit counter.
traffic|packets_inmetricReceived packets.
traffic|packets_outmetricTransmitted packets.
traffic|errors_inmetricReceive errors.
traffic|errors_outmetricTransmit errors.

VPN Gateway

One APM network-access gateway that terminates SSL VPN sessions. This is the APM layer that the native F5 integration does not cover.

Identifiers: adapter_host, device_key, gateway_key.

Data NameTypeDescription
availabilitymetric1 when the gateway was present in the cycle.
vendor / modelpropertyF5 / APM SSL VPN.
identity|namepropertyGateway name.
identity|typepropertyResource type, network-access by default.
identity|profilepropertyBound access profile.
identity|auth_methodpropertyConfigured authentication mechanisms.
identity|enabledpropertyEnabled flag.
sessions|active_sessionsmetricActive sessions on the gateway.
sessions|peak_sessionsmetricPeak sessions, when the AVR report is available.
sessions|throughputmetricAggregate throughput derived from session byte counters.
sessions|sessions_overflowmetricSessions not listed because of the per-cycle cap.

VPN Session

One VPN user session from the analytics endpoint. Sessions beyond the configured cap are not created as objects; their count is reported on the gateway instead.

Identifiers: adapter_host, device_key, session_id.

Data NameTypeDescription
availabilitymetric1 for a session present in the analytics list.
vendor / modelpropertyF5 / APM SSL VPN.
identity|session_idpropertySession identifier.
identity|userpropertyAuthenticated user.
identity|source_ippropertyClient source address.
identity|destinationpropertyDestination.
identity|protocolpropertyProtocol.
identity|statepropertySession state.
identity|start_timepropertySession start time.
sessions|active_sessionsmetric1 when the session is active, otherwise 0.
sessions|session_countmetric1 for this session.
sessions|throughputmetricRate derived from the combined byte counters.
sessions|durationmetricSession duration.

VPN Lease Pool

One IPv4 or IPv6 address pool handed out to VPN clients. The address family distinguishes the two.

Identifiers: adapter_host, device_key, pool_key.

Data NameTypeDescription
availabilitymetric1 when the pool was present in the cycle.
vendor / modelpropertyF5 / APM SSL VPN.
identity|pool_namepropertyPool name.
identity|familypropertyipv4 or ipv6.
identity|range_startpropertyFirst address in the range.
identity|range_endpropertyLast address in the range.
identity|netmaskpropertyNetmask or prefix.
identity|gatewaypropertyPool gateway.
identity|modepropertyAllocation mode.
identity|descriptionpropertyDescription.
identity|total_addressespropertyTotal addresses, computed from the range.
utilization|used_addressesmetricAddresses in use, derived from bound sessions.
utilization|free_addressesmetricFree addresses.
utilization|utilizationmetricUsed share of the pool.

VPN Security Policy

One item of an APM access policy. The action and the zones are item-level data, so the item is the object.

Identifiers: adapter_host, device_key, policy_key.

Data NameTypeDescription
availabilitymetric1 when the item was present in the cycle.
vendor / modelpropertyF5 / APM SSL VPN.
identity|policy_namepropertyParent access-policy name.
identity|item_namepropertyPolicy item name.
identity|actionpropertyItem action.
identity|zone_frompropertySource zone.
identity|zone_topropertyDestination zone.
identity|prioritypropertyItem priority.
identity|enabledpropertyEnabled flag.
traffic|hitsmetricRule hit counter, when AVR or reports are available.
traffic|bytesmetricRule byte counter, when AVR or reports are available.

VPN Virtual Server

One LTM virtual server. On an instance where LTM is not provisioned, no objects of this kind are created and no points are emitted, rather than zero-valued ones.

Identifiers: adapter_host, device_key, vs_key.

Data NameTypeDescription
availabilitymetric1 when the virtual server is available.
vendor / modelpropertyF5 / APM SSL VPN.
identity|namepropertyVirtual server name.
identity|destinationpropertyDestination address.
identity|poolpropertyBound pool.
identity|kindpropertyObject kind.
identity|enabled_statepropertyEnabled state.
traffic|connectionsmetricCurrent client connections.
traffic|requestsmetricTotal requests.
traffic|throughputmetricRate derived from the combined bit counters.
traffic|packets_inmetricReceived packets.
traffic|packets_outmetricTransmitted packets.

SSL Certificate

One certificate file. The days-to-expiration metric is computed from the certificate's own date.

Identifiers: adapter_host, device_key, cert_key.

Data NameTypeDescription
availabilitymetric1 when the certificate file was present.
vendor / modelpropertyF5 / APM SSL VPN.
identity|namepropertyCertificate name.
identity|partitionpropertyPartition.
identity|kindpropertyCertificate kind.
identity|issuerpropertyIssuer.
identity|subjectpropertySubject.
identity|key_typepropertyKey algorithm and size.
identity|serialpropertySerial number.
identity|expiration_datepropertyExpiration date.
validity|days_until_expirationmetricWhole days until expiration.

Metric groups

The collected metrics and properties are organised into the following groups. The top-level attributes are deliberately ungrouped, because external relationships and cross-vendor filters rely on the bare keys.

GroupDescription
identityNaming and classification attributes of an object.
statusOperational and availability state.
capacityCluster load.
systemDevice CPU, memory, disk and load.
addressingPort layer-3 addressing.
trafficPort, session, virtual-server and policy counters and rates.
sessionsSession counts, peak and throughput.
utilizationLease-pool address usage.
validityCertificate days until expiration.

Alerts

The following alert definitions are shipped with the Management Pack. All are symptom-based and carry a recommendation. Thresholds are proposals and are shared across vendors, so per-vendor tuning is a single threshold edit. Because a value a target does not expose is omitted rather than zeroed, an alert cannot fire on a metric that was never measured.

AlertObjectSeverityThreshold
Device is unreachableVPN DeviceCriticalavailability ≤ 0.
Device CPU usage is highVPN DeviceWarningsystem|cpu_usage > 80.
Device CPU usage is critically highVPN DeviceCriticalsystem|cpu_usage > 90.
Device memory usage is highVPN DeviceWarningsystem|memory_usage > 80.
Device memory usage is critically highVPN DeviceCriticalsystem|memory_usage > 90.
Device disk usage is highVPN DeviceWarningsystem|disk_usage > 80.
Device disk usage is critically highVPN DeviceCriticalsystem|disk_usage > 90.
Device load is highVPN DeviceWarningsystem|device_load > 80.
Cluster has no active memberVPN ClusterCriticalstatus|failover_state = standby and status|member_count ≥ 1.
Cluster is downVPN ClusterCriticalstatus|cluster_status ≤ 0.
VPN gateway is unreachableVPN GatewayCriticalavailability ≤ 0.
Certificate is about to expireSSL CertificateWarningvalidity|days_until_expiration ≤ 30.
Certificate expires shortlySSL CertificateCriticalvalidity|days_until_expiration ≤ 14.