VCF VPN Insight: Overview
Version: 2026.1.0.0
This page is the technical reference for VCF VPN Insight. Everything described here appears in Aria Operations once an adapter instance has been configured and a collection has completed. The first supported vendor is F5 BIG-IP APM SSL VPN; the object model is shared across vendors and carries no vendor names.
Dashboards
All dashboards are shipped inside the Management Pack, are placed in a dedicated folder named after the product, and are installed automatically with the adapter content. They are vendor-neutral: the same dashboards serve every supported VPN vendor, because they are built on the shared object model, not on vendor-specific keys.
VPN Overview
The VPN Overview dashboard is the entry point for the SSL VPN estate:
- VPN Clusters and VPN Devices: a resource list of the clusters and their member devices, coloured by the health badge and showing
availability. - VPN Alerts: the active alert list scoped to the objects produced by VCF VPN Insight.
- Cluster scores:
cluster_loadandstandby_membersfor the selected cluster. - Object relationship: a topology widget that shows how clusters, devices, gateways and the objects beneath them connect.
VPN Health
The VPN Health dashboard is a fast, whole-pack status check:
- VPN Devices: a heatmap coloured by health, so a degrading device stands out immediately.
- Active alert list: the alerts raised against the adapter, with severity.
- Availability and scoreboard tiles: how many devices and gateways were collected in the last cycle.
VPN Sessions
The VPN Sessions dashboard answers who is connected and how the address pools are coping:
- VPN Gateways:
active_sessionsandpeak_sessionsper gateway over time. - VPN Sessions: a table of session objects with user, source address, state and duration.
- VPN Lease Pools:
utilization,used_addressesandfree_addressesper pool. - Overflow tile:
sessions_overflow, the sessions above the per-cycle object cap, so a truncated list is never mistaken for a short one.
VPN Device Status
The VPN Device Status dashboard shows the base layer of each polled device:
- Scoreboards and line charts per device:
availability,cpu_usage,memory_usage,disk_usageanddevice_load. - Device table:
failover_state,sync_state,software_versionanddevice_type.
VPN Certificates
The VPN Certificates dashboard is the certificate renewal view:
- Certificate table:
days_until_expiration,issuerandexpiration_dateper certificate. - Bar chart: certificates sorted by days to expiry, ascending, so the nearest expiry is first.
- Alert list: the certificate-expiry alerts.
Custom Groups
| Custom Group Name | Description |
|---|---|
| VPN World | A single container group that aggregates every object produced by VCF VPN Insight, across all vendors and all nine object kinds. |
| VPN Clusters | VPN Devices grouped by their parent VPN Cluster. A backstop for the read-only case where the device group cannot be read and the cluster is synthesized. |
| VPN Devices by Type | VPN Devices filtered on the top-level device_type property: standalone or cluster member. |
| VPN Devices by Vendor | VPN Devices filtered on the top-level vendor property: F5 or Palo Alto. |
Collected objects
Relationships
The topology is rebuilt on every collection cycle. The hierarchy is:
- The adapter instance is the root of the hierarchy and the single API entry point. It parents the cluster.
- VPN Cluster is the HA group or device group. It parents every VPN Device, both the polled member and its peers.
- VPN Device is one BIG-IP member. It parents the network ports, the VPN gateways, the security policies, the virtual servers and the SSL certificates.
- VPN Gateway terminates SSL VPN sessions. It parents the sessions and the lease pools that its clients use.
- A VPN Session or a VPN Lease Pool that cannot be resolved to a gateway is attached to its device instead, so it stays visible rather than being orphaned.
- A VMware VirtualMachine is an external parent of VPN Device, joined on the management address.
- A phpIPAM IP Address is an external parent of VPN Cluster, VPN Device and VPN Port, matched on the bare
management_ipproperty.
Relationships are never declared in the adapter schema; they are added at collection time and cleared and rebuilt each cycle, so a relationship removed at the source disappears downstream.
VPN Cluster
The HA group or device group. When the read-only account cannot read the F5 Device Group, the cluster is synthesized from the device member list, so the object always exists.
Identifiers: adapter_host, cluster_key.
| Data Name | Type | Description |
|---|---|---|
availability | metric | 1 when the cluster was collected, 0 when it was expected but unreachable. |
management_ip | property | Management address of the cluster (active member). |
vendor | property | F5. |
model | property | APM SSL VPN. |
identity|name | property | Cluster name. |
identity|cluster_type | property | Device-group type, or synthesized / standalone. |
identity|cluster_ip | property | Cluster management address. |
identity|ha_mode | property | standalone, active/standby or active/active. |
status|cluster_status | metric | 1 when at least one member is reachable, otherwise 0. |
status|failover_state | property | Aggregate member state: active, standby, mixed or offline. |
status|sync_state | property | Synchronization state; present only when the account may read it. |
status|member_count | metric | Number of members in the group. |
status|standby_members | metric | Number of members in standby. |
capacity|cluster_load | metric | Average device load of the polled members. |
VPN Device
One BIG-IP in the HA group. The polled member carries the full system metrics; peer members carry properties and availability only, because their system is never read.
Identifiers: adapter_host, device_key.
| Data Name | Type | Description |
|---|---|---|
availability | metric | 1 when the device is present and reachable, 0 when it is offline. |
management_ip | property | Device management address. |
vendor | property | F5. |
model | property | APM SSL VPN. |
device_type | property | standalone or cluster member. |
identity|name | property | Device name, the HA identity. |
identity|hostname | property | Configured hostname. |
identity|hardware_model | property | Hardware model. |
identity|platform | property | Hardware platform. |
identity|serial_number | property | Chassis serial number. |
identity|software_version | property | TMOS version and build. |
status|failover_state | property | active, standby or offline. |
status|sync_state | property | Synchronization state, when readable. |
status|device_status | property | Provisioned modules of the polled device. |
system|cpu_usage | metric | CPU utilization. |
system|memory_usage | metric | Memory utilization, computed from used and total. |
system|disk_usage | metric | Disk utilization, computed from used and total. |
system|disk_free | metric | Free disk space. |
system|disk_total | metric | Total disk space. |
system|disk_used | metric | Used disk space. |
system|memory_free | metric | Free memory. |
system|memory_total | metric | Total memory. |
system|memory_used | metric | Used memory. |
system|device_load | metric | System load. |
VPN Port
One network interface of the polled device.
Identifiers: adapter_host, device_key, port_key.
| Data Name | Type | Description |
|---|---|---|
availability | metric | 1 when the interface is present and operational, 0 when it is down. |
management_ip | property | Port IPv4 address, or the device management address when the port has no layer-3 address. |
vendor / model | property | F5 / APM SSL VPN. |
identity|name | property | Interface name. |
identity|type | property | Interface type. |
identity|enabled | property | Administrative enabled flag. |
identity|speed | property | Negotiated media speed. |
identity|mtu | property | Interface MTU. |
identity|uid | property | Interface UID. |
identity|comments | property | Interface comment. |
addressing|ipv4_address | property | IPv4 address. |
addressing|ipv4_mask_length | property | IPv4 mask length. |
addressing|ipv6_address | property | IPv6 address. |
addressing|ipv6_mask_length | property | IPv6 mask length. |
addressing|ipv6_link_local | property | IPv6 link-local address. |
addressing|ipv6_autoconfig | property | IPv6 autoconfiguration state. |
status|admin_status | metric | Administrative state, 1 for up. |
status|operational_status | metric | Operational state, 1 for up. |
traffic|throughput_in | metric | Inbound rate derived from the cumulative bit counter. |
traffic|throughput_out | metric | Outbound rate derived from the cumulative bit counter. |
traffic|packets_in | metric | Received packets. |
traffic|packets_out | metric | Transmitted packets. |
traffic|errors_in | metric | Receive errors. |
traffic|errors_out | metric | Transmit errors. |
VPN Gateway
One APM network-access gateway that terminates SSL VPN sessions. This is the APM layer that the native F5 integration does not cover.
Identifiers: adapter_host, device_key, gateway_key.
| Data Name | Type | Description |
|---|---|---|
availability | metric | 1 when the gateway was present in the cycle. |
vendor / model | property | F5 / APM SSL VPN. |
identity|name | property | Gateway name. |
identity|type | property | Resource type, network-access by default. |
identity|profile | property | Bound access profile. |
identity|auth_method | property | Configured authentication mechanisms. |
identity|enabled | property | Enabled flag. |
sessions|active_sessions | metric | Active sessions on the gateway. |
sessions|peak_sessions | metric | Peak sessions, when the AVR report is available. |
sessions|throughput | metric | Aggregate throughput derived from session byte counters. |
sessions|sessions_overflow | metric | Sessions not listed because of the per-cycle cap. |
VPN Session
One VPN user session from the analytics endpoint. Sessions beyond the configured cap are not created as objects; their count is reported on the gateway instead.
Identifiers: adapter_host, device_key, session_id.
| Data Name | Type | Description |
|---|---|---|
availability | metric | 1 for a session present in the analytics list. |
vendor / model | property | F5 / APM SSL VPN. |
identity|session_id | property | Session identifier. |
identity|user | property | Authenticated user. |
identity|source_ip | property | Client source address. |
identity|destination | property | Destination. |
identity|protocol | property | Protocol. |
identity|state | property | Session state. |
identity|start_time | property | Session start time. |
sessions|active_sessions | metric | 1 when the session is active, otherwise 0. |
sessions|session_count | metric | 1 for this session. |
sessions|throughput | metric | Rate derived from the combined byte counters. |
sessions|duration | metric | Session duration. |
VPN Lease Pool
One IPv4 or IPv6 address pool handed out to VPN clients. The address family distinguishes the two.
Identifiers: adapter_host, device_key, pool_key.
| Data Name | Type | Description |
|---|---|---|
availability | metric | 1 when the pool was present in the cycle. |
vendor / model | property | F5 / APM SSL VPN. |
identity|pool_name | property | Pool name. |
identity|family | property | ipv4 or ipv6. |
identity|range_start | property | First address in the range. |
identity|range_end | property | Last address in the range. |
identity|netmask | property | Netmask or prefix. |
identity|gateway | property | Pool gateway. |
identity|mode | property | Allocation mode. |
identity|description | property | Description. |
identity|total_addresses | property | Total addresses, computed from the range. |
utilization|used_addresses | metric | Addresses in use, derived from bound sessions. |
utilization|free_addresses | metric | Free addresses. |
utilization|utilization | metric | Used share of the pool. |
VPN Security Policy
One item of an APM access policy. The action and the zones are item-level data, so the item is the object.
Identifiers: adapter_host, device_key, policy_key.
| Data Name | Type | Description |
|---|---|---|
availability | metric | 1 when the item was present in the cycle. |
vendor / model | property | F5 / APM SSL VPN. |
identity|policy_name | property | Parent access-policy name. |
identity|item_name | property | Policy item name. |
identity|action | property | Item action. |
identity|zone_from | property | Source zone. |
identity|zone_to | property | Destination zone. |
identity|priority | property | Item priority. |
identity|enabled | property | Enabled flag. |
traffic|hits | metric | Rule hit counter, when AVR or reports are available. |
traffic|bytes | metric | Rule byte counter, when AVR or reports are available. |
VPN Virtual Server
One LTM virtual server. On an instance where LTM is not provisioned, no objects of this kind are created and no points are emitted, rather than zero-valued ones.
Identifiers: adapter_host, device_key, vs_key.
| Data Name | Type | Description |
|---|---|---|
availability | metric | 1 when the virtual server is available. |
vendor / model | property | F5 / APM SSL VPN. |
identity|name | property | Virtual server name. |
identity|destination | property | Destination address. |
identity|pool | property | Bound pool. |
identity|kind | property | Object kind. |
identity|enabled_state | property | Enabled state. |
traffic|connections | metric | Current client connections. |
traffic|requests | metric | Total requests. |
traffic|throughput | metric | Rate derived from the combined bit counters. |
traffic|packets_in | metric | Received packets. |
traffic|packets_out | metric | Transmitted packets. |
SSL Certificate
One certificate file. The days-to-expiration metric is computed from the certificate's own date.
Identifiers: adapter_host, device_key, cert_key.
| Data Name | Type | Description |
|---|---|---|
availability | metric | 1 when the certificate file was present. |
vendor / model | property | F5 / APM SSL VPN. |
identity|name | property | Certificate name. |
identity|partition | property | Partition. |
identity|kind | property | Certificate kind. |
identity|issuer | property | Issuer. |
identity|subject | property | Subject. |
identity|key_type | property | Key algorithm and size. |
identity|serial | property | Serial number. |
identity|expiration_date | property | Expiration date. |
validity|days_until_expiration | metric | Whole days until expiration. |
Metric groups
The collected metrics and properties are organised into the following groups. The top-level attributes are deliberately ungrouped, because external relationships and cross-vendor filters rely on the bare keys.
| Group | Description |
|---|---|
identity | Naming and classification attributes of an object. |
status | Operational and availability state. |
capacity | Cluster load. |
system | Device CPU, memory, disk and load. |
addressing | Port layer-3 addressing. |
traffic | Port, session, virtual-server and policy counters and rates. |
sessions | Session counts, peak and throughput. |
utilization | Lease-pool address usage. |
validity | Certificate days until expiration. |
Alerts
The following alert definitions are shipped with the Management Pack. All are symptom-based and carry a recommendation. Thresholds are proposals and are shared across vendors, so per-vendor tuning is a single threshold edit. Because a value a target does not expose is omitted rather than zeroed, an alert cannot fire on a metric that was never measured.
| Alert | Object | Severity | Threshold |
|---|---|---|---|
| Device is unreachable | VPN Device | Critical | availability ≤ 0. |
| Device CPU usage is high | VPN Device | Warning | system|cpu_usage > 80. |
| Device CPU usage is critically high | VPN Device | Critical | system|cpu_usage > 90. |
| Device memory usage is high | VPN Device | Warning | system|memory_usage > 80. |
| Device memory usage is critically high | VPN Device | Critical | system|memory_usage > 90. |
| Device disk usage is high | VPN Device | Warning | system|disk_usage > 80. |
| Device disk usage is critically high | VPN Device | Critical | system|disk_usage > 90. |
| Device load is high | VPN Device | Warning | system|device_load > 80. |
| Cluster has no active member | VPN Cluster | Critical | status|failover_state = standby and status|member_count ≥ 1. |
| Cluster is down | VPN Cluster | Critical | status|cluster_status ≤ 0. |
| VPN gateway is unreachable | VPN Gateway | Critical | availability ≤ 0. |
| Certificate is about to expire | SSL Certificate | Warning | validity|days_until_expiration ≤ 30. |
| Certificate expires shortly | SSL Certificate | Critical | validity|days_until_expiration ≤ 14. |
