Kaseya VSA Integration Guide

Kaseya VSA is an RMM (Remote Monitoring and Management) tool used commonly among MSPs (Management Service Providers). RMM agents are installed on MSP customer endpoints to discover IT assets and remotely monitor and manage them.

This document describes how to use Kaseya VSA to discover and monitor a WatchGuard Firebox.

Platform and Software

The hardware and software used to complete the steps outlined in this document include:

  • Firebox installed with Fireware v12.8.2 or higher
  • Kaseya version VSA 9.5.14 (web login)
  • Probe installed on Windows 10 Education

Test Topology and Workflow

This diagram shows the test topology used in this integration:

Screen shot of Kaseya VSA topology with Firebox

Set Up the Firebox

You must configure the SNMP settings on the WatchGuard Firebox before you use Kaseya VSA to discover it.

To configure the SNMP settings on the Firebox:

  1. Log in to Fireware Web UI (https://<your Firebox IP address>:8080).
  2. Select System > SNMP.

  1. From the Version drop-down list, select v3.
  2. From the Authentication Protocol drop-down list, select SHA1.
  3. In the Password and Confirm text boxes, type the authentication password.
  4. From the Privacy Protocol drop-down list, select DES.
  5. In the Password and Confirm text boxes, type the encryption password.
  6. In the User Name text box, type WatchGuard.
  7. Keep other settings as the default values.
  8. Click Save.
  9. Select Firewall > Firewall Policies.
  10. Add an SNMP packet filter policy for traffic from Any-Trusted to Firebox.
    If you connect to an optional interface, specify Any-Optional instead of Any-Trusted.

Screen shot of SNMP packet filter policy

Set Up Kaseya

Deploy an Agent

To deploy an agent:

  1. Log in to Kaseya VSA as an administrator.

Screen shot of the Kaseya VSA Manage Packages page

  1. Download and install the Kaseya Agent on a probe computer. This computer must be in a LAN that connects to the WatchGuard Firebox.
    Each installed agent is assigned a unique VSA machine ID/group ID/organization ID. The Machine ID can be created automatically at the agent install time or individually prior to the agent installation.

Screen shot of Kaseya Discovery By Agent page

  1. In the left navigation bar, select Discovery > Networks > By Agent.
    The Probe computer shows on this page.

Create a New Network

To create a new network:

  1. In the left navigation bar, select Discovery > Networks > By Network.
  2. Click New to add a new network.

Screen shot of Kaseya New Network page

  1. In the Network Name text box, type your network name.
  2. In the Probe* text box, select the probe agent you deployed in the Deploy an Agent section.
  3. In the IP Scan Range text box, type the range of IP addresses include the probe machine and Firebox.
    • By default, the entire scan range configured for a network is specified. Example: 192.168.32-35.0-255
    • Multiple IP ranges separated by commas are supported. Example: 192.168.32-35.0-255, 10.10.14-15.0-255
  4. (Optional) In the IP Exclusions text box, type the exclusive IP address range.
  5. In the Organization* drop-down list, select your organization.
  6. Select the Alerts Active check box.
  7. Select the Monitor Network check box.
  8. Select the SNMP tab.

Screenshot of Kaseya New Network SNMP tab

  1. Select the Enable SNMP check box.
  2. Keep the Community String text box empty.
  3. Click Save.

Set Up SNMP Credentials

To set up SNMP Credentials:

  1. In the left navigation bar, select Network Monitor > Monitoring > View > group (KNM).

Screen shot of Kaseya Network Monitor

  1. Click Edit.

Screen shot of the Edit Group page Authentication tab

  1. Select the Authentication tab.
  2. For SNMP version, select SNMP v3.
  3. Configure the same SNMP authentication method, encryption method, and credentials that you configured in the Set Up the Firebox section.
  4. Click Save.

Screenshot of Discovery Networks By Network page

  1. To start the scan, select Discovery > Networks > By Network > Scan Now.
  2. To see discovered devices, select Discovery > Summary > Discovered Devices . In this example, The Fireboxes were discovered because the Firebox on this LAN is configured with SNMP enabled.

To install the gateway, make sure the discovered devices have the same Network as the Probe agent .

Screen shot of Discovered Devices page

  1. Select the Firebox. Click Make Asset.

Install the Gateway

To install the gateway:

  1. In the left navigation bar, select Network Monitor > Monitoring > View .

Screen shot of the Kaseya Network Monitor View panel

  1. Select Gateway (WGTest).

Screen shot of the Assets tab

  1. Select Install Gateway.

Screen shot of Install gateway Settings tab

  1. From the Select Agent drop-down list, select the agent probe you deployed in the Deploy an Agent section.
  2. Click Save.
    When the gateway installation completes, the Monitoring > View panel shows green check marks.

Screen shot of the Kaseya Network Monitor View panel

Apply the Template and Add Monitors

To apply the template and add monitors:

  1. In the View panel, select the Firebox.

Screen shot of the View panel

Screen shot of the Commands section

  1. In the Commands section, click Apply Template.

Screen shot of the Select template to apply page

  1. Select the WatchGuard XTM template.

Screen shot of the Apply Template Settings tab

  1. Click Proceed.
    The new attributes show for the Firebox.

Screen shot of the Assets tab

  1. Select the Firebox.

Screen shot of the Commands section

  1. In the Commands section, click Add new monitor.

Screen shot of the Select Monitor page

  1. Select SNMP > SNMP > Add monitor.

Screen shot of the Basic tab

  1. Configure the Object Identifier (OID). You can type the OID or select it from the MIB tree. If the OID value is a string, from the Value type drop-down list, select Text.

the screenshot of kaseya_Network-Monitor_015

  1. Click Save.
  2. Add two SNMP monitors:
    • XTM Device Model: OID .1.3.6.1.2.1.1.1.0
    • XTM Device Name: OID .1.3.6.1.2.1.1.5.0

For more information about Firebox MIB objects, see Enterprise MIB File Details in Fireware Help.

SNMP monitors information appears on the Monitors tab for the monitored device.

Screen shot of Monitors tab

Rename a discovered device

Because of security programs or the firewall configuration, Kaseya VSA might set the name of the discovered device to unknown-MAC address.

To rename a device:

  1. In the left navigation bar, select Discovery > Summary > Discovered Devices.

Screen shot of Discovered Devices list

  1. Select the device.
  2. Select Rename Device.
    The new device name shows in Network Monitor.

Screen shot of Network Monitor Monitoring View page