Skip to main content
Version: 2026.09

Sites

This is step 5 of the setup wizard (required). Each location you collect data from is added as a site. A site contains a single firewall or a high-availability (HA) pair. Sites are managed from the Setting management menu; click the + button above the list to add one.

Before you start, create the API account described in Firewall preparation.

Adding a site: general and mode configuration, firewall configuration

General and mode configuration​

SettingDescription
Is activeTurns data collection on for the site.
Site nameThe name shown in reports, for example Izmir-DC.
Site ModeWhere and how data is collected. See below.
Get logs from PanoramaIn gateway mode, connections are read from the device; turn this on to read traffic logs from Panorama.
API key lifetime minutesIf an API Key Lifetime is set on the firewall, enter the same value; the key is renewed at this interval. 0 means no renewal.
SSL verifyValidates the certificate of the firewall's web interface. See the note below.
Log Collection Delay (Seconds)How long to wait after a VPN session ends before collecting its traffic logs (default 60). Increase it where Panorama delivers logs with a delay.
Clear Session After Logout (Gateway Mode)On by default; we recommend leaving it on. Details below.
Inactivity Logout (Minutes)Must be the same as the GlobalProtect Inactivity Logout value on the firewall. Details below.
Work Shift EnabledTurns on working-hours calculation for this site. See Shifts and holidays.

Site mode​

ModeWhen to use
Gateway Mode (default)Enough for most deployments. Connection details are read directly from the firewall.
GlobalProtect Log ModeUse only when needed; duration calculations have a larger margin of error in this mode.
Gateway Over Panorama ModeFor deployments with a central Panorama, to read data from the relevant devices managed by Panorama. Devices are listed by serial number, separated by commas.

Inactivity logout​

If a user's internet drops without disconnecting the VPN, the firewall closes the session when this timeout expires. VPN Reporter subtracts this timeout from the connection to calculate the real connected time, so the value must match the firewall.

To find the value on the firewall:

  1. Go to Network → GlobalProtect → Gateways and click the gateway name.
  2. On the Agent tab, open Connection Settings.
  3. Check Inactivity Logout (min). If it shows 7, enter 7 in the site settings as well.

GlobalProtect Gateway: Agent → Connection Settings → Inactivity Logout

Clear session after logout​

Even after the VPN disconnects, sessions such as RDP can stay open on the firewall; an open session produces no traffic log, so that traffic does not appear in the logs. This option clears the open sessions of the VPN IP address after logout, so the sessions close, their logs are collected and reports stay consistent.

SSL verify​

If you turn on SSL verification, the VPN Reporter server must trust the certificate of the firewall's web interface. Define the firewall by the FQDN in its certificate rather than by IP address. If the firewall uses a self-signed certificate, add it under Trusted Certificates at the bottom of the page.

Firewall configuration​

FieldDescription
Firewall primaryManagement address of the firewall, for example 10.35.10.252.
Firewall secondaryAddress of the second device in an HA pair, for example 10.35.10.253.
Username / PasswordThe API account you created in Firewall preparation. The user name is case-sensitive.
TimezoneThe firewall's time zone.

Test and save​

  1. Open the Site Test Area at the bottom of the page.
  2. In Target Device Selection, choose the device to test. In an HA pair, test each device separately.
  3. Click Get Firewall API Key; Result should show Status: Success.
  4. Use Time & System Tests to read the firewall's clock and time zone.
  5. If the tests succeed, click Save.
Test before you save

The test uses the values currently on the screen, even if they are not saved yet; try a change first, then save it.

Site Test Area: API key retrieved

The site is added to the list and a Site created notification appears.

Site list

Changing the settings of a running site​

When you save the settings of a site that is collecting data, the Site configuration changed window opens. The collector keeps using the previous settings until it is stopped and started again.

ButtonWhat it does
Stop and Start NowRestarts the collector immediately so the new settings take effect. Recommended.
LaterCloses the window; the new settings take effect the next time the collector restarts.
Go to Worker ManagementOpens the Site Health & Status screen, where you can stop and start the site.

Site configuration changed

The "site stopped" warning​

After you add a site, a Site … is unreachable warning and a Site Issues — 1 stopped box at the bottom left appear. This is expected: the site does not run until a license is entered. After entering the license, start the site again.

Site completed, site stopped warning

Next step: Alarm management.