Adding SSL/TLS Certificate Sensor
- Log in to your PRTG Network Monitor dashboard.
- Navigate to the "Devices" tab and select the device hosting the SSL/TLS certificate you want to monitor.
- Click on "Add Sensor" and search for the "SSL Certificate" sensor type.
- Select the sensor and specify the target SSL/TLS certificate by entering its hostname or IP address.
- Configure additional settings such as scanning intervals and warning/error thresholds.
- Click "Create" to add the sensor to your monitoring setup.
Configuring OCSP Response Monitoring
- After adding the SSL/TLS certificate sensor, locate it in the device's sensor list.
- Click on the sensor to open its settings.
- Scroll down to the "Security" section and enable the "OCSP Stapling" option.
- Provide the necessary OCSP responder URL(s) for the monitored certificate(s).
- Save the settings to apply the OCSP response monitoring configuration.
Setting Up Notifications
- Proceed to the "Notifications" tab in the main menu.
- Click on "Add Notification" to create a new notification rule.
- Choose your preferred notification method (email, SMS, etc.).
- Define conditions for triggering notifications, such as when OCSP responses are unavailable or indicate certificate validation issues.
- Specify recipients who should receive the notifications.
- Save the notification rule.
Monitoring and Troubleshooting
- Monitor the status of SSL/TLS certificate OCSP responses in real-time on the PRTG dashboard.
- Receive notifications promptly if OCSP responses experience disruptions or fail to validate certificates.
- Investigate the root cause of OCSP response disruptions using PRTG's diagnostic tools, such as packet capture and log analysis.
- Take appropriate actions to resolve issues, such as verifying OCSP responder availability, checking certificate configurations, or addressing network connectivity problems.
Optimization and Fine-Tuning
- Regularly review monitoring thresholds and adjust them as needed to ensure accurate detection of OCSP response disruptions.
- Fine-tune notification rules based on feedback and evolving security requirements.
- Consider implementing additional security measures, such as certificate revocation checking and certificate expiration alerts, to enhance overall security posture.
By following the steps outlined in this manual, you can effectively utilize PRTG Network Monitor to monitor SSL/TLS certificate OCSP response disruptions and maintain the security and reliability of your network communications. Proactive monitoring, timely notifications, and thorough troubleshooting are essential for addressing certificate validation issues and ensuring a secure network environment.