Cisco Security :: Monitoring ASA 5510 Tunnels

Sep 22, 2008

I'm trying to monitor Tunnels activity. We want to gather statistics like bandwidth utilization per Tunnel and in the case of Remote Access also the user name associated with a tunnel. All this via SNMP
 
I've browse through the Cisco-IPSec-Flow MIB and found the TunnelTable, this seems to provide everything I need in Regards to Tunnels, I just need a tip in how to calculate or obtain the bytes Tx and Rx. I can obtain packets and Octets amounts but not actual bytes. Is there another OID I should be inquiring?
 
In regard to Remote Access I found the CRASSessionTable From here I can obtain the Group associated with the tunnel and I should be able to obtain the User name through the 1.3.6.1.4.1.9.9.392.1.3.21.1.1 OID, but I'm getting an UnSupported response when querying this particular OID.
 
What OID can provide the User name?
 
I know that Cisco Performance Monitor can in fact obtain all that info from the ASA so there must be an appropriate OID I can query to obtain this particular info.

View 3 Replies


ADVERTISEMENT

Cisco VPN :: VPN Tunnels Monitoring On ASA5510 With IOS 7.0

Jul 8, 2012

VPN Tunnels Monitoring on ASA5510 with IOS 7.0 (Monitoring through Nagios Server).I want to use Nagios to monitor each of the S2S Tunnels built on ASA 5510. I can use the icmp on Nagios by adding Nagios host in IPSEC network of each tunnel but in that case the change needs to be done at other end of Tunnel as well.

View 2 Replies View Related

Cisco Security :: MTU Size GRE Tunnels 6509

Nov 13, 2011

I've created a Tunnel between a Cisco 2811 router and a Switch 6509, the tunnel works fine. However, I would like to run Multicast down this tunnel to avoid using a non-supported 3rd party network device that doesn't support multicast. Some of the multicast packets are above 1500 bytes. I would like figure out why the 6509 tunnel does not support frame sizes over 1500 bytes and the 2811 router does. I have applied ip mtu 1576 but this does not really come into play as the packets are UDP. problems seen below:
 
See the difference with MTU sh int tunnel1 - why is this
 
Switch config  (s72033_rp-IPSERVICESK9-M), Version 12.2(18)SXF13)
 
interface Tunnel1
ip address 10.210.183.14 255.255.255.252
ip mtu 1576
[Code]....

View 1 Replies View Related

Cisco VPN :: IPSec Tunnels Between ASA 5510 And 5555

Nov 13, 2012

I have an ASA 5510 running ver 8.0(2) that has (4) Ipsec tunnels going from it to various other locations.  I am having an issue with data transfer speed on only one of the Tunnels.  This tunnel is between the 5510 and the 5555, on that link I am getting a dat transfer rate of a little over 120k a second, whereas if I pull the same set of files from another location I am seeing a transfer rate of 5m per second. 
 
I have verified that it is not a capacity issue on the Internet bandwidth on both locations, and I can pull the same data from the same location to various other locations via Ipsec tunnels, I am only having an issue with a specific tunnel going from the 5510 to the 5555. 
 
Since it is not affecting other tunnels on the 5510 nor is it affecting tunnels on the 5555 going to other locations, I am leaning toward a routing issue within the ISP?  I will say the ISP is taking me a long way around to stay in the same Metropolitan area.

View 1 Replies View Related

Cisco VPN :: ASA 5510 With 2 L2L Tunnels To Same Site / Network

Feb 24, 2010

I have an ASA  5510 at Site A with a L2L tunnel to another site, Site B. Single subnet at each site. In a few weeks we will be adding a second Internet connection to Site B, so both connections will be active. But we want traffic to go over the new connection unless it goes down, then use the other. How do I set that up on the ASA so it doesn't get confused as to which tunnel to take to get to the Site B subnet?

View 5 Replies View Related

Cisco VPN :: 5510 - VPN Tunnels Cannot Run Steadily At Same Time

Apr 1, 2012

I have a trouble with 2 IPSec tunnels on Cisco ASA 5510.Both of them are Site-to-Site tunnels.Both of them are established against the same public IP address on my site.It looks like they cannot run steadily in the same time. It looks like when one of them is actived, the other one could not be up.Is it some kind of limit of Cisco ASA?

View 6 Replies View Related

Cisco VPN :: ASA 5550 And 5510 / SNMP For IPsec Tunnels?

Jan 23, 2011

I tried to monitor via SNMP my ASA 5550&5510 my Active IPSEC tunnels , I want to receive Bandwidth for each tunnel interface.I’m running Version 8.2(1)?  which OID to use?

View 3 Replies View Related

Cisco VPN :: Separate L2L VPN Tunnels On Multiple External ISP Interfaces With ASA 5510

Oct 18, 2012

Due to special circumstances we have 2 ISP links on an ASA5510. I am trying to terminate some L2L VPN tunnels on one link and others on the second ISP Link, eg below:
 
LOCAL FIREWALL
crypto map outside-map_isp1 20 match address VPN_ACL_Acrypto map outside-map_isp1 20 set peer 1.1.1.1crypto map outside-map_isp1 20 set transform-set TS-Generic
crypto map outside-map_isp2 30 match address VPN_ACL_Bcrypto map outside-map_isp2 30 set peer 3.3.3.3crypto map outside-map_isp2 30 set transform-set TS-Generic
crypto map outside-map-isp1 interface ISP_1crypto map outside-map-isp2 interface ISP_2
crypto isakmp enable ISP_1crypto isakmp enable ISP_2
route ISP_1 0.0.0.0 0.0.0.0  1.1.1.254route ISP_2 3.3.3.3 255.255.255.255  2.2.2.254
 
Establising the VPN tunnels in either direction when using ISP_1 works fine establishing in either direction from remote access users and multiple L2L tunnels (only showing one for example).
 
On ISP_2
1. Peer 3.3.3.3 device establishes a VPN tunnel, but the return traffic does NOT get back to devices on 3.3.3.3 tunnel.
2. The local firewall does NOT establish a VPN tunnel going to 3.3.3.3
It would seem to indicate that the problems lies with this multihomed firewall not directing the traffic correctly to either return down and establised VPN tunnel (point1) or to intiate a tunnel if none exists (point 2).

Reconfiguring the VPN tunnel peer for 3.3.3.3 to be on ISP_1 of the local firewall, all springs into life! There are sufficient license etc...

View 4 Replies View Related

Cisco WAN :: 1941 - ASA 5510 Via VPN Tunnels For Communication Back To Servers Behind Firewall

Jun 20, 2012

I am setting up a network that will use the 1941 router with a cellular card (HWIC) to connect to the Internet for communication with remote stations in the field. The 1941 has a static IP address (166.142.xxx.yyy) on the Internet provided by the ISP (Verizon). The 1941 is connected via ethernet to the ASA5510. The end goal is to have the field cell routers (Digi Transport WR-44-R, also static IP) connect to the ASA5510 via VPN tunnels for communication back to the servers behind the firewall. I'm not sure exactly how to configure the 1941 so that the remote router can connect to the ASA using the public IP of the 1941 router. I have the 1941 working stand alone and can connect to the Internet and pass traffic, but I tried a static NAT to translate the public IP to the private IP of the ASA and cannot pass traffic. below is part of the 1941 configuration: [code]
 
Do I need to use VLAN bridging to accomplish the task or am I missing something with the NAT?

View 3 Replies View Related

Security / Firewalls :: Web Monitoring And Filtering Software?

May 10, 2012

good web monitoring/filtering software for use in the home? I want to be able to monitor/review visited websites and block harmful/unsuitable content.

Must be compatible with Mozilla Firefox.

View 2 Replies View Related

Cisco VPN :: Monitoring VPN Client On 2821 / ASA 5510?

Sep 25, 2012

I have a Cisco 2821 and ASA 5510 as a VPN Router in my network.Our remote users are using Cisco VPN Client 5.0.07 and I need to monitor them on a server and keep their Connection Info to generate some reports for my manager. 

View 1 Replies View Related

Cisco Firewall :: Best Practices For ASA 5510 Device Monitoring

Jan 10, 2012

What are considered the best practices for monitoring ASA's--specifically the 5510 with Sec+ License.
 
My current monitoring application keeps reporting issues with outbound interface buffers being too high, but there are not any performance issues and I believe the thresholds are just set absurdly low.

View 1 Replies View Related

Cisco Firewall :: ASA 5510 Failover Subinterfaces Monitoring

Jan 30, 2013

i have a couple of ASA 5510 in Active/Failover configuration. Failover LAN is configured on management0/0 e the ASA are connected with a back-to-back direct cable.
 
ASA has an interface in access mode inside with standby ip address and show failover is compliant with expected result in show failover (Normal)
 
ASA-PRIMARY# sh failover Failover On Failover unit PrimaryFailover LAN Interface: LANfailover Management0/0 (up)Unit Poll frequency 1 seconds, holdtime 15 secondsInterface Poll frequency 5 seconds, holdtime 25 secondsInterface Policy

[Code]....

View 2 Replies View Related

Cisco Firewall :: ASA 5510 - Enable SNMP For Bandwidth Monitoring Using PRTG?

May 1, 2012

I am using ASA 5510 Firewall and i have established VPN tunnels too  , now i want to Monitor the bandwidth utilization , i have installed PRTG Monitor application and want to add the firewall , how to enable the SNMP in ASA .

View 1 Replies View Related

Cisco Firewall :: ASA 5510 Monitoring Loses SNMP Connectivity With SCOM 2012

Apr 4, 2013

I'm currently implementing Microsoft System Center 2012 Operations Manager, the curent stage of the project is to add the network devices to SCOM via SNMP in order to monitor them, I am able to add them all and monitor; however, my ASA 5510, although SCOM discovers the ASA via SNMP and adds it to the network monitoring list, it loses SNMP connectivy every 30 minutes, and 15 later it reconnect with SCOM, then after another 15 minutes it loses the connection again, and so on and so for.

View 1 Replies View Related

Cisco Switching/Routing :: Monitoring Port-Security Error-Disable And HSRP With 1921 And 2960

Aug 1, 2012

I am looking to simply monitor Port-Security , Error-Disable and HSRP. I would like to receive an email when any of these are triggered.
 
Port Security - Port Is shut down
Err-Disable - Port goes into err-disable state (securedown)
HSRP - When HSRP standyby changes are detected
 
I need to receive emails with any of the able are triggered. What is the easiest way to do this? I know SNMP is the main option but I have never worked with SNMP and dont understand it too much.

Equipment:
2x Cisco 1921 series routers
3x Cisco 2960 POE switches stacked

View 1 Replies View Related

Cisco Security :: How Many Default Context In ASA 5510 Security Plus Edition

Aug 8, 2006

ASA 5510 security plus edition will it support active/active failover. and does it support context with securiyt plsu edition. and how many default context do we get with asa 5510 security plus edition.

View 3 Replies View Related

Cisco Security :: 2x ASA 5510 With AIP-SSM And CSC-SSM On Each One

Mar 23, 2012

I want to ask for the possibility of configuration below? 2x Cisco ASA 5510 running Multi-Context mode and Active/Active Failover1 Cisco ASA 5510 (ASA 1) has AIP-SSM1 Cisco ASA 5510 (ASA 2) has CSC-SSMThere are 2 contexts, context A and context BASA 1 is the primary firewall for context A, and secondary firewall for context BASA 2 is the primary firewall for context B, and secondary firewall for context A 

Can AIP-SSM on ASA 1 inspects traffic of context B which primarily runs on ASA 2?Can CSC-SSM on ASA 2 inspects traffic of context A which primarily runs on ASA 1? 

View 2 Replies View Related

Cisco Security :: ASA 5510 - Upgrade From 7.0(6) To 8.2(5)

Aug 18, 2011

I want to upgrade my ASA 5510 from version 7.0(6) to 8.2(5).  Reading the release notes for 8.2(5) it says the DRAM requirement is 256MB unless you have high CPU usage. Also it says I need to upgrade through the major releases, from 7.0(x) to 7.1(x) and 7.1(x) to 7.2(x) and then from 7.2(x) to 8.2(x).  The questions are:
 
- My ASA has 256MB of RAM and 68% of free memory, would you think it will run the 8.2(5) version with no problem?
- When making the upgrades to the major releases, is there any consideration regarding the configuration file? Or the versions to use for the 7.1 and 7.2 versions?
- Would you recommend making all the upgrades in one maintenance window?  How much time could it take?

View 2 Replies View Related

Cisco VPN :: ASA 5510 - Security Plus License

Aug 21, 2012

We’ve ordered ASA 5510 with security plus license as below description: 

ASA5510-K8
ASA 5510 Appliance with SW,   5FE, DES
L-ASA5510-SEC-PL=
ASA 5510 Security Plus License   w/ HA, GE, more VLANs + conns
 
The license details on the appliance shows as the below,
Fail over                        : Enabled 
Encryption-DES                  : Enabled 
Encryption-3DES-AES             : Disabled
Security Contexts                : Default 
GTP/GPRS                        : Disabled
Any Connect Premium Peers      : Default 
Other VPN Peers                 : Default 
Advanced Endpoint Assessment    : Disabled
Any Connect for Mobile            : Disabled
Any Connect for Cisco VPN Phone  : Disabled
Shared License                  : Disabled
UC Phone Proxy Sessions          : Default 
Total UC Proxy Sessions          : Default 
Any Connect Essentials            : Disabled
Bot net Traffic Filter            : Disabled
Inter company Media Engine        : Disabled 
  
I’ve noticed that the 3DES is disabled, do I need to order another license to use 3DES or not ?Also, I need 2 ~ 5 branches to connect simultaneously and have VPN access on their laptops to the main branch via vpn software, which VPN software I should use and is our license enough or I should order another license.

View 3 Replies View Related

Cisco Security :: Upgraded PIX 525 Lately To 5510 ASA

Sep 26, 2012

i have upgraded a PIX 525 lately to a 5510 ASA, but i have faced a problem after this.One of the DMZ's are connected to a switch that is not connected to my VTP domain on a DMZ port.
 
with access-list to permit from host to host with all ports opened.my problem is that the outside client is able to initiate a windows VPN to a server that i have in the DMZ, BUT it disconnects after almost 10minutes. What might be the reason of the disconnection.Note, a cisco remote access VPN is also configured on the FW, and it doesnt disconnect.

View 1 Replies View Related

Cisco Security :: IOS VPN Endpoint Behind ASA 5510

Aug 2, 2011

trying to TS a VPN device that is behind an ASA basic set up is IOS VPN<firewall/nat<internet>ASA/nat>IOS VPN
 
I do not have a lot of insight into the other side of the connection, although the tech on the other side claims all is good. so to the point.
 
Is the asa capable of allowing this tunnel to work? The configs and debug follow.
 
1.1.1.1 = my public ip
2.2.2.2 = peer public ip
The asa -

[Code]......

View 2 Replies View Related

Security / Firewalls :: Using NAT With Cisco ASA 5510 Firewall?

Mar 25, 2011

I was under the impression that those global addresses that we used with NAT were from the outside IP addresses range?Lets say my outside IP address is idk 192.112.40.11 /30 and I only had two usable IPs (since you can't use network and broadcast IPs) so how would I set up NAT for a couple of Inside addresses with a shorting of addresses like this? Idk if that makes sense what I'm trying to say

View 3 Replies View Related

Cisco Security :: ASA 5510 Client Static IP

Sep 28, 2011

I have a ASA 5510 that uses Radius for Authentication.  What I am trying to do is assign each user that logs into VPN to have a specfic static IP based on userid.  I have about 30 to 50 users.  I don't want to complicate this by having them select a different profile when logging into the ASA.  What is a clean and simply way to assign user static ip and not use local database for login?

View 1 Replies View Related

Cisco Security :: Replacing VPN Router With ASA 5510

Feb 20, 2011

I got a task to replace our current cisco 2800 series router which is used for easy vpn remote access with cisco asa 5510.I have a got a lot of users, i wish that user shall see no difference except of ip address they are going to use for remote login.

View 1 Replies View Related

Cisco Security :: ASA 5510 - Unable To Connect SSH?

Mar 12, 2013

I configured Cisco ASA5510 firewall, but i am facing the problem with ssh login, i gave ssh for inside and outside access, but i am getting "server ... error" i enabled LOCAL  for the authentication for ssh and HTTP. and i am able to acees the device through HTTP using ASDM, but not able to access from outside.
 
ASA Version 8.2(1)
!
hostname ASA5510

[Code].....

View 3 Replies View Related

Cisco Security :: Cannot Login To Firewall ASA 5510

Sep 1, 2012

i have in my network firewall ASA 5510 but the problem i cannot login to my firewall thru telnet or ssh even ASDM or bowser this is my configuration :
 
ASA Version 8.2(5)
!
hostname Amco-ASA

[Code].....

View 9 Replies View Related

Cisco :: ASA 5510 / Upgrade All Firewalls To Security Plus?

Sep 21, 2011

I am trying to upgrade all my firewalls to Security Plus but I am not sure what firewalls are needing the upgrade.  Is there a SNMP pull I can do to see what license is on my firewall?  example: "This platform has an ASA 5510 Security Plus license." via SNMP

View 1 Replies View Related

Cisco Security :: ASA 5510 Multiple Non-contiguous Blocks Of IPs?

Apr 30, 2012

Currently I have an asa 5510 set up with one block of outside IP addresses. Everything is working fine in regards to my initial setup. However we needed to purchase additional IPs from our provider and ended up being a whole complete different block. Where I am getting stuck is getting the new IPs to NAT to inside addresses.

View 2 Replies View Related

Cisco Security :: ASA 5510 - ASDM Software Won't Load

May 26, 2011

I've tried 3 different machines including a server.
 
Basically when I try to access my ASA 5510 with the ASDM software the software never loads.  So I have tried to access it through the management port https://192.168.1.2 and installed the software.  The software starts up, I enter the password and it connects and loads to 100% but doesn't go beyond that point.  I then try the java applet, and it as well loads up to 100% and says "Please wait, the main is coming up." 
 
I have http server enabled, and asdm image is pointed correctly
 
As I said, I've tried this on two Windows XP machines and a machine running Server 2008.
 
I can connect through CLI all day and all night, but I'd rather (read feel much safer) configuring it through ASDM. 
 
Here is some system version info
 
Cisco Adaptive Security Appliance Software Version 7.0(8)
Device Manager Version 5.0(8) 
Compiled on Sat 31-May-08 23:48 by builders
System image file is "disk0:/asa708-k8.bin"

View 4 Replies View Related

Cisco Security :: Change Ipsec Vpn To L2tp Over ASA 5510

Nov 14, 2011

i configurated ipsec vpn at cisco asa 5510. all them are working very well. now i want to change ipsec remote vpn to L2tp over ipsec.i have router, asa and 3750 switch. all nat translation are done at router , ipsec vpn configurate at asa.
 
this is my ipsec configuration. this is working config. as you see i do static nat asa outside ip for vpn at router. now i want l2tp over ipsec. before i do it i have some question
 
1. must i do static nat port  udp 1701 for l2tp over ipsec vpn?  can i write access list at asa to open port 1701?

2. can i remove this  static nat or i can not be change anything.is this nat is true for l2tp over ipsec vpn?
 
3.as you see user authentication from radius server at ipsec vpn. i also want this is same as l2tp over ipsec vpn..
 
4. i think that i must be add this addtional config. is this true? tunnel-group DefaultRAGroup ppp-attributesno authentication chapauthentication ms-chap-v2
 
is this config enougth for l2tp over ipsec vpn?? what is addtional config i need?

View 2 Replies View Related

Cisco Security :: 2911 Routers - Does ASA 5510 Support BGP

Jan 25, 2012

I have a new BGP configuration that consists of two asa 5510 and two routers 2911 at the back. My question is : Does asa 5510 support BGP?

View 1 Replies View Related

Cisco Firewall :: ASA 5510 Security For One Specific User

Jan 18, 2013

We have an ASA 5510 version 8.3 (2) that we accept VPN users via a radius server. Is there a way to lock down a specific user that connects to the ASA as a SSL client or IPSEC VPN user? If the specific user were to connect to the ASA, we would want the user to have minimal to not access to our system.

View 1 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved