Cisco :: Create Device Poller On Solarwinds Orion NPM For ASA5580-40?
Jan 15, 2013Has created a device poller on Solarwinds Orion NPM for the ASA5580-40?
View 1 RepliesHas created a device poller on Solarwinds Orion NPM for the ASA5580-40?
View 1 RepliesWe have noticed that some devices has dissapeared from HUM pollers and some quick reports have dissapeared too. It happened again some months ago. I would like to know:
1. How I can fix it.
2. Which logs I can see to troubleshoot the problem.
3. If is possible I can restore only the hum module from LMS backup
We use Orion for monitoring. We recently started monitoring a workstation switch and find many occurances of port speed changes indicated. Our workstation ports are configured with auto speed and duplex. Is it normal that we are detecting speed changes on the ports? Do workstations running XP automatically adjust their speed for traffic management or power save? Perhaps something like speeds changing when PC goes to sleep mode but has wake on LAN enabled? Is it possible that the MIB is misreporting?
I realize that there are many different NIC vendors/drivers that might act differently. Just wondering (in others experience) if it is somewhat normal or if there is anything on network I should be looking into as to why speeds are changing? We plan to not monitor workstation ports (only uplinks) on the switch.. but before we do, I thought I would see if what we are detecting needs to be addressed?
Here is an example from Orion of a speed changing. Seems always off hours:
6/1/2012 6:17:52 AM eventWoRKSTATION-3750-CLUSTER - GigabitEthernet1/0/14 · 2nd Floor Patch#11 Interface Speed changed from 10000000 to 1000000000 bps
6/1/2012 2:47:52 AM eventWoRKSTATION-3750-CLUSTER - GigabitEthernet1/0/14 · 2nd Floor Patch#11 Interface Speed changed from 1000000000 to 10000000 bps
How can I troubleshoot, what can I do if we get poller errors in HUM suddenly? It was running some days only.Its an installation in our solution center and Im in comparing the results with Cacti and Nagios/PnP - there is no problem at the same device and interfaces with this tools.
SCSwitchB
#
MIB VariableInstanceFailure StatusFailure CountLast Failed ReasonLast FailedifHCInOctetsGi3/2Permanent458No Such Instance - The specified instance is not availableMon, Jul 18 2011, 22:02:01 CESTifHCOutOctetsGi3/2Permanent458No Such Instance - The specified instance is not availableMon, Jul 18 2011, 22:02:01 CESTifHCOutOctetsGi3/3Permanent458No Such Instance - The specified instance is not availableMon, Jul 18 2011, 22:02:01 CESTifHCInOctetsGi3/3Permanent458No Such Instance - The specified instance is not availableMon, Jul 18 2011, 22:02:01 CEST
we are using the prime 4.2. want to know the capabilty of the HUM poller. How many interfaces can be added in a single hum poller ? And total interfaces can be managed by the HUM as recommended by the cisco ?
View 5 Replies View RelatedMonitoring H.323? I've got a 3925 running15.1(3)T with 9 PRI's. Because of our volume, syslogging is not the desired solution. We want something that we can potentially graph over an 8 hour period, so while the RTMT is accurate, either it won't store the data for 8 hours, or we aren't using it correctly (plus, mgmt may want access to the stats/graphs, and we're not keen on granting them access). So far, we've used: [code] None of these seem to accurately portray utilization. cdsp Active Channels seems to get the closest, so perhaps I have to tweak it a little bit, but so far, nothing accurate.
View 3 Replies View RelatedI came across some free bandwidth monitoring software by Solarwinds while doing some reading on other sites. I installed the software and now im stuck at setup. The Softaware is asking for...
Ip Address/Hostname
SNMP Version
Community string
I'm assuming the IP Address/Hostname would be my computers IPv4 on the network and as far as the SNMP Version goes im not sure, I can either choose from SNMP v1/2c or v3. For the community string, I'm assuming its Public but im not completely sure.When I attempt to go to the next step is says the credentials test failed So obviously something I entered is incorrect.
Note: this is on my own home network. Im using a Comcast all in one router and modem.
we are using solarwinds as monitoring toll for all network devices..the solarwinds shows proper memory & cpu utilization for catalyst 3750 switches but shows hogh cpu/memory utilization values for 6509-vss...when we log into vss via cli the util & memory values are normal but same are very high on solarwinds..i have checked the solarwinds site also and fond that there was issue for 6509 related to high cpu in relase before 9.2 and 9.2 release of solarwind has resolved this issue..is anything to be checked on 6509 or as such any known bug in this regard for 6509-vss i am using software s72033-ADVIPSERVICESK9_WAN-VZ.122-33.SXI4A on my vss.
View 9 Replies View RelatedI am trying to setup netflow with on 6509 and SolarWinds NetFlow Traffic Analyzer v3.10.0
The problem I have is that after configuring the basic settings of NetFlow on both side I can't see all the traffic I expected to capture in NetFlow.
The details of my problem.
I want to monitor the traffic on VLAN 20.
In the general configuration of the switch I have entered the following
ip flow-export source vlan 10
ip flow-export version 9
ip flow-export destination 132.5.200.123 8080
Where vlan 10 is the management vlan. Vlan10 can ping 132.5.200.123 no problem.
On VLAN20 interface I configured this
ip flow egress
ip flow ingress
ip route-cache flow
When I go to SolarWinds Netflow Traffic Analyzer I can see maybe 1 or 2 packets flows, like nothing of the data. If I do a capture of the traffic on VLAN 20 I can see there is loads of IP traffic on that VLAN but why is netflow not capturing the statistics of those flows and reporting it to NetFlow ?
command "ip flow-export source vlan 10" ?
I am currently testing Netflow accuracy on my Solarwinds platform. So I have been transferring a large file across an ASA 5520, which is set up to send Netflow data to out Solarwinds server.
The problem is that the Netflow data does not show up on Solarwinds for about 2.5 hours. Once it gets there the size is correct, but the time stamp on Solarwinds is 2.5 hours behind when the transfer happened. For routers it is showing up within a few minutes.
ASA is running 8.2(5) and Solarwinds NTA 3.9.0. Firewall and Solarwinds times / timezones are the same.
I was trying to search for cisco vpn client version 5.x for MAC OS but only saw the latest version at 4.9. If version 5 is out for MAC? Also, what the latest possible version of the vpn client is for MAC that is compatible with both the vpn 3080 concentrator and asa5580?
View 5 Replies View RelatedWe have recently upgraded oor LAN and we are using couple of Nexus5548UP switches in the core with 2960 stacks as access switches. Each access switches stack is connnected to both core switches with link being port-chanels and VPCs. All is working fine, but our SolarWinds management platform (NPM) is being flooded with "Physical Address changed" events. Here is an example of messages:
NSW_Core_2 - Ethernet1/7 Physical Address changed from 000000003811 to 73616D653811
NSW_Core_2 - Ethernet1/7 Physical Address changed from 200B82B43811 to 000000003811
For each interface I have messages like these repeating.I am not sure what those messages means or if there is actually anything wrong. Performance of the network is good, there are no errors on any interfaces and I do not see anything related in the switch loggs.
I'm trying to test Anyconnect VPN but after configuring the required configuraiton I'm not getting Anyconnect client downloading and it just log into the clientless webvpn. Below are my basic required configuration. I have tried with few other ASA the same configuration but it worked fine. I'm using the default SSL VPN base license (02) with the ASA5580 code running 8.2.2
webvpn
port 8080
enable nms-s90
[Code].....
I recently posted this same issue the other day, using TFTPd32. Now i am pretty close to fixing it. I do have a different setup; my pc ethernet port is broken so I am using an ethernet/usb adapter. I am attempting to backup my IOS from a 3550 switch to my PC.
This is the error I am getting. Code...
We are in the process of building a new DC and would like to know which is the recommended version of code to run on the following:
Firewall Services Module
Cisco ASA5580, 5550, 5520
ACE module
As part of a DC deploy, aI have to install 2 x ASA5580. My surprise was the missing connection bolts (or place) on the chassis for the grounding cable. All othes equipments (ASR, 6500, Nexus 7K) have a grounding connection on their chassis.
The Installation manual alerts and requests a good gorundid for it. But where should I put it??Note that the rack where it's installed on is already grounded.
Anyway, here's the situation I'm trying to configure several VLANs on my ASA to uniquely allocate to contexts, the VLANs will be trunked from my VSS. Unfortunately I'm not clear on how to achieve this, the configuration guide for 8.4 talks about multiple contexts and routed setups all which don't appear to apply exactly. I've configured the port channel at both ends and I've configured sub-interfaces on the port channel and assigned VLAN IDs. These sub-interfaces are then allocated to the contexts to set 'ip address' etc. I've not been able to successfully test this configuration and I am concerned that it is incorrect..
View 1 Replies View RelatedI am having issues with PXE boot images for PCs cannot be loaded from remotely.The diagnosis revealed that SunRPC & TFTP were being inspected by ASA causing drop of packets.So I excluded these two inspections for the particular server behind the firewall. It seem to resolve the issue for instance but it crawled back again.
Is there a way that the inspection can be turned off for that particular server at the IP level?
We have an active-active pair of cisco ASA5580-20 with software version 8.4(1)9. There are 8 contexts on it (including admin and system). 1 context is active on Primary node and other 7 are active on Secondary node. User traffic is going through this 1 context (2 interfaces - inside to users, outside to internet) and there are peaks to 1.16M concurrent connections, max bandwidth is 1.25Gbps. CPU usage for this context in peak hours is 63%, but we noticed that when we run "show cpu usage context all" from system it shows that system context is using 25% of CPU and "Total CPU utilization" (form output of show cpu detailed - on system context) is 88% which is bad. In non peak hours - user context use 33.6% CPU, system use 14.5%, total CPU usage is 50.5% So, is it normal this cpu utilization on system context (system on Primary node)?
View 1 Replies View RelatedRunning ASDM V6.3 connecting to a couple of ASA5580's V8.2. After initial configuration everything seemed to work great, however, as of a few days ago I can no longer view statistical information. I can attach to the devices without a problem, view and edit all configuration information but the dashboard applets do not pull or display any statistical info. Resource, Interface, and Traffic status all time out with the error "Lost Connetion to Firewall". The syslog info is not display rather the error "Syslog Lost Connection". My first thought was a java issue on the client. I have ripped out and reinstalled even back-revisioned to no avail. I'm to the point where a dumpe of the management workstation is the next step. I'd like to avoid that extreme if possible.
View 3 Replies View Relatedcustomer has a server which located in inside interace. and an outside interface connected to ISPA. cu config a static nat map inside server address to ISPA address, one day customer install a new outside interface to ISPB, cu config new static nat ,map same server inside server address to ISPB address. the server will allways be vistited from outside interface and reply, custome want traffic coming from ISPA will return to ISPA, traffic coming from ISPB will return to ISPB. but i found it is difficult implement this on ASA5580. i want use route-map on static nat, but it will not satisfy customer's request.
View 3 Replies View Relatedi have a problem customer has a server which located in inside interace. and an outside interface connected to ISPA. cu config a static nat map inside server address to ISPA address one day customer install a new outside interface to ISPB, cu config new static nat ,map same server inside server address to ISPB address. the server will allways be vistited from outside interface and reply, custome want traffic coming from ISPA will return to ISPA, traffic coming from ISPB will return to ISPB. but i found it is difficult implement this on ASA5580. i want use route-map on static nat, but it will not satisfy customer's request.
View 6 Replies View RelatedI am looking for the way to define an idle timeout for specific flows on an ASA5580 by using Cisco security manager. For ex I needed to define a specific idle timeout for connections beetween specific devices (Devices in vlan1, Device2 in vlan2).To test it I did following changes by CLI and it works fine. access-list L1 extended permit ip <@IP1> <mask1> host <@IP2> class-map CM1 match access-list L1 policy-map PM1 class CM1 set connection timeout idle 02:00:00
I try do do the same configuration with CSM in order to be able to manage each changes only by using CSM.So I defined Access control list, Traffic flow and then I define timeout in CSM --> PIX/ASA/FWSM Platform --> Service Policy Rules --> IPS, QoS and Connections Rules -> connections settings -> Traffic flow idle time-out. The problem is that each time I deploy the configuration with CSM I loose the timeout config line which is the most important for my application..
We are using LMS 3.2.1 with SP1 and Campus Manager 5.2.2.Server runs Windows 2003 R2.Everything runs fine except for User Tracking on two Catalyst 6500 switches running CatOS. These devices are discovered, reachable, SNMP works fine, neighbors seen. But when we try to launch acquisition, the UT utility complains with this error message:"Failed to start acquisition: Device unreachable. Please enter a valid device."When we wanted to add ports via Device Trap Configuration, LMS has fired a different error message: "There are no ports to configure for the selected device(s).Check whether you have selected any router(s)." I have checked the portsData.xml file, which doesn't have any ports included for the two devices: [code] We have tried to exclude / include the switches in the data collection, but that didn't work.
View 3 Replies View RelatedMy BEFSR81 is my primary router and has DHCP turned on. The router's DHCP range is set to accommodate 12 devices. I have three computers wired to it and their Host names (as specified in the set-up of each computer) show up in the router's DHCP device table. I also have two printers (one old Brother HL5250DN laser printer and one new HP Photosmart Premier C410a inkjet printer) connected and there are blanks where the Host name should go. I would like to be able to tell which printer is which when I am looking at the DHCP device table. How can I get a names associated with each printer's IP address in the router's DHCP device table? (The real problem is that the router seems to have both printers at the same IP address (192.168.1.100) and if I can get one of them to change I'd like to know which one it was!)
View 1 Replies View RelatedThe problem: I need to track a bus from city to city in real time.I'm thinking of a gps device without screen or apps, it only sends the current location to a server. Is this possible? What device can be useful?
View 1 Replies View Relatedtrying to perform a RME InventoryCollection job with cwcli inventory I wasn't able to perform this task.
View 2 Replies View RelatedI have problem with device cisco srp 521 , my problem is haw to create two VLAN-s first will be to WAN link, second for Management.
View 2 Replies View RelatedI need to create second VPN in same ASA5505, it has already a VPN to one of our clients. So it alredy have a transformset,cryptomap,policy.Now i need to create new one. i like to create a seperate transformset and crypto map for this 2nd VPN with a new name to identfy very easily.But i have doubt like may it will affect the current VPN? because it has another VPN with another tranformset and cryptomap.......
1) will it affect the current VPN?
2) do i need to create a seperate tranformset and cryptomap? or with same tranformset and cryptomap with different number.....if it possible to create multiple cryptomap then i would like that to create.....
I have an ASA5510 with VPN L2L two operand normally. I need to create another VPN L2L. When you add the 3rd VPN always drop one of those that were operating. What can be?
View 2 Replies View RelatedI need to create a LAG consisting of 4 ports on my SG 300-20.
When I go to create the ports via Port Management - Link Aggregation - LAG Management - LAG1 - Edit and move ports 5,6,13,14 over as LAG Members - Click apply I get Port gi5 belongs to a VLAN. If I try to add them individually I get the same error, i.e. port gi6 belongs to a VLAN, port gi13 belongs to a VLAN, etc..
how to get these ports out of a VLAN?
I'm baffled by a lot of new features of LMS4.2 and seem lost where to start looking.Our client needs to periodically make changes to switches to change their port settings.They have specific descriptions with a certain string. Let's say the description say "Cisco phone".The task is to create either template or ad-hoc Netconfig job that will send changes only to those switchports.
View 2 Replies View RelatedI have a weird problem. I can't create a vpn in windows xp. I click on create a new connection, the connection wizard opens up, I click "connect to the network at my workplace", and this happens mm31z.jpg at Free Image Hosting.I can't select VPN connection. I have no idea what is causing this, maybe a service is not running, I don't know. I tried uninstalling/ reinstalling my network and it did not work.
View 5 Replies View Related