Cisco ASA templates - YMMV

Templates, scripts for templates, scripts and requests for templates.

Moderators: Developers, Moderators

Alberello
Posts: 6
Joined: Tue Nov 21, 2006 10:16 am
Contact:

Re: Cisco ASA templates - YMMV

Post by Alberello »

fusion wrote:These were created for the Cisco ASA 5520
They doesn't work on my asa 5520 8.0(3)6

Just able to monitor cpu with a data template of cisco router.
Ilukester
Posts: 2
Joined: Sat Dec 27, 2008 2:40 pm

Cisco ASA

Post by Ilukester »

Hi, I am totally new to this whole Mib's thing. Some how I have my Total Sessions graph working but I don't have any other graph working. Could someone tell me how to fix this problem. Is it the Mibs? And how and which mibs would I need to install?
Thank you in advance. And if I figure it out i will post how I did up here.
southcat
Posts: 9
Joined: Fri Oct 31, 2008 2:18 am

Re: Cisco ASA templates - YMMV

Post by southcat »

fusion wrote:These were created for the Cisco ASA 5520
my session no graph? debug :
RRDTool command:

/usr/local/rrdtool/bin/rrdtool graph - \
--imgformat=PNG \
--start=-86400 \
--end=-60 \
--title="ciscoASA_5550 - Sessions" \
--base=1000 \
--height=120 \
--width=500 \
--alt-autoscale-max \
--lower-limit=0 \
--vertical-label="# of Sessions" \
--slope-mode \
--font TITLE:10: \
--font AXIS:8: \
--font LEGEND:8: \
--font UNIT:8: \
DEF:a="/var/www/html/rra/ciscoasa_5550_asa_ras_1341.rrd":asa_ras:AVERAGE \
DEF:b="/var/www/html/rra/ciscoasa_5550_asa_ras_1341.rrd":asa_ras:LAST \
DEF:c="/var/www/html/rra/ciscoasa_5550_asa_ras_1341.rrd":asa_ras:MIN \
DEF:d="/var/www/html/rra/ciscoasa_5550_asa_ras_1341.rrd":asa_ras:MAX \
DEF:e="/var/www/html/rra/ciscoasa_5550_total_1342.rrd":total:MIN \
:a#EAAF00FF:"Remote Access":STACK \
GPRINT:b:LAST:"Current\:%8.0lf" \
GPRINT:a:AVERAGE:"Average\:%8.0lf" \
GPRINT:d:MAX:"Maximum\:%8.0lf\n" \
COMMENT:"Graph Last Updated\:Sun 18 Jan 09\:44\:04 CST 2009\n"
RRDTool say:

ERROR: Could not make sense out of ':a#EAAF00FF:Remote Access:STACK'
ericgearhart
Posts: 11
Joined: Wed Feb 11, 2009 12:59 pm
Contact:

Cleaned up graph template for mem usage

Post by ericgearhart »

Hi folks

I did some work to clean up the ASA memory graph template, so that the Max value is not cut off, I added a 'Min' value and I moved the row labels to the top as column headers

I figured I'd give at least something back to the vibrant Cacti community :)
Attachments
cacti_graph_template_cisco_asa_-_memory_usage.xml
(18.78 KiB) Downloaded 1804 times
ASA Memory screenshot.png
ASA Memory screenshot.png (29.53 KiB) Viewed 24259 times
bitgod
Posts: 25
Joined: Thu Mar 31, 2005 2:03 pm
Location: Texas, USA

Post by bitgod »

Thanks for the ASA templates. I find these graphs are working well for PIX & ASAs running everything from 6.3(5), 7.2(3), 7.2(4) to 8.0(4).

I've run into one issue, which I don't believe is related to these templates, but someone here may be able to help. I'm not getting any graphs for traffics... I've got errors/discards, connections, cpu, memory - all working great. But the traffic sections just comes up with the names it correctly pulled as hyperlinks, and no graph image at all. If you follow the link you see the names for the 1 minute average, 5 minute, weekly, and so on... but still no graph image at all.

To troubleshoot this so far... I've confirmed my settings are set probably for my version of rrdtools and netsnmp. I've tried SNMP version 1 and 2c. I've also tried all the different options of in/out bits, bytes, 64 bit counters, 95th percentile. I've done a verbose query and see its getting data... but still to no avail.

Seeing that it is ONLY the "SNMP - Interface Statistics" Data Query that is failing, and its failing on PIX & ASAs on different version of code... can anyone provide me some guidance on what to look at trying next?

Thank you!


Regards,
User avatar
gandalf
Developer
Posts: 22383
Joined: Thu Dec 02, 2004 2:46 am
Location: Muenster, Germany
Contact:

Post by gandalf »

Thanks for posting this. We now encourage contributors to publish their work at the central cacti repository at http://docs.cacti.net/templates
Reinhard
bitgod
Posts: 25
Joined: Thu Mar 31, 2005 2:03 pm
Location: Texas, USA

Post by bitgod »

FYI, my problem with traffic graphs not working was fixed in 0.8.7d with the official snmp.php patch.
hinze57
Posts: 6
Joined: Wed Sep 12, 2007 3:31 pm
Location: Colorado

ASA Templates & SSL VPN

Post by hinze57 »

For the record, this is an awesome template and we rely on it heavily.

I was just wondering if anyone knows what OID's or such to add to graph SSL VPN connections.

Thanks,
ravenlord2009
Posts: 2
Joined: Wed May 27, 2009 8:48 am

Searching for Cisco ASA OID for L2L Session counter

Post by ravenlord2009 »

Hello

Can somebody help I am searching for the oid for the l2l Session counter? We want to graph only the l2l session seperated from the r2s sessions. We use an asa 5540 with 8.0(4) ios. In the past we did this with our concentrator 3030.
hinze57
Posts: 6
Joined: Wed Sep 12, 2007 3:31 pm
Location: Colorado

OID for L2L connections

Post by hinze57 »

I am not at work so can't do this right now, but hop on your ASA and run "show snmp-server oidlist" and it'll kick out all of the MIBs/OIDs it understands. That is how I found the SSL VPN Connection count. Although I'm still testing to see if I am polling the correct one!
ravenlord2009
Posts: 2
Joined: Wed May 27, 2009 8:48 am

ASA L2L OID

Post by ravenlord2009 »

Thanks. But I found only OID counters for IPSec, IKE, r2s, ssl sessions. All work fine. I found no counter for l2l session or tunnels only.

asa supports the following mibs:
ftp://ftp-sj.cisco.com/pub/mibs/support ... tlist.html
ftp://ftp.cisco.com/pub/mibs/v2/CISCO-I ... TOR-MIB.my

I think there is no counter for the l2l sessions.
MrRat
Cacti User
Posts: 136
Joined: Thu Jan 07, 2010 10:33 am

Post by MrRat »

I get errors for the null0 interfaces on each of my ASA's

Code: Select all

01/12/2010 10:12:01 AM - SPINE: Poller[0] ERROR: SQL Failed! Error:'1064', Message:'You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'Null0' interface' WHERE host_id='303' AND data_query_id='1' and arg1='.1.3.6.1.2' at line 1', SQL Fragment:'UPDATE poller_reindex SET assert_value='Adaptive Security Appliance 'Null0' interface' WHERE host_id='303' AND data_query_id='1' and arg1='.1.3.6.1.2.1.2.2.1.2.1''
01/12/2010 10:12:01 AM - SPINE: Poller[0] ERROR: SQL Failed! Error:'1064', Message:'You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'Null0' interface' WHERE host_id='304' AND data_query_id='1' and arg1='.1.3.6.1.2' at line 1', SQL Fragment:'UPDATE poller_reindex SET assert_value='Adaptive Security Appliance 'Null0' interface' WHERE host_id='304' AND data_query_id='1' and arg1='.1.3.6.1.2.1.2.2.1.2.1''

anyone have any idea how I can fix this one?
Robbsie
Posts: 4
Joined: Mon Jun 21, 2010 8:39 am

Post by Robbsie »

Thanks for that templates, works fine :)

Can anyone explain me what "IKE dropped packages" exactly means?
Thanks!
Attachments
graph_image.php.png
graph_image.php.png (22.45 KiB) Viewed 18161 times
dunxd
Posts: 18
Joined: Wed Sep 23, 2009 5:51 am
Location: London, UK

Post by dunxd »

IKE Dropped Packets are the number of packets within the VPN tunnel that have been dropped for whatever reason. You will likely see a few of these from time to time, but a sudden jump should alert you to a problem.

Can't explain further, and I could be wrong in my interpretation of course. If anyone else has a better understanding, please share!
abdulet
Posts: 4
Joined: Thu Apr 30, 2009 6:38 am

Bash script to create templates easily

Post by abdulet »

Hello all,

Here is a bash script that scan a device and allow the selection of items to be added to a template in a wizard way, it support extension by modules in two ways, to manage some special OIDs (like network device ones) and by defining output modules (that builds the final result, at the moment a zabbix template)

The zabbix template module can build multi or single graph items.

Just download, untar the file, cd make_template and run:

bash make_template.sh -i -a IP_ADDRESS SNMP OPTIONS

and follow the wizard.

The script generate an OID file that is used by template_modules to make the final template

send me bugs (sure they ll be there) improvements you do or whatever related to the script

enjoy it ;)
Attachments
make_template.tar.gz
(179.18 KiB) Downloaded 922 times
Post Reply

Who is online

Users browsing this forum: No registered users and 1 guest