cisco asa monitoring ipsec sa through snmp

hi guys,

is there a way to monitor all ipsec sa´s using snmp? i tunnel a couple of diffent networks using the same tunnel and i would like to know if a single ipsec sa times out or something....

i did not find anything when walking through the snmp output of the ASA. maybe one of you guys can drop me the OID or something....

cheers, /heri

Reply to
H. Steuer
Loading thread data ...

You'd probably need the Cisco MIBs to find it in the output of a walk. There definitely are some OIDs for tunnels, and it was discussed here some time in the past few months. Can't find it just now.

Reply to
alexd

I have never found any SNMP variables for normal IPsec sa's, not tunnel interfaces. Do you think they exist?

It would be interesting to know if an sa is up, and how much traffic is going through. It can be shown with "show crypto ipsec sa" in an awkward format, but can it be queried using SNMP?

Reply to
Rob

Walk the CISCO-IPSEC-FLOW-MONITOR-MIB on your device and see what it says.

Reply to
alexd

Thanks. It took me some time to figure out how to 'walk a specific MIB' as the tools I use can only walk an OID, but I found the OID by reading through that CISCO-IPSEC-FLOW-MONITOR-MIB and now it works. Always thought that walking from the root would return everything a device can support, but apparently that isn't true.

Reply to
Rob

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.