<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic hi, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5520-does-not-respond-to-snmp/m-p/2968012#M161354</link>
    <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;the 'management' interface usually responds to traffic where the ASA itself is the destination (i.e. ping, SSH, etc), but can't pass any transit traffic through the ASA to or from another interface. do you have this line under 'management' interface?&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;no management-only&lt;/EM&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 26 Jul 2016 01:59:38 GMT</pubDate>
    <dc:creator>johnlloyd_13</dc:creator>
    <dc:date>2016-07-26T01:59:38Z</dc:date>
    <item>
      <title>ASA 5520 does not respond to SNMP</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-does-not-respond-to-snmp/m-p/2968011#M161353</link>
      <description>&lt;P&gt;I recently replaced a pair of 5510s with 5520s going from 8.2 to 9.1. Aside from ACLs being cleaned WAY up, that's the only thing that's really changed here. The 5510s worked fine in NMS (Orion), but the 5520s will not.&lt;/P&gt;
&lt;P&gt;SNMP in this case goes over a site to site tunnel (remote location) on an interface labeled management:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;snmp-server host management 10.71.127.73 community *****&amp;nbsp;&lt;BR /&gt;snmp-server community *****&lt;BR /&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart warmstart&lt;BR /&gt;snmp-server enable traps ipsec start stop&lt;BR /&gt;snmp-server enable traps entity config-change fru-insert fru-remove&lt;BR /&gt;snmp-server enable traps remote-access session-threshold-exceeded&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;GigabitEthernet0/2.100 &amp;nbsp; management &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 10.0.100.254 &amp;nbsp; &amp;nbsp;255.255.255.0 &amp;nbsp; CONFIG&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;access-list CardAccessVPN extended permit ip 10.0.100.0 255.255.255.0 10.71.127.0 255.255.255.0 (tunnel ACL)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;NMS is on 10.71.127.73&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have the switch stack at this location (&lt;SPAN style="color: #00ff00;"&gt;10.0.100.11&lt;/SPAN&gt;) polling just fine.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I can see this at least:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;UDP outside 10.71.127.73:56514 management 10.0.100.254:161, idle 0:00:00, bytes 45, flags - &lt;BR /&gt; UDP outside 10.71.127.73:56768 management 10.0.100.254:161, idle 0:00:01, bytes 192, flags - &lt;BR /&gt; UDP outside 10.71.127.73:58258 management 10.0.100.254:161, idle 0:00:05, bytes 147, flags -&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #00ff00;"&gt;UDP outside 10.71.127.73:57766 management 10.0.100.11:161, idle 0:00:13, bytes 6724, flags - &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="color: #00ff00;"&gt; UDP outside 10.71.127.73:61260 management 10.0.100.11:161, idle 0:00:21, bytes 86, flags - &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Community and version match what I'm polling with on NMS - like I said, the "base" configs are the same. I cannot snmp walk the device either outside of Orion.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I've tried removing and re-adding the node in Orion, but no luck.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:03:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-does-not-respond-to-snmp/m-p/2968011#M161353</guid>
      <dc:creator>richard.schultz1</dc:creator>
      <dc:date>2019-03-12T08:03:29Z</dc:date>
    </item>
    <item>
      <title>hi,</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-does-not-respond-to-snmp/m-p/2968012#M161354</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;the 'management' interface usually responds to traffic where the ASA itself is the destination (i.e. ping, SSH, etc), but can't pass any transit traffic through the ASA to or from another interface. do you have this line under 'management' interface?&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;no management-only&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2016 01:59:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-does-not-respond-to-snmp/m-p/2968012#M161354</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2016-07-26T01:59:38Z</dc:date>
    </item>
    <item>
      <title>John,</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-does-not-respond-to-snmp/m-p/2968013#M161355</link>
      <description>&lt;P&gt;John,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;"management" in this case is really just a moniker for our management vlan(s), not the actual management interface itself.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;On this network it's the firewall itself as the gateway, a 3850 switch stack, a KVM, and a Cyclades.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The switch stack 10.0.100.11 responds to SNMP from 10.71.127.73 just fine, but the ASA 10.0.100.254 is no longer responding to them where as it used to prior to replacing hardware.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2016 02:35:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-does-not-respond-to-snmp/m-p/2968013#M161355</guid>
      <dc:creator>richard.schultz1</dc:creator>
      <dc:date>2016-07-26T02:35:17Z</dc:date>
    </item>
  </channel>
</rss>

