<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic On an ASA you need to in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/monitoring-an-interface-on-asa/m-p/2670177#M192161</link>
    <description>&lt;P&gt;On an ASA you need to specifically allow the management servers to make SNMP queries. Only RO is supported on an ASA.&lt;/P&gt;&lt;P&gt;For SNMP v2c, the command would be:&lt;/P&gt;&lt;P&gt;snmp-server host &amp;lt;nameif&amp;gt; &amp;lt;server IP&amp;gt;&amp;nbsp;community &amp;lt;snmp community string&amp;gt;&lt;/P&gt;</description>
    <pubDate>Tue, 28 Apr 2015 20:24:42 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2015-04-28T20:24:42Z</dc:date>
    <item>
      <title>Monitoring an Interface on ASA</title>
      <link>https://community.cisco.com/t5/network-security/monitoring-an-interface-on-asa/m-p/2670176#M192159</link>
      <description>&lt;P&gt;I have a 5550, we want to poll the inside interface using a snmp monitoring app. &amp;nbsp;I added the "management-access intfname" to allow the polling, but the snmp polling server isn't able to get info from the interface.&amp;nbsp; The poller is getting info from interfaces on equipment inside the ASA.&lt;/P&gt;&lt;P&gt;Any suggestions as to why this isn't working?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:51:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/monitoring-an-interface-on-asa/m-p/2670176#M192159</guid>
      <dc:creator>wesweber1</dc:creator>
      <dc:date>2019-03-12T05:51:23Z</dc:date>
    </item>
    <item>
      <title>On an ASA you need to</title>
      <link>https://community.cisco.com/t5/network-security/monitoring-an-interface-on-asa/m-p/2670177#M192161</link>
      <description>&lt;P&gt;On an ASA you need to specifically allow the management servers to make SNMP queries. Only RO is supported on an ASA.&lt;/P&gt;&lt;P&gt;For SNMP v2c, the command would be:&lt;/P&gt;&lt;P&gt;snmp-server host &amp;lt;nameif&amp;gt; &amp;lt;server IP&amp;gt;&amp;nbsp;community &amp;lt;snmp community string&amp;gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2015 20:24:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/monitoring-an-interface-on-asa/m-p/2670177#M192161</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-04-28T20:24:42Z</dc:date>
    </item>
    <item>
      <title>The snmp config was put on</title>
      <link>https://community.cisco.com/t5/network-security/monitoring-an-interface-on-asa/m-p/2670178#M192162</link>
      <description>&lt;P&gt;The snmp config was put on the ASA first and the snmp servers couldn't query the ASA. The management-access command was added to facilitate the snmp servers ability to talk to the ASA.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2015 22:15:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/monitoring-an-interface-on-asa/m-p/2670178#M192162</guid>
      <dc:creator>wesweber1</dc:creator>
      <dc:date>2015-04-28T22:15:59Z</dc:date>
    </item>
    <item>
      <title>You might try capturing the</title>
      <link>https://community.cisco.com/t5/network-security/monitoring-an-interface-on-asa/m-p/2670179#M192163</link>
      <description>&lt;P&gt;You might try capturing the traffic from the management server at the ASA and see what's happening.&lt;/P&gt;&lt;P&gt;Also, do you see any log messages when snmp polling fails? (assuming you have logging enabled at a sufficient level)&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2015 02:15:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/monitoring-an-interface-on-asa/m-p/2670179#M192163</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-04-29T02:15:35Z</dc:date>
    </item>
    <item>
      <title>The solution is, there is a</title>
      <link>https://community.cisco.com/t5/network-security/monitoring-an-interface-on-asa/m-p/2670180#M192165</link>
      <description>&lt;P&gt;The solution is, there is a bug in v8.4 and above that prevents monitoring traffic (ping, ssh, snmptraffic, etc) from a VPN tunnel to pass through the ASA and connect to the&amp;nbsp;interface with the management-access command applied on the ASA. &amp;nbsp;This bug is documented in the release notes for 8.4.&lt;/P&gt;&lt;P&gt;The workaround is to add the keyword route-lookup to any nat statements that involve the subnet the "management" interface resides in.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I added the keyword to the nat statement and was able to ping and do snmp polls to the interface.&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2015 22:12:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/monitoring-an-interface-on-asa/m-p/2670180#M192165</guid>
      <dc:creator>wesweber1</dc:creator>
      <dc:date>2015-05-29T22:12:15Z</dc:date>
    </item>
  </channel>
</rss>

