<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Monitoring Internet Availability using Cisco ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/monitoring-internet-availability-using-cisco-asa/m-p/1750252#M529809</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jeff,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Assuming you want to track failures upstream of the ASA and not the ASA's interface itself, SLA monitoring is probably your best bet. To be notified when the monitor fails, you can watch for syslog ID %ASA-6-622001. You can setup a custom logging list and have this syslog sent to an SNMP server like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging list sla-list message 622001&lt;/P&gt;&lt;P&gt;logging history sla-list&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will send %ASA-6-622001 messages to the SNMP server you have configured. Alternatively, you can also send it to a syslog server (logging trap sla-list) or to an email address (logging mail sla-list). Other than that, you'd have to have an internal server send pings out through the firewall and report back if they failed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 01 Oct 2011 17:03:03 GMT</pubDate>
    <dc:creator>mirober2</dc:creator>
    <dc:date>2011-10-01T17:03:03Z</dc:date>
    <item>
      <title>Monitoring Internet Availability using Cisco ASA</title>
      <link>https://community.cisco.com/t5/network-security/monitoring-internet-availability-using-cisco-asa/m-p/1750251#M529802</link>
      <description>&lt;P&gt;Just a general question to the group on how one monitors Internet availability/reachability via an ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The scenario right now is we have a number of offices with Internet feeds (primarily DSL/Cable/T1) connected to ASAs and we have the goal of being able to monitor if the Internet connected to the ASA is UP or DOWN.&amp;nbsp; My first thought was to configure an IP SLA and monitor the reachability of an upstream IP; however, all documentation I’ve read suggests that the ASA doesn’t support the SLA MIBs yet.&amp;nbsp; So I won’t be able to use SNMP to track its availability.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just throwing the feeler out there for comments and seeing how everyone else monitors Internet availability via the ASA platform.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks everyone.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:30:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/monitoring-internet-availability-using-cisco-asa/m-p/1750251#M529802</guid>
      <dc:creator>jc84_</dc:creator>
      <dc:date>2019-03-11T21:30:43Z</dc:date>
    </item>
    <item>
      <title>Monitoring Internet Availability using Cisco ASA</title>
      <link>https://community.cisco.com/t5/network-security/monitoring-internet-availability-using-cisco-asa/m-p/1750252#M529809</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jeff,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Assuming you want to track failures upstream of the ASA and not the ASA's interface itself, SLA monitoring is probably your best bet. To be notified when the monitor fails, you can watch for syslog ID %ASA-6-622001. You can setup a custom logging list and have this syslog sent to an SNMP server like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging list sla-list message 622001&lt;/P&gt;&lt;P&gt;logging history sla-list&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will send %ASA-6-622001 messages to the SNMP server you have configured. Alternatively, you can also send it to a syslog server (logging trap sla-list) or to an email address (logging mail sla-list). Other than that, you'd have to have an internal server send pings out through the firewall and report back if they failed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Oct 2011 17:03:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/monitoring-internet-availability-using-cisco-asa/m-p/1750252#M529809</guid>
      <dc:creator>mirober2</dc:creator>
      <dc:date>2011-10-01T17:03:03Z</dc:date>
    </item>
  </channel>
</rss>

