<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SNMP Query for Byspass Status (AIP5) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/snmp-query-for-byspass-status-aip5/m-p/1740340#M56031</link>
    <description>&lt;P&gt;I'd like to monitor the state of Bypass mode for the ASA-SSC-AIP-5 and would like to know if I can check this with SNMP and if so, which OID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I started messing with SNMP and the SSC5 a while back and started a thread about &lt;A _jive_internal="true" href="https://community.cisco.com/message/3353508#3353508" target="_blank"&gt;snmpwalk causing it to crash&lt;/A&gt;.&amp;nbsp; After that, I never really picked the project back up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've been known to miss the obvious every now and then, but I was dissapointed to see that there wasn't an (obvious) way for the device to alert you when it automatically goes into bypass mode.&amp;nbsp; This should be a feature request.&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 12:31:04 GMT</pubDate>
    <dc:creator>Mark^</dc:creator>
    <dc:date>2019-03-10T12:31:04Z</dc:date>
    <item>
      <title>SNMP Query for Byspass Status (AIP5)</title>
      <link>https://community.cisco.com/t5/network-security/snmp-query-for-byspass-status-aip5/m-p/1740340#M56031</link>
      <description>&lt;P&gt;I'd like to monitor the state of Bypass mode for the ASA-SSC-AIP-5 and would like to know if I can check this with SNMP and if so, which OID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I started messing with SNMP and the SSC5 a while back and started a thread about &lt;A _jive_internal="true" href="https://community.cisco.com/message/3353508#3353508" target="_blank"&gt;snmpwalk causing it to crash&lt;/A&gt;.&amp;nbsp; After that, I never really picked the project back up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've been known to miss the obvious every now and then, but I was dissapointed to see that there wasn't an (obvious) way for the device to alert you when it automatically goes into bypass mode.&amp;nbsp; This should be a feature request.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:31:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-query-for-byspass-status-aip5/m-p/1740340#M56031</guid>
      <dc:creator>Mark^</dc:creator>
      <dc:date>2019-03-10T12:31:04Z</dc:date>
    </item>
    <item>
      <title>Re: SNMP Query for Byspass Status (AIP5)</title>
      <link>https://community.cisco.com/t5/network-security/snmp-query-for-byspass-status-aip5/m-p/1740341#M56032</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;IPS provides SNMP traps for different interface conditions like link going down or up, traffic bypass started, etc. Below is one such example&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE style="font-family: courier, monospace; background-color: #f0ece6; white-space: pre-wrap; word-wrap: break-word; padding: 0.5em; border: 1pt solid #c0c0c0;"&gt;Received SNMPv2c Trap: Community: "public" 
From: 10.89.149.204 mib_2.1.3.0 = 38429472 
snmpModules.1.1.4.1.0 = ciscoMgmt.138.2.0.1 
ciscoMgmt.138.1.3.3.1.3 = 3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;====&amp;nbsp;&amp;nbsp;&amp;nbsp; index can be mapped to index obtained from snmpwalk 
ciscoMgmt.138.1.3.3.1.4 = 5&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;====&amp;nbsp;&amp;nbsp;&amp;nbsp; Traffic bypass started 
ciscoMgmt.138.1.3.3.1.5 = 4 
ciscoMgmt.138.1.3.3.1.6 = 38429472&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All you need to do is enable sending traps from the sensor.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;qssp-8085(config)# service notification &lt;/P&gt;&lt;P&gt;qssp-8085(config-not)# enable-set-get true&lt;/P&gt;&lt;P&gt;qssp-8085(config-not)# enable-notification true&lt;/P&gt;&lt;P&gt;qssp-8085(config-not)# read-only-community public&lt;/P&gt;&lt;P&gt;qssp-8085(config-not)# read-write-community private&lt;/P&gt;&lt;P&gt;qssp-8085(config-not)# trap-destinations x.x.x.x&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;===== trap destination&lt;/P&gt;&lt;P&gt;qssp-8085(config-not-tra)# exit&lt;/P&gt;&lt;P&gt;qssp-8085(config-not)# exit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can configure separate community name under trap-destination. If not provided then the read-write-community will be used to send with the trap.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Madhu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Oct 2011 14:27:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-query-for-byspass-status-aip5/m-p/1740341#M56032</guid>
      <dc:creator>mkodali</dc:creator>
      <dc:date>2011-10-18T14:27:39Z</dc:date>
    </item>
    <item>
      <title>Re: SNMP Query for Byspass Status (AIP5)</title>
      <link>https://community.cisco.com/t5/network-security/snmp-query-for-byspass-status-aip5/m-p/1740342#M56033</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you tell me what OID I want for bypass status?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;EDIT: Nevermind, I see you pointed it out right there.&amp;nbsp; Thank you!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Oct 2011 15:21:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-query-for-byspass-status-aip5/m-p/1740342#M56033</guid>
      <dc:creator>Mark^</dc:creator>
      <dc:date>2011-10-20T15:21:43Z</dc:date>
    </item>
    <item>
      <title>SNMP Query for Byspass Status (AIP5)</title>
      <link>https://community.cisco.com/t5/network-security/snmp-query-for-byspass-status-aip5/m-p/1740343#M56034</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Alright, so how would I turn this into an snmpget to just get the status of the bypass?&amp;nbsp; Maybe I am missing some MIB or something...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Oct 2011 16:13:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-query-for-byspass-status-aip5/m-p/1740343#M56034</guid>
      <dc:creator>Mark^</dc:creator>
      <dc:date>2011-10-27T16:13:39Z</dc:date>
    </item>
    <item>
      <title>SNMP Query for Byspass Status (AIP5)</title>
      <link>https://community.cisco.com/t5/network-security/snmp-query-for-byspass-status-aip5/m-p/1740344#M56035</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; We are revising the CISCO-CIDS-MIB in the later version of IPS software like 7.1-3 and 7.0-7. These versions are not out yet but whey you get them to load on your sensor you should be able to do a GET for Bypassmode as shown below :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By OID :&lt;/P&gt;&lt;P&gt;qats-174:23&amp;gt; ./getone -v2c 10.x.x.x &lt;COMMUNITY&gt; 1.3.6.1.4.1.9.9.383.1.4.27.0&lt;/COMMUNITY&gt;&lt;/P&gt;&lt;P&gt;cidsHealthSecMonByPassMode.0 = off(2)&lt;/P&gt;&lt;P&gt;By Name :&lt;/P&gt;&lt;P&gt;qats-174:24&amp;gt; ./getone -v2c 10.x.x.x &lt;COMMUNITY&gt; cidsHealthSecMonByPassMode.0&lt;/COMMUNITY&gt;&lt;/P&gt;&lt;P&gt;cidsHealthSecMonByPassMode.0 = off(2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;&lt;P&gt;Madhu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Oct 2011 16:34:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-query-for-byspass-status-aip5/m-p/1740344#M56035</guid>
      <dc:creator>mkodali</dc:creator>
      <dc:date>2011-10-27T16:34:03Z</dc:date>
    </item>
    <item>
      <title>SNMP Query for Byspass Status (AIP5)</title>
      <link>https://community.cisco.com/t5/network-security/snmp-query-for-byspass-status-aip5/m-p/1740345#M56036</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hmm, thanks Madhu.&amp;nbsp; Since I have the AIP5, software versions 7.x aren't supported.&amp;nbsp; Where can I get the proper MIB?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Oct 2011 16:39:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-query-for-byspass-status-aip5/m-p/1740345#M56036</guid>
      <dc:creator>Mark^</dc:creator>
      <dc:date>2011-10-27T16:39:00Z</dc:date>
    </item>
    <item>
      <title>SNMP Query for Byspass Status (AIP5)</title>
      <link>https://community.cisco.com/t5/network-security/snmp-query-for-byspass-status-aip5/m-p/1740346#M56037</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks like there are no plans to port this enhancement onto AIP-5 at this stage. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Madhu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Oct 2011 18:54:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-query-for-byspass-status-aip5/m-p/1740346#M56037</guid>
      <dc:creator>mkodali</dc:creator>
      <dc:date>2011-10-27T18:54:02Z</dc:date>
    </item>
    <item>
      <title>SNMP Query for Byspass Status (AIP5)</title>
      <link>https://community.cisco.com/t5/network-security/snmp-query-for-byspass-status-aip5/m-p/1740347#M56038</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you stating that I cannot get bypass status with an snmpget? &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Oct 2011 13:09:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-query-for-byspass-status-aip5/m-p/1740347#M56038</guid>
      <dc:creator>Mark^</dc:creator>
      <dc:date>2011-10-28T13:09:14Z</dc:date>
    </item>
    <item>
      <title>SNMP Query for Byspass Status (AIP5)</title>
      <link>https://community.cisco.com/t5/network-security/snmp-query-for-byspass-status-aip5/m-p/1740348#M56039</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Answering this is beyond my scope and I would suggest your account team to contact our IPS marketing. Sorry about that..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Madhu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Oct 2011 16:31:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-query-for-byspass-status-aip5/m-p/1740348#M56039</guid>
      <dc:creator>mkodali</dc:creator>
      <dc:date>2011-10-28T16:31:45Z</dc:date>
    </item>
    <item>
      <title>SNMP Query for Byspass Status (AIP5)</title>
      <link>https://community.cisco.com/t5/network-security/snmp-query-for-byspass-status-aip5/m-p/1740349#M56040</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok, no worries.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Oct 2011 17:08:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-query-for-byspass-status-aip5/m-p/1740349#M56040</guid>
      <dc:creator>Mark^</dc:creator>
      <dc:date>2011-10-28T17:08:56Z</dc:date>
    </item>
  </channel>
</rss>

