<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do you monitor your IPSec connections?? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-do-you-monitor-your-ipsec-connections/m-p/3762895#M8439</link>
    <description>Agreed Marvin.  I use solarwinds and using universal device poller you&lt;BR /&gt;schedule polling intervals for any OID and display it on chart&lt;BR /&gt;</description>
    <pubDate>Thu, 13 Dec 2018 11:45:02 GMT</pubDate>
    <dc:creator>Mohammed al Baqari</dc:creator>
    <dc:date>2018-12-13T11:45:02Z</dc:date>
    <item>
      <title>How do you monitor your IPSec connections??</title>
      <link>https://community.cisco.com/t5/network-security/how-do-you-monitor-your-ipsec-connections/m-p/3762643#M8430</link>
      <description>&lt;P&gt;Picking at an old topic here.&amp;nbsp;We have a PRTG installation for monitoring, but It can't handle all IPSec via SNMP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How do you monitor IPSec connections on ASA, and alert on them? Tools, scripts, anything...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Michael&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:34:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-do-you-monitor-your-ipsec-connections/m-p/3762643#M8430</guid>
      <dc:creator>Michael Bartholomæussen</dc:creator>
      <dc:date>2020-02-21T16:34:18Z</dc:date>
    </item>
    <item>
      <title>Re: How do you monitor your IPSec connections??</title>
      <link>https://community.cisco.com/t5/network-security/how-do-you-monitor-your-ipsec-connections/m-p/3762723#M8431</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;check these link might it help you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-analytics-and/vpn-monitoring-solution/td-p/742353" target="_blank"&gt;https://community.cisco.com/t5/security-analytics-and/vpn-monitoring-solution/td-p/742353&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/t5/networking-documents/how-can-i-monitor-vpn-tunnel-status-through-snmp/ta-p/3130785" target="_blank"&gt;https://community.cisco.com/t5/networking-documents/how-can-i-monitor-vpn-tunnel-status-through-snmp/ta-p/3130785&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Dec 2018 09:15:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-do-you-monitor-your-ipsec-connections/m-p/3762723#M8431</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2018-12-13T09:15:39Z</dc:date>
    </item>
    <item>
      <title>Re: How do you monitor your IPSec connections??</title>
      <link>https://community.cisco.com/t5/network-security/how-do-you-monitor-your-ipsec-connections/m-p/3762751#M8433</link>
      <description>&lt;P&gt;I was unaware of Security Manager until now, I'll have to give it a try.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The snmp&amp;nbsp;approach adds additional manual steps, since the OID changes when the tunnel re-keys. One would have to lookup the new value, and then change the monitoring to poll the new OID. This could potential give false alerts in the time span between a new OID and script execution. I might have approached it the wrong why. so there could be someone who has this running?&lt;/P&gt;</description>
      <pubDate>Thu, 13 Dec 2018 09:31:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-do-you-monitor-your-ipsec-connections/m-p/3762751#M8433</guid>
      <dc:creator>Michael Bartholomæussen</dc:creator>
      <dc:date>2018-12-13T09:31:42Z</dc:date>
    </item>
    <item>
      <title>Re: How do you monitor your IPSec connections??</title>
      <link>https://community.cisco.com/t5/network-security/how-do-you-monitor-your-ipsec-connections/m-p/3762812#M8434</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Did you try OID 1.3.6.1.4.1.9.9.171. It is for monitoring IPSec VPN&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://snmp.cloudapps.cisco.com/Support/SNMP/do/BrowseOID.do?local=en&amp;amp;translate=Translate&amp;amp;objectInput=1.3.6.1.4.1.9.9.171" target="_blank"&gt;https://snmp.cloudapps.cisco.com/Support/SNMP/do/BrowseOID.do?local=en&amp;amp;translate=Translate&amp;amp;objectInput=1.3.6.1.4.1.9.9.171&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 13 Dec 2018 10:08:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-do-you-monitor-your-ipsec-connections/m-p/3762812#M8434</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2018-12-13T10:08:02Z</dc:date>
    </item>
    <item>
      <title>Re: How do you monitor your IPSec connections??</title>
      <link>https://community.cisco.com/t5/network-security/how-do-you-monitor-your-ipsec-connections/m-p/3762867#M8436</link>
      <description>&lt;P&gt;Yes, I did look at the IP_SEC_FLOW_MONITOR mib, and the output is like this -&amp;gt;&lt;/P&gt;
&lt;TABLE border="0" cellspacing="1" cellpadding="1" align="left"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="45%" align="left"&gt;&lt;STRONG&gt;cikeTunStatus.12640256&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="55%" align="left;"&gt;active(1)&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;TABLE border="0" cellspacing="1" cellpadding="1" align="left"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="45%" align="left" bgcolor="#f2f2f2"&gt;&lt;STRONG&gt;cikeTunStatus.12787712&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="55%" align="left;" bgcolor="#f2f2f2"&gt;active(1)&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;TABLE border="0" cellspacing="1" cellpadding="1" align="left"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="45%" align="left"&gt;&lt;STRONG&gt;cikeTunStatus.12800000&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="55%" align="left;"&gt;active(1)&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;TABLE border="0" cellspacing="1" cellpadding="1" align="left"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="45%" align="left" bgcolor="#f2f2f2"&gt;&lt;STRONG&gt;cikeTunStatus.12808192&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="55%" align="left;" bgcolor="#f2f2f2"&gt;active(1)&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;TABLE border="0" cellspacing="1" cellpadding="1" align="left"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="45%" align="left"&gt;&lt;STRONG&gt;cikeTunStatus.12820480&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="55%" align="left;"&gt;active(1)&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;TABLE border="0" cellspacing="1" cellpadding="1" align="left"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="45%" align="left" bgcolor="#f2f2f2"&gt;&lt;STRONG&gt;cikeTunStatus.12865536&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="55%" align="left;" bgcolor="#f2f2f2"&gt;active(1)&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Where cikeTunStatus = 1.3.6.1.4.1.9.9.171.1.2.3.1.+(TUNNEL OID = 12820480). when the tunnel flaps or re-keys den OID changes. I can lookup the remote peer IP multiple places, to get the new OID, but some automation would have to lookup the new value, and update en entire OID in the monitoring software.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm trying Cisco security manager, but the installer takes forever. VPNTTG is able to provide the correct output (havn't tried it, but they promise that it can do the job)&lt;/P&gt;</description>
      <pubDate>Thu, 13 Dec 2018 10:53:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-do-you-monitor-your-ipsec-connections/m-p/3762867#M8436</guid>
      <dc:creator>Michael Bartholomæussen</dc:creator>
      <dc:date>2018-12-13T10:53:46Z</dc:date>
    </item>
    <item>
      <title>Re: How do you monitor your IPSec connections??</title>
      <link>https://community.cisco.com/t5/network-security/how-do-you-monitor-your-ipsec-connections/m-p/3762878#M8438</link>
      <description>&lt;P&gt;I'm not sure how they handle the OID, but SolarWinds NPM seems to work fine at monitoring IPsec VPNs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;CSM wouldn't be a good strategic investment in my opinion. I wouldn't be surprised to see it retired in the next year or two.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Dec 2018 11:05:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-do-you-monitor-your-ipsec-connections/m-p/3762878#M8438</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-12-13T11:05:13Z</dc:date>
    </item>
    <item>
      <title>Re: How do you monitor your IPSec connections??</title>
      <link>https://community.cisco.com/t5/network-security/how-do-you-monitor-your-ipsec-connections/m-p/3762895#M8439</link>
      <description>Agreed Marvin.  I use solarwinds and using universal device poller you&lt;BR /&gt;schedule polling intervals for any OID and display it on chart&lt;BR /&gt;</description>
      <pubDate>Thu, 13 Dec 2018 11:45:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-do-you-monitor-your-ipsec-connections/m-p/3762895#M8439</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2018-12-13T11:45:02Z</dc:date>
    </item>
    <item>
      <title>Re: How do you monitor your IPSec connections??</title>
      <link>https://community.cisco.com/t5/network-security/how-do-you-monitor-your-ipsec-connections/m-p/3762896#M8441</link>
      <description>&lt;P&gt;I agree, that CSM wouldn't be a viable solution - did Prime Security Manager provide this feature, despite that it's EOL, in favor for FMC on FTD?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How does NPM handle the dynamic OID?&lt;/P&gt;</description>
      <pubDate>Thu, 13 Dec 2018 11:53:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-do-you-monitor-your-ipsec-connections/m-p/3762896#M8441</guid>
      <dc:creator>Michael Bartholomæussen</dc:creator>
      <dc:date>2018-12-13T11:53:24Z</dc:date>
    </item>
    <item>
      <title>Re: How do you monitor your IPSec connections??</title>
      <link>https://community.cisco.com/t5/network-security/how-do-you-monitor-your-ipsec-connections/m-p/3763080#M8443</link>
      <description>&lt;P&gt;We do out of the box using Linux connect to ASA and get the out and graph them using elastic dash board.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Example as below : ( poll every 5min and get the details and make a graph)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;sh vpn-sessiondb detail anyconnect&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Dec 2018 15:48:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-do-you-monitor-your-ipsec-connections/m-p/3763080#M8443</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2018-12-13T15:48:17Z</dc:date>
    </item>
  </channel>
</rss>

