cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
12309
Views
25
Helpful
23
Replies

Monitoring ASA in Cisco Prime infrastructure 2.2

elnurh
Level 1
Level 1

Hi everybody.  I have some issue with cisco Prime Infrastructure  2.2.  We use this product in our network for monitoring network devices and I need to monitor also our ASA 5550 device with soft 8.4.  I  added ASA to Cisco PI but see only basic component like my device can reachable via  and read via snmp. But cannot see  CPU, RAM, Device ENV like Temperature, l2l vpn connection,  Interfaces status and Utilization that interfaces, cannot see sub interface that placed on ASA like that g0/0.20.  I need fully monitor ASA and See logs and trap for my device:

CPU RAM ENV (Temperature), Interface and sub interface status, L2L VPN  Status.

 

1 Cisco Prime infrastructure can full support  ASA for monitoring and logging.. IF YES how can i configure  that features in Cisco PI 2.2 for ASA

2 IF not which product Can full support that features for full monitoring and logging  ASA devices

 

I have a little deadline for finishing

thanks everybody before

23 Replies 23

elnurh
Level 1
Level 1

no one can help me in this direction ???????

Hi elnurh,

 

Here is the link to the supported device list for Prime 2.2. 

http://www.cisco.com/c/en/us/support/cloud-systems-management/prime-infrastructure/products-device-support-tables-list.html

For the ASA 5550s it appears that you need 9.1.(2) code for more support from Prime.  We have one of our ASAs being monitored through PI 2.1 currently and it has limitations as well with the 9.1.(2) code on the ASA.

the supported device list dun have WS-SVC-ASA-SM1 blade module for Cat6807.

anyone can confirm this is not supported?

chan zuan hua,

The PI 2.2 supported device list includes "Cisco Catalyst 6500 Series ASA Services Module OID:1.3.6.1.4.1.9.1.1277". That's the same module that's used in the 6807.

THanks I manage to use SNMPv3 to monitor, somehow when combine, SNMPv1 cannot run. 

Hello!

How did you configured it ?

I want to integrate an ASA 5520 with prime 2.2 (SNMP v3). The prime gives me the error:

Collection Status : SNMP Failure: Failed to create v3 USM User.

Please help

Thank you

What version of ASA software do you have?

PI requires ASA 9.1(2) or later to resolve an SNMP incompatibility issue.

Hello,

We use the ASA-s in multiple context.

My version is 8.2(5). Is there another way to integrate the ASA in prime with SNMP v3? I was not able to configure SNMP v2.c because I don't have Read and Write Community passwords to configure in CLI.

The issue has nothing to do with SNMP version.

There is an incompatibility with the older versions of ASA software being unable to interpret and respond to the SNMP queries as sent from Prime Infrastructure.

The requirement is documented in the PI 2.2 Supported Devices matrix:

http://www.cisco.com/c/en/us/support/cloud-systems-management/prime-infrastructure/products-device-support-tables-list.html

Hello,

In this case we will need to upgrade the ASA IOS.

Thank you very much

Hi All ,

I encountered the same error once which was really annoying.

However this is what I realised or how I got the solution .

  • The error came about when the two or more snmp-server users were using the same password . This caused  PI or prime to fail to authenticate with the correct user based on its the credential profile for v3 or the snmp v3 username being used to add the node to Prime .Since in prime the same authentication and privacy password was being used for two different users.

     For example

              snmp-server user prime TEST v3 auth md5 12345 priv aes 128 12345
             snmp-server user prime02 TEST v3 auth md5 12345 priv aes 128 12345

 

  • A device will  still show the two  snmp-server users details when you show snmp-server  user even though  you had used the no snmp-server user command format .
  • Workaround Configured the snmp-server user using different credentials  from any other previously used or entered to the device.Compared the details with the credential profile in Prime to verify  they are the same.

Thank you.

Hope this helps someone in case you run into such a problem in the future.

 

Hi,

Sorry to interfere in a thread initiated by someone . I have asa 5585 and pi2.2.

Unfortunately i cant even add the asa to the PI?(with only snmp parameters )

Please help

Thanks

You need to provide PI both SNMP RO and cli login credentials. With those, I have successfully added an ASA 5585 to PI 2.x.

Also, PI 3.x allows for collection of interface performance statistics from ASAs.

Hi ,

i am getting the error message below 

verification of one or more of the following fields failed
SNMP read community . Please fix this and retry

I made sure snmp community string are correct .

snmp-server host Inside 192.168.100.100 trap community ***** version 2c
no snmp-server location
no snmp-server contact
snmp-server enable traps syslog
snmp-server enable traps cpu threshold rising

Please help 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: