01-31-2023 01:12 AM
Hello Community,
I hope, I'm on the right Board posted.
I have a firepower 1120 device configured with dual WAN. Both ISP has their MRTG for internet monitoring. I observed frequent downtime in the primary ISP. When I informed my ISP, they always replied it was server maintenance and no service disruption, only the merge. Are there available logs on my Cisco firepower device available to check if there is traffic from the outside interface coming from ISP?
I hope someone can help me with this.
Thank you, Cisco community.
01-31-2023 01:50 AM
Smaller drops you may not noticed in the NMS, since you may be polling the Data every 5min using SNMP, this was missing most of the NMS systems, these kind of issue you may need some realtime monitoring system to identify the issue.
On the Firepower do you do not see this until it failover automatically due to any SLA created.
best is setup any script to monitor ISP using the path to interent.
or setup a netflow to get any telemetry data.
or decrease the snmp polling intervals to less than 10sec to monitor you can get any outcomes for the issue.
01-31-2023 01:53 AM
If you are using FMC, you can look at the Health Monitor page for the device and set a custom period for the time you want to see interface statistics.
01-31-2023 02:52 AM
Thanks to both of you Marvin and Bandi.
The MRTG is owned and managed by ISP, and they provided me a copy of mrtg link to monitor it. Also, I'm not sure about FMC. How to check if FMC is installed or running on my device?
Thank you
01-31-2023 05:15 AM
FMC is the Cisco Secure Firewall Management Center. It's an application that runs on a separate server. It provides a lot more functionality for an FTD installation; but it sounds like you don't have it.
The MRTG access would probably be your best bet for a small installation like yours. the on-box Firewall Device Manager (FDM) has very limited monitoring capability and what little it has is only real-time (i.e., almost no historical statistics).
01-31-2023 05:28 AM
Not sure if the MRTG link you are provided with would show you the interfaces of the ISP devices only or if your firewall WAN interfaces stats are included?! if not, I would recommend to configure NetFlow on your firewall WAN interfaces, or using ICMP to monitor those interfaces via you own instance of MRTG. MRTG should alert you with some email notifications about any disconnection.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide