02-11-2020 03:38 AM - edited 02-21-2020 09:54 AM
We're using FTD 2100 with FMC, need to get active RA VPN sessions counter over SNMP.
Information I've found is related to ASA and not suitable for FP.
Can anybody share useful FP OIDs or point to documentation links?
Solved! Go to Solution.
02-21-2020 03:14 AM
Enabling diagnostic interface it turned out we can use ASA-compatible SNMP mibs.
crasSVCNumSessions = 1.3.6.1.4.1.9.9.392.1.3.35.0 is the counter of RA VPN sessions.
Thanks for help, it was not so obvious from documentation.
02-11-2020 06:08 AM
Have you tried the ASA OIDs?
Assuming you are SNMP polling the diagnostic interface (not enabled by default), it should be the LINA/ASA code that is responding to your system - not the FTD or FX-OS parts of the system.
02-21-2020 03:14 AM
Enabling diagnostic interface it turned out we can use ASA-compatible SNMP mibs.
crasSVCNumSessions = 1.3.6.1.4.1.9.9.392.1.3.35.0 is the counter of RA VPN sessions.
Thanks for help, it was not so obvious from documentation.
02-21-2020 03:28 AM
You're welcome - you're right the documentation falls a bit short in this area.
03-23-2020 12:36 PM
Is there something you need to enable on the FTD or in FXOS?
I am trying to poll using that OID but all I get is:
SNMPv2-SMI::enterprises.9.9.392.1.3.35.0 = No Such Object available on this agent at this OID
03-23-2020 01:50 PM - edited 03-23-2020 01:50 PM
Yes, you need set up in FMC the IP for diagnistic interface which hosts aside management interface and do SNMP to that address.
05-24-2020 02:08 PM
If i understood correctly, i can use this oid for accounting of remote anyconnect users? Is it possible to use it to see in Zabbix accounts of users who are currently connected to anyconnect?
05-25-2020 01:30 AM
Support vareis by platform and version but you may be able to retrieve the usernames from here:
crasUsername | 1.3.6.1.4.1.9.9.392.1.3.21.1.1 |
Reference:
12-15-2020 08:39 AM
Hi,
we just replaced our ASA with a FTD 2110 and FMC, so this is completely new for me. I just enabled Diagnostic Interface via FMC with an IP in the same Subnet as the FXOS Management IP. However, I cannot ping it and also SNMP cannot reach it. How can I setup a Default Route for the Diagnostic Interface?
Do I need to import a new MIB file to my Monitoring or can I just use the one I used for ASA?
12-16-2020 07:48 AM
Hi,
I understand your confusing. Try to look at this thread https://community.cisco.com/t5/network-security/fp-diagnostic-interface-setting-up/td-p/4028172
12-21-2020 12:26 AM
Hello.
Good link, thanks.
10-28-2022 09:29 PM
hi, please tell me how to do it? in zabix and ftd?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide