10-04-2019 02:43 AM - edited 02-21-2020 09:33 AM
i have recently deployed a site to site between a Firepower FTD and a ASA which is up and working but im unable to monitor the FTD using SNMP over the VPN. i have enabled access via the platform settings however it seems im only able to get stats if i use the external IP address of the firewall. This is not an option as it would be sending all SNMP traffic over the internet and not down the tunnel. I know in the traditional ASA config you would apply the management-access command which would make inbound VPN connections terminate on an interface of your choosing. I thought about trying to apply a flex config with the management-access statement but im unsure if this would work.
has anyone else been able to deploy SNMP successfully to an FTD without using the FMC or the outside VPN address?
Solved! Go to Solution.
10-05-2019 08:00 AM
10-05-2019 08:00 AM
10-07-2019 12:29 AM
I'd like to second that statement. I have my monitoring centralized watching sites over VPN and adding management-access using FlexConfig allowed me to monitor the FTDs on one of the data interfaces behind the VPNs.
Regards
Fredrik
01-07-2022 09:48 AM
What guide/docs did you leverage to build the flexconfig parameters?
01-07-2022 09:46 AM
Im not seeing this documented in any of the configuration guides, is there a link or doc that outlines this process/configuration or is a TAC case the only way?
04-17-2020 02:32 PM
Would you mind sharing the exact commands used in order to get SNMP working over a VPN tunnel?
Thanks!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide