cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
765
Views
0
Helpful
2
Replies

Integration amongs Cisco FP with PRTG / Nagios

hanguye3
Cisco Employee
Cisco Employee

Hi team,

 

I am having an request to integrate our FMC (6.4.0.4, using FP-4110) with some monitoring tools like PRTG and Nagios.

 

Highly appreciated that any guys experienced with those tools can share some advises and the configuration as well...

 

Br,

hainm

2 Replies 2

nspasov
Cisco Employee
Cisco Employee

What type of integration are you looking to do? From a PRTG perspective, you can utilize SNMP.

Thank you for rating helpful posts!

@nspasov  

I have an SSL-Certificate alarm from PRTG correctly highlighting the "Unable to check revocation status"

Christory_0-1710354753554.png

 

 

with <sh crypto ca certificates> I can see that the issuing or root certification authority or the root certification authority is available to be queried.


I can also see the certificate via Cisco ASDM

>Configuration>Remote Access VPN>Certificate Management>CA Certificates.
I don't understand why I've been getting this alarm for 1 week on 3 out of 20 ASA firewalls.

 

I use the following command on the firewall in the CLI and if I do a firewall rule import from the firewall and then a deployment, the parameter is overwritten:     ssl trustp-point My_trustpoint

 

conf t
dynamic-access-policy-confi activate
vpn-addr-assign local reuse-delay 0
no ssl trust-point <My_trustpoint>

 

I don't understand why (CSM) Cisco Security Manager keeps deleting the last command line and unfortunately, I haven't found the corner of the CSM where this is configured....


This is probl the reason why messages appear in the prtg, coz the verified CA is not the right one or it is, by default, self-signed certificates on firewalls.

 

the chain is unfortunately not routed to internet." Unable to resolve domain name" is the message I got from ssllabs.com

 

Is there any workaround to validate or compare my settings?

 

 

 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card