Set Interface Index Persistence on Cisco ASA 554x
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-17-2015 12:44 AM - edited 03-11-2019 11:53 PM
Hi,
I have a network monitoring tool that fails after my FW restart because the SNMP MIB IfIndex changes everytime it reboots.
Searching on Cisco.com I see there is a feautre available on snmp-server config http://www.cisco.com/c/en/us/support/docs/ip/simple-network-management-protocol-snmp/28420-ifIndex-Persistence.html but I am not able to find out that option.
Firewall(config)# snmp
Firewall(config)# snmp?
configure mode commands/options:
snmp snmp-map snmp-server
Firewall(config)# snmp-ser
Firewall(config)# snmp-server ?
configure mode commands/options:
community Configure the community string
contact Text for mib object sysContact
enable Enable/Disable snmp-server or particular traps
group Define User Security Model Group
host Specify hosts to receive SNMP traps and send SNMP polls
listen-port Configure the SNMP engine's listening port
location Text for mib object sysLocation
user Define a user who can access the SNMP engine
Firewall(config)# snmp-server if
Firewall(config)# snmp-server if
Firewall(config)# snmp-server if?
ERROR: % Unrecognized command
Firewall(config)# snmp-server enab
Firewall(config)# snmp-server enable
FW1-JC(config)# snmp-server enable ?
configure mode commands/options:
traps Configure traps
<cr>
My hardware is the following
Compiled on Fri 30-Aug-13 19:48 by builders
System image file is "disk0:/asa847-k8.bin"
Config file at boot was "startup-config"
Hardware: ASA5540, 2048 MB RAM, CPU Pentium 4 2000 MHz
Internal ATA Compact Flash, 256MB
Where is located that option?
Thank you.
- Labels:
-
NGFW Firewalls

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-19-2016 09:16 AM
Hello
it seems that a request for enhancement is opened at cisco :
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCtx33616
rgds
Guillaume
rate if uselful !
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-07-2018 02:47 AM
I understand from the mentioned link CSCtx33616 above that it means "it is not a bug it is a feature". It is a phrase used if you do not want to fix some issue.
I have the same problem with Cisco Firepower 2100 device. So manual changing of SNMP indexes after every reboot is necessary. Do you still like Firepower firewalls?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-07-2018 04:29 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-17-2018 04:34 AM
We use WhatsUp Gold. But all monitoring tolls would be confused if the index is different. Theoretically, the SW can compare interfaces by other parameters (speed, MAC address etc) and prepare a list old index <> new index. Much easier is that the monitored systems use the same index as it was used before reboot.
