09-05-2012 05:04 AM - edited 03-11-2019 04:50 PM
Hello Everyone,
I have a pair of 5 pairs of active/standby ASA firewalls running 8.4.4(1)
All the active firewall respond to the SNMP requests, but the standby firewalls do not. I'm using SNMP v3. The configuration of primary and secondary firewalls is replica of each other, apart from the ip addressess.
I want the secondary firewall to respond to SNMP requests coming in from the monitoring server. Can someone please help ?
Thanks,
Rishi
09-05-2012 06:46 AM
Are you able to reach the SNMP server from the standby firewalls?? What information are you trying to poll from the standby machine?
Thanks,
Varun Rao
Security Team,
Cisco TAC
09-05-2012 01:15 PM
Assuming you can ping both firewalls, the problem is that the firewall pair shares the same config and therefore, the same SNMPv3 engineID. Some NMSs (e.g. WhatsUp Gold) do not support this and therefore only 1 firewall in the pair can be queried.
Doesn't look like this has been fixed yet:
Bug info: CSCtl88556 - ASA5520 failover pair has duplicate snmp v3 engine id
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide