cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
583
Views
0
Helpful
10
Replies

Zabbix is pinging devices via asa 5505 with 33% loss

dijix1990
VIP
VIP

 

We placed our devices behind our asa 5505 and after it I noticed that zabbix is pinging every devices behind the asa with loss where is the problem? Asa can't skip icmp without loss?

10 Replies 10

Hi

 Try to enable icmp inspection,  if not yet.

I didn't have it, but it didn't help

policy-map global_policy
class netflow-export-class
class inspection_default
inspect icmp

icmp permit any interface_switch

maybe the asa is dropping 1 out of 3 packets from zabbix because of the policy rate in default mode? there is very simple config for 100 devices, just permit icmp from zabbix to devices and permit snmp from zabbix to devices.
On the asa about 3000 conn

@dijix1990 hi, check firewall logs and make sure its dropped by firewall. if not this can be different issue like asymmetric routing, 

Please rate this and mark as solution/answer, if this resolved your issue
Good luck
KB

Hi, I have already watched and there was nothing. There are no drops at all.

1. Zabbix has ip 172.18.200.200 and is pinging devices which were placed in network 172.18.210./24 every 15 seconds

2. asa has ip 172.18.200.1 (vlan 100) and 172.18.210.1 (vlan200)

3.Zabbix can reach net 172.18.210.0/24 via 172.18.200.1

4. devices have default gateway as 172.18.210.1

When I move gw 172.18.200.1 and 172.18.210.1 to isr819 ping check becames perfect, I tested it for a day, there were no drops.

So it isn't asymmetric routing too

@dijix1990 hi, in that case we can suspect ASA. are you with latest recommended OS for ASA?

Please rate this and mark as solution/answer, if this resolved your issue
Good luck
KB

Yes. I installed this software asa924-33-k8.bin

@dijix1990 can you try enable debugging and share the output for specific flow?

Please rate this and mark as solution/answer, if this resolved your issue
Good luck
KB

To be honest no, but I will try today

Just start debug icmp trace?

dijix1990
VIP
VIP

hm it happens every 15 minutes

Review Cisco Networking for a $25 gift card