FWSM and ARP SNMP MIB

Hello

I have two cards FWSM in two 6513 switches with active failover.

Connected to the switches are several servers connected to different interfaces of the firewall. One of them is a HPOV (openview) needs the ARP table of the FWSM to reach and explore the net together to start to monitorize the network.

My problem is that I can't get the firewall ARP table, so I can't find out more devices, I am able to SNMP them by editing the poller SNMP in the configuration file of OVO, but even network devices is displayed, it cannot achieve the work.

I stick my worm here sh.

FWSM-1 # sh ver

FWSM Firewall Version 3.2 (1)

Version 5.2 (1) F Device Manager

Updated Friday, June 7 07 20:16 by which

FWSM-1 up to 7 days, 13 hours

1 year 94 days upwards failover cluster

Material:-WS-SVC-FWM-1, 1024 MB RAM, Pentium III 1000 MHz processor

Flash Flash STI 7.2.0 @ 0xc321, 20 MB

0: Int: do not license: irq 5

1: Int: do not license: irq 7

2: Int: do not license: irq 11

The activation key running is not set, using the default settings:

The devices allowed for this platform:

Maximum Interfaces: 256

Internal hosts: unlimited

Failover: Active/active

VPN - A: enabled

VPN-3DES-AES: enabled

Cut - through Proxy: enabled

Guardians: enabled

URL filtering: enabled

Security contexts: 2

GTP/GPRS: disabled

Heel of BGP: disabled

VPN peers: unlimited

Serial number: SAD101804FV

Activation key running: 0x00000000 0x00000000 0x00000000 0x00000000

Configuration changed from enable_1 to 13:59:35.590 THIS Monday, November 3, 2008

I think that version 3.2 can not recover the MIB for ARP, and I found this version 4.01 only. But I was unable to find any kind of upgrade notes here, and we have the control of server farms proyect sttoped for this problem.

Any who had this problem?

How did solve you this?

Thank you!

Angel,

You're right, '(IP - MIB) ARP table entries' MIB was introduced in 4.0 (1) and you have to upgrade to 4.0 code to get to the ARP Table via SNMP MIB.

And here is the document that contains information on the FWSM upgrade.

http://www.Cisco.com/en/us/docs/security/FWSM/fwsm40/configuration/guide/swcnfg_f.html#wp1052902

Kind regards

Arul

* Rate pls if it helps *.

Tags: Cisco Security

Similar Questions

  • SNMP MIB reference

    Hello

    I would need the reference of SNMP MIB for C-Codecs, etc. SX20.

    Thank you

    Tino

    C Series uses XML comments to provide the status and only supports of these OID described in RFC1213

    1.3.6.1.2.1.1.1

    1.3.6.1.2.1.1.2

    1.3.6.1.2.1.1.3

    1.3.6.1.2.1.1.4

    1.3.6.1.2.1.1.5

    1.3.6.1.2.1.1.6

    1.3.6.1.2.1.1.7

    (sysDescr, sysObjectID, sysUpTime, sysContact, sysName, sysLocation, sysServices)

    -----------------------------------------------------------------------

    Look at this topic:

    https://supportforums.Cisco.com/thread/2165290

    Paulo Souza

  • SNMP MIB for PowerConnect X 1000 series

    Hello

    Where can I download SNMP MIB for Dell PowerConnect X 1000 Series switch? I would like to use MIBs updated rather than generic Dell PowerConnect MIBs.

    Thank you!

    Firmware download includes MIB.

    http://Dell.to/1KADEsz

    See you soon

  • What are the optimal values for mac and arp timeout values

    Hi guys.

    What are the best values for 'mac address-table-time of ageing' and "arp timeout" by following scenarios? :

    -single sg300-10 as hosts Layer 3 - with a maximum of 10 local switch (directly connected)

    - and a 3750 x-stack with 100 local hosts + hsrp with a battery of the same kind

    or for asa 5520 as internet gateway for 500 customers?

    I use now a time of aging mac 300 seconds and a time-out of the arp of 3600 seconds.

    Is - this okay.?

    Thank you.

    These values should be fine. I don't know why the switch is layer 3 since you have of the 3750 and the ASA5520. If you start to see overflow errors, you should consider using the layer 2 switch.

    -Tom
    Please mark replied messages useful

  • Problem with FWSM and the same L3 interface switch

    I have two 6513 s with a 802. 1 q trunk linking them. Each switch is redundant Sup720s running in native mode, worm IOS 12.2 (18) SXF (that they were running out of SXD3). A FWSM (ver 2.3 (3), routed mode, unique context) is in each switch, Setup in failover mode.

    I can't get a PC in a virtual LAN that has the defined layer 3 interface on the switch with the active FWSM in this document, to communicate with the devices 'behind' the FWSM. If I move the configuration of layer 3 to this vlan to the other 6513, everything works fine.

    The MSFCs are inside the firewall, they have a configured layer 3 interface in the same vlan as the FWSM 'inside' interface. Several "same security level" interfaces are defined on the FWSM and used to protect the farms. I use OSPF on the MSFCs and FWSM and the routing table is correct.

    The FWSM generates connections to the attempts made by the PC with interface layer 3 defined on the same switch as the active FWSM very well, so this isn't a problem with FWSM ACL.

    A ping of the FWSM "inside" interface from a PC with the defined layer 3 interface on the same switch as the active FWSM fails, although debug icmp trace on the FWSM demand and response shows. A the packet capture, using the NAM-2, only shows the request packets. I captured on the vlan common and FWSM port channel interface bottom of basket.

    Just to add to the confusion, if I capture in the same places, but do the ping of a PC which is in a VLAN with the interface of layer 3 defined in the 6513 which does not contain the active FWSM, that works very well, I see the request and response on the capture of vlan common, but only on demand on the capture of the port channel.

    This problem has been there since the beginning of this implementation and has not changed with IOS and FWSM software upgrades. I had this experience with all the VLANS that I tried to define the interface of layer 3 to on the switch with the active FWSM. I turned on MLS.

    If anyone has experienced this and solved, or knows what is happening, I would be grateful for any ideas.

    Thank you.

    Keith

    Keith, are you running etherchannel distributed on of your 6513?

  • Script to join the domain, the role of configuration, add permissions and activate/SNMP configuration

    So I'm writing a script to install our vSphere hosts to work with our monitoring software.  Right now, it's all done by hand and I would like if possible to automate it.  So far, I came up with this.  I get to step 5 and that's where it fails.  I can get it manually run the Get-VIAccount command, but in the script, it fails.

    These are my steps

    1. connect to an existing host and retrieve role properties.

    2. connect to the new host

    3 join the domain.

    4. disconnect the new host and reconnect with the credentials of domain

    5. get the domain account, role of research/create and add permissions to host

    6. enable and configure SNMP

    7 restart MGMT officers.

    #Variables

    $vmhost = "Host03".

    $domaintojoin = "Domaine.org".

    $domainAlias = "domain".

    # $usernametograntpermissions = "service.account".

    $rolename = 'team - account control service '.

    #Connect to host17 to retrieve the role privileges

    to connect-viserver host17

    #Extract of privileges for the role of vcenter Monitoring Service

    $privsforrole = get-viprivilege-role (get-ferrule-name $rolename)

    Server VI #disconnect

    disconnect-viserver *-confirm: $false

    VSphere hosts #Connect above (enter the credentials of the root when prompted)

    SE connect-viserver-Server host03

    #Join field

    Get-vmhostauthentication - VMhost ctcvsphere3 | Game-VMHostAuthentication-domain $domaintojoin - user %-% - JoinDomain-confirm password password: $false

    credentials of the #disconnect root

    disconnect-viserver *-confirm: $false

    #reconnect with the credentials of domain

    SE connect-viserver-Server ctcvsphere3-user username-password password % domain\username

    #Get domain account and add to the host

    $viAccount = get-VIAccount-DOMAIN-User - ID service.account

    # Get the role

    $viRole = get-ferrule-name $roleName

    If (-not $viRole) {}

    throw the "Role of the creation.

    New-ferrule-name $rolename - Server $vmhost

    Together-ferrule-role (Get-ferrule-name $rolename - Server $vmhost) - AddPrivilege (get-VIPrivilege-id $privsforrole - Server $vmhost)

    }

    # Add permissions on VMHost

    New-VIPermission-Director $viAccount-role $viRole - entity $vmHost

    all VIServers #disconnect

    Disconnect-VIServer *-confirm: $false

    }

    #Configure SNMP

    Get-vmhostsnmp | set-vmhostsnmp-enabled: $true

    Get-vmhostsnmp | game-vmhostsnmp - ReadOnlyCommunity 'SNMP.

    #Restart Mgmt officers

    Get-VMHostService - VMHost $vmhost | where {$_.} Key - eq "vpxa"} | Restart-VMHostService - Confirm: $falese - ErrorAction SilentlyContinue

    Here is my error:

    Get-VIAccount: 27/02/2014-16:03:11 VIAccount Get A general system

    rror occurred: access to the directory error

    C:\ps1\vmware\snmp1.ps1:42 char: 28

    + $viAccount = get-VIAccount < < < < - domain - User - ID SERVICE. ACCOUNT

    + CategoryInfo: NotSpecified: (:)) [Get-VIAccount], SystemError)

    + FullyQualifiedErrorId: Client20_VmHostServiceImpl_RetrieveUserGroups_Vi

    Error, VMware.VimAutomation.ViCore.cmdlets.Commands.PermissionManagement.GE

    tVIAccount

    Get-VIAccount: 27/02/2014-16:03:11 Get - VIAccount VIAccount with the id

    "service.account" was not found using the specified filters.

    C:\ps1\vmware\snmp1.ps1:42 char: 28

    + $viAccount = get-VIAccount < < < < - domain - User - ID SERVICE. ACCOUNT

    + CategoryInfo: ObjectNotFound: (:)) [Get-VIAccount], VimExceptio)

    n

    + FullyQualifiedErrorId: Core_OutputHelper_WriteNotFoundError, VMware.VimA

    utomation.ViCore.Cmdlets.Commands.PermissionManagement.GetVIAccount

    New-VIPermission: Impossible to validate the argument on the parameter "principal." The argument

    ent is null or empty. Provide an argument that is not null or empty, and then try

    the command again.

    C:\ps1\vmware\snmp1.ps1:56 tank: 40

    + New-VIPermission-main < < < < $viAccount - $viRole - entity role

    y $vmHost

    + CategoryInfo: InvalidData: (:)) [new VIPermission], ParameterBi)

    ndingValidationException

    + FullyQualifiedErrorId: ParameterArgumentValidationError, VMware.VimAutom

    ation.ViCore.Cmdlets.Commands.PermissionManagement.NewVIPermission

    The term 'catch' is not recognized as a cmdlet, function, script fi

    the, or an executable program. Check the spelling of the name, or if a path has been included

    DED, make sure the path is correct, and then try again.

    C:\ps1\vmware\snmp1.ps1:57 tank: 12

    + captures < < < < {}

    + CategoryInfo: ObjectNotFound: (catch: String) [], CommandNotFou

    ndException

    + FullyQualifiedErrorId: CommandNotFoundException

    Thanks in advance!

    Dimitar did a nice write-up of this phenomenon and a possible solution.

    See ESXi hosts to join a domain and licensing with PowerCLI

  • Download SNMP MIB for Laserjet 5550 and 1505n. Paper, stuffing, etc.

    Please help me. I need the MIB files for SNMP messages as paper, jam, etc. Printers are LaserJet 5550 and 1505n. Rules of HP.

    Thank you very much for the help. I discovered a different way, but it's here:

    On the right side you can see the address and in the Middle, the data type and name. They are all in position 0.

    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_PaperJam, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.9
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_PaperOut, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.8
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_PeripheralError, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.6
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_ConnectionTerminationAck, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.5
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_NewMode, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.4
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_InterventionState, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.3
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_AtBusy, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.24
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_TcpBusy, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.23
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_LlcBusy, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.22
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_NovBusy, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.21
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_Reserved, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.20
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_PaperState, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.2
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_PaperOutput, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.19
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_Printing, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.18
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_DoorOpen, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.17
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_Initialize, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.16
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_Wait, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.15
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_Busy, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.14
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_IoActive, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.13
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_MemoryOut, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.12
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_PagePunt, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.11
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_TonerLow, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.10
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_LineState, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.1

    I hope it is useful for someone too.

    Best regards to all users of the forum!

    Cristian

  • What necessary SNMP MIB file

    Does anyone know where I could find information (MIB) machine for Toshiba MFP devices file. I googled had and checked the predominant sites for these types of files. I'm looking to get the OID for an eStudio-600 so I can configure the SNMP interruptions for alerts of toner and paper jams.

    Thank you

    Mike

    PS: I put here as a matter of SNMP network, if it's wrong please feel free to move it to the right forum.

    In my opinion, this forum is wrong place for this question. I think you should contact your local dealer where you bought your eStudio-600.
    They offer a type of support or not?

  • SNMP MIB for ASR5k

    Hi guys.

    I need monitor the status of the SCTP on HNBGW sessions. I use zabbix as SNMP server for this server.

    I must add MIB snmp STARENT - MIB.my. I found the next guide with this MIB:

    http://www.Cisco.com/c/dam/en/us/TD/docs/wireless/asr_5000/19-0/PDF/19-S...

    But this guide is not practical. I tried to find this MIB on the ftp server to cisco, but it was ineffective. Do you where I can download STARENT - MIB.my?

    Thank you.

    Yuliya salvation,

    I hope you do well,

    Find enclosed the STARENT-MIB. I changed the extension, please download and modify the .my extension.

    ****

    Starent - MIB.txt for starent - mib.my

    ****

    I hope that helps!

    Claudio Gonzalez

  • Cisco SPA122 gateway analog SNMP MIB

    Hello

    Anyone know where I can get the list of OID or MIB for analog gateway SPA122. I would like to be able to query the State of the line and recording.

    Thank you

    Ronald

    The entire OID tree on SPA122 contain approximately 4000 points about 25 MIB (or more).

    But I'm not sure there is information that you want.

    It seems that the SNMP protocol to provide standard information to the underlying operating system (Linux). Line status and registration is maintained by the speech application running on it and such request provide no SNMP information as far as I know.

    I saved whole SNMP tree in State of rest and again during a call. It seems not to have difference related to the State of the line.

  • PIX 6.3 SNMP MIB, problem with the CISCO-PROCESS compilation - MIB.oid

    I am Edgar Servín

    I have a cactus and got to watch the CPU of the PIX, I got the OID number:

    cpmCPUTotal5sec 1.3.6.1.4.1.9.9.109.1.1.1.1.3

    I used the Cisco SNMP Object Navigator and said:

    Compile the MIB

    Before you can compile CISCO-PROCESS-MIB, you need to compile the MIBS listed below in the order listed.

    Download all of these MIBs (WARNING: does not include non - Cisco MIB) or view details about each MIB below.

    How can I do?

    Hi Edgar,

    compiling the MIBs is necessary only when you are using HP OpenView or something similar. With the cactus, I confess that I have never used myself, but I'm pretty confident that you can just set the OID in Cacti and it will just make a periodic SNMP query for that object.

    HTH

    Herbert

  • vRops 6.0.1 SNMP MIB for external system alerts

    Hello

    IM struggling to find the MIB for 6.0.1 vROps then we can install them in our company, monitoring system and send THAT SNMP alerts him to vROps... any ideas where I can find... I have tuspect that they are in the TIME but its not easy to access int the VAPP find/extract the.

    See you soon

    John

    Not so easy to get out them of vApp... therefore installed a version of Windows and the extracts from there.

    After raising a VMware SR will probably raise a Ko for this.

    John

  • Is it possible to change the time it takes for SNMP MIB update?

    Hi all

    How will I know the time it takes to update the snmp information:

    hrSWRunTable
    OID: 1.3.6.1.2.1.25.4.2

    It is to change this time posibble?

    Thank you!

    Hello

    You must contact the TechNet forum, where we have some support professionals who are well equipped with knowledge on area issues, to do so please visit the link provided below.

    http://social.technet.Microsoft.com/forums/en-us/w7itproperf/threads

    Thank you, and in what concerns:

  • ASA 5510 replacement and ARP

    Hello support,

    Probably a simple question and can be buried in these forums (but I'm not).

    I am trying to replace one 5510 with another 5510 and have all kinds of difficulties.  Devices the PAT against the external interface have no problem out, but anything with a 1:1 NAT cannot.  Cries of an ARP issue; However, to restart the switch and firewall are without effect.  Is there something else I could potentially be missing.  Configurations are completely reversed.  And the firewall, that the I'm replacing has no problem going out with NAT (static) 1-to-1.  Any ideas?

    Hello

    I assume you mean a L3 switch that you begin with the ASA?

    If this isn't the case, then where is the gateway of your ASA L3 and who manages this device?

    One thing that comes to mind associated with ARP is that if you use several public subnets on your ASA. For example 30 for network connection between your site and the ISP and some 28 as a public subnet for purposes of NAT static. Then you may experience problems IF your software has changed to 8.4 (3) or something higher.

    If ARP is the problem then it is of course the option that makes you check the original interfaces of ASAs (connected to the ISP) MAC address and configure this same MAC address to the new WAN ASAs interface to the ISP.

    You can actually go under the interface and deliver MAC address with the command

    0000.1111.2222 Mac address

    In addition, naturally when it comes to configurations and firewall rules you can always use the command "packet - trace" to simulate the packets from your local network for the EXTENDED or WAN network to the local network and see the race passes through completely.

    -Jouni

  • dynamic inspection of arp and arp traffic

    Hello world

    Dynamic inspection arp only offers protection against fake gratuitous arp response by checking the free response against the dhcp binding or she also provides protection against all false arp traffic by checking all traffic against the dhcp binding arp?

    For example.

    H1 - f1/1SW - Dhcp Server

    H2 - f1/2

    H1 mac address is mac1 and assigned by dhcp 199.199.199.1 ip address

    H2 mac address is mac 2 and dhcp IP 199.199.199.2

    SW has following dhcp bindings

    Mac 1 199.199.199.1 f1/1 vlan 1

    mac2 199.199.199.2 vlan1 f1/2

    Let's say that a hacker connects to his office at sw to f1/3.  H1 needs to communicate with h2 but h1 arp table has no entry for 199.199.199.2 (de).

    As a result, H1 must send the request of broadcast arp to 199.199.199.2. The question is: If a wrong answer with its own mac address arp IE hacker craft

    MAC3 199.199.199.2 (where mac3 is the mac address of office hacker), dynamic arp inspection to check this answer arp against the dhcp bindings?

    Thank you.

    What you describe is exactly what wiill DAI protect you against.

    Sent by Cisco Support technique iPad App

Maybe you are looking for