Search 82,106 posts and 599 resources contributed by 40,315 members or post a topic.

Already Joined? Sign in
Cisco PIX 525 failover monitoring

Page 1 of 1 (8 items) | RSS

rated by 0 users
Not Answered This post has 0 verified answers | 7 Replies | 2 Followers | 863 Views


227 Posts
Points 977
SolarWinds Certified Professional
profzoom1 posted on Wed, Jun 10 2009 3:14 PM
rated by 0 users

Is there an alert or does someone out there know what OID's or Mibs to monitor to be alerted when a Cisco PIX 525 fails over to the standby PIX firewall.

We currently have 2 Cisco PIX 525 firewalls and they have failed over a couple of times and we are not alerted when this happens. Our Mars box gives this error - PIX-1-105005: (Secondary) Lost Failover communications with mate - I am not seeing anything in my syslog on my Orion box that says this for the time that this happened - Curious about that as well since we have all our pix syslogs going to our Orion box as well.

Is there a way to be alerted when this failover occurs?

Any help would be appreciated.

Operating System Windows 2003 Standard Edition OS Version 5.2.3790 Service Pack 2.0 Package Orion Network Performance Monitor V9.5 SLX Version 9.5 SP4 Solarwinds Engineers Toolset ver 10 Orion NCM 5.5 Lansurveyor ver. 10.2 Application Perf. Mon. ver. 3.0 sp1

VM Windows server 2008 RC1 - EOC 1.1.1.576

 

Follow me on Twitter

 

All Replies


676 Posts
Points 2,136
lchance replied on Thu, Jun 11 2009 10:05 AM
rated by 0 users

Do you have an account with Cisco forums? You might get your best answer from their Network Management forum. If you don't then I can try to ask for you.

Does Cisco PIX's inside interface support CDP where you could use UnDP to monitor for this condition? Just a thought...

  • | Post Points: 3

227 Posts
Points 977
SolarWinds Certified Professional
profzoom1 replied on Thu, Jun 11 2009 2:17 PM
rated by 0 users

I do not have an account on that forum and would appreciate the help in presenting the question on another forum.

As for the CDP being enabled on the inside interface is not enabled.

Operating System Windows 2003 Standard Edition OS Version 5.2.3790 Service Pack 2.0 Package Orion Network Performance Monitor V9.5 SLX Version 9.5 SP4 Solarwinds Engineers Toolset ver 10 Orion NCM 5.5 Lansurveyor ver. 10.2 Application Perf. Mon. ver. 3.0 sp1

VM Windows server 2008 RC1 - EOC 1.1.1.576

 

Follow me on Twitter

 

  • | Post Points: 7

676 Posts
Points 2,136
lchance replied on Thu, Jun 11 2009 3:04 PM
rated by 0 users

I'll let you know what/if I hear anything from that other forum.

  • | Post Points: 1

676 Posts
Points 2,136
lchance replied on Thu, Jun 11 2009 3:30 PM
rated by 0 users

By the way - have you tried using this Cisco PIX OID in UnDP? I've monitored VRRP and HSRP using something similar to watch for Active/Standby changes.

  • | Post Points: 3

54 Posts
Points 124
Riyaz Khan replied on Fri, Jun 12 2009 12:40 AM
rated by 0 users

Hi,

But how i monitor Active-Active Failover in PIX 535/FWSM Module,This will helpfull when we are using Active-Standby Failover.

Failover On
Last Failover at: 20:57:46 IST Apr 2 2009
 This context: Active
  Active time: 6099630 (sec)
    Interface outside (202.137.232.20): Normal
    Interface insideAS (202.137.239.1): Normal
 Peer context: Standby Ready
  Active time: 303385 (sec)
    Interface outside (202.137.232.21): Normal
    Interface insideAS (202.137.239.2): Normal

Stateful Failover Logical Update Statistics
 Status: Configured.
 Stateful Obj  xmit       xerr       rcv        rerr     
 RPC services   0          0          0          0        
 TCP conn  1723723700 0          10245      0        
 UDP conn  3852856396 0          41553      0        
 ARP tbl   2245583    0          0          36       
 Xlate_Timeout   0          0          0          0        

Regards,

Riyaz

  • | Post Points: 1

676 Posts
Points 2,136
lchance replied on Fri, Jun 12 2009 8:03 AM
rated by 0 users

profzoom1,

Here's the response I got back from another forum - I hope this helps:

 

Only if you do the following, which is basically a duplicate of the syslog you got, except as SNMP trap:

http://www.cisco.com/en/US/docs/security/pix/pix42/configuration/guide/pix42adv.html

"To receive security and failover SNMP traps from the PIX Firewall, compile the Cisco syslog MIB into your SNMP management application. If you do not compile the Cisco syslog MIB into your application, you only receive MIB-II traps for link up or down, and firewall cold and warm start."

 

  • | Post Points: 3

54 Posts
Points 124
Riyaz Khan replied on Fri, Jun 12 2009 8:19 AM
rated by 0 users

Hi,

But how i monitor Active-Active Failover in PIX 535/FWSM Module,This will helpfull when we are using Active-Standby Failover.

Failover On
Last Failover at: 20:57:46 IST Apr 2 2009
 This context: Active
  Active time: 6099630 (sec)
    Interface outside (202.137.232.20): Normal
    Interface insideAS (202.137.239.1): Normal
 Peer context: Standby Ready
  Active time: 303385 (sec)
    Interface outside (202.137.232.21): Normal
    Interface insideAS (202.137.239.2): Normal

Stateful Failover Logical Update Statistics
 Status: Configured.
 Stateful Obj  xmit       xerr       rcv        rerr     
 RPC services   0          0          0          0        
 TCP conn  1723723700 0          10245      0        
 UDP conn  3852856396 0          41553      0        
 ARP tbl   2245583    0          0          36       
 Xlate_Timeout   0          0          0          0        

Regards,

Riyaz

  • | Post Points: 1
Page 1 of 1 (8 items) | RSS

© 2003 - 2010 SolarWinds, Inc. All Rights Reserved.

Who is SolarWinds?

SolarWinds is rewriting the rules for how companies manage their networks. Guided by a global community of network engineers, SolarWinds develops simple and powerful network management software and network monitoring software for networks of all sizes. SolarWinds also offers a network certification program to become a SolarWinds Certified Professional (SCP).

What is thwack?

thwack, SolarWinds online community site, was designed by network engineers, for network engineers. thwack is a vibrant, growing community of more than 30,000 IT pros who share a passion for technology.

Explore Resources, Answers, Templates, and Advice

Download Free Networking Tools


Learn More About SolarWinds Products