Live Head Geek Video Chat: Virtualization Trends & Best Practices. Register Now >>
Search 100,860 posts and 877 resources contributed by 61,822 members or post a topic.

Already Joined? Sign in
Cisco PIX 525 failover monitoring

Page 1 of 1 (8 items) | RSS

rated by 0 users
Not Answered This post has 0 verified answers | 7 Replies | 2 Followers | 1,892 Views


246 Posts
Points 1,014
SolarWinds Certified Professional
profzoom1 replied on Wed, Jun 10 2009 3:14 PM
rated by 0 users

Is there an alert or does someone out there know what OID's or Mibs to monitor to be alerted when a Cisco PIX 525 fails over to the standby PIX firewall.

We currently have 2 Cisco PIX 525 firewalls and they have failed over a couple of times and we are not alerted when this happens. Our Mars box gives this error - PIX-1-105005: (Secondary) Lost Failover communications with mate - I am not seeing anything in my syslog on my Orion box that says this for the time that this happened - Curious about that as well since we have all our pix syslogs going to our Orion box as well.

Is there a way to be alerted when this failover occurs?

Any help would be appreciated.

Operating System Windows 2003 Enterprise Edition OS Version 5.2.3790 Service Pack 2.0 Orion
Module Name: Orion Core Version: 2010.1.0 APM Version: 3.5 NPM SLXVersion: 10.0.0 NTA Version: 3.6
NCM Version: 5.5.2 DR Server Orion Version: 2010.1.0
NPM 2000 Version: 10 VM Windows server 2008 RC1 - EOC 1.1.1.576

 

Follow me on Twitter

 

All Replies


892 Posts
Points 2,882
Thwack MVP
lchance replied on Thu, Jun 11 2009 10:05 AM
rated by 0 users

Do you have an account with Cisco forums? You might get your best answer from their Network Management forum. If you don't then I can try to ask for you.

Does Cisco PIX's inside interface support CDP where you could use UnDP to monitor for this condition? Just a thought...

  • | Post Points: 3

246 Posts
Points 1,014
SolarWinds Certified Professional
profzoom1 replied on Thu, Jun 11 2009 2:17 PM
rated by 0 users

I do not have an account on that forum and would appreciate the help in presenting the question on another forum.

As for the CDP being enabled on the inside interface is not enabled.

Operating System Windows 2003 Enterprise Edition OS Version 5.2.3790 Service Pack 2.0 Orion
Module Name: Orion Core Version: 2010.1.0 APM Version: 3.5 NPM SLXVersion: 10.0.0 NTA Version: 3.6
NCM Version: 5.5.2 DR Server Orion Version: 2010.1.0
NPM 2000 Version: 10 VM Windows server 2008 RC1 - EOC 1.1.1.576

 

Follow me on Twitter

 

  • | Post Points: 7

892 Posts
Points 2,882
Thwack MVP
lchance replied on Thu, Jun 11 2009 3:04 PM
rated by 0 users

I'll let you know what/if I hear anything from that other forum.

  • | Post Points: 1

892 Posts
Points 2,882
Thwack MVP
lchance replied on Thu, Jun 11 2009 3:30 PM
rated by 0 users

By the way - have you tried using this Cisco PIX OID in UnDP? I've monitored VRRP and HSRP using something similar to watch for Active/Standby changes.

  • | Post Points: 3

54 Posts
Points 124
Riyaz Khan replied on Fri, Jun 12 2009 12:40 AM
rated by 0 users

Hi,

But how i monitor Active-Active Failover in PIX 535/FWSM Module,This will helpfull when we are using Active-Standby Failover.

Failover On
Last Failover at: 20:57:46 IST Apr 2 2009
 This context: Active
  Active time: 6099630 (sec)
    Interface outside (202.137.232.20): Normal
    Interface insideAS (202.137.239.1): Normal
 Peer context: Standby Ready
  Active time: 303385 (sec)
    Interface outside (202.137.232.21): Normal
    Interface insideAS (202.137.239.2): Normal

Stateful Failover Logical Update Statistics
 Status: Configured.
 Stateful Obj  xmit       xerr       rcv        rerr     
 RPC services   0          0          0          0        
 TCP conn  1723723700 0          10245      0        
 UDP conn  3852856396 0          41553      0        
 ARP tbl   2245583    0          0          36       
 Xlate_Timeout   0          0          0          0        

Regards,

Riyaz

  • | Post Points: 1

892 Posts
Points 2,882
Thwack MVP
lchance replied on Fri, Jun 12 2009 8:03 AM
rated by 0 users

profzoom1,

Here's the response I got back from another forum - I hope this helps:

 

Only if you do the following, which is basically a duplicate of the syslog you got, except as SNMP trap:

http://www.cisco.com/en/US/docs/security/pix/pix42/configuration/guide/pix42adv.html

"To receive security and failover SNMP traps from the PIX Firewall, compile the Cisco syslog MIB into your SNMP management application. If you do not compile the Cisco syslog MIB into your application, you only receive MIB-II traps for link up or down, and firewall cold and warm start."

 

  • | Post Points: 3

54 Posts
Points 124
Riyaz Khan replied on Fri, Jun 12 2009 8:19 AM
rated by 0 users

Hi,

But how i monitor Active-Active Failover in PIX 535/FWSM Module,This will helpfull when we are using Active-Standby Failover.

Failover On
Last Failover at: 20:57:46 IST Apr 2 2009
 This context: Active
  Active time: 6099630 (sec)
    Interface outside (202.137.232.20): Normal
    Interface insideAS (202.137.239.1): Normal
 Peer context: Standby Ready
  Active time: 303385 (sec)
    Interface outside (202.137.232.21): Normal
    Interface insideAS (202.137.239.2): Normal

Stateful Failover Logical Update Statistics
 Status: Configured.
 Stateful Obj  xmit       xerr       rcv        rerr     
 RPC services   0          0          0          0        
 TCP conn  1723723700 0          10245      0        
 UDP conn  3852856396 0          41553      0        
 ARP tbl   2245583    0          0          36       
 Xlate_Timeout   0          0          0          0        

Regards,

Riyaz

  • | Post Points: 1
Page 1 of 1 (8 items) | RSS

© 2003 - 2010 SolarWinds, Inc. All Rights Reserved.

Who is SolarWinds?

SolarWinds is rewriting the rules for how companies manage their networks. Guided by a global community of network engineers, SolarWinds develops simple and powerful network management software and network monitoring software for networks of all sizes. SolarWinds also offers a network certification program to become a SolarWinds Certified Professional (SCP).

What is thwack?

thwack, SolarWinds online community site, was designed by network engineers, for network engineers. thwack is a vibrant, growing community of more than 30,000 IT pros who share a passion for technology.

Explore Resources, Answers, Templates, and Advice

Download Free Networking Tools


Learn More About SolarWinds Products