
9-42
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 9 Accessing and Monitoring PIX Firewall
Using SNMP
The PIX Firewall SNMP traps available to an SNMP management station are as follows:
• Generic traps:
–
Link up and link down (cable connected to the interface or not; cable connected to an interface
working or not working)
–
Cold start
–
Authentication failure (mismatched community string)
• Security-related events sent via the Cisco syslog MIB:
–
Global access denied
–
Failover syslog messages
–
Syslog messages
Use CiscoWorks for Windows or any other SNMP V1, MIB-II compliant browser to receive SNMP traps
and browse an MIB. SNMP traps occur at UDP port 162.
MIB Support
Note The PIX Firewall does not support browsing of the Cisco syslog MIB.
You can browse the System and Interface groups of MIB-II. Browsing an MIB is different from sending
traps.
Browsing means doing an snmpget or snmpwalk of the MIB tree from the management station
to determine values.
PIX Firewall Version 6.3(2) and higher supports the following additional Interface objects of MIB-II:
• ifOutQLen
• ifInUnknownProtos
The Cisco Firewall MIB and Cisco Memory Pool MIB are available.
PIX Firewall does not support the following in the Cisco Firewall MIB:
• cfwSecurityNotification NOTIFICATION-TYPE
• cfwContentInspectNotification NOTIFICATION-TYPE
• cfwConnNotification NOTIFICATION-TYPE
• cfwAccessNotification NOTIFICATION-TYPE
• cfwAuthNotification NOTIFICATION-TYPE
• cfwGenericNotification NOTIFICATION-TYPE
SNMP CPU Utilization
PIX Firewall Version 6.2 and higher supports monitoring CPU utilization through SNMP. This feature
allows network administrators to monitor PIX
Firewall CPU usage using SNMP management software,
(such as HP OpenView) for capacity planning.
This functionality is implemented through support for the cpmCPUTotalTable of the Cisco Process MIB
(CISCO-PROCESS-MIB.my.) The other two tables in the MIB, cpmProcessTable and
cpmProcessExtTable are not supported in this release.
Comentarios a estos manuales