Cacti (home)ForumsRepositoryDocumentation
Cacti: offical forums and support
It is currently Mon May 21, 2012 8:32 am


ATTENTION: All users passwords have been cleared.
Please use the "Forgot Password" feature to reset your password.


All times are UTC - 5 hours




Post new topic Reply to topic  [ 3 posts ] 
Author Message
 Post subject: Cisco ASA Traffic Graph Per Tunnel
PostPosted: Wed Aug 22, 2007 4:27 am 
Offline

Joined: Wed Aug 22, 2007 4:16 am
Posts: 1
Location: Dublin, Ireland
Hi, just want to say first off that cacti is an amazing piece of software, and has helped make work a LOT easier! But on to the point..

There are several Cisco ASA Firewalls in our network, and I was asked to graph the traffic on each on a per vlan basis. I looked extensively for a template or previous work on this, but couldn't find anything that did what I wanted. Although I am new to cacti, I decided to jump in and try to write what I wanted myself, and this is the result.

It's a Data Query, Data Template and Graph Template for graphing traffic per Cisco IKE Tunnel. There may be a few bugs, but it does *seem* to be doing what it's supposed to, so I thought I'd put it up here for anyone like myself that needs something to build on.

The graph names come from the end point of the tunnel, as I found the OID for cikeTunRemoteName to more often than not be NULL.

As I've said, I'm a newcomer to cacti and this is my first post on the forum, and first attempt at writing a data template, so any constructive criticism or advice on something I have wrong is welcome! :)


Attachments:
File comment: Data Query for getting tunnel(s) statistics. Put in your snmp_queries directory.
cikeTunnel.xml [1.08 KiB]
Downloaded 1451 times
File comment: Graph Template for graphing Cisco ASA IKE Tunnels
cisco_asa_tun.xml [12.82 KiB]
Downloaded 1363 times

_________________
He felt that his whole life was some kind of dream and he sometimes wondered whose it was and whether they were enjoying it.
Top
 Profile  
 
 Post subject: Weird bug with Cisco ASA IKE counters
PostPosted: Fri Aug 24, 2007 11:42 am 
Offline
Cacti User
User avatar

Joined: Mon Dec 13, 2004 2:55 pm
Posts: 145
Location: San Jose, CA
Thanks mk429,

I put something together along the same lines, but I am seeing some inexplicably small amounts of data in each tunnel according to cikeTunInOctets and cikeTunOutOctets (as well as cikeTunInPkts and cikeTunOutPkts). Originally I had thought this to be a Cacti data template problem, but noticed that the counter values weren't changing nearly frequently enough.

Here are some screenshots from two of our ASAs (versions 8.0(2) and 7.2(1)) that show the problem. From the period of 12:00 the the end of the graph there is ~2Mbs of traffic traversing the tunnel.

Anyone else seen this before?


Attachments:
File comment: ASA 8.0(2)
graph_image.php-savasa.jpg
graph_image.php-savasa.jpg [ 33.06 KiB | Viewed 11056 times ]
File comment: ASA 7.2(1)
graph_image.php-tsasa.jpg
graph_image.php-tsasa.jpg [ 32.91 KiB | Viewed 11056 times ]
Top
 Profile  
 
 Post subject:
PostPosted: Tue Aug 28, 2007 12:42 pm 
Offline
Cacti User
User avatar

Joined: Mon Dec 13, 2004 2:55 pm
Posts: 145
Location: San Jose, CA
Looks like the majority of the traffic is IPSec: http://forums.cacti.net/viewtopic.php?t=12873


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 3 posts ] 

All times are UTC - 5 hours


Who is online

Users browsing this forum: No registered users and 5 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  

Protected by Anti-Spam ACP Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group