Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

SNMP or SYSLOG status of PIX VPN Tunnel

Status
Not open for further replies.

DavidHalko

Technical User
Dec 8, 2002
20
0
0
US
Is there a way to determine the status of a PIX VPN tunnel either through SNMP Traps, SNMP Gets or Syslog Alerts?

When a PIX to PIX tunnel is established and it fails,
I would like to get an indication of when the tunnel fails.

I would also like to be able to query the device to find
out all tunnels as well as their status... possibly even
statistics (passed packet, passed bytes, etc.)

Thanks, EMS Architect
 
David, hi.

Does PIX write something to the syslog when tunnelling fails? Mike

Want to get great answers to your Tek-Tips questions? Have a look at faq219-2884
 
> Does PIX write something to the syslog when tunnelling fails?

I do not know!

I am also in need of such information using the VPN technology in standard Cisco IOS routers... I have a couple of those too! EMS Architect
 
David,

SNMP. Have you had a look at the MIB for the PIX? There may well be something in there for you. Mike

Want to get great answers to your Tek-Tips questions? Have a look at faq219-2884
 
The "pollable" snmp MIBS are pretty weak.
I have not found any interesting "SNMP traps" either.

Heck - I can't even find any easy command line'ers to tell what IPSEC tunnels are built and operating correctly!

It seems like management was the LAST thing they thought about when building this subsystem. EMS Architect
 
Great....

Is there any online documentation I could look at? Mike

Want to get great answers to your Tek-Tips questions? Have a look at faq219-2884
 
Hi David,

Right....

Are syslog messages enabled?

Are syslog messages being redirected to a UNIX syslog host?

Assuming you can see your syslog:
If you issue the command:
logging buffered 7
PIX will log everything it can think of - and then some.

Logging levels are:

0 emergency, System unusable.
1 alert, Immediate action needed.
2 critical, Critical condition.
3 error, Error condition.
4 warning, Warning condition.
5 notification, Normal but significant condition.
6 informational, Informational message only.
7 debugging, Appears during debugging only

If you're not currently redirecting syslog messages to a UNIX host then almost any UNIX host will do, so it's worth thinking about...

Am I aiming in the right direction here? Mike

Want to get great answers to your Tek-Tips questions? Have a look at faq219-2884
 
Hey -

Yes - logging to a UNIX syslog server already.

You really never want to log at a debugging level of 7.

That is way too much trash to read through...
... establishing a connection from x to y
... tearing down a connection from x to y
and so forth.

There is just so much stuff coming out that unless you know what you are looking for, it is really useless.

I still have not seen anything on VPN connections via IPSec in those log files... does not mean they are not in there.

I also have not found anything with what the IDS codes are.

I have read through the error messages, and they have been less than helpful.

It is like looking for a needle in a hay stack.

- Thanks,
Dave EMS Architect
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top