Ip sla monitoring on asa ver 7.0 (6)

how to configure ip sla monitoring on asa ver 7.0 (6) ?

Hello,
In fact was introduced on 7.2.(1)
Components Used
The information in this document is based on these software and hardware versions:
Cisco PIX Security Appliance 515E with software version 7.2(1) or later
Cisco Adaptive Security Device Manager 5.2(1) or later
Related Products
You can also use this configuration with the Cisco ASA 5500 Series Security Appliance version 7.2(1).
Please rate helpful posts,
Julio

Similar Messages

  • ASA /Router -SNMP Trap when IP SLA monitored (ICMP timeout)

    Hi,
    I am looking for some solution for my below requirment
    Requirment is :
    How do I configure ASA or Router to send SNMP Trap when IP SLA monitored  features enabled (ICMP request or 900 millisecond delay from destination IP)
    Thanks in advance..

    Hi,
    Maybe this thread might help you?
    https://supportforums.cisco.com/thread/2039293
    I have not personally configured these type of SLA configurations on an ASA other than for testing purposes. We handle Dual ISP setups outside the ASA firewalls.
    - Jouni

  • Cisco ASA SLA monitoring

    I'm trying to configure an SLA on some of our ASAs and I want to monitor the hostname of a destination rather than the IP address.  The CLI gives me an option to enter IP or hostname, but when I try and use a name rather than an IP address I get:
    (config-sla-monitor)# type echo protocol ipIcmpEcho ?
    sla-monitor mode commands/options:
      Hostname or A.B.C.D  IP address or hostname
    (config-sla-monitor)# type echo protocol ipIcmpEcho google.com
                                                                   ^
    ERROR: % Invalid Hostname
    (config)# ping google.com
    Type escape sequence to abort.
    Sending 5, 100-byte ICMP Echos to 173.194.37.128, timeout is 2 seconds:
    Success rate is 100 percent (5/5), round-trip min/avg/max = 40/46/50 ms
    Any ideas or suggestions?  I've tried local hostnames just to make sure it wasn't a resolution issue.  Substituting with the IP address works fine.  We just have a particluar vendor we depend on that has a propensity to change IP addresses to a cloud app we depend on and not tell us.
    If this posts answers your question or is helpful, please consider rating it and/or marking as answered.       

    Hi,
    Always used the IP address so I have no previous expirience of configuring with hostname.
    The Command Reference is very vague with regards to the definition of the hostname.
    Initially I thought that he problem might be that the DNS lookups are not enabled on the ASA so it is not able to determine the IP address itself.
    This didnt seem to make a difference.
    Then I configured the following
    name 1.1.1.1 test
    After which it accepted the command with the hostname configured as "test".
    So I am guessing the hostname refers to the "name" configurations of the  ASA and if that is the case then I would consider it a pretty useless option.
    I tried to configure an "object network GOOGLE" that uses "fqdn www.google.com" but it doesnt accept this "object" as the value for the hostname. So I am not really sure if I am missing something with regards to what else could be entered there other than something referenced in the "name" configuration.
    On a quick search I could not find anything online in which someone is actually using a hostname instead of the IP address.
    Also slightly adding to the confusion is the fact that the Configuration Guide makes no mention of hostname when giving instructions on configuring the target which to monitor for route tracking.
    Starting to seem to me that there is no option to use a DNS name as the target for monitoring.
    - Jouni

  • ASA5510 sla monitor does not fail back

    I've been down this path before and never got a resolution to this issue.
    ASA5510 Security Plus
    Primary ISP conn is Comcast cable
    Secondary ISP conn is fract T1
    I duplicated the SLA code from http://www.cisco.com/en/US/partner/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml
    When I pull the conn from primary ISP the default route to the secondary comes up
    When I reconnect the primary the default route to the secondary does not go away.
    I must either reload the ASA or remove/readd the two default outside routes.
    Anyone have this same experience and could lend a hand?
    Are there any commands I might have in my config that break SLA?
    If so I would have hoped either the Configuration Guide or Command Reference for 8.2 would say so, but I don't see any mentioned.
    I'm working remotely with my customer so I can't play with this except on off-hours.
    ASA running 8.2(2) so as to use AnyConnect Essentials.
    Thx,
    Phil

    Pls. read and try the workaround.
    CSCtc16148    SLA monitor fails to fail back when ip verify reverse is applied
    Symptom:
    Route Tracking may fail to fail back to the primary link/route when restored.
    Conditions:
    SLA monitor must configured along with ip verify reverse path on the tracked interface.
    Workaround:
    1. Remove ip verify reverse path off of the tracked interface
    or
    2. add a static route to the SLA target out the primary tracked interface.
    [Wrap text]  [Edit this enclosure]
    Release-note: Added 09/23/2009 20:28:24 by kusankar
    [Unwrap text]  [Edit this enclosure]
    Release-note: Added 09/23/2009 20:28:24 by kusankar
    [Uwrap text]  [Edit this enclosure]
    fixed-in-broadview-8.3.1.1_interim-by-cl104097: Added 03/23/2010 11:54:08 by perforce
    fixed-in-broadview-8.3.1.1_interim-by-cl104097: Added 03/23/2010 11:54:08 by perforceCan not view this . file attachment inline, please click on the following link to view the attachment.
    http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCtc16148&title=fixed-in-broadview-8.3.1.1_interim-by-cl104097&ext=&type=FILE
    fixed-in-broadview-8.3.1.1_interim-by-cl104097: Added 03/23/2010 11:54:08 by perforceCan not view this . file attachment inline, please click on the following link to view the attachment.
    http://
    [UnWrap text]  [Edit this enclosure]
    fixed-in-broadview-8.3.1.1_interim-by-cl104097: Added 03/23/2010 11:54:08 by perforce
    [Wrap Text]  [Edit this enclosure]
    fixed-in-broadview-8.3.1.1_interim-by-cl104097: Added 03/23/2010 11:54:08 by perforce
    [Uwrap text]  [Edit this enclosure]
    fixed-in-broadview-8.3.1_fcs_throttle-by-cl103850: Added 03/22/2010 15:48:05 by perforce
    fixed-in-broadview-8.3.1_fcs_throttle-by-cl103850: Added 03/22/2010 15:48:05 by perforceCan not view this . file attachment inline, please click on the following link to view the attachment.
    http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCtc16148&title=fixed-in-broadview-8.3.1_fcs_throttle-by-cl103850&ext=&type=FILE
    fixed-in-broadview-8.3.1_fcs_throttle-by-cl103850: Added 03/22/2010 15:48:05 by perforceCan not view this . file attachment inline, please click on the following link to view the attachment.
    http://
    [UnWrap text]  [Edit this enclosure]
    fixed-in-broadview-8.3.1_fcs_throttle-by-cl103850: Added 03/22/2010 15:48:05 by perforce
    [Wrap Text]  [Edit this enclosure]
    fixed-in-broadview-8.3.1_fcs_throttle-by-cl103850: Added 03/22/2010 15:48:05 by perforce
    [Uwrap text]  [Edit this enclosure]
    fixed-in-broadview-bennu-by-cl101314: Added 02/18/2010 19:06:08 by perforce
    fixed-in-broadview-bennu-by-cl101314: Added 02/18/2010 19:06:08 by perforceCan not view this . file attachment inline, please click on the following link to view the attachment.
    http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCtc16148&title=fixed-in-broadview-bennu-by-cl101314&ext=&type=FILE
    fixed-in-broadview-bennu-by-cl101314: Added 02/18/2010 19:06:08 by perforceCan not view this . file attachment inline, please click on the following link to view the attachment.
    http://
    [UnWrap text]  [Edit this enclosure]
    fixed-in-broadview-bennu-by-cl101314: Added 02/18/2010 19:06:08 by perforce
    [Wrap Text]  [Edit this enclosure]
    fixed-in-broadview-bennu-by-cl101314: Added 02/18/2010 19:06:08 by perforce
    [Uwrap text]  [Edit this enclosure]
    fixed-in-broadview-idfw-by-cl101317: Added 02/18/2010 19:09:07 by perforce
    fixed-in-broadview-idfw-by-cl101317: Added 02/18/2010 19:09:07 by perforceCan not view this . file attachment inline, please click on the following link to view the attachment.
    http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCtc16148&title=fixed-in-broadview-idfw-by-cl101317&ext=&type=FILE
    fixed-in-broadview-idfw-by-cl101317: Added 02/18/2010 19:09:07 by perforceCan not view this . file attachment inline, please click on the following link to view the attachment.
    http://
    [UnWrap text]  [Edit this enclosure]
    fixed-in-broadview-idfw-by-cl101317: Added 02/18/2010 19:09:07 by perforce
    [Wrap Text]  [Edit this enclosure]
    fixed-in-broadview-idfw-by-cl101317: Added 02/18/2010 19:09:07 by perforce
    [Uwrap text]  [Edit this enclosure]
    fixed-in-broadview-logging-ng-by-cl101311: Added 02/18/2010 19:03:08 by perforce
    fixed-in-broadview-logging-ng-by-cl101311: Added 02/18/2010 19:03:08 by perforceCan not view this . file attachment inline, please click on the following link to view the attachment.
    http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCtc16148&title=fixed-in-broadview-logging-ng-by-cl101311&ext=&type=FILE
    fixed-in-broadview-logging-ng-by-cl101311: Added 02/18/2010 19:03:08 by perforceCan not view this . file attachment inline, please click on the following link to view the attachment.
    http://
    [UnWrap text]  [Edit this enclosure]
    fixed-in-broadview-logging-ng-by-cl101311: Added 02/18/2010 19:03:08 by perforce
    [Wrap Text]  [Edit this enclosure]
    fixed-in-broadview-logging-ng-by-cl101311: Added 02/18/2010 19:03:08 by perforce
    [Uwrap text]  [Edit this enclosure]
    fixed-in-broadview-main-by-cl101300: Added 02/18/2010 18:27:07 by perforce
    fixed-in-broadview-main-by-cl101300: Added 02/18/2010 18:27:07 by perforceCan not view this . file attachment inline, please click on the following link to view the attachment.
    http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCtc16148&title=fixed-in-broadview-main-by-cl101300&ext=&type=FILE
    fixed-in-broadview-main-by-cl101300: Added 02/18/2010 18:27:07 by perforceCan not view this . file attachment inline, please click on the following link to view the attachment.
    http://
    [UnWrap text]  [Edit this enclosure]
    fixed-in-broadview-main-by-cl101300: Added 02/18/2010 18:27:07 by perforce
    [Wrap Text]  [Edit this enclosure]
    fixed-in-broadview-main-by-cl101300: Added 02/18/2010 18:27:07 by perforce
    [Uwrap text]  [Edit this enclosure]
    fixed-in-sedona-64bit-by-cl101362: Added 02/19/2010 04:52:24 by perforce
    fixed-in-sedona-64bit-by-cl101362: Added 02/19/2010 04:52:24 by perforceCan not view this . file attachment inline, please click on the following link to view the attachment.
    http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCtc16148&title=fixed-in-sedona-64bit-by-cl101362&ext=&type=FILE
    fixed-in-sedona-64bit-by-cl101362: Added 02/19/2010 04:52:24 by perforceCan not view this . file attachment inline, please click on the following link to view the attachment.
    http://
    [UnWrap text]  [Edit this enclosure]
    fixed-in-sedona-64bit-by-cl101362: Added 02/19/2010 04:52:24 by perforce
    [Wrap Text]  [Edit this enclosure]
    fixed-in-sedona-64bit-by-cl101362: Added 02/19/2010 04:52:24 by perforce
    [Uwrap text]  [Edit this enclosure]
    fixed-in-sedona-bv64-by-cl101426: Added 02/19/2010 11:42:41 by perforce
    fixed-in-sedona-bv64-by-cl101426: Added 02/19/2010 11:42:41 by perforceCan not view this . file attachment inline, please click on the following link to view the attachment.
    http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCtc16148&title=fixed-in-sedona-bv64-by-cl101426&ext=&type=FILE
    fixed-in-sedona-bv64-by-cl101426: Added 02/19/2010 11:42:41 by perforceCan not view this . file attachment inline, please click on the following link to view the attachment.
    http://
    [UnWrap text]  [Edit this enclosure]
    fixed-in-sedona-bv64-by-cl101426: Added 02/19/2010 11:42:41 by perforce
    [Wrap Text]  [Edit this enclosure]
    fixed-in-sedona-bv64-by-cl101426: Added 02/19/2010 11:42:41 by perforce
    [Uwrap text]  [Edit this enclosure]
    fixed-in-sedona-main-by-cl101297: Added 02/18/2010 18:24:15 by perforce
    fixed-in-sedona-main-by-cl101297: Added 02/18/2010 18:24:15 by perforceCan not view this . file attachment inline, please click on the following link to view the attachment.
    http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCtc16148&title=fixed-in-sedona-main-by-cl101297&ext=&type=FILE
    fixed-in-sedona-main-by-cl101297: Added 02/18/2010 18:24:15 by perforceCan not view this . file attachment inline, please click on the following link to view the attachment.
    http://
    [UnWrap text]  [Edit this enclosure]
    fixed-in-sedona-main-by-cl101297: Added 02/18/2010 18:24:15 by perforce
    [Wrap Text]  [Edit this enclosure]
    fixed-in-sedona-main-by-cl101297: Added 02/18/2010 18:24:15 by perforce
    [Uwrap text]  [Edit this enclosure]
    fixed-in-titan-8.2.2_fcs_throttle-by-cl101307: Added 02/18/2010 18:57:08 by perforce
    fixed-in-titan-8.2.2_fcs_throttle-by-cl101307: Added 02/18/2010 18:57:08 by perforceCan not view this . file attachment inline, please click on the following link to view the attachment.
    http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCtc16148&title=fixed-in-titan-8.2.2_fcs_throttle-by-cl101307&ext=&type=FILE
    fixed-in-titan-8.2.2_fcs_throttle-by-cl101307: Added 02/18/2010 18:57:08 by perforceCan not view this . file attachment inline, please click on the following link to view the attachment.
    http://
    [UnWrap text]  [Edit this enclosure]
    fixed-in-titan-8.2.2_fcs_throttle-by-cl101307: Added 02/18/2010 18:57:08 by perforce
    [Wrap Text]  [Edit this enclosure]
    fixed-in-titan-8.2.2_fcs_throttle-by-cl101307: Added 02/18/2010 18:57:08 by perforce
    [Uwrap text]  [Edit this enclosure]
    fixed-in-titan-bennu-by-cl101294: Added 02/18/2010 18:24:08 by perforce
    fixed-in-titan-bennu-by-cl101294: Added 02/18/2010 18:24:08 by perforceCan not view this . file attachment inline, please click on the following link to view the attachment.
    http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCtc16148&title=fixed-in-titan-bennu-by-cl101294&ext=&type=FILE
    fixed-in-titan-bennu-by-cl101294: Added 02/18/2010 18:24:08 by perforceCan not view this . file attachment inline, please click on the following link to view the attachment.
    http://
    [UnWrap text]  [Edit this enclosure]
    fixed-in-titan-bennu-by-cl101294: Added 02/18/2010 18:24:08 by perforce
    [Wrap Text]  [Edit this enclosure]
    fixed-in-titan-bennu-by-cl101294: Added 02/18/2010 18:24:08 by perforce
    [Uwrap text]  [Edit this enclosure]
    fixed-in-titan-main-by-cl101282: Added 02/18/2010 16:48:04 by perforce
    fixed-in-titan-main-by-cl101282: Added 02/18/2010 16:48:04 by perforceCan not view this . file attachment inline, please click on the following link to view the attachment.
    http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCtc16148&title=fixed-in-titan-main-by-cl101282&ext=&type=FILE
    fixed-in-titan-main-by-cl101282: Added 02/18/2010 16:48:04 by perforceCan not view this . file attachment inline, please click on the following link to view the attachment.
    http://
    [UnWrap text]  [Edit this enclosure]
    fixed-in-titan-main-by-cl101282: Added 02/18/2010 16:48:04 by perforce
    [Wrap Text]  [Edit this enclosure]
    fixed-in-titan-main-by-cl101282: Added 02/18/2010 16:48:04 by perforce
    [Uwrap text]  [Edit this enclosure]
    sla-mon-sh-tech: Added 09/23/2009 20:43:52 by kusankar
    sla-mon-sh-tech: Added 09/23/2009 20:43:52 by kusankarCan not view this .log file attachment inline, please click on the following link to view the attachment.
    http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCtc16148&title=sla-mon-sh-tech&ext=log&type=FILE
    sla-mon-sh-tech: Added 09/23/2009 20:43:52 by kusankarCan not view this .log file attachment inline, please click on the following link to view the attachment.
    http://
    [UnWrap text]  [Edit this enclosure]
    sla-mon-sh-tech: Added 09/23/2009 20:43:52 by kusankar
    [Wrap Text]  [Edit this enclosure]
    sla-mon-sh-tech: Added 09/23/2009 20:43:52 by kusankar
    [Uwrap text]  [Edit this enclosure]
    static-analysis-titan-main: Added 02/18/2010 16:48:07 by perforce
    static-analysis-titan-main: Added 02/18/2010 16:48:07 by perforceCan not view this . file attachment inline, please click on the following link to view the attachment.
    http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCtc16148&title=static-analysis-titan-main&ext=&type=FILE
    static-analysis-titan-main: Added 02/18/2010 16:48:07 by perforceCan not view this . file attachment inline, please click on the following link to view the attachment.
    http://
    [UnWrap text]  [Edit this enclosure]
    static-analysis-titan-main: Added 02/18/2010 16:48:07 by perforce
    [Wrap Text]  [Edit this enclosure]
    static-analysis-titan-main: Added 02/18/2010 16:48:07 by perforce
    -KS

  • SLA Monitoring

    I have 2 static routes from source to destination on ASA. I want to give preference to first path and the second path will be the backup path. In case if first path will goes down only then the second path will be used. For this I want to enable SLA monitoring. If i will set number of packets=100, Frequency=20 sec, Timeout= 2sec. I want that when all the 100 packets will be dropped only the backup path will be used. 
    How can i set this requirement?
    Regards,
    Mukesh Kumar
    Network Engineer
    Spooster IT Services

    Hello Mukesh ,
    I understand that you are trying to achieve redundancy using ipsla track feature and at the same time you want some delay ( you said untill 100 packets are dropped ) in installing secondary route in RIB .
    Kindly correct me if wrong .
    As a simpler solution , I think you can add delay in number of seconds under track statement , that will achieve same thing but in terms of seconds . So lets say if you have threshold to 20 seconds and delay of 60 seconds , in case of failure condition router will wait untill IPSLA is triggered 3 times with consecutive failures ( as per frequency ) .
    Anyways , in case you still need IPSLA track feature based on number of packets drop , please see below as per my understanding :
    As you say you will set number of packets = 100 , i assume you are using ICMP-jitter based IPSLA and that can report such drops in reaction configuration . you can use "traponly" keyword to have a log generated when configured number of drop threshold is reached ( kindly ensure to have ip sla logging trap configured ) . 
    Now you can use this log ( threshold exceeded ) as trigger for an EEM script and do whatever changes are needed in configuration ( eg, static route AD manipulation etc ) .
    hope to help .
    For any further help please let me know .
    Regards
    Sunil Bhadauria

  • IP SLA Monitor

    Hi all!
    We are using IP SLA to monitor the WAN IP from a client:
    ip sla monitor 1
    type echo protocol ipIcmpEcho 192.168.251.206 source-interface GigabitEthernet0/1
    request-data-size 10
    timeout 2000
    threshold 4000
    frequency 5
    ip sla monitor schedule 1 life forever start-time now
    track 104 rtr 1 reachability
    delay down 8 up 30
    When the link is down, traffic is switched to another link. The problem is that when we are doing maintenance with the problem link, any  oscillation (up/down) causes the link to be switched back to the link with problem. The only solution we found for this case is to give a shutdown on the interface that is being repaired.
    Does anyone know what I can do to prevent traffic is switched to the link that is being repaired?
    Appreciate any help

    Hi Sachin!
    I think it would be interesting to increase the monitoring time, if the main link becomes down. You know  I can  how do this without using load balancing (HSRP, VRRP, GLBP ...)? Because we are monitoring the wan interface of the client, ie, on the other end of the cloud.
    Thanks.

  • Cisco ASA5505 sla monitoring

    Hello,
    I'm not sure how does the SLA monitoring works...
    Example:
    sla monitor 123
    type echo protocol ipIcmpEcho 10.0.0.1 interface outside
    num-packets 3
    frequency 10!--- Configure a new monitoring process with the ID 123.  Specify the
    !--- monitoring protocol and the target network object whose availability the tracking
    !--- process monitors.  Specify the number of packets to be sent with each poll.
    !--- Specify the rate at which the monitor process repeats (in seconds).
    When does the routing table change the default route?
    If the 3 send packets will get 3x timeout response or it's enought that just one of those 3 packets dont respond?
    I would like to set up that the routing table (default route) will rebuild after 30 second of timeout the primary default gateway.
    Many thanks
    http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml

    Hi Martin,
    You are missing the track configuration. Track 1 rtr 123 reachability
    And then:
    sla monitor schedule 123 life forever start-time now
    The track is attached to the SLA, so when you pick one default route to monitor (The one with the lower administrative distance) you add the track command, for example:
    route outside 0.0.0.0 0.0.0.0 200.20.20.1 1 track 1
    route outside2 0.0.0.0 0.0.0.0 200.30.30.1 254
    The firewall will be monitoring the first route and when it fails, it will remove it from the routing table.
    If the 3 send packets will get 3x timeout response or it's enought that just one of those 3 packets dont respond?
    There is a threshold that can be configured to say how many packets you will expect.
    Mike
    Mike

  • IP SLA Monitor on Cisco 2911

    Dear all,
    I have a cisco 2911 router that is located in my head office LAN and I use this router to connect to my branch networks. I want to configure IP SLA Monitor on this router to track my WAN Links but it does not support the command IP SLA Monitor. My IOS VERSION is  c2900-universalk9-mz.SPA.151-2.T1.bin. Please help tell me how I can configure IP SLA on my router.
    Any assistance will be highly appreciated.

    The Data Technology Package License part number SL-29-DATA-K9 was changed to the AppX Technology Package License that includes DATA and WAAS features with part number SL-29-APP-K9.
    SL-29-APP-K9 (AppX License for Cisco 2900 Series) - USD 1,000.00
    Please check the Change in Product Part Number Announcement for the Cisco 2900 Series Integrated Services Routers Data Technology Package Licenses link below for your reference(s): 
    http://www.cisco.com/c/en/us/products/collateral/routers/2900-series-integrated-services-routers-isr/eos-eol-notice-c51-730946.html

  • IP SLA Monitor /Tracking 2921

    I am looking or IOS code for a Cisco 2921/K9 that will allow me to do IP SLA Tracking. The current code "c2900-universalk9-mz.SPA.151-4.M.bin" will only allow me to sset up IP SLA responder or IP SLA Server but  NOT IP SLA Monitor or IP SLA RTR.
    I have used the Cisco feature set research tool and chose what it recommended but to no avail.
    Am I missing something? Will the Server or Responder perform tracking?
    Thanks in advance to anyone who can  assist..
    ~g

    Dear All,
    I have the same problem with C2921. I want to config IP SLA for my C2921 but it seems do not support. The below for your reference.
    ####### Do not have option monitor
    ip sla ?
      key-chain  Use MD5 Authentication for IP SLAs Control Messages
      responder  Enable IP SLAs Responder
      server     IPPM server configuration
    Show version
    System image file is "flash0:c2900-universalk9-mz.SPA.151-4.M1.bin"
    License Info:
    License UDI:
    Device#   PID                   SN
    *0        CISCO2921/K9          FGL153913PM    
    Technology Package License Information for Module:'c2900'
    Technology    Technology-package           Technology-package
                  Current       Type           Next reboot 
    ipbase        ipbasek9      Permanent      ipbasek9
    security      None          None           None
    uc            None          None           None
    data          None          None           None
    Please kindly advise what ios I can use for configuring IP SLA. there're any problem with my licence for that
    Best Regards,
    Binh

  • How to perform near realtime monitoring of ASA?

    Hi,
    we would like to have option to monitor in close to realtime the performances of the ASA.
    Need to be able to eg get an alert (email, pager) when number of connection reaches certain level, when CPU goes high, when traffic reaches certain level, etc. What would be Cisco solution to these challenges? Can MARS fulfill this task? Any other third-party solutions to this problem?
    Thanks in advance for pointing me in right directions.
    Regards

    Hi,
       You can enable NSEL to do real time monitoring of your ASA traffic. Please refer the below links to monitor Cisco ASA with NSEL.
    https://blogs.manageengine.com/netflowanalyzer/2010/07/22/configuring-cisco-asa-netflow-via-asdm
    https://forums.manageengine.com/#topic/49000003577011
    Visit http://www.opmanager.com to monitor Cisco ASA health metrics.
    Thanks
    Don
    ManageEngine NetFlow Analyzer
    www.netflowanalyzer.com

  • ASA SLA Monitoring Options

    Hi,
    Does the "Number of packets" option mean that all the packets specified must exceed the threshold, or is it only one that can be missed? The internet connection for the config below is not very reliable and ping responses are regularly dropped. I beleive this could be causing the route to change to the backup connection when not needed.
    Thanks

    Hello Dustin,
    The "number of packets" configuration is the amount of ICMP request packets that are going to go out from the ASA to the target, and these packets are the ones that are going to be inspected or monitored so if they are getting regularly dropped the test is not going to pass and a Failover between the routes will happen.
    Please rate helpful posts.
    Have a good one
    Julio!!!

  • How do I use Cisco MARS to monitor two ASA (active/stby) with IPS modules?

    Hi
    The two ASA with IPS modules are in active/standby mode. When I try to add both the two IP (active/standby) into the MARS, the MARS will complain duplicated hostnames.
    How to setup MARS to monitor ASA with IPS with active standby topology?
    Thanks!

    Hi,
    The fundamental problem with this scenario is that you have non-failover capable modules in a failover chassis - think of the ASA failover pair as one device and the IPS modules as two completely separate devices.
    Then, as already mentioned, add only the primary ASA. (The secondary will never be passing traffic in standby mode so it's not actually needed in MARS) Then, with the first IPS module you can add it as a module of the ASA or as a standalone device (MARS doesn't care). With the second IPS module the only option is to add it as a separate device anyway.
    In a failover scenario the ASA's swap IP's but the IPS's don't so whereas you'll only ever get messages from the active ASA you'll get messages from both IPS IP's depending on which one happens to be in the active ASA at the time.
    Don't forget that you have to manually replicate all IPS configuration every time you make a change.
    HTH
    Andrew.

  • Can we develop SLA monitoring tool in abap which will monitor HP service manager?

    Hi Experts,
    Can we design tool in ABAP or webdynpro where tool will monitor SLA for incidents in HPSM (HP service manager)?
    Please let me know if such option is available.
    Regards,
    Sanjana

    Hi,
    I have the same issue. SCOM --> OMU 9.10 works fine, OMU 9.10 --> SCOM doesn't work.
    What do you exactky mean with "The user configured for use with the integration pack must have its time zone preferences set to Greenwich/Universal with a date format of mm/dd/yy." Where do you have setup this configuration?
    Thanks for help.

  • SLA monitoring of MPLS service

    Hi Guys..we have MPLS links to about 5 offices around the globe, Bandwidth is around 2 mb across all links, managed by a single ISP. Now we have had various outages recently and we do not have transparency of the average bandwidth. The ISP has his own portal but it doesn't work when needed the most. They have an option where we can pay for getting SNMP feeds but there is no provisioning for capturing Netflow. I guess thay use that for their own portal purposes.
    The routers at the CPE side (our side), are managed by the ISP.
    What tools/applications I can use on my side to maintain visibility over the MPLS links provided to us?

    Hi,
    You can make use of the "IP SLA" features between your CPE devices. Though CPE's are connected via MPLS VPN network the enterprise network (your network)is actually unaware of MPLS technology and all you need for IP SLA to work is the ip reachability between devices. CPE to CPE "IP SLA" can be configured which will give you lot of informations that can be gathered. It also has MIB and OID values associated with it. So you can use a free network monitoring tool with OID values so that you can even view the pictorial presentation of your network uptime and lot of performance parameters (jitter, packet loss, latency, etc.)
    You can get some insight to "IP SLA":
    http://www.cisco.com/en/US/prod/collateral/iosswrel/ps6537/ps6555/ps6602/prod_presentation0900aecd8047bab5.pdf
    HTH.. Pls rate if useful..
    cheers
    Arun Kumar

  • Tools use to monitor cisco asa

    Hi all,
    I just roll out a cisco asa 5540 and use it as a SSL vpn concentrator.
    Can i know what tools you use to monitor the cisco ASA, eg account with most number of login attempts, number of fail attempts etc
    TIA!

    You can look at Cisco Prime Collaboration Assurance if you're willing to upgrade to 10.0; they have started providing a free Standard license. They of course hope to upsell you to Advanced but the goal is for Standard to be an alternative to RTMT. There are also a plethora of ecosystem partners with product offerings in the Developer Marketplace.
    Please remember to rate helpful responses and identify helpful or correct answers.

Maybe you are looking for

  • Adjusting order of songs in playli

    hi ppl, i wan to noe is it possible to adjust the order of the song being played after u have put it into a playlist? for eg. i wan my current track 7 of the playlist to move up to track 2 and vice versa.... isit possible?or do i have to create a new

  • Flex 4.1 stackview

    Hi All, I am testing migration from flex sdk 3.5 to 4.1. In flex 3.5 I use viewstack to separate all forms and call each at the time from a menu. <mx:ViewStack id="VS" x="0" y="0" width="100%" height="100%" creationPolicy="all">      <custom:test id=

  • Please give me ask about my ibook.

    Please give me ask, I have a ibook G4 with OS 10.5.8. Now, Could I upgrate to 10.6.8?

  • HELP! possible to load images into a component?

    wanna load a help file that has pictures in it and display using a dialog. what component shld i use? the dialog shld have a vertical scroll pane n the user shld be able to read the info from the file. the pictures will be inserted at random in the f

  • Unidentifi​ed error

    I have an HP photosmart C5580 All-in-One machine.  a few months ago, it stopped working all together.  I turned it on one day and got a blue screen with a power symbol on it and an error code that shows up nowhere in the manual.  I unplugged the mach