Show ip nat statistics snmp oid
Hello,
I'm trying to monitor nat stats using snmp in the newer IOS versions. I had it working pre 12.4(22)T, but now it seems as if the oid has changed.
2811#show ip nat statistics
Total active translations: 29 (0 static, 29 dynamic; 29 extended)
Peak translations: 43, occurred 1d13h ago
Outside interfaces:
FastEthernet0/1
Inside interfaces:
Loopback0, Virtual-Template1
Hits: 82385 Misses: 0
CEF Translated packets: 66829, CEF Punted packets: 3876
Expired translations: 5233
Dynamic mappings:
-- Inside Source
[Id: 1] access-list nat pool inet refcount 30
pool inet: netmask 255.255.255.192
start 111.111.111.110 end 111.111.111.111
type generic, total addresses 1, allocated 1 (100%), misses 0
Total doors: 1
Appl doors: 1
Normal doors: 0
Queued Packets: 0
The number i'm looking for is the Total active translations. If you try it on a router that has 12.4(20)T it will work, seems as if anything newer does not.
Dan.
Hi Dan,
There is currently no MIB that has the "show ip nat statistics" output. An enhancement
request was opened against this, but so far there are no plans to add this to the MIBs.
Here is the enhancement request ID and release notes:
CSCdr25202 no mib variable for ip nat statistics for total active translations
"snmp mib variable for the command: show ip nat statistics for the total active
translations is not present at the moment.
This is an enhancement request. The work-around is to issue the command on the device itself (via CLI)."
Thanks,
Gaganjeet
Similar Messages
-
SNMP OID to get active static NAT number of a router
Hello,
I try to get by SNMP the number of active one-to-one NAT translations of a 3825 router.
I only find the way to get the number of active PAT translations with the OID 1.3.6.1.4.1.9.10.77.1.2.3.0.
But il does not work for one-to-one active NAT translations.
Does anyone have a solution to get that ?
Thanks
JulienHi Julien,
I have done some search and found (internally) that this counter is not supported, there was an enhancement request filed to have it but it's not in the pipe so I don't believe it will be any time soon. The "workaround" explicitly specify to use the CLI command...
However, if you are running a 3800 series with a recent IOS version, I believe you may have support for EEM scripts and custom SNMP MIBs. A good workaround for you might be to use the following script:
http://forums.cisco.com/eforum/servlet/EEM?page=eem&fn=script&scriptId=1741
Check the TCL file header for an example on how to configure it, you'll need to specify all the variables needed among which those two:
event manager environment match_cmd show ip nat stat
event manager environment match_pattern .*Total active translations: ([0-9]+) .*
The value of the counter should appear in 1.3.6.1.2.1.90.1.2.1.1.3.5.99.105.115.99.111.7.99.117.115.116.111.109.49 -
Snmp oids for the command "show counters interface intx/y delta"
Hello,
I have a question about SNMP OIDs for the command "show counters interface intx/y delta" on Catalyst6500. The customer wants to create graphs for the following values:Overruns, qos0Outlost, InErrors, OutErrors, InDiscards, OutDiscards etc..
Is possible to get these values using SNMP??
Thank you
RomanThank you, Dan. These OIDs are for the output from the command "show interface int x/y". But I think, that these OIDs are not for the command "show interface int x/y delta".
Roman -
Cisco ASA SNMP OIDs (show name, show vpn-sessiondb l2l)
Hi all,
I am trying to figure out the SNMP OIDs that is equivalent to the following ASA commands:
show name
show vpn-sessiondb l2l
Thanks!im looking for the solution ? did u ever find out if this was possible?
-
The cisco snmp oids do not work, I can't get cpu or memory data.
Hello. I want to monitor the cpu and memory usages on my cisco devices using snmp. I found the snmp oids related to cpu in the following page :
http://www.cisco.com/en/US/tech/tk648/tk362/technologies_tech_note09186a0080094a94.shtml
I just copy the table here:
But the oids in the table do not work on my devices. For example, I have a cisco 3550 switch with the ip 192.168.1.211, version 12.2(25)when I want to get the informations about the oids up in the table, I got these results:
It shows that the oids cisco given up in the table are not existed in my 3550 switch's MIB. More weird is that when i add a number "1" to
the end of the oid cisco given, I can get some meaningless data for some unkonwn item names like "entreprises.x.x".
For most mib items, the snmp oids work well on my switch. For example, the following graph shows the interface out rate of the swtich:
I think the essence is when I executed the following command:
in all the output results, there's not any item relevant with "cpu" or "memory", but most other items are ok, such as interfaces, as shown below:
IF-MIB::ifDescr.47 = STRING: FastEthernet0/39
IF-MIB::ifDescr.48 = STRING: FastEthernet0/40
IF-MIB::ifDescr.49 = STRING: GigabitEthernet0/1
IF-MIB::ifDescr.50 = STRING: GigabitEthernet0/2
IF-MIB::ifDescr.51 = STRING: Null0
IF-MIB::ifDescr.52 = STRING: Vlan1
IF-MIB::ifType.1 = INTEGER: ethernetCsmacd(6)
IF-MIB::ifType.2 = INTEGER: ethernetCsmacd(6)
IF-MIB::ifType.3 = INTEGER: ethernetCsmacd(6)
IF-MIB::ifType.4 = INTEGER: ethernetCsmacd(6)
IF-MIB::ifType.5 = INTEGER: ethernetCsmacd(6)
So why the cisco given oids won't work on my cisco switch, and how can I get the datas I want? Anyone has some advices? Thanks in advance!
In case the pictures I inserted missing, I attach my problem in the doc.Have you looked at this previous discussion:
Can't Activate FaceTime -
Hello
Someone could tell me where to find a list of SNMP OIDs for solaris 8
thank you for your cooperationThank you, Dan. These OIDs are for the output from the command "show interface int x/y". But I think, that these OIDs are not for the command "show interface int x/y delta".
Roman -
Vpdn: searching for snmp oid to log out vpdn session
Hello colleagues,
Cisco 7204 works as vpdn server.
There are two problems:
1) I'm searching for snmp oid to log out , terminate vpdn session
2) radius server does not receives snmp statistics of incoming traffic of vpdn users.
Please is anyone able to assist me?
aaa new-model
aaa authentication login default local
aaa authentication ppp default group radius local
aaa authentication ppp VPDN local group radius
aaa authorization network default local group radius
aaa accounting delay-start
aaa accounting update periodic 3
aaa accounting exec default start-stop group radius
aaa accounting network default start-stop group radius
aaa session-id common
vpdn enable
vpdn-group 1
! Default PPTP VPDN group
description HOMENET
accept-dialin
protocol pptp
virtual-template 3
interface Virtual-Template3
ip unnumbered Loopback1
peer default ip address pool vpdn-pool
no keepalive
ppp authentication chap VPDN
snmp-server community xxxxxxx RW
snmp-server chassis-id 0x0E
snmp-server enable traps tty
radius-server host x.x.x.x auth-port 1812 acct-port 1813
radius-server timeout 60
radius-server key 7
radius-server authorization permit missing Service-Type
Best regards, Petr AkimovHello –
I received a reply from the developer of the script, and listed below is the new code that was suggested:
#!/bin/bash
value=`snmpwalk $1 -v1 -c $2 .1.3.6.1.2.1.25.1.5.0 | cut -d " " -f4`
if [[ value -gt $3 ]]
then
echo " $value Users Online, Critical!"
retval=2;
else
if [[ $value -gt $4 ]]
then
echo " $value users online, Warning!"
retval=1;
else
echo " $value Users online, fine."
retval=0;
fi
fi
exit $retval;
I checked the server in question, and there were two, 2, user logins active on the system. I ran the snmpwalk command, and the output was the following:
HOST-RESOURCES-MIB::hrSystemNumUsers.0 = Gauge32: 15
I then modified the script to include the above text, and ran it again. The output was the following:
15 users on line, Normal.
For some reason, the value of 12 appears to be that for no users logged into the system. I am not sure why that is the case.
If nothing else, progress has been made with the modification of the script. The snmp service that I have installed on the server is that which came bundled as a
feature with the server. The only thing that was not installed was the SNMP WMI Provider option. -
EEM detector SNMP OID does not work
i want to use EEM to detector policy-map class traffic rate, if class traffic is more than a number, trigger syslog message.
below is my EEm script on ASR1002 ( asr1000rp1-adventerprisek9.02.04.02.122-33.XND2.bin)
event manager applet Rate-limit
event snmp oid ".1.3.6.1.4.1.9.9.166.1.15.1.1.10.50.196608" get-type exact entry-op gt entry-val "100" poll-interval 10
action 1.0 syslog msg "policy Rate-limit"
but i did not see anything showing on syslog. from debug, i got below error msg :
Jun 1 02:21:49.160 GMT: fh_fd_snmp_process_async
Jun 1 02:21:49.160 GMT: fh_fd_snmp_process_poll_timer: re=0x3D144824, timer_type=POLL
Jun 1 02:21:49.160 GMT: fh_fd_snmp_process_poll_timer: OID unavailable, value check skipped
Jun 1 02:21:49.160 GMT: fh_fd_snmp_start_poll_timer: start_t=10000
but i could get number from snmpwalk command :
xchen-mac:~ xchen$ snmpwalk -v 2c -c <string> -m ALL stde1002a .1.3.6.1.4.1.9.9.166.1.15.1.1.10.50.196608
SNMPv2-SMI::enterprises.9.9.166.1.15.1.1.10.50.196608 = Counter64: 112938
please help me where is wrong ?Duplicate post.
Go here: https://supportforums.cisco.com/discussion/12219976/eem-detect-snmp-event-not-working -
Hi,
Does the ASA have an SNMP OID which will provide information like the show conn command ?2 years later, how's LLDP support via SNMP?
If Cisco does not support LLDP via SNMP, please remove the wrong information from
http://tools.cisco.com/ITDIT/MIBS/MainServlet?ReleaseSel=2514&PlatformSel=231&fsSel=705
Stop lying! -
ASA 5512 - monitor power supply status via snmp oid
Device – ASA 5512 running 9.1(1).
Show version:
ASA-1# sh ver
Cisco Adaptive Security Appliance Software Version 9.1(1)
Device Manager Version 6.6(1)
Compiled on Wed 28-Nov-12 11:15 PST by builders
System image file is "disk0:/asa911-smp-k8.bin"
Config file at boot was "startup-config"
ASA-1 up 8 hours 38 mins
Hardware: ASA5512-K7, 4096 MB RAM, CPU Clarkdale 2792 MHz, 1 CPU (2 cores)
ASA: 2048 MB RAM, 1 CPU (1 core)
Internal ATA Compact Flash, 4096MB
BIOS Flash MX25L6445E @ 0xffbb0000, 8192KB
Issue: looking for a snmp OID to poll power supply status (Inbuilt Power Supply - no redundant power supply in this scenario). Possibly what we see in show environment.
CSE analysis:
I tried using the OIDs belonging to CISCO-ENTITY-FRU-CONTROL-MIB , like cefcFRUPowerOperStatus and cefcFRUPowerAdminStatus but it didn’t return anything.
NOTE: I have done all the snmp walks from the Linux server. Do I doubt it’s something to do from the snmp manager side.
Couple of observations. The CISCO-ENTITY-FRU-CONTROL-MIB talks about the field replaceable power supplies, so I doubt if it’s going to return the value for inbuilt power supply.
Second, I noticed that there are snmp traps supported for power supply and threshold setting. See configuration below. Is it that only traps works for power supply and environment related details?
Snmpwalk on cefcFRUPowerStatusEntry returns nothing:
[root@tonbenso-eagle bin]# ./snmpwalk -v2c -c public 172.16.169.29 1.3.6.1.4.1.9.9.117.1.1.2.1
SNMPv2-SMI::enterprises.9.9.117.1.1.2.1 = No Such Object available on this agent at this OID
Snmpwalk on cefcFRUPowerOperStatus returns nothing:
[root@tonbenso-eagle bin]# ./snmpwalk -v2c -c public 172.16.169.29 1.3.6.1.4.1.9.9.117.1.1.2.1.2
SNMPv2-SMI::enterprises.9.9.117.1.1.2.1.2 = No Such Instance currently exists at this OID
Snmpwalk on cefcFRUPowerAdminStatus returns nothing:
[root@tonbenso-eagle bin]# ./snmpwalk -v2c -c public 172.16.169.29 1.3.6.1.4.1.9.9.117.1.1.2.1.1
SNMPv2-SMI::enterprises.9.9.117.1.1.2.1.1 = No Such Instance currently exists at this OID
[root@tonbenso-eagle bin]#
login as: root
I tried polling the ciscoEntityFRUControlMIB to see what all values it return. It just returned enterprises.9.9.117.1.3.1.0 = INTEGER: 2. Meaning cefcMIBEnableStatusNotification is FALSE (value 2). Meaning cefcModuleStatusChange, cefcPowerStatusChange, cefcFRUInserted, cefcFRURemoved, cefcUnrecognizedFRU and cefcFanTrayStatusChange are prevented from being sent.
Snmpwalk on ciscoEntityFRUControlMIB
[1]+ Stopped ./snmpwalk -v2c -c public 172.16.169.29
[root@tonbenso-eagle bin]# ./snmpwalk -v2c -c public 172.16.169.29 1.3.6.1.4.1.9.9.117
SNMPv2-SMI::enterprises.9.9.117.1.3.1.0 = INTEGER: 2
Object
cefcMIBEnableStatusNotification
OID
1.3.6.1.4.1.9.9.117.1.3.1
Type
TruthValue
Permission
read-write
Status
current
MIB
CISCO-ENTITY-FRU-CONTROL-MIB ; - View Supporting Images
Description
"This variable indicates whether the system
produces the following notifications:
cefcModuleStatusChange, cefcPowerStatusChange,
cefcFRUInserted, cefcFRURemoved,
cefcUnrecognizedFRU and cefcFanTrayStatusChange.
A false value will prevent these notifications
from being generated."
Found couple of bugs:
CSCty32558 – but then this is for 5585 and I see it is fixed in 8.4
CSCul90037 – New state
Show snmp-server oidlist:
http://www-tac.cisco.com/Teams/ks/c3/getLargeFile.php?srId=632222409&fileName=20141030-013905_ASA-show-snmp-server-oidlist.txt
Show tech:
Sh run | in snmp:
ASA-1# sh run | in snmp
snmp-server host asa 172.18.123.228 community *****
no snmp-server location
no snmp-server contact
snmp-server community *****
snmp-server enable traps entity power-supply-presence power-supply-temperature -----à I was talking about this trap above
any help will be appreciated.Hi
I've got an ASA with redundant power supplies. An ASA5585. So I have the need to monitor them. :-) So how can we do it?
Also I've made a SNMP-Walk through the ASA v8.4(2)8 and it doesn't show up any ENV-MIB values. The
1.3.6.1.4.1.9.9.13 tree is not available. Are you shure it's available on the ASA?
Funny is also that the command "show snmp-server oidlist" from the 8.4 configuration guide is not available on the real CLI. I think the documentation guys were faster than the coders. ;-)
Kind regards
Roberto -
I am trying to build a basic TCL skeleton script that reads a remote SNMP OID and displays the value on the screen.
I don't want it to be an EEM Event, I just want to run it from the (tcl)# prompt.
So I guess I'm asking if you can use cli_exec and other commands in the "namespace import ::cisco::eem::*" in a normal non-EEM script - can I do that?
This is the error I get:
OTN.159(tcl)#source flash:TCL_SNMP_Remote_Read.tcl
invalid command name "::cisco::eem::event_register_none" ^
% Invalid input detected at '^' marker.
What am I missing?
================= TCL_SNMP_Remote_Read.tcl ==============================
::cisco::eem::event_register_none
namespace import ::cisco::eem::*
namespace import ::cisco::lib::*
if [catch {cli_open} RESULT]
{ error $RESULT $errorInfo }
else { array set cli1 $RESULT }
if [catch {cli_exec $cli1(fd) "snmp get v2c 192.168.1.100 public timeout 1 oid 1.3.6.1.2.1.1.1.0" } RESULT]
{ error $RESULT $errorInfo }
else { set SnmpSysDesc $RESULT }
if [catch {cli_close $cli1(fd) $cli1(tty_id)} RESULT] {
error $RESULT $errorInfo
puts $SnmpSysDesc
=========================================================================
In the sho-run config I have:
event manager directory user policy "flash:/"
event manager session cli username "cisco"
Any help to get me started would be greatly appreciated!
TimIf you don't want an EEM policy, then don't use any of the EEM constructs. Instead, all you need is this:
set output [exec "snmp get v2c 192.168.1.100 public timeout 1 oid 1.3.6.1.2.1.1.1.0"]puts $output -
Show IP SLA statistics output definitions
Does anyone have a link or documentation that defines ALL the fields in a show ip sla statistics command? Some are clearly obvious, but in Packet Loss Values for instance what are the measurement values for Source to Destination Loss Periods Number: or Source to Destination Loss Periods Number: ?
IPSLA operation id: 8502
Start Time Index: 13:56:14 UTC Tue Mar 25 2014
Type of operation: udp-jitter
Voice Scores:
MinOfICPIF: 0 MaxOfICPIF: 0 MinOfMOS: 0 MaxOfMOS: 0
RTT Values:
Number Of RTT: 48157 RTT Min/Avg/Max: 54/56/503 milliseconds
Latency one-way time:
Number of Latency one-way Samples: 0
Source to Destination Latency one way Min/Avg/Max: 0/0/0 milliseconds
Destination to Source Latency one way Min/Avg/Max: 0/0/0 milliseconds
Jitter Time:
Number of SD Jitter Samples: 43824
Number of DS Jitter Samples: 43824
Source to Destination Jitter Min/Avg/Max: 0/1/142 milliseconds
Destination to Source Jitter Min/Avg/Max: 0/1/81 milliseconds
Packet Loss Values:
Loss Source to Destination: 96
Source to Destination Loss Periods Number: 796
Source to Destination Loss Period Length Min/Max: 1/17
Source to Destination Inter Loss Period Length Min/Max: 1/2828
Loss Destination to Source: 5746
Destination to Source Loss Periods Number: 4319
Destination to Source Loss Period Length Min/Max: 1/17
Destination to Source Inter Loss Period Length Min/Max: 1/321
Out Of Sequence: 0 Tail Drop: 1
Packet Late Arrival: 0 Packet Skipped: 0
Number of successes: 18
Number of failures: 30this is a great document as well, but doesn't dive down deep enough. The best example would be Packet Loss, where is says -
Packet Loss
Five types of packet loss or assimilated events can be measured with IP SLA:
Packet loss in the source to destination (packetLossSD)
Packet loss in the destination source (packetLossDS)
Tail Drop: we know it has been dropped, but we do not know in which direction. This is when the last packet(s) of the test streams were dropped, because in this case, we do not receive the sequence numbers. In older releases, this is called Packet MIA for missing in action. In the MIB, the notation PacketMIA is still in use.
Packet Late Arrival: the packet did arrive, but so late that the underlying application probably considered it as dropped, or at least not useful. Think about a VoIP application. If one packet arrives much later than expected, it is too late because the conversation keeps going. This packet is assimilated to a drop.
Packet Misordering: the packet arrived but not in the right order. This may or may not be considered as a packet drop. (packetOutOfOrder)
The cool thing is the power that lies behind those numbers. Differenct values can be calculated the way you want it. For instance the total amount of packet dropped is:
packetDropped = RTTMonPacketLossSD + RTTMonPacketLossDS + RTTMonPacketMIA
The total percentage of packets that have dropped during the instance is:
drop_rate_%age = 100 * packetDropped / (RTTMonNumOfRTT + packetDropped)
Many other values can be calculated, and that is entirely up to you to decide what parameters are important.
But does not address the fields that I am looking for -
Source to Destination Loss Period Length Min/Max: 1/17
Source to Destination Inter Loss Period Length Min/Max: 1/2828
Destination to Source Loss Periods Number: 4319
Destination to Source Loss Period Length Min/Max: 1/17
Destination to Source Inter Loss Period Length Min/Max: 1/321
appreciate all the input though Vinod! -
SG-500 - SNMP OID for CPU Load?
Hello,
i have several SG500 (Standalone and stacked). How can i get the CPU Load via SNMP? Who knows the correct SNMP OID for CPU Load?
In the MIB which are provided as download a wasn't able to find the correct OID.Hello,
There are three OIDs available for CPU usage:
CPU utilization for 5 seconds
.1.3.6.1.4.1.9.6.1.101.1.7.0
CPU utilization for 1 minutes
.1.3.6.1.4.1.9.6.1.101.1.8.0
CPU utilization for 5 minutes
.1.3.6.1.4.1.9.6.1.101.1.9.0
This came from a scrap note I had in an e-mail, so I am not exactly sure where this information is originally.
Let me know if that works for you,
Christopher Ebert - Network Support Engineer
Cisco Small Business Support Center
*please rate helpful posts* -
SNMP OID on Catalyst 3750G & 3650G
Hallo guys,
we have a couple of 3750Gs and sveral 3650Gs in my company lan, and I'm looking for the SNMP OIDs supported with which the very basic status of these switches can be retrieved. I mean generic status like the switch is being active, or experiencing technical error etc...
I was advised to take 1.3.6.1.2.1.4.1.0 (IPForwarding), but I'm not sure if it is the right one. I'd appreciate if someone can give me a hint..
Thank you!
Li LuYour request is pretty generic. There are a lot of OIDs which can provide device health. You might want to start with ifInOctets, ifOutOctets, ifInErrors, and ifOutErrors. Those will give you per-port byte and error counts in both the ingress and egress directions.
As for whole-device help, take a look at the moduleTable from the CISCO-STACK-MIB. The object moduleStatus will tell you the status of the fixed switch itself. -
What snmp OID to use to monitor control-plane of router
Hi there!
I've applied policy-maps on control-plane, based on cisco recomandation.
Now i need to know, what snmp OID i've to use to monitor them (i'm using zabbix)
Let me know.
Regards!If you are using IOS which uses a policy-map to configure Control Plane Policing then you are asking in the wrong place as this forum is for IOS-XR not IOS but you can poll objects in the CISCO-CLASS-BASED-QOS-MIB::cbQosPoliceStatsTable (for example cbQosCMDropByte64, cbQosPoliceExceededByte64, cbQosPoliceConformedByte64).
If you mean you have changed the LPTS policers to help protect the control-plane in IOS-XR then I believe there is currently no support for polling the counters via SNMP. See the section on monitoring in Xander's document https://supportforums.cisco.com/document/93456/asr9000xr-local-packet-transport-services-lpts-copp
Maybe you are looking for
-
Images are not showing in uitable view .
When running the app on simulator the images are comming well in table view , but no images are showing during in iPad Device and also showing no error . I debuged the app ane the pointer is going to - (UITableViewCell *)tableView:(UITableView *)tabl
-
Flash slideshow display problem in IE
Hi, I've just inserted a .swf file into my (DW) site and viewed it in a number of browers without a problem. Apart from IE which displays 'content on this page requires new version of flash' text/image. What I'd like to know is that is there a wa
-
I can't export my video which contains only photos, sound tracks nor play it in fullscreen iMovie it shuts down. And now my whole file won't open at all it'll open with nothing inside ??
-
Migrating emails from G3 to iMac G5
Hi, Does anyboby now if it's possible to import emails from outlook (from a mac running mac os 9.6) to a G5 iMac running mac os X v.10.4 ? Would it work if I simply open Mail on the iMac and select import mailboxes? (after I have copied all the folde
-
Determining number of teenagers living in a street
I'm creating a java program to determine how many people are in a street, and how many of those people are teenagers. The information is gathered from an input file which is featured below. INPUT FILE* 12 20 13 19 34 80 0 14 75 17 50 1 11 11 30 90 15