DX NetOps

Expand all | Collapse all

Unable to monitor SNMPv3 enabled Cisco ASA due to duplicateEngineID

  • 1.  Unable to monitor SNMPv3 enabled Cisco ASA due to duplicateEngineID

    Posted 11-27-2015 06:44 AM

    As it was already mentioned by DanOviatt as comment in this idea Disable snmp Engine ID Verfication in Spectrum, some devices have by design failover methods which will lead to a duplicateEngineID for SNMPv3 monitoring.

     

    Due to this, we're unable to fully monitor Cisco ASA 55xx and SNMPv3 enabled with Spectrum.

     

    As Cisco is also very reluctant to change this, is there any known workaround to monitor the primary and failover system of Cisco ASA with v3 and both on the same server?

    Cisco Bug: https://tools.cisco.com/bugsearch/bug/CSCtl88556/?referring_site=bugquickviewredir

     



  • 2.  Re: Unable to monitor SNMPv3 enabled Cisco ASA due to duplicateEngineID

    Posted 11-30-2015 09:52 AM

    Have you already tried to set the EngineID manually?

    I know it is possible on some types of Cisco Devices /iOS's but i am not sure about the ASA.



  • 3.  Re: Unable to monitor SNMPv3 enabled Cisco ASA due to duplicateEngineID

    Posted 11-30-2015 01:43 PM

    The ASA snmp engine is a mess.  It doesn't support a bunch of MIBs that it should based on what the OS supports, it doesn't support VACM, and you can't manually set engine IDs.  Cisco really needs to fix the whole thing, not just engine IDs.