I constructed a MRTG/Routers2 configuration template for the Cisco ASA firewall which consists the OIDs (graphs) for the interfaces, CPU, memory, VPNs, connections, ping times, and traceroute hop counts. With only four search-and-replace changes as well as a few further specifications, the whole SNMP monitoring for that firewall is configured.
With this template, the following graphs are shown:
- Interfaces
- CPU & Memory
- Connections
- VPN Sessions (RA & S2S total count)
- VPN Remote Access Sessions (IPsec, AnyConnect, WebVPN)
- Ping Outside IP (mrtg-ping-probe script covered here)
- Ping Inside IP through VPN-Tunnel (if available)
- Hop Count to Outside IP (with my script from here)
- Short Summary (only: CPU, connections, VPN, outside interface, ping outside)
Download the Template
This is the *.cfg template file. Follow the first comment lines in the file to replace the correct values inside the template.
data:image/s3,"s3://crabby-images/bc24d/bc24d825108d042aceb887cf330cf7d40b65b93d" alt=""
MRTG-Routers2 Template Cisco ASA 18.33 KB
Sample Graphs
Here is a gallery with all the graphs from that template (all in the “weekly” view):
data:image/s3,"s3://crabby-images/5c609/5c60919b6fc4e8da17b6b09036b22639970f9a15" alt="CPU"
data:image/s3,"s3://crabby-images/9c52d/9c52dbd625c125d4c3438a7f45fc89e4f7f942d0" alt="Memory"
data:image/s3,"s3://crabby-images/2bf63/2bf638909f4014178f1748cb16b8d3aa44a28625" alt="Connections"
data:image/s3,"s3://crabby-images/c482b/c482b53f312f2427df617257afe81b389e2d7870" alt="Interface"
data:image/s3,"s3://crabby-images/8e914/8e91442d1d700a51d8ebd0e357501fbd5026dc27" alt="VPNs (Site-to-Site & Remote Access)"
data:image/s3,"s3://crabby-images/364a9/364a9adcec1a1357f068e58efd249b3c81caae9c" alt="Remote Access VPNs Detail"
data:image/s3,"s3://crabby-images/23a42/23a421f161d29c8b2dcf07f4f00f5d5cb9984386" alt="Traceroute"
data:image/s3,"s3://crabby-images/1e1e2/1e1e29d6a70c187f9a0a67475e7441afc1052643" alt="Ping Outside"
data:image/s3,"s3://crabby-images/f3011/f3011ec7f927fb5f8d3667dd33c6de17fcae6285" alt="Ping Inside"
And here a few graphs with the values over two years to see the trends:
data:image/s3,"s3://crabby-images/16136/161367090c45e894b803eb45726fccf7c7b75b4a" alt="Connections constantly increasing"
data:image/s3,"s3://crabby-images/0511f/0511f4560671bae4d6a6ecbc41808e0c5a329ca0" alt="Traffic only a bit increasing"
data:image/s3,"s3://crabby-images/683de/683de0513ce3d5d67c08f748bf434c87398f42bd" alt="VPNs"