Zabbix 監控 Cisco ASA5525 流量


簡介:shell

Zabbix 監控 Cisco ASA5525 網絡接口流量服務器

1、Zabbix 支持 SNMP、Cisco 開啓 SNMP網絡

2、測試ide

shell > snmpwalk -v 2c -c public 192.168.2.254 system  # 查看系統信息
SNMPv2-MIB::sysDescr.0 = STRING: Cisco Adaptive Security Appliance Version 8.6(1)2
SNMPv2-MIB::sysObjectID.0 = OID: SNMPv2-SMI::enterprises.9.1.1408
DISMAN-EVENT-MIB::sysUpTimeInstance = Timeticks: (3248815000) 376 days, 0:29:10.00
SNMPv2-MIB::sysContact.0 = STRING: 
SNMPv2-MIB::sysName.0 = STRING: ciscoasa
SNMPv2-MIB::sysLocation.0 = STRING: 
SNMPv2-MIB::sysServices.0 = INTEGER: 4

# -v 指定版本,-c 指定共同體名,IP,指令測試

shell > snmpwalk -v 2c -c public 192.168.2.254 interface  # 查看接口信息

# IF-MIB::ifDescr 接口名稱
# IF-MIB::ifType 類型
# IF-MIB::ifSpeed 速率
# IF-MIB::ifMtu MTU
# IF-MIB::ifPhysAddress MAC
# IF-MIB::ifAdminStatus 狀態
# IF-MIB::ifInOctets 傳輸字節數spa

# 等pwa

3、確認須要監控網絡接口代理

ciscoasa > show running-config interface
!
interface GigabitEthernet0/0
 duplex full
 nameif outside-1
 security-level 0
 ip address xx.xx.xx.xx 255.255.255.224 

# Cisco ASA 查看發現,GigabitEthernet0/0 爲 outside-1 即外網接口,且配置着公網IPcode

shell > snmpwalk -v 2c -c public 192.168.2.254 ifDescr
IF-MIB::ifDescr.2 = STRING: Adaptive Security Appliance 'asa_mgmt_plane' interface
IF-MIB::ifDescr.3 = STRING: Adaptive Security Appliance 'outside-1' interface
IF-MIB::ifDescr.4 = STRING: Adaptive Security Appliance 'GigabitEthernet0/1' interface
IF-MIB::ifDescr.5 = STRING: Adaptive Security Appliance 'inside' interface
IF-MIB::ifDescr.6 = STRING: Adaptive Security Appliance 'GigabitEthernet0/3' interface
IF-MIB::ifDescr.7 = STRING: Adaptive Security Appliance 'GigabitEthernet0/4' interface
IF-MIB::ifDescr.8 = STRING: Adaptive Security Appliance 'GigabitEthernet0/5' interface
IF-MIB::ifDescr.9 = STRING: Adaptive Security Appliance 'GigabitEthernet0/6' interface
IF-MIB::ifDescr.10 = STRING: Adaptive Security Appliance 'GigabitEthernet0/7' interface
IF-MIB::ifDescr.11 = STRING: Adaptive Security Appliance 'Internal-Data0/1' interface
IF-MIB::ifDescr.12 = STRING: Adaptive Security Appliance 'cplane' interface
IF-MIB::ifDescr.13 = STRING: Adaptive Security Appliance 'mgmt_plane_int_tap' interface
IF-MIB::ifDescr.14 = STRING: Adaptive Security Appliance 'Management0/0' interface
IF-MIB::ifDescr.15 = STRING: Adaptive Security Appliance 'Virtual254' interface

# 服務器上查找,返現 outside-1 對應的設備 ID 爲 IF-MIB::ifDescr.3blog

shell > snmpwalk -v 2c -c public 192.168.2.254 IF-MIB::ifInOctets.3   # 外網口進方向
IF-MIB::ifInOctets.3 = Counter32: 2965376258

shell > snmpwalk -v 2c -c public 192.168.2.254 IF-MIB::ifOutOctets.3  # 外網口出方向
IF-MIB::ifOutOctets.3 = Counter32: 3522107956

4、建立主機、模板

一、主機

建立主機 -> SNMP 192.168.2.254 161 -> 建立

二、模板

建立模板 -> 模板名稱 Cisco -> 羣組 Templates -> 建立

建立應用 -> network interface

建立監控項 -> 名稱 GigabitEthernet0/0 - In
           -> 類型 SNMPv2 端點代理模式
           -> 鍵值 ifHCInOctets.3
           -> SNMP OID IF-MIB::ifHCInOctets.3
           -> SNMP community public
           -> 單位 bps
           -> 使用自定倍數 8
           -> 存儲值 差量(每秒速率)
           -> 應用集 network interface
           -> 建立

# 拿到的是 byte 要轉換成 bit 即 bps,1 byte = 8 bit,因此要設置倍數爲 8
# 照這樣設置 GigabitEthernet0/0 - Out 便可,注意鍵值爲 ifHCOutOctets.3,OID 爲 OID IF-MIB::ifHCOutOctets.3

三、圖形

建立圖形 -> 名稱 GigabitEthernet0/0 -> 加入監控項 -> 繪圖風格 梯度線 -> 設置顏色 -> 建立

5、爲主機添加模板

主機 -> 模板 -> 選擇模板 -> Cisco -> 添加 -> 更新

# 收工 !

相關文章
相關標籤/搜索