簡介:shell
Zabbix 監控 Cisco ASA5525 網絡接口流量服務器
1、Zabbix 支持 SNMP、Cisco 開啓 SNMP網絡
2、測試ide
shell > snmpwalk -v 2c -c public 192.168.2.254 system # 查看系統信息 SNMPv2-MIB::sysDescr.0 = STRING: Cisco Adaptive Security Appliance Version 8.6(1)2 SNMPv2-MIB::sysObjectID.0 = OID: SNMPv2-SMI::enterprises.9.1.1408 DISMAN-EVENT-MIB::sysUpTimeInstance = Timeticks: (3248815000) 376 days, 0:29:10.00 SNMPv2-MIB::sysContact.0 = STRING: SNMPv2-MIB::sysName.0 = STRING: ciscoasa SNMPv2-MIB::sysLocation.0 = STRING: SNMPv2-MIB::sysServices.0 = INTEGER: 4
# -v 指定版本,-c 指定共同體名,IP,指令測試
shell > snmpwalk -v 2c -c public 192.168.2.254 interface # 查看接口信息
# IF-MIB::ifDescr 接口名稱
# IF-MIB::ifType 類型
# IF-MIB::ifSpeed 速率
# IF-MIB::ifMtu MTU
# IF-MIB::ifPhysAddress MAC
# IF-MIB::ifAdminStatus 狀態
# IF-MIB::ifInOctets 傳輸字節數spa
# 等pwa
3、確認須要監控網絡接口代理
ciscoasa > show running-config interface ! interface GigabitEthernet0/0 duplex full nameif outside-1 security-level 0 ip address xx.xx.xx.xx 255.255.255.224
# Cisco ASA 查看發現,GigabitEthernet0/0 爲 outside-1 即外網接口,且配置着公網IPcode
shell > snmpwalk -v 2c -c public 192.168.2.254 ifDescr IF-MIB::ifDescr.2 = STRING: Adaptive Security Appliance 'asa_mgmt_plane' interface IF-MIB::ifDescr.3 = STRING: Adaptive Security Appliance 'outside-1' interface IF-MIB::ifDescr.4 = STRING: Adaptive Security Appliance 'GigabitEthernet0/1' interface IF-MIB::ifDescr.5 = STRING: Adaptive Security Appliance 'inside' interface IF-MIB::ifDescr.6 = STRING: Adaptive Security Appliance 'GigabitEthernet0/3' interface IF-MIB::ifDescr.7 = STRING: Adaptive Security Appliance 'GigabitEthernet0/4' interface IF-MIB::ifDescr.8 = STRING: Adaptive Security Appliance 'GigabitEthernet0/5' interface IF-MIB::ifDescr.9 = STRING: Adaptive Security Appliance 'GigabitEthernet0/6' interface IF-MIB::ifDescr.10 = STRING: Adaptive Security Appliance 'GigabitEthernet0/7' interface IF-MIB::ifDescr.11 = STRING: Adaptive Security Appliance 'Internal-Data0/1' interface IF-MIB::ifDescr.12 = STRING: Adaptive Security Appliance 'cplane' interface IF-MIB::ifDescr.13 = STRING: Adaptive Security Appliance 'mgmt_plane_int_tap' interface IF-MIB::ifDescr.14 = STRING: Adaptive Security Appliance 'Management0/0' interface IF-MIB::ifDescr.15 = STRING: Adaptive Security Appliance 'Virtual254' interface
# 服務器上查找,返現 outside-1 對應的設備 ID 爲 IF-MIB::ifDescr.3blog
shell > snmpwalk -v 2c -c public 192.168.2.254 IF-MIB::ifInOctets.3 # 外網口進方向 IF-MIB::ifInOctets.3 = Counter32: 2965376258 shell > snmpwalk -v 2c -c public 192.168.2.254 IF-MIB::ifOutOctets.3 # 外網口出方向 IF-MIB::ifOutOctets.3 = Counter32: 3522107956
4、建立主機、模板
一、主機
建立主機 -> SNMP 192.168.2.254 161 -> 建立
二、模板
建立模板 -> 模板名稱 Cisco -> 羣組 Templates -> 建立 建立應用 -> network interface 建立監控項 -> 名稱 GigabitEthernet0/0 - In -> 類型 SNMPv2 端點代理模式 -> 鍵值 ifHCInOctets.3 -> SNMP OID IF-MIB::ifHCInOctets.3 -> SNMP community public -> 單位 bps -> 使用自定倍數 8 -> 存儲值 差量(每秒速率) -> 應用集 network interface -> 建立
# 拿到的是 byte 要轉換成 bit 即 bps,1 byte = 8 bit,因此要設置倍數爲 8
# 照這樣設置 GigabitEthernet0/0 - Out 便可,注意鍵值爲 ifHCOutOctets.3,OID 爲 OID IF-MIB::ifHCOutOctets.3
三、圖形
建立圖形 -> 名稱 GigabitEthernet0/0 -> 加入監控項 -> 繪圖風格 梯度線 -> 設置顏色 -> 建立
5、爲主機添加模板
主機 -> 模板 -> 選擇模板 -> Cisco -> 添加 -> 更新
# 收工 !