Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

Cisco ASA: SNMP traps for configuration changes

Posted on 2013-06-03
3
Medium Priority
?
1,470 Views
Last Modified: 2013-06-05
Hello All,

Has anyone been able to get snmp-traps sent from an ASA that fire off on a configuration change?  I have what I thought would work but I don't see the traps coming into the snmp server.

snmp-server host snmpvlan 4.3.2.1 community *****
snmp-server enable traps entity config-change

Open in new window


Am I correct in thinking this is the correct syntax to reply on running-config changes?
Note:  I have the snmp-server device receiving  traps correctly on other devices (routers etc).

Thanks for your time!
0
Comment
Question by:NE_Tech_Dude
3 Comments
 
LVL 65

Assisted Solution

by:btan
btan earned 750 total points
ID: 39218924
may want to take a look at the full steps and run thru but it seems to state that ASA  "entConfigChange" trap is only generated when a security context is added/removed (multi-mode) or an SSM is inserted/removed (though OID is not officially supported).

http://www.cisco.com/en/US/docs/security/asa/asa72/system/message/logconf.html#wp1104110

hence, I saw another in solarwind forum using Cisco EEM applet (in addition to normal SNMP trap configuration). They are saying "snmp-server enable traps config" but seems to be of older version

http://thwack.solarwinds.com/thread/29526

Others....

SNMP MIBs and Traps on the ASA - Additional Information
https://supportforums.cisco.com/docs/DOC-1295#ENTITYMIB

Adaptive Security Appliance MIB Support List
ftp://ftp.cisco.com/pub/mibs/supportlists/asa/asa-supportlist.html
0
 
LVL 22

Accepted Solution

by:
eeRoot earned 750 total points
ID: 39220846
Rather then SNMP, you can use a syslog server to receive wr mem alerts.
0
 
LVL 2

Author Comment

by:NE_Tech_Dude
ID: 39223464
I think I'm going to handle this via AAA Accounting.  No trap for this is disappointing.
0

Featured Post

VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Unable to change the program that handles the scan event from a network attached Canon/Brother printer/scanner. This means you'll always have to choose which program handles this action, e.g. ControlCenter4 (in the case of a Brother).
How to fix a SonicWall Gateway Anti-Virus firewall blocking automatic updates to apps like Windows, Adobe, Symantec, etc.
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…

572 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question