wbrown

Comments

  • When I was still trying to get topology discovery to work I did see that switch uplinks also need to be monitored in order for discovery to detect the connection. I started running a discovery to populate the switch nodes into NPM. Then I manually added the uplink ports (on all connected switches from that discovery).…
  • There is one other gotcha to watch out for: Rights assigned to AD groups are not additive. When a user is a member of multiple AD groups then the rights assigned will be those assigned to the first applicable group listed alphabetically within AD. The closest I've been able to get to what you are proposing is to assign the…
  • "OID not supported" in not an Orion issue: it means the SNMP agent on the monitored device has not implemented that OID. I tested the specified OIDs on my 7k's (versions range from 5.2(5) to 6.1(3)). None of them support those OIDs. You can get info from your device regarding which OID are supported. First execute "show…
  • I don't believe the ASA supports the OIDs that Hardware Health polls. I'm running NPM 10.3.1, monitoring ASA 5520s, 5540s, and 5585-Xs. The ASAs are running 8.2(x) and 8.4(x). None of these devices show Hardware Health as a selectable resource when listing resources.
  • Sounds like what you want is to configure an IP SLA operation on RTR1, using RTR2 as the responder, and to have that SLA operation monitored by Orion. The IP SLA monitoring module is an add-on module to NPM. IP SLA is a feature of IOS but availability is dependent on the IOS version and feature set. In older IOS versions…
  • Verify that ICMP is allowed to the firewall's interface. A node may be manageable via SNMP, but will show down if ICMP is blocked. And if you're curious: per support, there is no means to disable ICMP polling while retaining SNMP polling.
  • My initial guess is that the ifindex values for those interfaces changed. However, I would expect re-listing the resources to show the interfaces you need and enable you to monitor them as you expect. If the ifindex values did indeed change then you're going to lose your history anyway as the data may no longer be…
  • Bob - I didn't like the sort order either. Here's link to how I hacked the sort order of the Alerts page to sort by date/time:
  • A huge problem with Cisco's SNMP implementation on ASAs is that there is a great deal of data that has not been implemented in the SNMP agent despite being defined. Looking at my ASA running 9.2(3)4, the only useful OID I can find regarding this is 1.3.6.1.4.1.9.9.392.1.1.1 (crasMaxSessionsSupportable). There is a…
  • I would recommend the approach mentioned by @chris_t above: create a separate rule for each line. I've had issues with ACL entries appearing to get reordered when they are pasted in. If you "show ip access-list ___" the line numbering will show the correct order, but the display order is not correct. If you paste in your…
  • What you want requires the use of custom properties. 1: Create a custom property for volumes. Call it something such as WarningThreshold. 2: Create an alert that compares the measured usage value to the value in the WarningThreshold custom property field. I would also add a condition to the alert that first checks…
  • I see no reason to monitor a NULL interface, but although I do not do so I can understand monitoring the loopback interface of a router. As stated above, a loopback interface will always be up. Therefore if there's any available route to that host then the host will be up. Monitoring the loopback interface for up/down…
  • I don't know for certain about Riverbed appliances, but there are a number of ASA UnDPs around on thwack. I've posted a couple and I know others have as well. Look through Content Exchange and you should find them.
  • Current and desired functionality for single context devices: 1: Failover status (I'm using cfwHardwareStatusValue and cfwHardwareStatusLabel) 1a: Alert - Is failover enabled? 1b: Is the primary active? 2: Hardware health (specifically power supply status). May have to use "show environment" output to get this info. 3:…
  • There is another option that you can use if you want the alert to trigger when the poll determines your threshold is crossed, rather than waiting to look at a daily report. As has been mentioned in the forums previously, you can add a custom field to your volumes, specify a threshold value in that custom field, and then…
  • I finally got a sort-of answer from support yesterday regarding my boxes no longer being recognized correctly. "Our development found another bug wherein the F5 is responding as Linux when being queried through SNMP even if the OID is 1.3.6.1.4.1.3375. Dev is now preparing for the fix and will be released in Core version…
  • I'm pretty sure my boxes were correctly recognized in NPM 10.x. Definitely being recognized in NPM 11.5. All my LTMs are running 11.x. I haven't had any issue with NPM recognizing the LTMs in any of the 11.x BigIP releases. First thing I would check would be the SNMP config on the LTM. Screenshot of my LTM config is here:…
  • Quick answer: you can't. Unlike other product suites such as OpenView or Unicenter you cannot import MIBs. But you can create UnDPs to monitor what isn't available in NPM out of the box. The hardest part is figuring out which OIDs you want to monitor. If you do some searching through the forums you'll probably find the…
  • We used an approach similar to what and mentioned above. The alerts for my network devices reference a custom property (specifically the Department out of the box field). Anything that doesn't have a Department field matching what I'm looking for doesn't generate an alert. Same is done for out Intel, Storage, Citrix, etc…
  • Look through the content exchange. I forget who, but someone created a widget that does exactly what you're looking for. I use it in my installation to filter out the exact same thing you're trying to get rid of. Based on what I see in my usual download folder, the file you're looking for is events.filtered_9.5.1 I'm using…
  • First thing that comes to mind is the ability to schedule IPAM discoveries. Specifically I'd rather be able to schedule time windows for super/subnets rather than a period of every x minutes. Discovery during non-business hours when workstations are more likely to be powered off or not present is just a wast of processing…
  • Any devs out there that can answer these questions or give insight to the expression evaluation process? Does the entire ruleset get evaluated before the trigger/no-trigger decision is made? Is short-circuit evaluation used? (as soon as first trigger condition is met then is any further evaluation performed?) Are all the…
  • I'd say it depends on what you're trying to alert on. "Free space issue on drive X" or "Server A has drive space issue" I'm curious what the performance difference would be on the polling and DB servers. Does either of those methods create a greater workload? Another possibility would be to add a custom property to the…
  • Custom properties don't do anything by themselves. They are just another column added to a database table. So the only direct impact of adding custom properties is more database space is needed to store this field for every node/volume/interface (whichever the property is added to). As such, the number that can be added is…
  • 1.3.6.1.4.1.9.1.1286 Cisco 4507R+E (NOT the same as a 4507R-E) 1.3.6.1.4.1.9.12.3.1.3.1084 Cisco Nexus 5548 chassis 1.3.6.1.4.1.9.1.1194 Cisco ASA 5585-SSP-10 1.3.6.1.4.1.9.1.1196 Cisco ASA 5585-SSP-40
  • These devices just show up as "Cisco" in NPM 10.1.3 Cisco ASA 5585 SSP 10 1.3.6.1.4.1.9.1.1194 Cisco ASA 5585 SSP 20 1.3.6.1.4.1.9.1.1195 Cisco ASA 5585 SSP 40 1.3.6.1.4.1.9.1.1196 Cisco ASA 5585 SSP 60 1.3.6.1.4.1.9.1.1197
  • We had a similar issue on one of our Cat6500s. Data was coming into the chassis via 10G fiber. The 100Mb connection to a remote site was showing a very high number of output drops. Our suspicion was that the output buffers of the 100Mb line card were being overrun. Changing out the 10/100Mb linecard for a 1000/100/10Mb…
  • I've been getting the same results on a number of my devices. I haven't bothered to troubleshoot or open a case. My discoveries are configured as /24 and the subnets being discovered are configured as /24. I don't recall if we saw this during 10.1 or 10.2.
  • I have similar issues with my Cisco Catalyst switches where multiple layer 3 interfaces are present. Once thing that helped (when it did show connections) was to ensure the connecting interfaces/trunks are monitored on both sides of a link and then rediscover the connected switches in the same discovery. This showed more…
  • I was having the same issue when my SQL and Orion servers were VMs. Support could never resolve it and would typically give me 1 of 3 answers: 1: There's an issue with SQL. That "issue" was never identified. 2: The VM doesn't have enough resources 3: Known issue with the polling engine that is fixed in the latest version…