nv-l

RE: [nv-l] Monitoring a VPN Concentrator

2003-03-04 13:51:20
Subject: RE: [nv-l] Monitoring a VPN Concentrator
From: "Clinkscales, Charles" <cclinkscales AT firstam DOT com>
To: "'Davis, Donald'" <donald.davis AT firstcitizens DOT com>, "'Dietmar Gaulhofer'" <DIETMAR_GAULHOFER AT at.ibm DOT com>, nv-l AT lists.tivoli DOT com
Date: Tue, 04 Mar 2003 12:40:41 -0600
Thanks for the info Don.  I will give it a try.
-----Original Message-----
From: Davis, Donald [mailto:donald.davis AT firstcitizens DOT com]
Sent: Tuesday, March 04, 2003 10:30 AM
To: 'Dietmar Gaulhofer'; nv-l AT lists.tivoli DOT com
Subject: RE: [nv-l] Monitoring a VPN Concentrator

Dietmar,
I have several Cicso/3000 VPN Concentrators.
I have tried various options, including SNMP polling, Discovery off, config polling 5yrs, DEFAULT IP as indicated below. Nothing prevented the dynamic interfaces from being discovered managed, except the following.

Edit the /usr/OV/conf/oid to type file and add the appropriate OID with an "I".

#  I    Treat the device as if it did not support SNMP. This would be used
#       to disable SNMP operations to devices whose agents misbehaved in
#       such a way as to cause problems.
1.3.6.1.4.1.3076.1.2.1.1.1.2:cisco Systems:Cisco Switch:I  #3000 VPN Concentrator

The "I" prevents the dynamic interfaces from being discovered.
This is the only way I could get it to work for me.
This gives me the correct symbol and only a single "real" interface.
I really don't care about the dynamic interfaces and don't want them turning my map red.

The only other option that I can think of would be to write a "auto-acknowledge" or "auto-unmanage" script that monitors these nodes and acknowledges or unmanages the interfaces when they fail.  This seems like a lot of unnecessary work.

=======================
Don Davis
 


-----Original Message-----
From: Dietmar Gaulhofer [mailto:DIETMAR GAULHOFER AT at.ibm DOT com]
Sent: Tuesday, March 04, 2003 8:33 AM
To: nv-l AT lists.tivoli DOT com
Subject: Re: [nv-l] Monitoring a VPN Concentrator


try to add:

DEFAULT IP: : :U

on top of the /usr/OV/conf/oid to type

if i change oid/registration  files i do always a     /usr/OV/bin/ovw
-config
                                          /usr/OV/bin/ovw -fields
                                    /usr/OV/bin/ovw -verify

Also you might want to use the location.conf - if you have a lot of
networks created in the vpn area to have them in one location - and not
populated on the root map.

Regards,

Dietmar


*************************************************************
Dietmar Gaulhofer, IBM Österreich
Systems Engineer
ITS - Integrated Technology Services - Unit Austria
Email: Dietmar Gaulhofer AT at.ibm DOT com
Tel: +43/1/21145-2756
**************************************************************


"Clinkscales, Charles" <cclinkscales AT firstam DOT com> on 04.03.2003 13:45:10

To:    "'nv-l AT lists.tivoli DOT com'" <nv-l AT lists.tivoli DOT com>
cc:
Subject:    [nv-l] Monitoring a VPN Concentrator




Hello All,

I am running Netview version  7.1.2 on AIX 4.3.3.

I have a Cisco Series 3000 VPN  Concentrator.  When VPN connections are
made, Netview discovers the  interface and adds it to the map, under the
VPN Node. When the VPN connection is  terminated, the virtual interface is
no longer present and Netview changes the  status to red.  We need a way to
ignore the virtual interfaces or at a  minimum, discover them as unmanaged.
Because these nodes are interfaces and not  nodes, we are unable to exclude
the IP ranges in the seed file and using the  "discover unmanaged" option
in SNMP Configuration does not work  either.

How do others manage these  types of devices?

Thank you in advance for any  help,

Charlie  Clinkscales
First American Real Estate  Information Services, Inc.
cclinkscales AT firstam DOT com











---------------------------------------------------------------------
To unsubscribe, e-mail: nv-l-unsubscribe AT lists.tivoli DOT com
For additional commands, e-mail: nv-l-help AT lists.tivoli DOT com

*NOTE*
This is not an Offical Tivoli Support forum. If you need immediate
assistance from Tivoli please call the IBM Tivoli Software Group
help line at 1-800-TIVOLI8(848-6548)

------------------------------------------------------------------------------
This electronic mail and any files transmitted with it are confidential and are intended solely for the use of individual or entity to whom they are addressed. If you are not the intended recipient or the person responsible for delivering the electronic mail to the intended recipient, be advised that you have received this electronic mail in error and that any use, dissemination, forwarding, printing, or copying of this electronic mail is strictly prohibited. If you have received this electronic mail in error, please immediately notify the sender by return mail.

==============================================================================

<Prev in Thread] Current Thread [Next in Thread>