cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2033
Views
0
Helpful
12
Replies

LMS Questions

brianwagerer
Level 1
Level 1

Hello,

I have installed LMS 2.5 and upgraded to LMS 2.6 how do i configure my PIX 515e to show up in LMS?

I can not figure out how to set the snmp ro and rw strings.

1 Accepted Solution

Accepted Solutions

You need to add an snmp-server host command for your CiscoWorks server. For example, if your CiscoWorks server's address is 10.1.1.1, and it is on the inside interface of the PIX:

snmp-server host inside 10.1.1.1

View solution in original post

12 Replies 12

Joe Clarke
Cisco Employee
Cisco Employee

You will first need to make sure you have all of the latest RME 4.0.5 device packages installed from Cisco.com. You can do this under Common Services > Software Center > Device Update. The PIX 515E support was added recently.

To add a device and credentials into LMS 2.5+, go to Common Services > Device and Credentials > Device Management, and click Add. First fill in all of the device identity information (i.e. hostname, IP, etc.), then click Next to fill in the credentials (including the community strings).

Note: you only need a read-only community string for PIXes.

acomiskey
Level 10
Level 10

there is no rw in pix.

Ok I have the ro string set in the PIX

However when I run the inventory collection it fails on the PIX with Transport session to device failed. Cause: Authentication failed on device.

Inventory Collection or Config Collection? This error looks more like a configuration archive sync message. What version of the Pix RME device package do you have? Does SNMP Walk of the PIX work in the LMS Device Center using the same RO community string you specified in DCR?

Failed to snmpwalk the device. Please check your community string and starting OID, and try again.

How do i konw what the starting OID is?

The problem is most likely not the starting OID (though you can try .1.3.6.1.2.1.1), but rather with the SNMP configuration on the PIX. What is your configuration? Is the LMS server allowed to query the PIX via SNMP?

In the PIX i have these settings

snmp-server location MTR

snmp-server contact ******

snmp-server community ******

snmp-server enable traps snmp

You need to add an snmp-server host command for your CiscoWorks server. For example, if your CiscoWorks server's address is 10.1.1.1, and it is on the inside interface of the PIX:

snmp-server host inside 10.1.1.1

Ok that worked, so i have to do the same for a VPN 3000 Concentrator?

You first need to enable SNMP on the concentrator, then add your strings, and save your configuration. See http://www.cisco.com/en/US/products/hw/vpndevc/ps2284/products_configuration_guide_chapter09186a00803ee11f.html#wp999648 for documentation.

I have already configured these settings.

Then double-check the community string is valid DCR for the Concentrator, and make sure there are no firewalls between the LMS server and the Concentrator that could be blocking SNMP.

You should also check your Concentrator filters and rules to see if you're blocking SNMP. That is done under Configuration > Policy Management > Traffic Management.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: