Topology Graph Question...

Unanswered Question
Jun 23rd, 2008

I have many site-to-site tunnels and the Graph doesn't seem to display the connectivity between sites(Peers). It displays them as separate networks with their own Internet Cloud(ISP Gateway). Is it possible or is it a limitation since it is trying to traverse the Internet and an ISPs network. I was hoping that Mars, since that it is a part of Interesting traffic, show at least a line through the clouds to the routers respective peers.



I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)

Hi Patrick,

I'm in the same boat. I have 100+ IPSec spokes, and the topology graph is a total mess. Giving the MARS knowledge of IPSec links has been on my wishlist since day one.

There are also other issues:

Say your spoke device is a PIX or whatever that gets its "outside" IP address via DHCP from some NATting DSL router over which you have no control. Let's say it gets given

Now let's say that there's a second PIX behind another router from the same vendor, and this PIX gets given

The MARS will think that both of these PIXes are on the same "outside" subnet, which of course they are not. RFC1918 allows us non-unique address space, which the MARS just can't handle.


pjkline Mon, 06/23/2008 - 08:53

Sorry and I'm glad I am not the only one. I did find a workaround, but it doesn't clean things up any. I created a loopback between the peers and added the subnet to the ACL. It now give me the line connecting them, but also shows the cloud. I have a call into my rep. to talk to some of their MARS experts.

Thanks again,


pmccubbin Wed, 06/25/2008 - 09:19

Hi Patrick,

Thanks for posting the work around, even though it didn't clean things up the way you wanted. I give it a "5" for helping make this forum useful for others in the same situation.

Speaking of being in the same situation, I wish I had a nickel for everytime someone had told me how unsatisfactory they found the Topology Map in MARS! As someone who does implementations for a living I have found it best to concentrate on the more useful elements of MARS like its ability to correlate syslogs and NetFlow, and the reporting functions. These more than make up for the Maps.

I'm sure Cisco has been given an earful on more than one occassion about how they should fix this and that eventually they will.



pjkline Thu, 03/26/2009 - 11:48

I have upgraded to v6.0 and the problem with the VPNs and the Topo Graph still exist. Has Cisco corrected this or should I still be using the loopback work-around?




This Discussion