cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1149
Views
0
Helpful
2
Replies

PIX failover notification via SNMP

yjdabear
VIP Alumni
VIP Alumni

Does anyone know if the following is implying that the only way to receive PIX failover notification via SNMP is to send syslogs as SNMP traps?

http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_62/config/failover.htm

"To receive SNMP syslog traps (SNMP failover traps), configure the SNMP agent to send SNMP traps to SNMP management stations, define a syslog host, and compile the Cisco syslog MIB into your SNMP management station. See the snmp-server and logging command in the Cisco PIX Firewall Command Reference for more information."

Had a stateful failover between two PIXes recently, a syslog was received, but no SNMP trap. "snmp-server enable traps" is configured.

2 Replies 2

thomas.chen
Level 6
Level 6

You need to have the "logging history debug" command to generate all standard and syslog traps

Refer to 'Configuring PIX 5.1 and Later for a Subset of Traps' section of

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094a13.shtml#snmptothepixtraps

We have this config:

logging history errors

snmp-server enable traps

The way I read that doc, even "logging history alert" should have gotten us a failover trap, should it not?