Re: Cisco IPSec Tunnel Bandwidth Utilization

"Longar, Dennis" <[email protected]> Wed, 30 Aug 2006 11:10:09 -0500
Newsgroups gmane.comp.security.vpn
Message-ID <[email protected]>
This message is in MIME format. Since your mail reader does not understand
this format, some or all of this message may not be legible.

--===============0343200348==
Content-Type: multipart/alternative;
	boundary="----_=_NextPart_001_01C6CC4E.C3C76D60"

This message is in MIME format. Since your mail reader does not understand
this format, some or all of this message may not be legible.

------_=_NextPart_001_01C6CC4E.C3C76D60
Content-Type: text/plain;
	charset="iso-8859-1"

MRTG should be able to handle the case you are talking about below.
 
It has several options for tracking an interface or connection.
 
When you run cfgmaker you can specify a ifref options which can
track by IP or interface name etc.
 
Here are the options that MRTG can track on.  Hopefully one of these
will work for you.
 
Options:
     --ifref=nr        interface references by Interface Number (default)
     --ifref=ip                         ... by Ip Address
     --ifref=eth                        ... by Ethernet Number
     --ifref=descr                      ... by Interface Description
     --ifref=name                       ... by Interface Name
     --ifref=type                       ... by Interface Type
 
 
Thanks!
 
-Dennis

-----Original Message-----
From: Paul Lundgren [mailto:[email protected]]
Sent: Tuesday, August 29, 2006 4:24 PM
To: [email protected]
Subject: [VPN] Cisco IPSec Tunnel Bandwidth Utilization


I have a Cisco ASA 5520 supporting multiple VPNs - both remote-access and
Lan-to-Lan.  I would like to monitor the bandwidth utilization on a single
IPSec Lan-to-Lan tunnel.  The particular tunnel I want to monitor is quite
unstable and each time the VPN goes down and re-establishes itself the
interface index changes thus changing the SNMP OID used to measure the tx
and rx bytes for that respective tunnel.  Is anyone familiar with a network
management app that can handle this case and continue to monitor a tunnel
over the long-term?  I'm currently using MRTG and can write a script to try
to accomplish this myself but I'd prefer a cleaner solution since my coding
skills lean towards the novice side. 

Thanks,
-Paul



------_=_NextPart_001_01C6CC4E.C3C76D60
Content-Type: text/html;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; =
charset=3Diso-8859-1">


<META content=3D"MSHTML 6.00.2900.2912" name=3DGENERATOR></HEAD>
<BODY>
<DIV><FONT face=3DArial color=3D#0000ff size=3D2><SPAN =
class=3D561150416-30082006>MRTG=20
should be able to handle the case you are&nbsp;talking about=20
below.</SPAN></FONT></DIV>
<DIV><FONT face=3DArial color=3D#0000ff size=3D2><SPAN=20
class=3D561150416-30082006></SPAN></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial color=3D#0000ff size=3D2><SPAN =
class=3D561150416-30082006>It has=20
several options for tracking an interface or =
connection.</SPAN></FONT></DIV>
<DIV><FONT face=3DArial color=3D#0000ff size=3D2><SPAN=20
class=3D561150416-30082006></SPAN></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial color=3D#0000ff size=3D2><SPAN =
class=3D561150416-30082006>When=20
you run cfgmaker you can specify a ifref options which =
can</SPAN></FONT></DIV>
<DIV><FONT face=3DArial color=3D#0000ff size=3D2><SPAN =
class=3D561150416-30082006>track=20
by IP or interface name etc.</SPAN></FONT></DIV>
<DIV><FONT face=3DArial color=3D#0000ff size=3D2><SPAN=20
class=3D561150416-30082006></SPAN></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial color=3D#0000ff size=3D2><SPAN =
class=3D561150416-30082006>Here=20
are the options that MRTG can track on.&nbsp; Hopefully one of=20
these</SPAN></FONT></DIV>
<DIV><FONT face=3DArial color=3D#0000ff size=3D2><SPAN =
class=3D561150416-30082006>will=20
work for you.</SPAN></FONT></DIV>
<DIV><FONT face=3DArial color=3D#0000ff size=3D2><SPAN=20
class=3D561150416-30082006></SPAN></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial color=3D#0000ff size=3D2><SPAN=20
class=3D561150416-30082006>Options:<BR>&nbsp;&nbsp;&nbsp;&nbsp;=20
--ifref=3Dnr&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; interface =
references by=20
Interface Number (default)<BR>&nbsp;&nbsp;&nbsp;&nbsp;=20
--ifref=3Dip&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;=20
... by Ip Address<BR>&nbsp;&nbsp;&nbsp;&nbsp;=20
--ifref=3Deth&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;=20
... by Ethernet Number<BR>&nbsp;&nbsp;&nbsp;&nbsp;=20
--ifref=3Ddescr&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=20
... by Interface Description<BR>&nbsp;&nbsp;&nbsp;&nbsp;=20
--ifref=3Dname&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;=20
... by Interface Name<BR>&nbsp;&nbsp;&nbsp;&nbsp;=20
--ifref=3Dtype&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;=20
... by Interface Type</SPAN></FONT></DIV>
<DIV><FONT face=3DArial color=3D#0000ff size=3D2><SPAN=20
class=3D561150416-30082006></SPAN></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial color=3D#0000ff size=3D2><SPAN=20
class=3D561150416-30082006></SPAN></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial color=3D#0000ff size=3D2><SPAN=20
class=3D561150416-30082006>Thanks!</SPAN></FONT></DIV>
<DIV><FONT face=3DArial color=3D#0000ff size=3D2><SPAN=20
class=3D561150416-30082006></SPAN></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial color=3D#0000ff size=3D2><SPAN=20
class=3D561150416-30082006>-Dennis</SPAN></FONT></DIV>
<BLOCKQUOTE=20
style=3D"PADDING-LEFT: 5px; MARGIN-LEFT: 5px; BORDER-LEFT: #0000ff 2px =
solid">
  <DIV class=3DOutlookMessageHeader dir=3Dltr align=3Dleft><FONT =
face=3DTahoma=20
  size=3D2>-----Original Message-----<BR><B>From:</B> Paul Lundgren=20
  [mailto:[email protected]]<BR><B>Sent:</B> Tuesday, August 29, =
2006 4:24=20
  PM<BR><B>To:</B> [email protected]<BR><B>Subject:</B> [VPN] Cisco =
IPSec=20
  Tunnel Bandwidth Utilization<BR><BR></FONT></DIV>I have a Cisco ASA =
5520=20
  supporting multiple VPNs - both remote-access and Lan-to-Lan.&nbsp; I =
would=20
  like to monitor the bandwidth utilization on a single IPSec =
Lan-to-Lan=20
  tunnel.&nbsp; The particular tunnel I want to monitor is quite =
unstable and=20
  each time the VPN goes down and re-establishes itself the interface =
index=20
  changes thus changing the SNMP OID used to measure the tx and rx =
bytes for=20
  that respective tunnel.&nbsp; Is anyone familiar with a network =
management app=20
  that can handle this case and continue to monitor a tunnel over the=20
  long-term?&nbsp; I'm currently using MRTG and can write a script to =
try to=20
  accomplish this myself but I'd prefer a cleaner solution since my =
coding=20
  skills lean towards the novice side.=20
<BR><BR>Thanks,<BR>-Paul<BR></BLOCKQUOTE></BODY></HTML>

------_=_NextPart_001_01C6CC4E.C3C76D60--

--===============0343200348==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
VPN mailing list
[email protected]
http://lists.shmoo.com/mailman/listinfo/vpn
--===============0343200348==--