Description

Template for Cisco Firewalls like ASA and PIX. Monitors both connections and URL processing parameters like connection set up rate, url drop rate, url processing rate, UDP connections rate, TCP connections rate and URL requests denied rate.

Prerequisites

SNMP should be enabled in end device and device should support CISCO-UNIFIED-FIREWALL-MIB OIDs and SNMP credentials should be attached against the device in portal.

Metric Parameters

Metric Parameters
ParameterDescription
Frequency
  • Frequency is the interval in which you want to probe and collect metric data from the target device/resource
  • Frequency is defined in minutes (min).
  • Warning ThresholdIf the metric value satisfies the condition defined along with Warning Threshold value, then a notification is sent to the user.
    Critical ThresholdIf the metric value satisfies the condition defined along with Critical Threshold value, then a notification is sent to the user.
    AlertThe alert value can be set to either Yes or No. If it is Yes, then an alert message is sent to the user.

    Metrics

    fw.udp.conn.rate

    Metric Details

    Metric Details
    Applicable forDevice
    SNMP OID1.3.6.1.4.1.9.9.491.1.1.4.1.1.10.6
    ExpressionNULL
    DescriptionThe connection setup rate averaged over the last 300 seconds.
    [OID: 1.3.6.1.4.1.9.9.491.1.1.4.1.1.10.6]
    CategorySNMP monitors
    Collector TypeGateway
    Monitor NameCisco Firewall Connection Statistics
    Unitpsec

    Possible Inputs

    Possible Inputs
    MetricInput ValueRange of Values
    Frequency51 – 1440 (mins)
    Filter
    Warning Operator
    Warning Threshold
    Warning Repeat Count
    Critical Operator
    Critical Threshold
    Critical Repeat Count
    AlertNoYes/No
    Graph (Yes/No)YesYes/No

    Note: As Alert is not enabled on the above metric, the fields are left blank.

    Sample Output

    Firewall - UDP Connection Rate

    Firewall - UDP Connection Rate

    fw.tcp.conn.rate

    Metric Details

    Metric Details
    Applicable forDevice
    SNMP OID1.3.6.1.4.1.9.9.491.1.1.4.1.1.10.7
    ExpressionNULL
    DescriptionThe connection setup rate averaged over the last 300 seconds.
    [OID: 1.3.6.1.4.1.9.9.491.1.1.4.1.1.10.7]
    CategorySNMP monitors
    Collector TypeGateway
    Monitor NameCisco Firewall Connection Statistics
    Unitpsec

    Possible Inputs

    Possible Inputs
    MetricInput ValueRange of Values
    Frequency51 – 1440 (mins)
    Filter
    Warning Operator
    Warning Threshold
    Warning Repeat Count
    Critical Operator
    Critical Threshold
    Critical Repeat Count
    AlertNoYes/No
    Graph (Yes/No)YesYes/No

    Note: As Alert is not enabled on the above metric, the fields are left blank.

    Sample Output

    Firewall - TCP Connection Rate

    Firewall - TCP Connection Rate

    fw.conn.setup.rate

    Metric Details

    Metric Details
    Applicable forDevice
    SNMP OID1.3.6.1.4.1.9.9.491.1.1.1.11.0
    ExpressionNULL
    DescriptionThe averaged number of connections which the firewall establishing per second, averaged over the last 300 seconds. [OID: 1.3.6.1.4.1.9.9.491.1.1.1.11.0]
    CategorySNMP monitors
    Collector TypeGateway
    Monitor NameCisco Firewall Connection Statistics
    Unitpsec

    Possible Inputs

    Possible Inputs
    MetricInput ValueRange of Values
    Frequency51 – 1440 (mins)
    Filter
    Warning Operator
    Warning Threshold
    Warning Repeat Count
    Critical Operator
    Critical Threshold
    Critical Repeat Count
    AlertNoYes/No
    Graph (Yes/No)YesYes/No

    Note: As Alert is not enabled on the above metric, the fields are left blank.

    Sample Output

    Firewall - Connection Set Up Rate

    Firewall - Connection Set Up Rate

    fw.url.drop.rate

    Metric Details

    Metric Details
    Applicable forDevice
    SNMP OID1.3.6.1.4.1.9.9.491.1.3.1.15.0
    ExpressionNULL
    DescriptionThe rate at which incoming URL access requests were dropped by the firewall because of resource constraints, averaged over the last 300 seconds. [OID: 1.3.6.1.4.1.9.9.491.1.3.1.15.0]
    CategorySNMP monitors
    Collector TypeGateway
    Monitor NameCisco Firewall Connection Statistics
    Unitpsec

    Possible Inputs

    Possible Inputs
    MetricInput ValueRange of Values
    Frequency51 – 1440 (mins)
    Filter
    Warning Operator
    Warning Threshold
    Warning Repeat Count
    Critical Operator
    Critical Threshold
    Critical Repeat Count
    AlertNoYes/No
    Graph (Yes/No)YesYes/No

    Note: As Alert is not enabled on the above metric, the fields are left blank.

    Sample Output

    Firewall - URL Drop Rate

    Firewall - URL Drop Rate

    fw.url.processing.rate

    Metric Details

    Metric Details
    Applicable forDevice
    SNMP OID1.3.6.1.4.1.9.9.491.1.3.1.4.0
    ExpressionNULL
    DescriptionThe number of URL access requests processed per second by this firewall.
    [OID: 1.3.6.1.4.1.9.9.491.1.3.1.4.0]
    CategorySNMP monitors
    Collector TypeGateway
    Monitor NameCisco Firewall Connection Statistics
    Unitpsec

    Possible Inputs

    Possible Inputs
    MetricInput ValueRange of Values
    Frequency51 – 1440 (mins)
    Filter
    Warning Operator
    Warning Threshold
    Warning Repeat Count
    Critical Operator
    Critical Threshold
    Critical Repeat Count
    AlertNoYes/No
    Graph (Yes/No)YesYes/No

    Note: As Alert is not enabled on the above metric, the fields are left blank.

    Sample Output

    Firewall - URL Processing Rate

    Firewall - URL Processing Rate

    fw.url.requests.denied.rate

    Metric Details

    Metric Details
    Applicable forDevice
    SNMP OID1.3.6.1.4.1.9.9.491.1.3.1.8
    ExpressionNULL
    DescriptionThe rate at which URL access requests were denied by this firewall, due to a directive from a URL filtering server, a static policy configured on the firewall, due to resource constraints or any other reason, averaged over the last 300 seconds. [OID: 1.3.6.1.4.1.9.9.491.1.3.1.8]
    CategorySNMP monitors
    Collector TypeGateway
    Monitor NameCisco Firewall Connection Statistics
    Unitpsec

    Possible Inputs

    Possible Inputs
    MetricInput ValueRange of Values
    Frequency51 – 1440 (mins)
    Filter
    Warning Operator
    Warning Threshold
    Warning Repeat Count
    Critical Operator
    Critical Threshold
    Critical Repeat Count
    AlertNoYes/No
    Graph (Yes/No)YesYes/No

    Note: As Alert is not enabled on the above metric, the fields are left blank.

    Sample Output

    Firewall - Requests Denied Rate

    Firewall - Requests Denied Rate

    fw.conn.active

    Metric Details

    Metric Details
    Applicable forDevice
    SNMP OID1.3.6.1.4.1.9.9.491.1.1.1.6.0
    ExpressionNULL
    DescriptionMonitors the number of connections which are currently active. [OID: 1.3.6.1.4.1.9.9.491.1.1.1.6.0]
    CategorySNMP monitors
    Collector TypeGateway
    Monitor NameCisco Firewall Active Connections
    Unitpsec

    Possible Inputs

    Possible Inputs
    MetricInput ValueRange of Values
    Frequency51 – 1440 (mins)
    Filter
    Warning Operator
    Warning Threshold
    Warning Repeat Count
    Critical Operator
    Critical Threshold
    Critical Repeat Count
    AlertNoYes/No
    Graph (Yes/No)YesYes/No

    Note: As Alert is not enabled on the above metric, the fields are left blank.

    Sample Output

    Current Active Connections

    Current Active Connections

    fw.conn.attempted

    Metric Details

    Metric Details
    Applicable forDevice
    SNMP OID1.3.6.1.4.1.9.9.491.1.1.1.1.0
    ExpressionNULL
    DescriptionMonitors the the number of connections which are attempted to be set up through the firewall. [OID: 1.3.6.1.4.1.9.9.491.1.1.1.1.0]
    CategorySNMP monitors
    Collector TypeGateway
    Monitor NameCisco Firewall Additional Connection Stats
    Unitpsec

    Possible Inputs

    Possible Inputs
    MetricInput ValueRange of Values
    Frequency51 – 1440 (mins)
    Filter
    Warning Operator
    Warning Threshold
    Warning Repeat Count
    Critical Operator
    Critical Threshold
    Critical Repeat Count
    AlertNoYes/No
    Graph (Yes/No)YesYes/No

    Note: As Alert is not enabled on the above metric, the fields are left blank.

    Sample Output

    No graph

    fw.conn.setups.aborted

    Metric Details

    Metric Details
    Applicable forDevice
    SNMP OID1.3.6.1.4.1.9.9.491.1.1.1.2.0
    ExpressionNULL
    DescriptionMonitors the number of connection setup attempts that were aborted before the connection could proceed to completion. The counter includes setup attempts aborted by the firewall as well as those aborted by the initiator and/or the responder(s) of/to the connection setup attempt.
    [OID: 1.3.6.1.4.1.9.9.491.1.1.1.2.0]
    CategorySNMP monitors
    Collector TypeGateway
    Monitor NameCisco Firewall Additional Connection Stats
    Unitpsec

    Possible Inputs

    Possible Inputs
    MetricInput ValueRange of Values
    Frequency51 – 1440 (mins)
    Filter
    Warning Operator
    Warning Threshold
    Warning Repeat Count
    Critical Operator
    Critical Threshold
    Critical Repeat Count
    AlertNoYes/No
    Graph (Yes/No)YesYes/No

    Note: As Alert is not enabled on the above metric, the fields are left blank.

    Sample Output

    No graph

    fw.conn.policy.declined

    Metric Details

    Metric Details
    Applicable forDevice
    SNMP OID1.3.6.1.4.1.9.9.491.1.1.1.3.0
    ExpressionNULL
    DescriptionMonitors the The number of connections which were attempted to be setup but which were declined due to reasons of security policy. This includes the connections that failed authentication.
    [OID: 1.3.6.1.4.1.9.9.491.1.1.1.3.0]
    CategorySNMP monitors
    Collector TypeGateway
    Monitor NameCisco Firewall Additional Connection Stats
    Unitpsec

    Possible Inputs

    Possible Inputs
    MetricInput ValueRange of Values
    Frequency51 – 1440 (mins)
    Filter
    Warning Operator
    Warning Threshold
    Warning Repeat Count
    Critical Operator
    Critical Threshold
    Critical Repeat Count
    AlertNoYes/No
    Graph (Yes/No)YesYes/No

    Note: As Alert is not enabled on the above metric, the fields are left blank.

    Sample Output

    No graph

    fw.conn.res.declined

    Metric Details

    Metric Details
    Applicable forDevice
    SNMP OID1.3.6.1.4.1.9.9.491.1.1.1.4.0
    ExpressionNULL
    DescriptionMonitors the number of connections which were attempted to be setup but which were declined due to non-availability of required resources. [OID: 1.3.6.1.4.1.9.9.491.1.1.1.4.0]
    CategorySNMP monitors
    Collector TypeGateway
    Monitor NameCisco Firewall Additional Connection Stats
    Unitpsec

    Possible Inputs

    Possible Inputs
    MetricInput ValueRange of Values
    Frequency51 – 1440 (mins)
    Filter
    Warning Operator
    Warning Threshold
    Warning Repeat Count
    Critical Operator
    Critical Threshold
    Critical Repeat Count
    AlertNoYes/No
    Graph (Yes/No)YesYes/No

    Note: As Alert is not enabled on the above metric, the fields are left blank.

    Sample Output

    Resources Unavailability Declined Connections

    Resources Unavailability Declined Connections

    fw.conn.halfopen

    Metric Details

    Metric Details
    Applicable forDevice
    SNMP OID1.3.6.1.4.1.9.9.491.1.1.1.5.0
    ExpressionNULL
    DescriptionMonitors the number of connections which are in the process of being setup but which have not yet reached the established state in the connection table. [OID: 1.3.6.1.4.1.9.9.491.1.1.1.5.0]
    CategorySNMP monitors
    Collector TypeGateway
    Monitor NameCisco Firewall Additional Connection Stats
    Unit

    Possible Inputs

    Possible Inputs
    MetricInput ValueRange of Values
    Frequency51 – 1440 (mins)
    Filter
    Warning Operator
    Warning Threshold
    Warning Repeat Count
    Critical Operator
    Critical Threshold
    Critical Repeat Count
    AlertNoYes/No
    Graph (Yes/No)YesYes/No

    Note: As Alert is not enabled on the above metric, the fields are left blank.

    Sample Output

    No graph

    fw.conn.expired

    Metric Details

    Metric Details
    Applicable forDevice
    SNMP OID1.3.6.1.4.1.9.9.491.1.1.1.7.0
    ExpressionNULL
    DescriptionMonitors the number of connections which were active but which were since normally terminated. [OID: 1.3.6.1.4.1.9.9.491.1.1.1.7.0]
    CategorySNMP monitors
    Collector TypeGateway
    Monitor NameCisco Firewall Additional Connection Stats
    Unitpsec

    Possible Inputs

    Possible Inputs
    MetricInput ValueRange of Values
    Frequency51 – 1440 (mins)
    Filter
    Warning Operator
    Warning Threshold
    Warning Repeat Count
    Critical Operator
    Critical Threshold
    Critical Repeat Count
    AlertNoYes/No
    Graph (Yes/No)YesYes/No

    Note: As Alert is not enabled on the above metric, the fields are left blank.

    Sample Output

    No graph

    fw.conn.aborted

    Metric Details

    Metric Details
    Applicable forDevice
    SNMP OID1.3.6.1.4.1.9.9.491.1.1.1.8.0
    ExpressionNULL
    DescriptionMonitors the number of connections which were active but which were aborted by the firewall due to reasons of policy or resource rationing. [OID: 1.3.6.1.4.1.9.9.491.1.1.1.8.0]
    CategorySNMP monitors
    Collector TypeGateway
    Monitor NameCisco Firewall Additional Connection Stats
    Unitpsec

    Possible Inputs

    Possible Inputs
    MetricInput ValueRange of Values
    Frequency51 – 1440 (mins)
    Filter
    Warning Operator
    Warning Threshold
    Warning Repeat Count
    Critical Operator
    Critical Threshold
    Critical Repeat Count
    AlertNoYes/No
    Graph (Yes/No)YesYes/No

    Note: As Alert is not enabled on the above metric, the fields are left blank.

    Sample Output

    No graph

    fw.conn.embryonic

    Metric Details

    Metric Details
    Applicable forDevice
    SNMP OID1.3.6.1.4.1.9.9.491.1.1.1.9.0
    ExpressionNULL
    DescriptionMonitors the number of embryonic application layer connections (that is, connections in which the signaling channel has been established while the data channel is awaiting setup).
    [OID: 1.3.6.1.4.1.9.9.491.1.1.1.9.0]
    CategorySNMP monitors
    Collector TypeGateway
    Monitor NameCisco Firewall Additional Connection Stats
    Unit

    Possible Inputs

    Possible Inputs
    MetricInput ValueRange of Values
    Frequency51 – 1440 (mins)
    Filter
    Warning Operator
    Warning Threshold
    Warning Repeat Count
    Critical Operator
    Critical Threshold
    Critical Repeat Count
    AlertNoYes/No
    Graph (Yes/No)YesYes/No

    Note: As Alert is not enabled on the above metric, the fields are left blank.

    Sample Output

    No graph

    fw.conn.mem.usage

    Metric Details

    Metric Details
    Applicable forDevice
    SNMP OID1.3.6.1.4.1.9.9.491.1.1.2.1.0
    ExpressionNULL
    DescriptionMonitors the amount of memory occupied by all structures required to maintain the state of all connections which are either being established or are active. [OID: 1.3.6.1.4.1.9.9.491.1.1.2.1.0]
    CategorySNMP monitors
    Collector TypeGateway
    Monitor NameCisco Firewall Additional Connection Stats
    UnitKB

    Possible Inputs

    Possible Inputs
    MetricInput ValueRange of Values
    Frequency51 – 1440 (mins)
    Filter
    Warning Operator
    Warning Threshold
    Warning Repeat Count
    Critical Operator
    Critical Threshold
    Critical Repeat Count
    AlertNoYes/No
    Graph (Yes/No)YesYes/No

    Note: As Alert is not enabled on the above metric, the fields are left blank.

    Sample Output

    No graph