
9-45
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 9 Accessing and Monitoring PIX Firewall
Using SNMP
Step 5 Start sending syslog traps to the management station with the logging on command.
Step 6 To disable sending syslog traps, use the no logging on command or the no snmp-server enable traps
command.
The commands in Example 9-11 specify that PIX Firewall can receive the SNMP requests from host
192.168.3.2 on the inside interface but does not send SNMP syslog traps to any host.
Example 9-11 Enabling SNMP
snmp-server host 192.168.3.2
snmp-server location building 42
snmp-server contact kim lee
snmp-server community ohwhatakeyisthee
The location and contact commands identify where the host is and who administers it. The community
command specifies the password in use at the PIX
Firewall SNMP agent and the SNMP management
station for verifying network access between the two systems.
Compiling Cisco Syslog MIB Files
To receive security and failover SNMP traps from the PIX Firewall, compile the Cisco SMI MIB and the
Cisco syslog MIB into your SNMP management application. If you do not compile the Cisco syslog MIB
into your application, you only receive traps for link up or down, firewall cold start and authentication
failure.
You can select Cisco MIB files for PIX Firewall and other Cisco products from the following website:
http://www.cisco.com/public/sw-center/netmgmt/cmtk/mibs.shtml
From this page, select PIX Firewall from the Cisco Secure & VPN selection list.
Follow these steps to compile Cisco syslog MIB files into your browser using CiscoWorks for Windows
(SNMPc):
Step 1 Get the Cisco syslog MIB files.
Step 2 Start SNMPc.
Step 3 Click Config>Compile MIB.
Step 4 Scroll to the bottom of the list, and click the last entry.
Step 5 Click Add.
Step 6 Find the Cisco syslog MIB files.
Note With certain applications, only files with a .mib extension may show in the file selection window
of the SNMPc. The Cisco syslog MIB files with the .my extension will not be shown. In this
case, you should manually change the .my extension to a .mib extension.
Step 7 Click CISCO-FIREWALL-MIB.my (CISCO-FIREWALL-MIB.mib) and click OK.
Step 8 Scroll to the bottom of the list, and click the last entry.
Step 9 Click Add.
Komentáře k této Příručce