I am currently using the latest community edition and looking to go to the professional subscription. With a Cisco ASA 9.4(3)6 and graphing the Remote Access Sessions, I am seeing odd data and it looks like others have had the same issue for a couple years now. I attached a screenshot of what I am seeing.
From Cisco CLI - show vpn-sessiondb anyconnect summary:
VPN Session Summary --------------------------------------------------------------------------- Active : Cumulative : Peak Concur : Inactive ---------------------------------------------- AnyConnect Client : 96 : 8582 : 101 : 3 SSL/TLS/DTLS : 96 : 8582 : 101 : 3
From Observium interface snapshot is attached.
Is there any fix for this? Also, can we graph per anyconnect group?
Thanks, Rich Reitenauer Sr. Infrastructure Analyst 1 Meridian Blvd, Suite 2C01 Wyomissing, PA 19610 O: 610-373-7999 x1255 rreitenauer@ugies.commailto:rreitenauer@ugies.com
Dear
Just FYI
This started occurring after 9.4.3 release, and still present as of 9.7.1
All releases pre-9.4.3 do not seem to have this issue, and correctly report 0 clientless vpn (when only using anyconnect sslvpn)
Kind regards
From: observium [mailto:observium-bounces@observium.org] On Behalf Of Richard Reitenauer Sent: dinsdag 14 maart 2017 19:43 To: observium@observium.org Subject: [Observium] Cisco ASA 9.4(3)6 Remote Access Sessions
I am currently using the latest community edition and looking to go to the professional subscription. With a Cisco ASA 9.4(3)6 and graphing the Remote Access Sessions, I am seeing odd data and it looks like others have had the same issue for a couple years now. I attached a screenshot of what I am seeing.
From Cisco CLI - show vpn-sessiondb anyconnect summary:
VPN Session Summary
---------------------------------------------------------------------------
Active : Cumulative : Peak Concur : Inactive
----------------------------------------------
AnyConnect Client : 96 : 8582 : 101 : 3
SSL/TLS/DTLS : 96 : 8582 : 101 : 3
From Observium interface snapshot is attached.
Is there any fix for this? Also, can we graph per anyconnect group?
Thanks,
Rich Reitenauer
Sr. Infrastructure Analyst
1 Meridian Blvd, Suite 2C01
Wyomissing, PA 19610
O: 610-373-7999 x1255
rreitenauer@ugies.com mailto:rreitenauer@ugies.com
Hi Stef,
Did you manage to resolve the ASA VPN session issue mentioned back in March?
The graph below is for AnyConnect (SSL) VPN sessions but seems to display correctly as "Clientless".
[image: Inline images 1]
Thanks for any advice
Darren
On 15 March 2017 at 08:34, Stef Renders stef.renders@cronos.be wrote:
Dear
Just FYI
This started occurring after 9.4.3 release, and still present as of 9.7.1
All releases pre-9.4.3 do not seem to have this issue, and correctly report 0 clientless vpn (when only using anyconnect sslvpn)
Kind regards
*From:* observium [mailto:observium-bounces@observium.org] *On Behalf Of *Richard Reitenauer *Sent:* dinsdag 14 maart 2017 19:43 *To:* observium@observium.org *Subject:* [Observium] Cisco ASA 9.4(3)6 Remote Access Sessions
I am currently using the latest community edition and looking to go to the professional subscription. With a Cisco ASA 9.4(3)6 and graphing the Remote Access Sessions, I am seeing odd data and it looks like others have had the same issue for a couple years now. I attached a screenshot of what I am seeing.
From Cisco CLI – show vpn-sessiondb anyconnect summary:
VPN Session Summary
Active : Cumulative : Peak Concur : Inactive ------------------------------
AnyConnect Client : 96 : 8582 : 101 : 3
SSL/TLS/DTLS : 96 : 8582 : 101 : 3
From Observium interface snapshot is attached.
Is there any fix for this? Also, can we graph per anyconnect group?
Thanks,
Rich Reitenauer
Sr. Infrastructure Analyst
1 Meridian Blvd, Suite 2C01
Wyomissing, PA 19610
O: 610-373-7999 x1255
rreitenauer@ugies.com
observium mailing list observium@observium.org http://postman.memetic.org/cgi-bin/mailman/listinfo/observium
Check the returned data on these devices:
snmpwalk -v2c -c public -M mibs/rfc:mibs/cisco -m CISCO-REMOTE-ACCESS-MONITOR-MIB crasEmailNumSessions.0 crasIPSecNumSessions.0 crasL2LNumSessions.0 crasLBNumSessions.0 crasSVCNumSessions.0 crasWebvpnNumSessions.0
(from inside the observium dir)
adam. On 2017-10-20 10:41:52, Storer, Darren darren.storer@gmail.com wrote: Hi Stef,
Did you manage to resolve the ASA VPN session issue mentioned back in March?
The graph below is for AnyConnect (SSL) VPN sessions but seems to display correctly as "Clientless".
[Inline images 1]
Thanks for any advice
Darren
On 15 March 2017 at 08:34, Stef Renders <stef.renders@cronos.be [mailto:stef.renders@cronos.be]> wrote:
Dear Just FYI This started occurring after 9.4.3 release, and still present as of 9.7.1 All releases pre-9.4.3 do not seem to have this issue, and correctly report 0 clientless vpn (when only using anyconnect sslvpn) Kind regards From: observium [mailto:observium-bounces@observium.org [mailto:observium-bounces@observium.org]] On Behalf Of Richard Reitenauer Sent: dinsdag 14 maart 2017 19:43 To: observium@observium.org [mailto:observium@observium.org] Subject: [Observium] Cisco ASA 9.4(3)6 Remote Access Sessions I am currently using the latest community edition and looking to go to the professional subscription. With a Cisco ASA 9.4(3)6 and graphing the Remote Access Sessions, I am seeing odd data and it looks like others have had the same issue for a couple years now. I attached a screenshot of what I am seeing.
From Cisco CLI – show vpn-sessiondb anyconnect summary:
VPN Session Summary --------------------------------------------------------------------------- Active : Cumulative : Peak Concur : Inactive ---------------------------------------------- AnyConnect Client : 96 : 8582 : 101 : 3 SSL/TLS/DTLS : 96 : 8582 : 101 : 3
From Observium interface snapshot is attached.
Is there any fix for this? Also, can we graph per anyconnect group? Thanks, Rich Reitenauer Sr. Infrastructure Analyst 1 Meridian Blvd, Suite 2C01 Wyomissing, PA 19610 O: 610-373-7999 x1255 rreitenauer@ugies.com [mailto:rreitenauer@ugies.com]
_______________________________________________ observium mailing list observium@observium.org [mailto:observium@observium.org] http://postman.memetic.org/cgi-bin/mailman/listinfo/observium [http://postman.memetic.org/cgi-bin/mailman/listinfo/observium]
_______________________________________________ observium mailing list observium@observium.org http://postman.memetic.org/cgi-bin/mailman/listinfo/observium
Err i mean :
snmpwalk -v2c -c <COMMUNITY> -M mibs/rfc:mibs/cisco -m CISCO-REMOTE-ACCESS-MONITOR-MIB <HOSTNAME> crasEmailNumSessions.0 crasIPSecNumSessions.0 crasL2LNumSessions.0 crasLBNumSessions.0 crasSVCNumSessions.0 crasWebvpnNumSessions.0
Changing the hostname and community.
adam. On 2017-10-25 11:02:44, Adam Armstrong adama@observium.org wrote: Check the returned data on these devices:
snmpwalk -v2c -c public -M mibs/rfc:mibs/cisco -m CISCO-REMOTE-ACCESS-MONITOR-MIB crasEmailNumSessions.0 crasIPSecNumSessions.0 crasL2LNumSessions.0 crasLBNumSessions.0 crasSVCNumSessions.0 crasWebvpnNumSessions.0
(from inside the observium dir)
adam. On 2017-10-20 10:41:52, Storer, Darren darren.storer@gmail.com wrote: Hi Stef,
Did you manage to resolve the ASA VPN session issue mentioned back in March?
The graph below is for AnyConnect (SSL) VPN sessions but seems to display correctly as "Clientless".
[Inline images 1]
Thanks for any advice
Darren
On 15 March 2017 at 08:34, Stef Renders <stef.renders@cronos.be [mailto:stef.renders@cronos.be]> wrote:
Dear Just FYI This started occurring after 9.4.3 release, and still present as of 9.7.1 All releases pre-9.4.3 do not seem to have this issue, and correctly report 0 clientless vpn (when only using anyconnect sslvpn) Kind regards From: observium [mailto:observium-bounces@observium.org [mailto:observium-bounces@observium.org]] On Behalf Of Richard Reitenauer Sent: dinsdag 14 maart 2017 19:43 To: observium@observium.org [mailto:observium@observium.org] Subject: [Observium] Cisco ASA 9.4(3)6 Remote Access Sessions I am currently using the latest community edition and looking to go to the professional subscription. With a Cisco ASA 9.4(3)6 and graphing the Remote Access Sessions, I am seeing odd data and it looks like others have had the same issue for a couple years now. I attached a screenshot of what I am seeing.
From Cisco CLI – show vpn-sessiondb anyconnect summary:
VPN Session Summary --------------------------------------------------------------------------- Active : Cumulative : Peak Concur : Inactive ---------------------------------------------- AnyConnect Client : 96 : 8582 : 101 : 3 SSL/TLS/DTLS : 96 : 8582 : 101 : 3
From Observium interface snapshot is attached.
Is there any fix for this? Also, can we graph per anyconnect group? Thanks, Rich Reitenauer Sr. Infrastructure Analyst 1 Meridian Blvd, Suite 2C01 Wyomissing, PA 19610 O: 610-373-7999 x1255 rreitenauer@ugies.com [mailto:rreitenauer@ugies.com]
_______________________________________________ observium mailing list observium@observium.org [mailto:observium@observium.org] http://postman.memetic.org/cgi-bin/mailman/listinfo/observium [http://postman.memetic.org/cgi-bin/mailman/listinfo/observium]
_______________________________________________ observium mailing list observium@observium.org http://postman.memetic.org/cgi-bin/mailman/listinfo/observium
participants (4)
-
Adam Armstrong
-
Richard Reitenauer
-
Stef Renders
-
Storer, Darren