How to monitor IPSec VPN tunnel traffic rate using SNMP?

From: simonkc@netsol.co.in
Date: Thu Apr 24 2003 - 04:47:18 GMT-3


Hi,

I have an IPSec tunnel between a c2600 router to a PIX. By polling the c2600
router using SNMP MIBs, i want to be able to find out the Input bps and
Output bps traffic rate for the tunnel. And no, i do not want to poll the
remote PIX for operational reasons.

I have tried using the IPSEC-FlowMonitor MIB, but i am faced with a problem
here.
I am polling the
.iso.org.dod.internet.private.enterprises.cisco.ciscoMgmt.ciscoIpSecFlowMoni
torMIB.cipSecMIBObjects.cipSecPhaseTwo.cipSecTunnelTable.cipSecTunnelEntry.c
ipSecTunInOctets and cipSecTunOutOctets variables.

but the instance values keep changing every time. Also , the number of
instances keep changing every time(for e.g. there are 2 and sometimes 3
instance entries for a single tunnel ) . These 2 problems make it difficult
to monitor the tunnel's traffic rate.

How can i accurately and reliably monitor the IPSec tunnel traffic rate??

Cheers
Simon



This archive was generated by hypermail 2.1.4 : Thu May 01 2003 - 13:36:04 GMT-3