Security Compliance
Determining whether you have Cisco CAT OS devices and need the Cat OS connector
This article describes the Cat OS connector and whether it applies to your SEM environment.
First published date
Last published date
Overview
This article discusses the Cisco Cat OS connector, and whether it applies to your environment.
Product section
Resolution
When the connector discovery runs "Scan for New Nodes" under the SEM/GUI console, Manage > Nodes section, it is possible for the SEM to register a false positive on the CatOS when the data is actually Cisco IOS data. The data is so similar it is difficult for our connector discovery to determine the appropriate connector.
The Cisco Catalyst Switch was originally released by Cisco with the CatOS operating system. Some time later Cisco switched over to the IOS operating system for the Catalyst Switch. The confusion occurs because the environment might have a Catalyst Switch supported by CatOS.
The CatOS platform has been on Cisco’s end of life list since 2007. The CatOS devices aren’t very common and should have been phased out with a standard equipment life-cycle policy.
The Cisco document below discusses EOL (End of Life) for the last version (Version 8.0) of CatOS :
http://www.cisco.com/c/en/us/products/collateral/switches/catalyst-6500-series-switches/prod_end-of-life_notice0900aecd80699e1a.html (© 2017 Cisco, available at https://www.cisco.com, obtained on November 22, 2017)
This discusses the EOL for the 12.2 hybrid management (CatOS Supervisor)
http://www.cisco.com/en/US/products/hw/switches/ps708/prod_eol_notice0900aecd80699ddb.html (© 2017 Cisco, available at https://www.cisco.com, obtained on November 22, 2017)
Most switches in current production networks should either IOS 12.X or 15. IOS 12.X would be the most common for an older switch, for which support for IOS 12.X ended in 2016. All newer, or current switches, are on the IOS 15 platform which should be supported by the IOS/PIX connector.
If your environment does have a Cisco CatOS version of a switch, be sure to isolate this data in a different syslog log file, and assign the CatOS connector to that particular log file.
Be aware that there are actually 5 different types of Cisco data that need to be separated into different syslog log files. These are:
- Cisco IOS
- Cisco CatOS
- Cisco VPN
- Cisco Nexus
- Cisco WLC (wireless LAN & IOS-XE software)
If the IOS data is sent to local2, then send the CatOS to local6. If the Nexus data was sent to local7, then send the VPN data to local5, and so on. We just can't allow them to send data to the same log file. Otherwise they can grab each others' data, resulting in unmatched data in the SEM console and database. Data will still go into the database, but we may not get every field (every part) of the data.
Disclaimer: Please note, any content posted herein is provided as a suggestion or recommendation to you for your internal use. This is not part of the SolarWinds software or documentation that you purchased from SolarWinds, and the information set forth herein may come from third parties. Your organization should internally review and assess to what extent, if any, such custom scripts or recommendations will be incorporated into your environment. You elect to use third party content at your own risk, and you will be solely responsible for the incorporation of the same, if any.