Network Management

What privileges does an account need to monitor Cisco ASA or Cisco Nexus devices?

Network Insight for Cisco ASA devices and Network Insight for Cisco Nexus devices require additional credentials for logging in to the devices, and for polling the device. Learn more about privileges required for an account to monitor Cisco ASA and Nexus devices. Network Insight for Cisco ASA devices was introduced in NPM 12.2, Network Insight for Cisco Nexus devices in NPM 12.3.

First published date

10/24/2018 6:46 PM

Last published date

8/3/2021 7:19 AM

Overview

Network Insight for Cisco ASAs and Cisco Nexus devices polls data from the devices by a combination of SNMP and CLI polling.

CLI polling requires credentials for logging in to the device, and for polling the device.

Product section

Network Performance Monitor

Resolution

When polling your Cisco ASA or Nexus devices, you need to enable CLI polling and provide credentials to access the device and poll the device.

The requirements for credentials depend on the device you are monitoring and on Orion Platform products used for monitoring.

  • ASA devices
  • Nexus devices

Credentials required for monitoring ASA devices 

  • User name and password for logging into the ASA device. The user must be able to run the following commands on the ASA device:
    • enable
    • show run interface
    • show firewall
    • show asp drop flow
    • show mode
    • show context
    • show failover state
    • show version | include Serial
    • show running-config crypto map
    • show module
    • show failover
    • changeto system
    • show clock
    • show running-config names
    • show run names
  • Enable password: if you are using enable passwords on your ASA device, you need to provide it to allow CLI polling. Without the Enable Password, CLI polling does not work.

Credentials required for monitoring Nexus devices (NPM 12.3) 

User name and password for logging into the Nexus device. The user must be able to run the following commands on the device:

  • show vpc brief
  • show port-channel summary
  • show int snmp-ifindex
  • show vpc peer-keepalive
  • show ip arp {ipaddress} vrf all
  • show interface {interfacename} | i address