A. The Monitoring Center for Performance 2.0 component, within the CiscoWorks VPN/Security Solution (VMS), is a web-based tool for monitoring and troubleshooting the health and performance of services that contribute to enterprise network security. The Monitoring Center for Performance enables users, without requiring expertise with IPSEC or other security technologies, to increase service availability by isolating, troubleshooting significant events in their network as they occur
Q. Who are the customers for MCP?
A. The Monitoring Center for Performance is ideal for enterprises with needs for ongoing operational management of security & content infrastructure. These customers range from small-to-medium and large enterprises, to large IT data centers.
Q. Why do customers need MCP?
A. As enterprises seek to decrease their security concerns by deploying security infrastructure such as Firewall, VPN, the need for effective ongoing maintenance and management of security infrastructure is critical. Designed to enable companies for better operational management, MCP proactively manages the availability of security infrastructure in Cisco powered networks.
Q. What problems does MCP solve for security operations?
A. MCP allows administrators to monitor the device health of all VPN & Firewall aspects resulting in increased productivity. The Real time monitoring component allows operators to monitor Mission critical VPN & Firewall aspects and quickly identify events that impact business. In addition, administrators can quickly isolate and troubleshoot significant events in their VPN network, without needing to understand VPN & IPSEC terms. The Historical/Trending feature set allows administrators to perform more meaningful capacity planning for their security infrastructure
FEATURES
Q. What are the key features of MCP?
A. MCP offers the following key features:
• Performance Monitoring of Cisco VPN routers, Cisco PIX Firewalls, Catalyst 6500 service modules (FW, VPN, CSM, SSL) in Cisco powered network
• Rapid Troubleshooting of security devices, with on-line help and customized help to aid in troubleshooting
• Secure graphic user interface with Historical reporting/trending for data up to one year
• Upper layer NMS/OSS integration with SYSLOG, trap, email notifications and historical data export in XML, CSV or PDF formats as reports export
Q. What devices does MCP support?
A. MCP supports the following devices in Cisco powered data centers:
A. MCP can be launched from the CiscoWorks desktop in the CiscoWorks VPN/Security Solution (VMS).
Q. How do users monitor the performance of their security infrastructure using MCP?
A. If a user is monitoring VPN related information using MCP, instant view of VPN tunnel status, structure and activity is presented to user under the Site-Site VPN service, located in the monitoring tab of the application. The user can drill down for details on tunnels, interfaces, and perform a tunnel lookup in site-site VPN deployments. In the Remote Access deployments a user can get information on VPN Clusters, and perform user lookup in addition to monitoring details of devices. If a user is monitoring Firewall related information using MCP, devices status (up/down) along with the details on blocks, memory, interfaces, and connections is presented in the Firewall service, located in monitoring tab of the application. Faults are highlighted in the event browser window, which is accessible under all supported services. Filtering and sorting by priority enables users to view and act upon selected faults.
Q. How does MCP gather fault and performance data?
A. MCP queries standard and Cisco-published MIBs via the Simple Network Management Protocol (SNMP) whenever possible. Administrators can specify polling intervals per SNMP MIB table. For the Firewall devices, MCP leverages the HTTPS interface on these devices.
Q. How does MCP notify users when tunnel failure or system failures occurs?
A. Security administrators can set up performance thresholds for the monitored attributes with specified actions and fault priorities. When thresholds are exceeded or the device reports reports a failure of a tunnel, a syslog, trap, or e-mail notification is generated. Fault conditions are also signaled in the event browser on the Web-based, secure GUI.
Q. Can there be multiple syslog or trap receivers that receive messages from MCP?
A. Yes. Multiple syslog or trap receivers can be defined.
Q. Does MCP monitor device traps from the security infrastructure?
A. Yes. MCP currently monitors the Firewall/VPN/Content/SSL services using a combination of SNMP polling and traps. SNMP traps are used to provide real-time status changes.
Q. What support does MCP provide for Catalyst® 6500 SSL Module?
A. MCP supports Monitoring and reporting of Catalyst® 6500 SSL Module
Q. Does MCP support the Cisco Catalyst 7600 Switch?
A. No. MCP does not support the monitoring/reporting of Cisco Catalyst 7600 Switch
Q. Can MCP be used to generate historical data reports?
A. Yes. MCP offers historical data reports for key health metrics i.e. CPU utilization, memory usage, bandwidth, total connections etc. MCP also offers reporting on Top10 users, Failures, usage, performance and throughput for Remote Acesss VPN. For Firewall the users can get information on total TCP connections, total service hits, connections, CPU utilization, and so forth. Reports can also be e-mailed periodically. Reports are available in both tabular and graphic formats.
Q. How much historical data can MCP store?
A. MCP can provide up to a one year worth of historical data. Administrators can specify both aggregation and truncation frequencies for the monitored data.
Q. Does MCP support export of historical data?
A. Yes. Historical data and views can be exported in CSV or XML formats from the UI.
INTEROPERABILITY AND COMPATIBILITY
Q. Which Web browser versions does MCP support?
A. MCP supports Microsoft Internet Explorer 6.0.26 and 6.0.28 on Windows and Netscape 4.79 on Windows, Netscape 4.76 on Solaris
Q. Which server platform does MCP support?
A. MCP currently is supported on Solaris 2.7or 2.8
Q. Does MCP support any network management industry standards?
A. Yes. MCP uses SNMP and Cisco published MIBs to gather fault and performance data.
Q. What is the integration between the MCP and CiscoWorks2000?
A. CiscoWorks2000 Cisco Management Connection integration code can be downloaded from Cisco.com to create a folder for MCP on the CiscoWorks desktop. CiscoWorks2000 customers can directly launch MCP from CiscoWorks 2000 desktop.
ORDERING AND UPGRADING
Q. Is MCP part of the CiscoWorks family?
A. Yes. MCP is the part of the CiscoWorks VPN/Security Management Solution (VMS).
Q. Does MCP have a similar "look and feel" to that of the CiscoWorks Management Center for Firewalls and the Management Center for IDS Sensors? Is it a standalone product?
A. MCP is not a standalone product, it is a part of CiscoWorks VMS. MCP does share a common interface with the CiscoWorks Management Center for Firewalls and the Management Center for IDS Sensors, and they are all launched from the CiscoWorks desktop.
Q. Can MCP be separately purchased?
A. No. MCP is exclusively available with CiscoWorks VPN/Security Management Solution (VMS)
A. For more information on VMS and MCP, contact your local Cisco sales representative. You can also access additional product information at http://www.cisco.com/go/vms