Guest

CiscoWorks Monitoring Center for Performance

Monitoring Center for Performance (MCP) Version 2.0

Q & A
Q. What is Monitoring Center for Performance?
A. The Monitoring Center for Performance 2.0 component, within the CiscoWorks VPN/Security Solution (VMS), is a web-based tool for monitoring and troubleshooting the health and performance of services that contribute to enterprise network security. The Monitoring Center for Performance enables users, without requiring expertise with IPSEC or other security technologies, to increase service availability by isolating, troubleshooting significant events in their network as they occur
Q. Who are the customers for MCP?
A. The Monitoring Center for Performance is ideal for enterprises with needs for ongoing operational management of security & content infrastructure. These customers range from small-to-medium and large enterprises, to large IT data centers.
Q. Why do customers need MCP?
A. As enterprises seek to decrease their security concerns by deploying security infrastructure such as Firewall, VPN, the need for effective ongoing maintenance and management of security infrastructure is critical. Designed to enable companies for better operational management, MCP proactively manages the availability of security infrastructure in Cisco powered networks.
Q. What problems does MCP solve for security operations?
A. MCP allows administrators to monitor the device health of all VPN & Firewall aspects resulting in increased productivity. The Real time monitoring component allows operators to monitor Mission critical VPN & Firewall aspects and quickly identify events that impact business. In addition, administrators can quickly isolate and troubleshoot significant events in their VPN network, without needing to understand VPN & IPSEC terms. The Historical/Trending feature set allows administrators to perform more meaningful capacity planning for their security infrastructure

FEATURES

Q. What are the key features of MCP?
A. MCP offers the following key features:

• Performance Monitoring of Cisco VPN routers, Cisco PIX Firewalls, Catalyst 6500 service modules (FW, VPN, CSM, SSL) in Cisco powered network

• Rapid Troubleshooting of security devices, with on-line help and customized help to aid in troubleshooting

• Secure graphic user interface with Historical reporting/trending for data up to one year

• Upper layer NMS/OSS integration with SYSLOG, trap, email notifications and historical data export in XML, CSV or PDF formats as reports export

Q. What devices does MCP support?
A. MCP supports the following devices in Cisco powered data centers:

• Cisco 3000 Concentrator series

• Cisco VPN Routers: 800,900,1600,1700,2600,3600,7400

• Cisco PIX Firewalls: PIX 501,505,515,520,535

• Cisco Catalyst 6500 Services Module: Firewall Service Module

• Cisco Catalyst 6500 Services Module: VPN Service Module

• Cisco Catalyst 6500 Services Module: Content Switching Module

• Cisco Catalyst 6500 Service Module: SSL Module

Q. How does a user access MCP?
A. MCP can be launched from the CiscoWorks desktop in the CiscoWorks VPN/Security Solution (VMS).
Q. How do users monitor the performance of their security infrastructure using MCP?
A. If a user is monitoring VPN related information using MCP, instant view of VPN tunnel status, structure and activity is presented to user under the Site-Site VPN service, located in the monitoring tab of the application. The user can drill down for details on tunnels, interfaces, and perform a tunnel lookup in site-site VPN deployments. In the Remote Access deployments a user can get information on VPN Clusters, and perform user lookup in addition to monitoring details of devices. If a user is monitoring Firewall related information using MCP, devices status (up/down) along with the details on blocks, memory, interfaces, and connections is presented in the Firewall service, located in monitoring tab of the application. Faults are highlighted in the event browser window, which is accessible under all supported services. Filtering and sorting by priority enables users to view and act upon selected faults.
Q. How does MCP gather fault and performance data?
A. MCP queries standard and Cisco-published MIBs via the Simple Network Management Protocol (SNMP) whenever possible. Administrators can specify polling intervals per SNMP MIB table. For the Firewall devices, MCP leverages the HTTPS interface on these devices.
Q. How does MCP notify users when tunnel failure or system failures occurs?
A. Security administrators can set up performance thresholds for the monitored attributes with specified actions and fault priorities. When thresholds are exceeded or the device reports reports a failure of a tunnel, a syslog, trap, or e-mail notification is generated. Fault conditions are also signaled in the event browser on the Web-based, secure GUI.
Q. Can there be multiple syslog or trap receivers that receive messages from MCP?
A. Yes. Multiple syslog or trap receivers can be defined.
Q. Does MCP monitor device traps from the security infrastructure?
A. Yes. MCP currently monitors the Firewall/VPN/Content/SSL services using a combination of SNMP polling and traps. SNMP traps are used to provide real-time status changes.
Q. What support does MCP provide for Catalyst® 6500 SSL Module?
A. MCP supports Monitoring and reporting of Catalyst® 6500 SSL Module
Q. Does MCP support the Cisco Catalyst 7600 Switch?
A. No. MCP does not support the monitoring/reporting of Cisco Catalyst 7600 Switch
Q. Can MCP be used to generate historical data reports?
A. Yes. MCP offers historical data reports for key health metrics i.e. CPU utilization, memory usage, bandwidth, total connections etc. MCP also offers reporting on Top10 users, Failures, usage, performance and throughput for Remote Acesss VPN. For Firewall the users can get information on total TCP connections, total service hits, connections, CPU utilization, and so forth. Reports can also be e-mailed periodically. Reports are available in both tabular and graphic formats.
Q. How much historical data can MCP store?
A. MCP can provide up to a one year worth of historical data. Administrators can specify both aggregation and truncation frequencies for the monitored data.
Q. Does MCP support export of historical data?
A. Yes. Historical data and views can be exported in CSV or XML formats from the UI.

INTEROPERABILITY AND COMPATIBILITY

Q. Which Web browser versions does MCP support?
A. MCP supports Microsoft Internet Explorer 6.0.26 and 6.0.28 on Windows and Netscape 4.79 on Windows, Netscape 4.76 on Solaris
Q. Which server platform does MCP support?
A. MCP currently is supported on Solaris 2.7or 2.8
Q. Does MCP support any network management industry standards?
A. Yes. MCP uses SNMP and Cisco published MIBs to gather fault and performance data.
Q. What is the integration between the MCP and CiscoWorks2000?
A. CiscoWorks2000 Cisco Management Connection integration code can be downloaded from Cisco.com to create a folder for MCP on the CiscoWorks desktop. CiscoWorks2000 customers can directly launch MCP from CiscoWorks 2000 desktop.

ORDERING AND UPGRADING

Q. Is MCP part of the CiscoWorks family?
A. Yes. MCP is the part of the CiscoWorks VPN/Security Management Solution (VMS).
Q. Does MCP have a similar "look and feel" to that of the CiscoWorks Management Center for Firewalls and the Management Center for IDS Sensors? Is it a standalone product?
A. MCP is not a standalone product, it is a part of CiscoWorks VMS. MCP does share a common interface with the CiscoWorks Management Center for Firewalls and the Management Center for IDS Sensors, and they are all launched from the CiscoWorks desktop.
Q. Can MCP be separately purchased?
A. No. MCP is exclusively available with CiscoWorks VPN/Security Management Solution (VMS)
Q. What are the system requirements for MCP?
A. System requirements for the MCP are documented in the CiscoWorks VMS 2.2 deployment guide, which is available at:
http://www.cisco.com/en/US/products/sw/cscowork/ps2330/products_white_paper09186a00801aa80c.shtml
Q. Where can I find more information on MCP?
A. For more information on VMS and MCP, contact your local Cisco sales representative. You can also access additional product information at http://www.cisco.com/go/vms
Text Box:  Corporate HeadquartersCisco Systems, Inc.170 West Tasman DriveSan Jose, CA 95134-1706USAwww.cisco.comTel:   408 526-4000    800 553-NETS (6387)Fax: 408 526-4100    European HeadquartersCisco Systems International BVHaarlerbergparkHaarlerbergweg 13-191101 CH AmsterdamThe Netherlandswww-europe.cisco.comTel:  31 0 20 357 1000Fax:    31 0 20 357 1100    Americas HeadquartersCisco Systems, Inc.170 West Tasman DriveSan Jose, CA 95134-1706USAwww.cisco.comTel:    408 526-7660Fax:    408 527-0883    Asia Pacific HeadquartersCisco Systems, Inc.168 Robinson Road#28-01 Capital Tower Singapore 068912www.cisco.comTel: +65 6317 7777Fax: +65 6317 7799Cisco Systems has more than 200 offices in the following countries and regions. Addresses, phone numbers, and fax numbers are listed on the Cisco Web site at www.cisco.com/go/offices.Argentina · Australia · Austria · Belgium · Brazil · Bulgaria · Canada · Chile · China PRC · Colombia · Costa Rica · Croatia · Cyprus  Czech Republic · Denmark · Dubai, UAE · Finland · France · Germany · Greece · Hong Kong SAR · Hungary · India · Indonesia · Ireland Israel · Italy · Japan · Korea · Luxembourg · Malaysia · Mexico · The Netherlands · New Zealand · Norway · Peru · Philippines · Poland Portugal · Puerto Rico · Romania · Russia · Saudi Arabia · Scotland · Singapore · Slovakia · Slovenia · South Africa · Spain · Sweden Switzerland · Taiwan · Thailand · Turkey · Ukraine · United Kingdom · United States · Venezuela · Vietnam · Zimbabwe                      Copyright  2004 Cisco Systems, Inc. All rights reserved. CCIP, CCSP, the Cisco Powered Network mark, Cisco Unity, Follow Me Browsing, FormShare, and StackWise are trademarks of Cisco Systems, Inc.; Changing the Way We Work, Live, Play, and Learn, and iQuick Study are service marks of Cisco Systems, Inc.; and Aironet, ASIST, BPX, Catalyst, CCDA, CCDP, CCIE, CCNA, CCNP, Cisco, the Cisco Certified Internetwork Expert logo, Cisco IOS, the Cisco IOS logo, Cisco Press, Cisco Systems, Cisco Systems Capital, the Cisco Systems logo, Empowering the Internet Generation, Enterprise/Solver, EtherChannel, EtherSwitch, Fast Step, GigaStack, Internet Quotient, IOS, IP/TV, iQ Expertise, the iQ logo, iQ Net Readiness Scorecard, LightStream, Linksys, MGX, MICA, the Networkers logo, Networking Academy, Network Registrar, Packet, PIX, Post-Routing, Pre-Routing, RateMUX, Registrar, ScriptShare, SlideCast, SMARTnet, StrataView Plus, Stratm, SwitchProbe, TeleRouter, The Fastest Way to Increase Your Internet Quotient, TransPath, and VCO are registered trademarks of Cisco Systems, Inc. and/or its affiliates in the United States and certain other countries.All other trademarks mentioned in this document or Web site are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (0402R)       204105.21_ETMG_LF_10.04Printed in the USA Text Box:  Corporate HeadquartersCisco Systems, Inc.170 West Tasman DriveSan Jose, CA 95134-1706USAwww.cisco.comTel:    408 526-4000    800 553-NETS (6387)Fax: 408 526-4100    European HeadquartersCisco Systems International BVHaarlerbergparkHaarlerbergweg 13-191101 CH AmsterdamThe Netherlandswww-europe.cisco.comTel:  31 0 20 357 1000Fax:    31 0 20 357 1100    Americas HeadquartersCisco Systems, Inc.170 West Tasman DriveSan Jose, CA 95134-1706USAwww.cisco.comTel:    408 526-7660Fax:    408 527-0883    Asia Pacific HeadquartersCisco Systems, Inc.168 Robinson Road#28-01 Capital Tower Singapore 068912www.cisco.comTel: +65 6317 7777Fax: +65 6317 7799Cisco Systems has more than 200 offices in the following countries and regions. Addresses, phone numbers, and fax numbers are listed on the Cisco Web site at www.cisco.com/go/offices.Argentina · Australia · Austria · Belgium · Brazil · Bulgaria · Canada · Chile · China PRC · Colombia · Costa Rica · Croatia · Cyprus  Czech Republic · Denmark · Dubai, UAE · Finland · France · Germany · Greece · Hong Kong SAR · Hungary · India · Indonesia · Ireland Israel · Italy · Japan · Korea · Luxembourg · Malaysia · Mexico · The Netherlands · New Zealand · Norway · Peru · Philippines · Poland Portugal · Puerto Rico · Romania · Russia · Saudi Arabia · Scotland · Singapore · Slovakia · Slovenia · South Africa · Spain · Sweden Switzerland · Taiwan · Thailand · Turkey · Ukraine · United Kingdom · United States · Venezuela · Vietnam · Zimbabwe                      Copyright  2004 Cisco Systems, Inc. All rights reserved. CCIP, CCSP, the Cisco Powered Network mark, Cisco Unity, Follow Me Browsing, FormShare, and StackWise are trademarks of Cisco Systems, Inc.; Changing the Way We Work, Live, Play, and Learn, and iQuick Study are service marks of Cisco Systems, Inc.; and Aironet, ASIST, BPX, Catalyst, CCDA, CCDP, CCIE, CCNA, CCNP, Cisco, the Cisco Certified Internetwork Expert logo, Cisco IOS, the Cisco IOS logo, Cisco Press, Cisco Systems, Cisco Systems Capital, the Cisco Systems logo, Empowering the Internet Generation, Enterprise/Solver, EtherChannel, EtherSwitch, Fast Step, GigaStack, Internet Quotient, IOS, IP/TV, iQ Expertise, the iQ logo, iQ Net Readiness Scorecard, LightStream, Linksys, MGX, MICA, the Networkers logo, Networking Academy, Network Registrar, Packet, PIX, Post-Routing, Pre-Routing, RateMUX, Registrar, ScriptShare, SlideCast, SMARTnet, StrataView Plus, Stratm, SwitchProbe, TeleRouter, The Fastest Way to Increase Your Internet Quotient, TransPath, and VCO are registered trademarks of Cisco Systems, Inc. and/or its affiliates in the United States and certain other countries.All other trademarks mentioned in this document or Web site are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (0402R)       204105.21_ETMG_LF_10.04Printed in the USA