Re: [fw-wiz] Cisco Security Manager clone?

Hi Mike,

Not so much for monitoring as you're suggesting, but if all you want
is to push configurations to all your devices, then Kiwi CatTools
works well. Not free for that amount of devices, but very cheap.

If monitoring is what you want, then for a lot less than the $100K you
were quoted, maybe a MARS device is what you need. I have a MARS 50
and it handles all kinds of traffic with no problem.

If, on the other hand you want to monitor only availability, then
OpenNMS or Zabbix might do the trick for you (or even Nagios, like I




On Wed, Apr 30, 2008 at 11:01 AM, Mike Davis <mdavis@xxxxxxx> wrote:

This is my first posting so be gentle ;-)

I have an environment that is all Cisco based firewalls for my edge
protection and site to site vpns. I have a little over 100 remote sites
running on ASA 5505's with an AES Tunnel to both the primary (HQ) and
secondary (DR ) sites. It is working quite nicely and has been for years
now but the problem I have is this… all my remote site firewalls are not
centrally managed in the sense that I can make one change in a console and
push it globally to all my remote firewalls so that when a change is
required, I have to log into each and every one (I use SSH) and make the

I know that Cisco Security Manager will allow me to do that but at the 100K
pricetag I was quoted from Cisco with the blink of an eye… I just cannot put
that into my budget.

Does anyone know of or can recommend any freeware or low-cost-ware
application that will allow me to monitor and make global config changes
without having to SSH to each one? The ability to segregate into groups and
manage based upon groups would certainly be a plus as well but not a

Thanks in advance!

Mike Davis

firewall-wizards mailing list

firewall-wizards mailing list

Relevant Pages

  • Re: [fw-wiz] SNMP RW ASA 7.2.1
    ... Security Focus Retired: Cisco Security Monitoring Analysis and Response System multiple vulnerabilities. ... notice I said the VMS replacement. ...
  • RE: Traffic Monitor
    ... > FreeBSD box (I want to use this box for traffic monitoring) ... > and then one port for the rest of the network which connects ... I'd go pick up a Cisco switch ... Switch to "mirror" all traffic to one port, ...
  • Re: Managing ASA55xx with additional software
    ... Cisco and our AVVID partners offer a variety of applications to manage ... Single device management ... It provides comprehensive management and monitoring of a single Cisco ... for all the different services offered by the Cisco ASA 5500 Series. ...
  • Re: ipsec vpn logging
    ... remote sites. ... This is for the purposes of internal node monitoring at ... down so we know if it's the vpn's or the actual remote nodes. ...