Skip to content

Latest commit

 

History

History
62 lines (42 loc) · 2.29 KB

File metadata and controls

62 lines (42 loc) · 2.29 KB

Cisco FTD via HTTP

Back up Cisco FTD firewalls via the HTTP API. This model uses the configexport method to export the configuration as a zip file, then extracts the JSON configuration from this file.

Configuration

Ensure that the HTTP input is enabled in the Oxidized configuration, e.g.:

input:
  default: ssh, http

Oxidized will need to use the FTD's admin login. Set the username at the model level:

models:
  ftd:
    username: admin

When integrating with LibreNMS, you may need to override the IP address used by Oxidized (e.g. if SNMP and the HTTP API are listening on different interfaces on your FTD). This can be done with a mapping rule, e.g.:

lnms config:set oxidized.maps.ip.hostname.+ '{"match": "HOSTNAME", "value": "IP"}'

(Where HOSTNAME is the hosname/IP address used when adding the device to LibreNMS, and IP is the IP address for the HTTP API.)

The port for the HTTP API can be overridden with a variable. For example, create a mapping rule to assign the device to a group, e.g.:

lnms config:set oxidized.maps.group.hostname.+ '{"match": "HOSTNAME", "value": "GROUP"}'

(Where HOSTNAME is the hosname/IP address used when adding the device to LibreNMS, and GROUP is an appropriate group name.)

Then set the port variable at the group level. You can also override the password here if necessary, e.g.:

groups:
  GROUP:
    vars:
      ftd_api_port: 8443
    password: secret

Variables

The following variables can be used to control the behaviour of the model:

  • ftd_api_endpoint: URL path to the FTD API (default: /api/fdm/latest)
  • ftd_api_port: HTTPS port for the FTD API (default: 443)
  • ftd_config_filename: Filename to use for the configexport method call (default: oxidized.zip)
  • ftd_polls: Number of times to poll the status of the configexport job (default: 10, minimum: 1)
  • ftd_poll_wait: Seconds to wait between polls (default: 10, minimum: 1)

Limitations

If your FTDs are in an HA pair, then backups will only succeed on the active device.

Back to Model-Notes