163 lines
4.2 KiB
Markdown
163 lines
4.2 KiB
Markdown
# Configuración para Zabbix - Cisco MAC Monitor LLD
|
|
# ================================================
|
|
|
|
## CONFIGURACIÓN DEL JAVASCRIPT EN ZABBIX
|
|
|
|
### 1. Crear el Script JavaScript en Zabbix
|
|
|
|
**Administración > Scripts > Crear Script**
|
|
- Nombre: `Cisco MAC LLD`
|
|
- Tipo: `Script`
|
|
- Ejecutar en: `Zabbix server`
|
|
- Comandos: [Copiar contenido de zabbix_lld_script.js]
|
|
|
|
### 2. Configurar Discovery Rule
|
|
|
|
**Configuración > Hosts > [Tu Host Cisco] > Discovery > Crear regla de descubrimiento**
|
|
|
|
- Nombre: `Cisco MAC Address Discovery`
|
|
- Tipo: `Script`
|
|
- Clave: `cisco.mac.discovery`
|
|
- Script: `Cisco MAC LLD`
|
|
- Intervalo: `1h` (o según necesites)
|
|
- Periodo de conservación de elementos perdidos: `7d`
|
|
|
|
### 3. Configurar Macros del Host
|
|
|
|
**Configuración > Hosts > [Tu Host Cisco] > Macros**
|
|
|
|
Crear las siguientes macros:
|
|
|
|
```
|
|
{$CISCO_SERVICE_URL} = https://tu-servidor:8443
|
|
{$CISCO_HOST} = {HOST.CONN} # O la IP específica
|
|
{$CISCO_USERNAME} = tu_usuario_ssh
|
|
{$CISCO_PASSWORD} = tu_contraseña_ssh
|
|
{$CISCO_TIMEOUT} = 60
|
|
```
|
|
|
|
### 4. Configurar Item Prototypes
|
|
|
|
Una vez creada la Discovery Rule, crear los siguientes Item Prototypes:
|
|
|
|
#### Item 1: Contador de MACs por Puerto
|
|
- Nombre: `Port {#PORT_NAME} - MAC Count`
|
|
- Tipo: `Dependent item`
|
|
- Clave: `cisco.port.mac.count[{#PORT_NAME}]`
|
|
- Master item: `cisco.mac.discovery`
|
|
- Preprocessing:
|
|
- JSONPath: `$.data[?(@['{#PORT_NAME}'] == '{#PORT_NAME}')]['{#MAC_COUNT}'].first()`
|
|
|
|
#### Item 2: Lista de MACs por Puerto
|
|
- Nombre: `Port {#PORT_NAME} - MAC Addresses`
|
|
- Tipo: `Dependent item`
|
|
- Clave: `cisco.port.mac.addresses[{#PORT_NAME}]`
|
|
- Tipo de información: `Text`
|
|
- Master item: `cisco.mac.discovery`
|
|
- Preprocessing:
|
|
- JSONPath: `$.data[?(@['{#PORT_NAME}'] == '{#PORT_NAME}')]['{#MAC_ADDRESSES}'].first()`
|
|
|
|
#### Item 3: VLANs por Puerto
|
|
- Nombre: `Port {#PORT_NAME} - VLANs`
|
|
- Tipo: `Dependent item`
|
|
- Clave: `cisco.port.vlans[{#PORT_NAME}]`
|
|
- Tipo de información: `Text`
|
|
- Master item: `cisco.mac.discovery`
|
|
- Preprocessing:
|
|
- JSONPath: `$.data[?(@['{#PORT_NAME}'] == '{#PORT_NAME}')]['{#VLANS}'].first()`
|
|
|
|
### 5. Configurar Triggers (Opcional)
|
|
|
|
#### Trigger 1: Puerto con muchas MACs
|
|
- Nombre: `Port {#PORT_NAME} has too many MAC addresses`
|
|
- Expresión: `last(/Template/cisco.port.mac.count[{#PORT_NAME}])>50`
|
|
- Severidad: `Warning`
|
|
|
|
#### Trigger 2: Cambio en número de MACs
|
|
- Nombre: `MAC count changed on port {#PORT_NAME}`
|
|
- Expresión: `change(/Template/cisco.port.mac.count[{#PORT_NAME}])<>0`
|
|
- Severidad: `Information`
|
|
|
|
## CONFIGURACIÓN DEL SERVICIO HTTPS
|
|
|
|
### Variables de entorno necesarias:
|
|
```bash
|
|
CISCO_SERVICE_PORT=8443
|
|
SSL_CERT_PATH=/path/to/certificate.pem
|
|
SSL_KEY_PATH=/path/to/private.key
|
|
```
|
|
|
|
### Comando para generar certificado autofirmado:
|
|
```bash
|
|
openssl req -x509 -newkey rsa:4096 -keyout key.pem -out cert.pem -days 365 -nodes \
|
|
-subj "/C=ES/ST=Madrid/L=Madrid/O=Organization/CN=cisco-monitor"
|
|
```
|
|
|
|
## ESTRUCTURA ESPERADA DE RESPUESTA JSON
|
|
|
|
```json
|
|
{
|
|
"data": [
|
|
{
|
|
"port": "Gi1/0/1",
|
|
"data": {
|
|
"count": 2,
|
|
"vlans": "600,601",
|
|
"addresses": "F0:8E:DB:2E:4D:86 600\nF0:8E:DB:2E:4D:86 601",
|
|
"timestamp": 1763048672
|
|
}
|
|
},
|
|
{
|
|
"port": "Gi1/0/10",
|
|
"data": {
|
|
"count": 1,
|
|
"vlans": "151",
|
|
"addresses": "00:50:56:A6:91:69 151",
|
|
"timestamp": 1763048672
|
|
}
|
|
},
|
|
{
|
|
"port": "Gi1/0/11",
|
|
"data": {
|
|
"count": 0,
|
|
"vlans": "",
|
|
"addresses": "",
|
|
"timestamp": 1763048672
|
|
}
|
|
}
|
|
],
|
|
"timestamp": "2024-11-13T10:30:00",
|
|
"unix_timestamp": 1700000000,
|
|
"device_hostname": "cisco-switch",
|
|
"total_ports": 24,
|
|
"total_macs": 45,
|
|
"ports_with_macs": 12,
|
|
"ports_without_macs": 12
|
|
}
|
|
```
|
|
|
|
## TROUBLESHOOTING
|
|
|
|
### 1. Verificar logs de Zabbix
|
|
```bash
|
|
tail -f /var/log/zabbix/zabbix_server.log | grep "Cisco"
|
|
```
|
|
|
|
### 2. Probar el servicio manualmente
|
|
```bash
|
|
curl -k -X POST https://tu-servidor:8443/mac-monitor \
|
|
-H "Content-Type: application/json" \
|
|
-d '{
|
|
"host": "192.168.1.10",
|
|
"username": "admin",
|
|
"password": "password"
|
|
}'
|
|
```
|
|
|
|
### 3. Verificar conectividad HTTPS desde Zabbix
|
|
Usar "Administration > Scripts > Test" en Zabbix con un script simple:
|
|
```javascript
|
|
var req = new HttpRequest();
|
|
var response = req.get("https://tu-servidor:8443/health");
|
|
return response;
|
|
``` |