308 lines
8.9 KiB
Markdown
308 lines
8.9 KiB
Markdown
# Plantilla de Zabbix para Cisco MAC Monitor
|
|
# ==========================================
|
|
|
|
## Discovery Rule
|
|
|
|
```xml
|
|
<discovery_rule>
|
|
<name>Cisco MAC Discovery</name>
|
|
<type>EXTERNAL</type>
|
|
<key>cisco_mac_discovery.sh</key>
|
|
<delay>5m</delay>
|
|
<description>Descubre puertos de switches Cisco con direcciones MAC conectadas</description>
|
|
<item_prototypes>
|
|
<item_prototype>
|
|
<name>MAC Count on {#DEVICE_HOSTNAME} port {#PORT_NAME}</name>
|
|
<type>CALCULATED</type>
|
|
<key>cisco.mac.count[{#DEVICE_HOSTNAME},{#PORT_NAME}]</key>
|
|
<delay>0</delay>
|
|
<value_type>UNSIGNED</value_type>
|
|
<params>{#MAC_COUNT}</params>
|
|
<description>Número de direcciones MAC en el puerto</description>
|
|
</item_prototype>
|
|
|
|
<item_prototype>
|
|
<name>MAC Addresses on {#DEVICE_HOSTNAME} port {#PORT_NAME}</name>
|
|
<type>CALCULATED</type>
|
|
<key>cisco.mac.addresses[{#DEVICE_HOSTNAME},{#PORT_NAME}]</key>
|
|
<delay>0</delay>
|
|
<value_type>TEXT</value_type>
|
|
<params>{#MAC_ADDRESSES}</params>
|
|
<description>Lista de direcciones MAC en formato JSON</description>
|
|
</item_prototype>
|
|
|
|
<item_prototype>
|
|
<name>VLANs on {#DEVICE_HOSTNAME} port {#PORT_NAME}</name>
|
|
<type>CALCULATED</type>
|
|
<key>cisco.mac.vlans[{#DEVICE_HOSTNAME},{#PORT_NAME}]</key>
|
|
<delay>0</delay>
|
|
<value_type>TEXT</value_type>
|
|
<params>{#VLANS}</params>
|
|
<description>VLANs presentes en el puerto</description>
|
|
</item_prototype>
|
|
|
|
<item_prototype>
|
|
<name>Last Update {#DEVICE_HOSTNAME} port {#PORT_NAME}</name>
|
|
<type>CALCULATED</type>
|
|
<key>cisco.mac.lastupdate[{#DEVICE_HOSTNAME},{#PORT_NAME}]</key>
|
|
<delay>0</delay>
|
|
<value_type>TEXT</value_type>
|
|
<params>{#LAST_UPDATE}</params>
|
|
<description>Timestamp de última actualización</description>
|
|
</item_prototype>
|
|
</item_prototypes>
|
|
|
|
<trigger_prototypes>
|
|
<trigger_prototype>
|
|
<expression>{Template Cisco MAC:cisco.mac.count[{#DEVICE_HOSTNAME},{#PORT_NAME}].change()}>0</expression>
|
|
<name>MAC count changed on {#DEVICE_HOSTNAME} port {#PORT_NAME}</name>
|
|
<priority>INFO</priority>
|
|
<description>El número de direcciones MAC en el puerto ha cambiado</description>
|
|
</trigger_prototype>
|
|
|
|
<trigger_prototype>
|
|
<expression>{Template Cisco MAC:cisco.mac.count[{#DEVICE_HOSTNAME},{#PORT_NAME}].last()}>5</expression>
|
|
<name>Too many MACs on {#DEVICE_HOSTNAME} port {#PORT_NAME}</name>
|
|
<priority>WARNING</priority>
|
|
<description>Demasiadas direcciones MAC en un solo puerto (posible loop o hub)</description>
|
|
</trigger_prototype>
|
|
|
|
<trigger_prototype>
|
|
<expression>{Template Cisco MAC:cisco.mac.addresses[{#DEVICE_HOSTNAME},{#PORT_NAME}].change()}>0</expression>
|
|
<name>MAC addresses changed on {#DEVICE_HOSTNAME} port {#PORT_NAME}</name>
|
|
<priority>INFO</priority>
|
|
<description>Las direcciones MAC en el puerto han cambiado</description>
|
|
</trigger_prototype>
|
|
</trigger_prototypes>
|
|
|
|
<graph_prototypes>
|
|
<graph_prototype>
|
|
<name>MAC Count - {#DEVICE_HOSTNAME} {#PORT_NAME}</name>
|
|
<graph_items>
|
|
<graph_item>
|
|
<item>cisco.mac.count[{#DEVICE_HOSTNAME},{#PORT_NAME}]</item>
|
|
</graph_item>
|
|
</graph_items>
|
|
</graph_prototype>
|
|
</graph_prototypes>
|
|
</discovery_rule>
|
|
```
|
|
|
|
## Items Adicionales (nivel de host)
|
|
|
|
```xml
|
|
<!-- Item para estadísticas generales -->
|
|
<item>
|
|
<name>Cisco MAC Monitor - Total Devices</name>
|
|
<type>DEPENDENT</type>
|
|
<key>cisco.mac.total_devices</key>
|
|
<master_item>cisco_mac_discovery.sh</master_item>
|
|
<preprocessing>
|
|
<step>
|
|
<type>JSONPATH</type>
|
|
<params>$.total_devices</params>
|
|
</step>
|
|
</preprocessing>
|
|
<description>Número total de dispositivos monitorizados</description>
|
|
</item>
|
|
|
|
<item>
|
|
<name>Cisco MAC Monitor - Total Ports</name>
|
|
<type>DEPENDENT</type>
|
|
<key>cisco.mac.total_ports</key>
|
|
<master_item>cisco_mac_discovery.sh</master_item>
|
|
<preprocessing>
|
|
<step>
|
|
<type>JSONPATH</type>
|
|
<params>$.total_ports</params>
|
|
</step>
|
|
</preprocessing>
|
|
<description>Número total de puertos con MACs</description>
|
|
</item>
|
|
|
|
<item>
|
|
<name>Cisco MAC Monitor - Last Timestamp</name>
|
|
<type>DEPENDENT</type>
|
|
<key>cisco.mac.timestamp</key>
|
|
<master_item>cisco_mac_discovery.sh</master_item>
|
|
<preprocessing>
|
|
<step>
|
|
<type>JSONPATH</type>
|
|
<params>$.timestamp</params>
|
|
</step>
|
|
</preprocessing>
|
|
<description>Timestamp de la última ejecución</description>
|
|
</item>
|
|
```
|
|
|
|
## Triggers de Host
|
|
|
|
```xml
|
|
<trigger>
|
|
<expression>{Template Cisco MAC:cisco.mac.timestamp.nodata(15m)}>0</expression>
|
|
<name>Cisco MAC Monitor - No data received</name>
|
|
<priority>WARNING</priority>
|
|
<description>No se han recibido datos del monitor MAC en los últimos 15 minutos</description>
|
|
</trigger>
|
|
|
|
<trigger>
|
|
<expression>{Template Cisco MAC:cisco.mac.total_devices.last()}<1</expression>
|
|
<name>Cisco MAC Monitor - No devices monitored</name>
|
|
<priority>HIGH</priority>
|
|
<description>No hay dispositivos siendo monitorizados</description>
|
|
</trigger>
|
|
```
|
|
|
|
## Macros de Template
|
|
|
|
```xml
|
|
<macros>
|
|
<macro>
|
|
<name>{$CISCO.MAC.MAX_PER_PORT}</name>
|
|
<value>5</value>
|
|
<description>Máximo número de MACs permitidas por puerto</description>
|
|
</macro>
|
|
|
|
<macro>
|
|
<name>{$CISCO.MAC.DATA_TIMEOUT}</name>
|
|
<value>15m</value>
|
|
<description>Timeout para considerar datos obsoletos</description>
|
|
</macro>
|
|
|
|
<macro>
|
|
<name>{$CISCO.MAC.DISCOVERY_INTERVAL}</name>
|
|
<value>5m</value>
|
|
<description>Intervalo de discovery</description>
|
|
</macro>
|
|
</macros>
|
|
```
|
|
|
|
## Scripts de Actions
|
|
|
|
### Script para notificaciones con detalles de MACs
|
|
|
|
```bash
|
|
#!/bin/bash
|
|
# Script para enviar detalles de cambios MAC
|
|
|
|
DEVICE="{ALERT.SUBJECT}"
|
|
PORT="{ITEM.KEY1}"
|
|
MAC_DATA="{ITEM.VALUE}"
|
|
|
|
# Formatear mensaje
|
|
MESSAGE="
|
|
Cambio detectado en tabla MAC:
|
|
Dispositivo: ${DEVICE}
|
|
Puerto: ${PORT}
|
|
Timestamp: $(date)
|
|
|
|
Direcciones MAC actuales:
|
|
${MAC_DATA}
|
|
"
|
|
|
|
# Enviar notificación (ejemplo con email)
|
|
echo "${MESSAGE}" | mail -s "Alerta MAC - ${DEVICE}" admin@empresa.com
|
|
```
|
|
|
|
### Script para análisis de MACs no autorizadas
|
|
|
|
```python
|
|
#!/usr/bin/env python3
|
|
import json
|
|
import sys
|
|
|
|
# Cargar lista de MACs autorizadas
|
|
authorized_macs = {
|
|
"aa:bb:cc:dd:ee:01": "Servidor Principal",
|
|
"aa:bb:cc:dd:ee:02": "Workstation Admin",
|
|
# ... más MACs autorizadas
|
|
}
|
|
|
|
# Obtener datos del item
|
|
mac_data = sys.argv[1] if len(sys.argv) > 1 else "{}"
|
|
|
|
try:
|
|
macs = json.loads(mac_data)
|
|
unauthorized = []
|
|
|
|
for mac_entry in macs:
|
|
mac = mac_entry.get('mac')
|
|
if mac and mac not in authorized_macs:
|
|
unauthorized.append({
|
|
'mac': mac,
|
|
'vlan': mac_entry.get('vlan'),
|
|
'type': mac_entry.get('type')
|
|
})
|
|
|
|
if unauthorized:
|
|
print(f"MACs no autorizadas detectadas: {len(unauthorized)}")
|
|
for mac in unauthorized:
|
|
print(f" - {mac['mac']} (VLAN {mac['vlan']})")
|
|
else:
|
|
print("Todas las MACs están autorizadas")
|
|
|
|
except Exception as e:
|
|
print(f"Error procesando datos MAC: {e}")
|
|
```
|
|
|
|
## Configuración de Web Scenarios
|
|
|
|
```xml
|
|
<web_scenario>
|
|
<name>Cisco MAC Monitor Container Health</name>
|
|
<delay>5m</delay>
|
|
<steps>
|
|
<step>
|
|
<name>Check Container Status</name>
|
|
<url>http://localhost:8080/health</url>
|
|
<status_codes>200</status_codes>
|
|
<required>OK</required>
|
|
</step>
|
|
</steps>
|
|
</web_scenario>
|
|
```
|
|
|
|
## Dashboard Widget
|
|
|
|
```json
|
|
{
|
|
"type": "graph",
|
|
"name": "Cisco MAC Activity",
|
|
"fields": {
|
|
"source_type": "1",
|
|
"itemid": {
|
|
"cisco.mac.total_ports": "Total Ports with MACs"
|
|
}
|
|
}
|
|
}
|
|
```
|
|
|
|
## Media Types para Alertas
|
|
|
|
### Webhook para Slack
|
|
|
|
```json
|
|
{
|
|
"name": "Cisco MAC Slack Alert",
|
|
"type": "webhook",
|
|
"parameters": {
|
|
"url": "https://hooks.slack.com/services/YOUR/SLACK/WEBHOOK",
|
|
"channel": "#network-alerts",
|
|
"message": "🚨 Cisco MAC Alert\nDevice: {ALERT.SUBJECT}\nMessage: {ALERT.MESSAGE}\nTime: {DATE} {TIME}"
|
|
}
|
|
}
|
|
```
|
|
|
|
### Webhook para Teams
|
|
|
|
```json
|
|
{
|
|
"name": "Cisco MAC Teams Alert",
|
|
"type": "webhook",
|
|
"parameters": {
|
|
"url": "https://outlook.office.com/webhook/YOUR/TEAMS/WEBHOOK",
|
|
"title": "Cisco MAC Monitor Alert",
|
|
"text": "Device: {ALERT.SUBJECT}\\nStatus: {TRIGGER.STATUS}\\nMessage: {ALERT.MESSAGE}"
|
|
}
|
|
}
|
|
``` |