Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Jesse13612
New Contributor

SNMP information for interface members

Hi All,

 

I have a Fortigate (60E 6.0.2 build0163) that has 2 WAN ports, a 7 port "internal" switch, and a DMZ port.

We recently introduced a tool called Auvik into our network, and this tool does some network monitoring and troubleshooting for us. It gains access to this Fortigate via both SNMP (v3, although v2 is enabled for troubleshooting) and the CLI via SSH.

 

In the Internal ports I have ports 1-4 plugged into different switches throughout different parts of our building, and port 7 plugged into a server.

 

The problem I am running into is that Auvik sees all 7 internal ports as a single interface, well because they are. Because of this it is causing problems with the tool where it does not know where certain devices lie as it can not tell what is in port 1, vs what is in port 2, etc.

 

Now in the CLI if I use something like "diagnose hardware deviceinfo nic" it lists out the individual interface members, however I can not seem to find a place to do that over SNMP. OID 1.3.6.1.2.1.32.1.1.1.1.x shows me the name of the interfaces but it only lists "internal" it does not list "internal1" like I see in the CLI. OID 1.3.6.1.2.1.2.2.1.1 lists off 7 interfaces, but these are my DMZ, both WANs, my Modem interface, an SSL tunnel interface, the "internal" interface and an IPSec tunnel interface. The individual members are not listed. In fact if I do a full OID walk of the device I find no mention of the individual members.

 

So ultimately is there a way to set up the individual interfaces (or rather interface members) to show up individually in SNMP while still having only a single internal IP for the fortigate and maintaining all our current firewall settings etc. 

 

Additional information:

The internal interface is configured as a "hardware switch".

DHCP is not running on the router itself but rather on a DC.

The IP address of the interface is statically set.

0 REPLIES 0
Labels
Top Kudoed Authors