Hot!cannot query snmp

Author
alain
New Member
  • Total Posts : 9
  • Scores: 0
  • Reward points: 0
  • Joined: 2019/07/22 01:07:32
  • Status: offline
2019/07/22 01:17:05 (permalink)
0

cannot query snmp

Hi,
we have a fortigate HA pair 5.6.6 = FG200E-5.6.6-FW-build1630-180913
We would like to poll snmp by the mgmt interface 172.16.11.135 from 172.16.1.104.
Ping is ok
snmp is enable on the mgmt interface
host ip is defined
but snmp v1,v2 or even does not work at all.
Here is the debug log :
 
snmpd: request 1(root)/4/172.16.1.104 == comm 1/0/172.16.1.104/255.255.255.255
snmpd: matched community "public"
snmpd: get-next: ifXEntry.1 -> () -> 0
snmpd: </msg> 0
snmpd: <msg> 44 bytes 172.16.1.104:7423 -> 172.16.11.135/172.16.11.135:161 (itf 4.4)
snmpd: checking if community "public" is valid
snmpd: checking against community "public"
snmpd: request 1(root)/4/172.16.1.104 == comm 1/0/172.16.1.104/255.255.255.255
snmpd: matched community "public"
snmpd: get-next: ifXEntry.1 -> () -> 0
snmpd: </msg> 0
snmpd: <msg> 44 bytes 172.16.1.104:7423 -> 172.16.11.135/172.16.11.135:161 (itf 4.4)
snmpd: checking if community "public" is valid
snmpd: checking against community "public"
snmpd: request 1(root)/4/172.16.1.104 == comm 1/0/172.16.1.104/255.255.255.255
snmpd: matched community "public"
snmpd: get-next: ifXEntry.1 -> () -> 0
snmpd: </msg> 0
#1

16 Replies Related Threads

    Dave Hall
    Expert Member
    • Total Posts : 1457
    • Scores: 160
    • Reward points: 0
    • Joined: 2012/05/11 07:55:58
    • Location: Canada
    • Status: offline
    Re: cannot query snmp 2019/07/22 09:41:00 (permalink)
    0
    This may sound silly, but is the SNMP agent enabled?
     

    NSE4/FMG-VM64/FortiAnalyzer-VM/5.4/6.0 (FWF40C/FW92D/FGT200D/FGT101E)/ FAP220B/221C
    #2
    alain
    New Member
    • Total Posts : 9
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/07/22 01:07:32
    • Status: offline
    Re: cannot query snmp 2019/07/23 00:25:32 (permalink)
    0
    yes snmp is enabled with a community name v1/v2c. Tried with v3 without luck.
    #3
    ChristianM
    New Member
    • Total Posts : 2
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/07/23 02:25:49
    • Status: offline
    Re: cannot query snmp 2019/07/23 02:31:20 (permalink)
    0
    Hi,
     
    do you have "trusted hosts" in the admin account defined?
    Is the queriing server listed there?
     
    Routing back to the server correct?
    172.16.1.104 is routed through mgmt-interface?
    If not, a policy is needed, to allow traffic from incoming interface to mgmt-interface
     
    Chris
     
    post edited by ChristianM - 2019/07/23 02:36:26
    #4
    alain
    New Member
    • Total Posts : 9
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/07/22 01:07:32
    • Status: offline
    Re: cannot query snmp 2019/07/23 04:22:29 (permalink)
    0

    do you have "trusted hosts" in the admin account defined?
    >> yes hosts are trusted for SNMP and adding them in admin account for login changes nothing.
     
    Is the queriing server listed there?
    >> yes
     
    Routing back to the server correct? 
    >> ping the IP of mgmt interface is OK so I suppose it is correct ?
     

    172.16.1.104 is routed through mgmt-interface?
    If not, a policy is needed, to allow traffic from incoming interface to mgmt-interface
    >> 172.16.1.104 is the SNMP host that  is trying to poll snmp with the IP adress of management interface. 
    >> Do I miss something ?
     
    Alain 
    #5
    ChristianM
    New Member
    • Total Posts : 2
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/07/23 02:25:49
    • Status: offline
    Re: cannot query snmp 2019/07/23 06:39:57 (permalink)
    0
    Hi Alain,
     
    >> Do I miss something?
    Yes ;) But what...
     
    Please check (again) if the "SNMP Agent"-slider in the SNMP-page is "on". Even if the page
    says "v2c Enabeld", you have to enable the agent extra.
     
     
     
     
     
     
    #6
    Dave Hall
    Expert Member
    • Total Posts : 1457
    • Scores: 160
    • Reward points: 0
    • Joined: 2012/05/11 07:55:58
    • Location: Canada
    • Status: offline
    Re: cannot query snmp 2019/07/23 11:02:19 (permalink)
    0
    Initially, when we started to play around with snmp monitoring, we were on 5.0/5.2 but never fully got it working.  On 5.4, we used the CLI to config snmp and was reported to be working (with our network monitoring tools).
     
    config system snmp sysinfo
    set status enable
    set description "test.fortiddns.com"
    set contact-info "admin@test.ca"
    set location "Test"
    end

    config system snmp community
    edit 1
    set name "public"
    config hosts
    edit 1
    set ip 222.188.66.126 255.255.255.255
    set interface "wan1"
    next
    end
    set events cpu-high mem-low log-full intf-ip vpn-tun-up vpn-tun-down ha-switch ha-hb-failure ips-signature ips-anomaly av-virus av-oversize av-pattern av-fragmented fm-if-change bgp-established bgp-backward-transition ha-member-up ha-member-down ent-conf-change av-conserve av-bypass av-oversize-passed av-oversize-blocked ips-pkg-update ips-fail-open faz-disconnect wc-ap-up wc-ap-down fswctl-session-up fswctl-session-down
    next
    end




    NSE4/FMG-VM64/FortiAnalyzer-VM/5.4/6.0 (FWF40C/FW92D/FGT200D/FGT101E)/ FAP220B/221C
    #7
    emnoc
    Expert Member
    • Total Posts : 5208
    • Scores: 339
    • Reward points: 0
    • Joined: 2008/03/20 13:30:33
    • Location: AUSTIN TX AREA
    • Status: offline
    Re: cannot query snmp 2019/07/23 13:18:08 (permalink)
    0
    Do you have allowaccess and snmp enabled on that interface
     
    e.g
     
    config sys interface 
      edit wan1
          set allowaccess ssh https snmp
    end
    http://socpuppet.blogspot.com/2014/12/locking-down-fortigate-admin-access.html
     
    Ken Felix

    PCNSE,  NSE , Forcepoint ,  StrongSwan Specialist
    #8
    alain
    New Member
    • Total Posts : 9
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/07/22 01:07:32
    • Status: offline
    Re: cannot query snmp 2019/07/30 08:48:41 (permalink)
    0
    yes it is "on"
    #9
    alain
    New Member
    • Total Posts : 9
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/07/22 01:07:32
    • Status: offline
    Re: cannot query snmp 2019/07/30 09:00:20 (permalink)
    0
    and snmp is allowed on the mgmt interface
     
     
    #10
    alain
    New Member
    • Total Posts : 9
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/07/22 01:07:32
    • Status: offline
    Re: cannot query snmp 2019/07/30 09:02:19 (permalink)
    0
    is it supported to query snmp on the Mgmt interface ?
     
     
    #11
    Dave Hall
    Expert Member
    • Total Posts : 1457
    • Scores: 160
    • Reward points: 0
    • Joined: 2012/05/11 07:55:58
    • Location: Canada
    • Status: offline
    Re: cannot query snmp 2019/07/30 10:11:52 (permalink)
    0
    Supposedly.  Though make sure the Trusted Hosts is set accordingly.
     
     

    Attached Image(s)


    NSE4/FMG-VM64/FortiAnalyzer-VM/5.4/6.0 (FWF40C/FW92D/FGT200D/FGT101E)/ FAP220B/221C
    #12
    alain
    New Member
    • Total Posts : 9
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/07/22 01:07:32
    • Status: offline
    Re: cannot query snmp 2019/07/31 02:54:28 (permalink)
    0
     
     
    sometimes strangely, community names are empty using the web interface :

     
    the poller is 172.16.1.104
     
    #13
    alain
    New Member
    • Total Posts : 9
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/07/22 01:07:32
    • Status: offline
    Re: cannot query snmp 2019/08/19 01:42:32 (permalink)
    0
    any idea ?
    #14
    emnoc
    Expert Member
    • Total Posts : 5208
    • Scores: 339
    • Reward points: 0
    • Joined: 2008/03/20 13:30:33
    • Location: AUSTIN TX AREA
    • Status: offline
    Re: cannot query snmp 2019/08/19 02:07:56 (permalink)
    0
    Dump the cfg from cli
     
    show full sys snmp community
    show full sys snmp sysinfo
     
    Here's a screenshot of a test 
     
    FWF50E3U1700XXXXX #   show full-configuration  sys snmp  communityconfig system snmp community    edit 1        set name "mycommunity"        set status enable        config hosts            edit 1                set source-ip 0.0.0.0                set ip 0.0.0.0 0.0.0.0                set ha-direct disable                set host-type any            next        end        set query-v1-status enable        set query-v1-port 161        set query-v2c-status enable        set query-v2c-port 161        set trap-v1-status enable        set trap-v1-lport 162        set trap-v1-rport 162        set trap-v2c-status enable        set trap-v2c-lport 162        set trap-v2c-rport 162        set events cpu-high mem-low log-full intf-ip vpn-tun-up vpn-tun-down ha-switch ha-hb-failure ips-signature ips-anomaly av-virus av-oversize av-pattern av-fragmented fm-if-change bgp-established bgp-backward-transition ha-member-up ha-member-down ent-conf-change av-conserve av-bypass av-oversize-passed av-oversize-blocked ips-pkg-update ips-fail-open faz-disconnect wc-ap-up wc-ap-down fswctl-session-up fswctl-session-down load-balance-real-server-down per-cpu-high    nextend 
     
    FWF50E3U170XXXXX # show full-configuration  sys snmp  sysinfo 
    config system snmp sysinfo   
    set status enable   
    set engine-id ''   
    set description "socpuppetsblogs"   
    set contact-info ''   
    set location "socpupps"   
    set trap-high-cpu-threshold 80   
    set trap-low-memory-threshold 80   
    set trap-log-full-threshold 90end  
     
    Ken Felix
     
    post edited by emnoc - 2019/08/19 02:09:28

    Attached Image(s)


    PCNSE,  NSE , Forcepoint ,  StrongSwan Specialist
    #15
    emnoc
    Expert Member
    • Total Posts : 5208
    • Scores: 339
    • Reward points: 0
    • Joined: 2008/03/20 13:30:33
    • Location: AUSTIN TX AREA
    • Status: offline
    Re: cannot query snmp 2019/08/19 02:11:54 (permalink)
    0
    Note above is from v6.0
     
    Ken Felix
     
     

    Attached Image(s)


    PCNSE,  NSE , Forcepoint ,  StrongSwan Specialist
    #16
    alain
    New Member
    • Total Posts : 9
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/07/22 01:07:32
    • Status: offline
    Re: cannot query snmp 2019/08/19 02:36:35 (permalink)
    0
    here are the results from cli :
    FortiFW-1 # show full sys snmp community
    config system snmp community
    edit 1
    set name "public"
    set status enable
    config hosts
    edit 1
    set source-ip 0.0.0.0
    set ip 172.16.1.104 255.255.255.255
    set ha-direct disable
    set host-type any
    next
    edit 2
    set source-ip 0.0.0.0
    set ip 172.28.0.1 255.255.255.255
    set ha-direct disable
    set host-type any
    next
    end
    set query-v1-status enable
    set query-v1-port 161
    set query-v2c-status enable
    set query-v2c-port 161
    set trap-v1-status enable
    set trap-v1-lport 162
    set trap-v1-rport 162
    set trap-v2c-status enable
    set trap-v2c-lport 162
    set trap-v2c-rport 162
    set events cpu-high mem-low log-full intf-ip vpn-tun-up vpn-tun-down ha-switch ha-hb-failure ips-signature ips-anomaly av-virus av-oversize av-pattern av-fragmented fm-if-change bgp-established bgp-backward-transition ha-member-up ha-member-down ent-conf-change av-conserve av-bypass av-oversize-passed av-oversize-blocked ips-pkg-update ips-fail-open power-supply-failure faz-disconnect wc-ap-up wc-ap-down fswctl-session-up fswctl-session-down load-balance-real-server-down per-cpu-high
    next
    end

    FortiFW-1 # show full sys snmp sysinfo
    config system snmp sysinfo
    set status enable
    set engine-id ''
    set description "FW Fortinet"
    set contact-info ''
    set location "BTA - Salle informatique"
    set trap-high-cpu-threshold 80
    set trap-low-memory-threshold 80
    set trap-log-full-threshold 90
    end
    #17
    Jump to:
    © 2019 APG vNext Commercial Version 5.5