Hot!cannot query snmp

Page: 12 > Showing page 1 of 2
Author
alain
New Member
  • Total Posts : 14
  • Scores: 0
  • Reward points: 0
  • Joined: 2019/07/22 01:07:32
  • Status: offline
2019/07/22 01:17:05 (permalink)
0

cannot query snmp

Hi,
we have a fortigate HA pair 5.6.6 = FG200E-5.6.6-FW-build1630-180913
We would like to poll snmp by the mgmt interface 172.16.11.135 from 172.16.1.104.
Ping is ok
snmp is enable on the mgmt interface
host ip is defined
but snmp v1,v2 or even does not work at all.
Here is the debug log :
 
snmpd: request 1(root)/4/172.16.1.104 == comm 1/0/172.16.1.104/255.255.255.255
snmpd: matched community "public"
snmpd: get-next: ifXEntry.1 -> () -> 0
snmpd: </msg> 0
snmpd: <msg> 44 bytes 172.16.1.104:7423 -> 172.16.11.135/172.16.11.135:161 (itf 4.4)
snmpd: checking if community "public" is valid
snmpd: checking against community "public"
snmpd: request 1(root)/4/172.16.1.104 == comm 1/0/172.16.1.104/255.255.255.255
snmpd: matched community "public"
snmpd: get-next: ifXEntry.1 -> () -> 0
snmpd: </msg> 0
snmpd: <msg> 44 bytes 172.16.1.104:7423 -> 172.16.11.135/172.16.11.135:161 (itf 4.4)
snmpd: checking if community "public" is valid
snmpd: checking against community "public"
snmpd: request 1(root)/4/172.16.1.104 == comm 1/0/172.16.1.104/255.255.255.255
snmpd: matched community "public"
snmpd: get-next: ifXEntry.1 -> () -> 0
snmpd: </msg> 0
#1

23 Replies Related Threads

    Dave Hall
    Expert Member
    • Total Posts : 1504
    • Scores: 165
    • Reward points: 0
    • Joined: 2012/05/11 07:55:58
    • Location: Canada
    • Status: offline
    Re: cannot query snmp 2019/07/22 09:41:00 (permalink)
    0
    This may sound silly, but is the SNMP agent enabled?
     

    NSE4/FMG-VM64/FortiAnalyzer-VM/5.4/6.0 (FWF40C/FW92D/FGT200D/FGT101E)/ FAP220B/221C
    #2
    alain
    New Member
    • Total Posts : 14
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/07/22 01:07:32
    • Status: offline
    Re: cannot query snmp 2019/07/23 00:25:32 (permalink)
    0
    yes snmp is enabled with a community name v1/v2c. Tried with v3 without luck.
    #3
    ChristianM
    New Member
    • Total Posts : 2
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/07/23 02:25:49
    • Status: offline
    Re: cannot query snmp 2019/07/23 02:31:20 (permalink)
    0
    Hi,
     
    do you have "trusted hosts" in the admin account defined?
    Is the queriing server listed there?
     
    Routing back to the server correct?
    172.16.1.104 is routed through mgmt-interface?
    If not, a policy is needed, to allow traffic from incoming interface to mgmt-interface
     
    Chris
     
    post edited by ChristianM - 2019/07/23 02:36:26
    #4
    alain
    New Member
    • Total Posts : 14
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/07/22 01:07:32
    • Status: offline
    Re: cannot query snmp 2019/07/23 04:22:29 (permalink)
    0

    do you have "trusted hosts" in the admin account defined?
    >> yes hosts are trusted for SNMP and adding them in admin account for login changes nothing.
     
    Is the queriing server listed there?
    >> yes
     
    Routing back to the server correct? 
    >> ping the IP of mgmt interface is OK so I suppose it is correct ?
     

    172.16.1.104 is routed through mgmt-interface?
    If not, a policy is needed, to allow traffic from incoming interface to mgmt-interface
    >> 172.16.1.104 is the SNMP host that  is trying to poll snmp with the IP adress of management interface. 
    >> Do I miss something ?
     
    Alain 
    #5
    ChristianM
    New Member
    • Total Posts : 2
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/07/23 02:25:49
    • Status: offline
    Re: cannot query snmp 2019/07/23 06:39:57 (permalink)
    0
    Hi Alain,
     
    >> Do I miss something?
    Yes ;) But what...
     
    Please check (again) if the "SNMP Agent"-slider in the SNMP-page is "on". Even if the page
    says "v2c Enabeld", you have to enable the agent extra.
     
     
     
     
     
     
    #6
    Dave Hall
    Expert Member
    • Total Posts : 1504
    • Scores: 165
    • Reward points: 0
    • Joined: 2012/05/11 07:55:58
    • Location: Canada
    • Status: offline
    Re: cannot query snmp 2019/07/23 11:02:19 (permalink)
    0
    Initially, when we started to play around with snmp monitoring, we were on 5.0/5.2 but never fully got it working.  On 5.4, we used the CLI to config snmp and was reported to be working (with our network monitoring tools).
     
    config system snmp sysinfo
    set status enable
    set description "test.fortiddns.com"
    set contact-info "admin@test.ca"
    set location "Test"
    end

    config system snmp community
    edit 1
    set name "public"
    config hosts
    edit 1
    set ip 222.188.66.126 255.255.255.255
    set interface "wan1"
    next
    end
    set events cpu-high mem-low log-full intf-ip vpn-tun-up vpn-tun-down ha-switch ha-hb-failure ips-signature ips-anomaly av-virus av-oversize av-pattern av-fragmented fm-if-change bgp-established bgp-backward-transition ha-member-up ha-member-down ent-conf-change av-conserve av-bypass av-oversize-passed av-oversize-blocked ips-pkg-update ips-fail-open faz-disconnect wc-ap-up wc-ap-down fswctl-session-up fswctl-session-down
    next
    end




    NSE4/FMG-VM64/FortiAnalyzer-VM/5.4/6.0 (FWF40C/FW92D/FGT200D/FGT101E)/ FAP220B/221C
    #7
    emnoc
    Expert Member
    • Total Posts : 5301
    • Scores: 347
    • Reward points: 0
    • Joined: 2008/03/20 13:30:33
    • Location: AUSTIN TX AREA
    • Status: offline
    Re: cannot query snmp 2019/07/23 13:18:08 (permalink)
    0
    Do you have allowaccess and snmp enabled on that interface
     
    e.g
     
    config sys interface 
      edit wan1
          set allowaccess ssh https snmp
    end
    http://socpuppet.blogspot.com/2014/12/locking-down-fortigate-admin-access.html
     
    Ken Felix

    PCNSE,  NSE , Forcepoint ,  StrongSwan Specialist
    #8
    alain
    New Member
    • Total Posts : 14
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/07/22 01:07:32
    • Status: offline
    Re: cannot query snmp 2019/07/30 08:48:41 (permalink)
    0
    yes it is "on"
    #9
    alain
    New Member
    • Total Posts : 14
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/07/22 01:07:32
    • Status: offline
    Re: cannot query snmp 2019/07/30 09:00:20 (permalink)
    0
    and snmp is allowed on the mgmt interface
     
     
    #10
    alain
    New Member
    • Total Posts : 14
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/07/22 01:07:32
    • Status: offline
    Re: cannot query snmp 2019/07/30 09:02:19 (permalink)
    0
    is it supported to query snmp on the Mgmt interface ?
     
     
    #11
    Dave Hall
    Expert Member
    • Total Posts : 1504
    • Scores: 165
    • Reward points: 0
    • Joined: 2012/05/11 07:55:58
    • Location: Canada
    • Status: offline
    Re: cannot query snmp 2019/07/30 10:11:52 (permalink)
    0
    Supposedly.  Though make sure the Trusted Hosts is set accordingly.
     
     

    Attached Image(s)


    NSE4/FMG-VM64/FortiAnalyzer-VM/5.4/6.0 (FWF40C/FW92D/FGT200D/FGT101E)/ FAP220B/221C
    #12
    alain
    New Member
    • Total Posts : 14
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/07/22 01:07:32
    • Status: offline
    Re: cannot query snmp 2019/07/31 02:54:28 (permalink)
    0
     
     
    sometimes strangely, community names are empty using the web interface :

     
    the poller is 172.16.1.104
     
    #13
    alain
    New Member
    • Total Posts : 14
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/07/22 01:07:32
    • Status: offline
    Re: cannot query snmp 2019/08/19 01:42:32 (permalink)
    0
    any idea ?
    #14
    emnoc
    Expert Member
    • Total Posts : 5301
    • Scores: 347
    • Reward points: 0
    • Joined: 2008/03/20 13:30:33
    • Location: AUSTIN TX AREA
    • Status: offline
    Re: cannot query snmp 2019/08/19 02:07:56 (permalink)
    0
    Dump the cfg from cli
     
    show full sys snmp community
    show full sys snmp sysinfo
     
    Here's a screenshot of a test 
     
    FWF50E3U1700XXXXX #   show full-configuration  sys snmp  communityconfig system snmp community    edit 1        set name "mycommunity"        set status enable        config hosts            edit 1                set source-ip 0.0.0.0                set ip 0.0.0.0 0.0.0.0                set ha-direct disable                set host-type any            next        end        set query-v1-status enable        set query-v1-port 161        set query-v2c-status enable        set query-v2c-port 161        set trap-v1-status enable        set trap-v1-lport 162        set trap-v1-rport 162        set trap-v2c-status enable        set trap-v2c-lport 162        set trap-v2c-rport 162        set events cpu-high mem-low log-full intf-ip vpn-tun-up vpn-tun-down ha-switch ha-hb-failure ips-signature ips-anomaly av-virus av-oversize av-pattern av-fragmented fm-if-change bgp-established bgp-backward-transition ha-member-up ha-member-down ent-conf-change av-conserve av-bypass av-oversize-passed av-oversize-blocked ips-pkg-update ips-fail-open faz-disconnect wc-ap-up wc-ap-down fswctl-session-up fswctl-session-down load-balance-real-server-down per-cpu-high    nextend 
     
    FWF50E3U170XXXXX # show full-configuration  sys snmp  sysinfo 
    config system snmp sysinfo   
    set status enable   
    set engine-id ''   
    set description "socpuppetsblogs"   
    set contact-info ''   
    set location "socpupps"   
    set trap-high-cpu-threshold 80   
    set trap-low-memory-threshold 80   
    set trap-log-full-threshold 90end  
     
    Ken Felix
     
    post edited by emnoc - 2019/08/19 02:09:28

    Attached Image(s)


    PCNSE,  NSE , Forcepoint ,  StrongSwan Specialist
    #15
    emnoc
    Expert Member
    • Total Posts : 5301
    • Scores: 347
    • Reward points: 0
    • Joined: 2008/03/20 13:30:33
    • Location: AUSTIN TX AREA
    • Status: offline
    Re: cannot query snmp 2019/08/19 02:11:54 (permalink)
    0
    Note above is from v6.0
     
    Ken Felix
     
     

    Attached Image(s)


    PCNSE,  NSE , Forcepoint ,  StrongSwan Specialist
    #16
    alain
    New Member
    • Total Posts : 14
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/07/22 01:07:32
    • Status: offline
    Re: cannot query snmp 2019/08/19 02:36:35 (permalink)
    0
    here are the results from cli :
    FortiFW-1 # show full sys snmp community
    config system snmp community
    edit 1
    set name "public"
    set status enable
    config hosts
    edit 1
    set source-ip 0.0.0.0
    set ip 172.16.1.104 255.255.255.255
    set ha-direct disable
    set host-type any
    next
    edit 2
    set source-ip 0.0.0.0
    set ip 172.28.0.1 255.255.255.255
    set ha-direct disable
    set host-type any
    next
    end
    set query-v1-status enable
    set query-v1-port 161
    set query-v2c-status enable
    set query-v2c-port 161
    set trap-v1-status enable
    set trap-v1-lport 162
    set trap-v1-rport 162
    set trap-v2c-status enable
    set trap-v2c-lport 162
    set trap-v2c-rport 162
    set events cpu-high mem-low log-full intf-ip vpn-tun-up vpn-tun-down ha-switch ha-hb-failure ips-signature ips-anomaly av-virus av-oversize av-pattern av-fragmented fm-if-change bgp-established bgp-backward-transition ha-member-up ha-member-down ent-conf-change av-conserve av-bypass av-oversize-passed av-oversize-blocked ips-pkg-update ips-fail-open power-supply-failure faz-disconnect wc-ap-up wc-ap-down fswctl-session-up fswctl-session-down load-balance-real-server-down per-cpu-high
    next
    end

    FortiFW-1 # show full sys snmp sysinfo
    config system snmp sysinfo
    set status enable
    set engine-id ''
    set description "FW Fortinet"
    set contact-info ''
    set location "BTA - Salle informatique"
    set trap-high-cpu-threshold 80
    set trap-low-memory-threshold 80
    set trap-log-full-threshold 90
    end
    #17
    alain
    New Member
    • Total Posts : 14
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/07/22 01:07:32
    • Status: offline
    Re: cannot query snmp 2019/08/20 03:03:14 (permalink)
    0
    Any comments on my config ?
    Is there a way to restart "SNMP agent"  from cli ?
    What do you think of just rebooting the box ?
    #18
    emnoc
    Expert Member
    • Total Posts : 5301
    • Scores: 347
    • Reward points: 0
    • Joined: 2008/03/20 13:30:33
    • Location: AUSTIN TX AREA
    • Status: offline
    Re: cannot query snmp 2019/08/20 04:36:44 (permalink)
    0
    If int4.4 is a mgmt interface and you have no local filters and the community is correct and allowaccess shows snmp allowed, it should work unless routing is bad to 172.16.1.104
     
    Since ping is working, I would suspect routing is good. Are you sure the community has no whitespace or other issues?
     
    You should not need to restart the host or snmp-agent but if you desire you could killed  HUP snmpd
     
    diag sys kill HUP PID
     
    e.g killing update pid based on top
     
    Run Time:  226 days, 1 hours and 58 minutes
    0U, 0N, 0S, 100I, 0WA, 0HI, 0SI, 0ST; 2021T, 1618F
           forticron      129      S       0.1     0.6
              flcfgd      159      S       0.1     0.2
             cmdbsvr      102      S       0.0     1.1
             pyfcgid      123      S       0.0     1.1
              cw_acd      153      S       0.0     0.8
              httpsd      122      S       0.0     0.8
             miglogd      120      S       0.0     0.8
             pyfcgid      180      S       0.0     0.7
             pyfcgid      178      S       0.0     0.7
             pyfcgid      179      S       0.0     0.7
             cw_wtpd      156      S       0.0     0.7
              httpsd      188      S       0.0     0.6
              httpsd      735      S       0.0     0.6
               fgfmd      152      S       0.0     0.5
              newcli     9136      S       0.0     0.5
             miglogd      172      S       0.0     0.5
     initXXXXXXXXXXX        1      S       0.0     0.4
              httpsd      187      S       0.0     0.4
             updated      136      S       0.0     0.4
           ipshelper     9143      S <     0.0     0.3
     
    SOMESTUPIDFGTFW # diag sys kill 9 136
     
    To get the pid do a dump
     
     
    SOMESTUPIDFGTFW # diag sys  process pidof snmpd
    137
     
     
    So in the above case you will kill off pid#137 and ensure it restarts and grab a new pid
     
    SOMESTUPIDFGTFW # diag sys kill 9 137
     
    SOMESTUPIDFGTFW # diag sys  process pidof snmpd
    9154
     
    Your cfg looks good btw. Status are enabled, I doubt the services are running on that interface. I would try another interface for eliminatation with the same community. I seen dedicated mgmt interface do weird things some times.
     
    Also ensure trusted hosted are  not impacting any items.
     
    Ken Felix
     
     
     
     

    PCNSE,  NSE , Forcepoint ,  StrongSwan Specialist
    #19
    alain
    New Member
    • Total Posts : 14
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/07/22 01:07:32
    • Status: offline
    Re: cannot query snmp 2019/08/27 05:12:03 (permalink)
    0
    Hi,
    there is no snmpd process listed with the "top" command...
    Run Time: 55 days, 15 hours and 48 minutes
    0U, 0N, 0S, 100I, 0WA, 0HI, 0SI, 0ST; 3963T, 3318F
    src-vis 169 S 0.1 1.0
    insmod 111 S 0.1 0.0
    miglogd 209 S 0.0 1.8
    miglogd 144 S 0.0 0.9
    pyfcgid 19264 S 0.0 0.7
    cmdbsvr 126 S 0.0 0.7
    forticron 154 S 0.0 0.7
    httpsd 16721 S 0.0 0.6
    httpsd 11002 S 0.0 0.6
    sslvpnd 159 S 0.0 0.6
    pyfcgid 19267 S 0.0 0.5
    pyfcgid 19266 S 0.0 0.5
    pyfcgid 19265 S 0.0 0.5
    cw_acd 179 S 0.0 0.5
    httpsd 147 S 0.0 0.5
    hasync 166 S < 0.0 0.4
    initXXXXXXXXXXX 1 S 0.0 0.3
    updated 362 S 0.0 0.3
    ipshelper 193 S < 0.0 0.3
    httpsd 210 S 0.0 0.3
     
    How can I start snmpd or Do i miss something ?
    #20
    Page: 12 > Showing page 1 of 2
    Jump to:
    © 2019 APG vNext Commercial Version 5.5