Ad Widget

Collapse

SNMP v3 Issue - Cisco Switch

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Maso
    Junior Member
    • Oct 2020
    • 1

    #1

    SNMP v3 Issue - Cisco Switch

    Hi,

    I've just started setting up Zabbix, I've added about a dozen Cisco switches, and all are working fine apart from one (all have the same configuration applied for SNMP v3 PRIV, including credentials).

    If I look under the host in Zabbix I can see the error:-

    "Cannot connect to "10.62.1.241:161": Authentication failure (incorrect password, community or key)"

    I assumed I'd typo'd so removed the switch config and applied it again, still the same error, so I then removed the host and re-added it again, but it does the same thing.

    I used snmpwalk on the Zabbix server and confirmed it works fine, I also checked and am able to use snmpget:-

    snmpget -v3 -l authPriv -u zabbix -a SHA -A SomethingSecret -x AES -X SomethingSecret 10.62.1.241 1.3.6.1.2.1.1.3.0
    iso.3.6.1.2.1.1.3.0 = Timeticks: (914496776) 105 days, 20:16:07.76

    I'm really at a loss, we have three switches that are identical, purchased at the same time, same IOS version etc, the other two just worked fine without any issue, this third one is just not wanting to play along!

    Just wondered if anyone had any further suggestions, at this point it feels like an issue in Zabbix?

    Thanks
    Maso
  • NilsA
    Senior Member
    • Sep 2020
    • 102

    #2
    Hi,
    I've run into a similar issue. My best guess is that zabbix tries to snmpget with a different SHA than the switch is configured to allow.
    Try using MD5 and DES and if that works, try all the other encryption and auth methods.

    Hope that helps

    Comment

    • zabfish
      Junior Member
      • Nov 2022
      • 3

      #3
      Based on what I have read, snmpwalk will only support crypto of aes-128. This checked out when I created the "v3 priv" group and the user with sha MAC and "aes 128" crypto. In situations like this you can do a config dump and diff them or look at packets/logs. Usually the error is right, you just have to figure out which side is fumbling the credentials and why.

      Comment

      Working...