Ad Widget

Collapse

SNMPv3 failed?

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • John Jin
    Junior Member
    • Dec 2020
    • 2

    #1

    SNMPv3 failed?

    Hello All,

    I'm trying to implement SNMPv3 with my cisco C1113-8P IOS-XE 17.03.02 as SNMP server, and Fedora 30 as SNMP client.
    The connection is fine and working since previously SNMPv2c worked
    on cisco, the following command:
    snmp-server group my_group v3 priv
    snmp-server user my_user my_group v3 auth SHA my_auth_pw priv AES my_priv


    From every perspective of the cisco device it seems the SNMP is working properly, yet onto the server, I noticed the following issue:
    The packets are sent and received ok
    Authentication stage is passed (if I type a wrong password it does show the authentication failure message)
    both snmpwalk and snmpget command give timeout errors
    zabbix-server gives timeout error


    Thank you for any help
    John
  • GreenHorn
    Member
    • Nov 2020
    • 54

    #2
    I have same issue.

    Comment

    • NilsA
      Senior Member
      • Sep 2020
      • 102

      #3
      Not currently working with Cisco devices but I have run into a similar problem with Lancom WAPs and routers. The issue presents itself especially with SNMPv3 - I'm assuming it has something to do with the encryption process taking too long.
      In my case, graphs had lots of gaps on my web interface. I "fixed" it in the end by changing the config so that unreachable and unavailable delay are at the minimum values. Let me know if this helps at all.

      Comment


      • GreenHorn
        GreenHorn commented
        Editing a comment
        This could be right. Have you some steps? On which side could be change time for unreachable and unavailable delay and which config, please? I have issue with commcell from commvault.

        Thank you
    • John Jin
      Junior Member
      • Dec 2020
      • 2

      #4
      I found the cause for my case.
      My Fedora 30 uses net-snmp and net-snmp-utils . Both of these only supports AES-128 bits.
      For AES-192 and AES-256 bits, I'll need to separately configure my Fedora 30. Which I didn't.

      Comment

      • NilsA
        Senior Member
        • Sep 2020
        • 102

        #5
        GreenHorn just adjust these values in your Zabbix server / proxy config (/etc/zabbix/zabbix....conf).

        Comment

      • Rudlafik
        Senior Member
        • Nov 2018
        • 144

        #6
        Hi, I have the same problem on Cisco on cheap switches. On CISCO ASA, everything is fine when using SNMPv3. Also the HPE and SNMPv3 servers on our ZBX 5.4.8 are OK. However, it is interesting behavior when querying OID from different MiB according to RFC. Of course, everything is fine on SNMPv2 and everything will load. According to CISCO, the RFC of some MiB libraries is poorly implemented. For some SNMPv3 OID queries, you will not get an answer for some. I combined different levels of authPriv security and nowhere did I find a working way to apply functional SNMPv3 to CISCA's soho products. After consulting with LAN / WAN product professionals, I came to the conclusion that CISCO branded another company's product and emulated - strangely - its IOS in its Linux OS. Just another waste from CISCO. We are now disposing of these switches and buying active components from HPE and Fortigate. They are cheaper in price, performance in the same way as CISCO and at least comply with RFC standards. Before the HPE arrives, the "waste" CISCO goes to SNMPv2.Click image for larger version

Name:	snmp_LI.jpg
Views:	625
Size:	88.8 KB
ID:	436613

        Comment

        Working...