Ad Widget

Collapse

SNMPv3 cisco switch - Authentication failure (incorrect password, community or key)

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • erasedhammer
    Member
    • Aug 2020
    • 58

    #1

    SNMPv3 cisco switch - Authentication failure (incorrect password, community or key)

    I've been having this problem for a while.

    I have a cisco 2960.
    I enable snmpv2 and everything works fine.

    I change to snmpv3 and suddenly zabbix says authentication failure.
    I ssh into the zabbix server and run snmpwalk with the exact same credentials as I put in zabbix. It works FINE and pulls data back.

    For an example:
    Code:
    [FONT=monospace][COLOR=#000000]$ snmpget -v 3 -u manager -l authPriv -A password1 -a md5 -x aes -X password2 172.20.11.2 1.3.6.1.4.1.9.2.1.58.0 [/COLOR]
    iso.3.6.1.4.1.9.2.1.58.0 = INTEGER: 6[/FONT]
    But the exact same item put on the zabbix host page:
    Click image for larger version  Name:	item2.png Views:	0 Size:	30.7 KB ID:	420619
    Click image for larger version  Name:	item.png Views:	0 Size:	58.1 KB ID:	420620
    Click image for larger version

Name:	host.png
Views:	2180
Size:	26.5 KB
ID:	420623

    It is clearly not a cisco issue.
    Can someone help me troubleshoot this?
    Last edited by erasedhammer; 13-03-2021, 22:24.
  • Rudlafik
    Senior Member
    • Nov 2018
    • 144

    #2
    Hi, I have the same problem on Cisco on cheap switches. On CISCO ASA, everything is fine when using SNMPv3. Also the HPE and SNMPv3 servers on our ZBX 5.4.8 are OK. However, it is interesting behavior when querying OID from different MiB according to RFC. Of course, everything is fine on SNMPv2 and everything will load. According to CISCO, the RFC of some MiB libraries is poorly implemented. For some SNMPv3 OID queries, you will not get an answer for some. I combined different levels of authPriv security and nowhere did I find a working way to apply functional SNMPv3 to CISCA's soho products. After consulting with LAN / WAN product professionals, I came to the conclusion that CISCO branded another company's product and emulated - strangely - its IOS in its Linux OS. Just another waste from CISCO. We are now disposing of these switches and buying active components from HPE and Fortigate. They are cheaper in price, performance in the same way as CISCO and at least comply with RFC standards. Before the HPE arrives, the "waste" CISCO goes to SNMPv2.Click image for larger version

Name:	snmp_LI.jpg
Views:	2063
Size:	88.8 KB
ID:	436609

    Comment

    • Rudlafik
      Senior Member
      • Nov 2018
      • 144

      #3
      Hi, I next proble with Checkpoint FW in HA. AES128 SHA256 SNMPv3. Than I clear cache "zabbix_server -R snmp_cache_reload" the marks then turned green.

      Comment

      Working...