Ad Widget

Collapse

Zabbix sending dummy snmp v3 request. BUG???

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • icol
    Member
    • Aug 2014
    • 31

    #1

    Zabbix sending dummy snmp v3 request. BUG???

    We are monitoring and equipment box with snmp v3. We have many of these boxes
    We built our own template with some oids and it seems it worked very well
    Then we notice some equipemts stop responding snmp after 99 days and 12 hours.
    I took a tcpdump and i notice zabbix is sending a dummy request quite often (see in picture)
    Evry time zabbix sends a dummy request we get a reply with 1.3.6.1.6.3.15.1.1.4 wich means:

    The total number of packets received by the SNMP
    engine which were dropped because they referenced an
    snmpEngineID that was not known to the SNMP engine.


    I could see the normal oids been send and replied normaly

    After 99 days and 12 hours

    The normal oid requests were replied with 1.3.6.1.6.3.15.1.1.2.0 which means:

    The total number of packets received by the SNMPClick image for larger version

Name:	dummySnmp.jpg
Views:	415
Size:	98.9 KB
ID:	429851
    engine which were dropped because they appeared
    outside of the authoritative SNMP engine's window.

    After a reboot of the monitored system all workes well again.

    Why does ZAbbix sends such dummy request?
  • icol
    Member
    • Aug 2014
    • 31

    #2
    Forgot to say i am running zabbix 5

    Comment

    • icol
      Member
      • Aug 2014
      • 31

      #3
      Thank you very much for your reply! We could verify the AuthoritativeEngine time was less than 150 secs for working systems and more that 150 secs for system not responding to snmp.

      You say that when reboots and everything is ok then you suspect a problem in the device. When we reboot shouldn't the AuthoritativeEngineBoots increase one value and AuthoritativeEngine time reset to 0 and communicated to zabbix? At this time bothe zabbix and equipment should have both counters identical

      Any way we will take a tcpdump to a system we expect to fail today and see how it fails

      Comment

      • cyber
        Senior Member
        Zabbix Certified SpecialistZabbix Certified Professional
        • Dec 2006
        • 4807

        #4
        IIRC, that dummy request is totally legit query for doing engineID discovery. I have seen those in snmpv3 tcpdumps from Zabbix to devices almost for each query...It is like saying "Hello, how can we talk to each other" - "ok, heres my boot count, engineID and boottime"...
        This document describes the User-based Security Model (USM) for Simple Network Management Protocol (SNMP) version 3 for use in the SNMP architecture. It defines the Elements of Procedure for providing SNMP message level security. This document also includes a Management Information Base (MIB) for remotely monitoring/managing the configuration parameters for this Security Model. This document obsoletes RFC 2574. [STANDARDS-TRACK]

        if something is answered with 1.3.6.1.6.3.15.1.1.2.0, then you may have too big time differences in devices.. RFC says +-150 sec...
        If the extracted value of msgAuthoritativeEngineID is the same as the value of snmpEngineID of the processing SNMP engine (meaning this is the authoritative SNMP engine), then if any of the following conditions is true, then the message is considered to be outside of the Time Window:
        - the local value of snmpEngineBoots is 2147483647;
        - the value of the msgAuthoritativeEngineBoots field differs from the local value of snmpEngineBoots; or,
        - the value of the msgAuthoritativeEngineTime field differs from the local notion of snmpEngineTime by more than +/- 150 seconds.
        And if you reboot your device and everything turns OK, then I suspect that is the issue with that device, not Zabbix.

        Comment

        • cyber
          Senior Member
          Zabbix Certified SpecialistZabbix Certified Professional
          • Dec 2006
          • 4807

          #5
          After device reboot it will not report to zabbix anything before zabbix comes and queries again....

          Comment

          Working...