Skip to main content
jangelis
Staff
Staff
April 25, 2022

Technical Tip: SNMP access to FortiGate

  • April 25, 2022
  • 0 replies
  • 19840 views

Description

This article describes what to check on FortiGate when polling from the SNMP manager does not work.

 

Network topology

Network topology

Scope

FortiGate.

Solution

  1. The SNMP must be configured (for versions 1 and 2c, the same community string must be used), and the SNMP manager must be within the configured range (the particular IP or range containing the IP must be configured).

 

SNMP configuration:

SNMP configuration

 

  1. The SNMP must be enabled on the ingress interface.

Interface configuration:

Interface configuration


  1. If trust host configuration is used for all of the admin accounts, the IP address of the SNMP manager must be part of any admin account's trust host configuration: Troubleshooting Tip: FortiGate HTTPS, SSH access if the trusted hosts feature is enabled.


1.png


If the SNMP manager IP address is not configured under the Admin’s trusted hosts, SNMP requests originating from that manager will not be permitted by the FortiGate.

Local-in policies are the first check. Even if there is an accept policy, trusted-hosts becomes a secondary check that further limits access to SNMP, hence why the IP must be included as a trusted-host. If no local-in policies are configured, FortiGate relies only on trusted-hosts.

When performing a debug flow on the FortiGate, the SNMP traffic can be observed matching the Implicit Deny Policy and being dropped.

  1. If SNMP v3 is enabled, it will not allow adding networks (only hosts). Unlike SNMPv2, the hosts option under SNMPv3 is to notify hosts for sending SNMP traps only. Restricting SNMP managers(hosts) from polling the FortiGate on SNMPv3 can only be achieved through either Trusted-hosts configuration or Local-in Policy.

 

SNMP.png

 

SNMP1.png

 

As a workaround, if the trusted host is enabled for all administrator access, make sure the SNMP host IP is included in at least one of these trusted IP/subnets.

Troubleshooting commands:

SSH1:

diagnose debug reset

diagnose debug console timestamp enable

diagnose debug application snmpd -1

diagnose debug enable

 

 

SSH2:

 

diagnose sniffer packet any 'host <SNMP_Manager_IP> and (port 161 or port 162)' 6 0 l

 

Related articles:  

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!