SNMP error after FortiGate 7.2.11 to 7.4.8 upgrade
Hello everyone,
I have a FortiGate 400F and updated it from version 7.2.11 to version 7.4.8. I'm currently trying to access Zabbix via SNMP, but I'm getting errors. When I try manually using snmpwalk on my Ubuntu server, I get No Response From... and Timeout errors. I've tried SNMP v2 and SNMP v3, removed the AUTO settings, and still the same thing.
The servers I am testing are added as trusted hosts, SNMP is active on the interface side, there is no Local in policy, and even if I manually add and allow them, timeout errors continue.
Another server in the same src network was already accessing via SNMP before the update, so there is no problem with the firewall policies.
diagnose debug application snmpd -1
diagnose debug enable
commands do not produce any logs. They are currently being tested.
When I examine the issue at the kernel debug level (with the commands below)
diagnose debug flow filter clear
diagnose debug flow filter saddr 192.168.1.212
diagnose debug flow filter daddr 192.168.1.45
diagnose debug flow filter proto 17
diagnose debug flow filter dport 161
diagnose debug flow show function-name enable
diagnose debug flow trace start 100
diagnose debug enable
id=65308 trace_id=11 func=init_ip_session_common line=6204 msg="allocate a new session-31ded8f8"
id=65308 trace_id=11 func=__vf_ip_route_input_rcu line=1989 msg="find a route: flag=80000000 gw-0.0.0.0 via root"
id=65308 trace_id=11 func=fw_local_in_handler line=620 msg="iprope_in_check() check failed on policy 0, drop"
id=65308 trace_id=12 func=print_pkt_detail line=6005 msg="vd-root:0 received a packet(proto=17, 192.168.1.212:44592->192.168.1.45:161) tun_id=0.0.0.0 from x5. "
id=65308 trace_id=12 func=init_ip_session_common line=6204 msg="allocate a new session-31dee75f"
id=65308 trace_id=12 func=__vf_ip_route_input_rcu line=1989 msg="find a route: flag=80000000 gw-0.0.0.0 via root"
id=65308 trace_id=12 func=fw_local_in_handler line=620 msg="iprope_in_check() check failed on policy 0, drop"
id=65308 trace_id=13 func=print_pkt_detail line=6005 msg="vd-root:0 received a packet(proto=17, 192.168.1.212:44592->192.168.1.45:161) tun_id=0.0.0.0 from x5. "
id=65308 trace_id=13 func=init_ip_session_common line=6204 msg="allocate a new session-31def5d5"
id=65308 trace_id=13 func=__vf_ip_route_input_rcu line=1989 msg="find a route: flag=80000000 gw-0.0.0.0 via root"
id=65308 trace_id=13 func=fw_local_in_handler line=620 msg="iprope_in_check() check failed on policy 0, drop"
id=65308 trace_id=14 func=print_pkt_detail line=6005 msg="vd-root:0 received a packet(proto=17, 192.168.1.212:44592->192.168.1.45:161) tun_id=0.0.0.0 from x5. "
id=65308 trace_id=14 func=init_ip_session_common line=6204 msg="allocate a new session-31df02d1"
id=65308 trace_id=14 func=__vf_ip_route_input_rcu line=1989 msg="find a route: flag=80000000 gw-0.0.0.0 via root"
id=65308 trace_id=14 func=fw_local_in_handler line=620 msg="iprope_in_check() check failed on policy 0, drop"
id=65308 trace_id=15 func=print_pkt_detail line=6005 msg="vd-root:0 received a packet(proto=17, 192.168.1.212:44592->192.168.1.45:161) tun_id=0.0.0.0 from x5. "
id=65308 trace_id=15 func=init_ip_session_common line=6204 msg="allocate a new session-31df1092"
id=65308 trace_id=15 func=__vf_ip_route_input_rcu line=1989 msg="find a route: flag=80000000 gw-0.0.0.0 via root"
id=65308 trace_id=15 func=fw_local_in_handler line=620 msg="iprope_in_check() check failed on policy 0, drop"
id=65308 trace_id=16 func=print_pkt_detail line=6005 msg="vd-root:0 received a packet(proto=17, 192.168.1.212:44592->192.168.1.45:161) tun_id=0.0.0.0 from x5. "
id=65308 trace_id=16 func=init_ip_session_common line=6204 msg="allocate a new session-31df1e95"
id=65308 trace_id=16 func=__vf_ip_route_input_rcu line=1989 msg="find a route: flag=80000000 gw-0.0.0.0 via root"
id=65308 trace_id=16 func=fw_local_in_handler line=620 msg="iprope_in_check() check failed on policy 0, drop"
id=65308 trace_id=17 func=print_pkt_detail line=6005 msg="vd-root:0 received a packet(proto=17, 192.168.1.212:38409->192.168.1.45:161) tun_id=0.0.0.0 from x5. "
id=65308 trace_id=17 func=init_ip_session_common line=6204 msg="allocate a new session-31df6264"
id=65308 trace_id=17 func=__vf_ip_route_input_rcu line=1989 msg="find a route: flag=80000000 gw-0.0.0.0 via root"
id=65308 trace_id=17 func=fw_local_in_handler line=620 msg="iprope_in_check() check failed on policy 0, drop"
id=65308 trace_id=18 func=print_pkt_detail line=6005 msg="vd-root:0 received a packet(proto=17, 192.168.1.212:38409->192.168.1.45:161) tun_id=0.0.0.0 from x5. "
id=65308 trace_id=18 func=init_ip_session_common line=6204 msg="allocate a new session-31df7062"
id=65308 trace_id=18 func=__vf_ip_route_input_rcu line=1989 msg="find a route: flag=80000000 gw-0.0.0.0 via root"
id=65308 trace_id=18 func=fw_local_in_handler line=620 msg="iprope_in_check() check failed on policy 0, drop"
id=65308 trace_id=19 func=print_pkt_detail line=6005 msg="vd-root:0 received a packet(proto=17, 192.168.1.212:38409->192.168.1.45:161) tun_id=0.0.0.0 from x5. "
id=65308 trace_id=19 func=init_ip_session_common line=6204 msg="allocate a new session-31df7d93"
id=65308 trace_id=19 func=__vf_ip_route_input_rcu line=1989 msg="find a route: flag=80000000 gw-0.0.0.0 via root"
id=65308 trace_id=19 func=fw_local_in_handler line=620 msg="iprope_in_check() check failed on policy 0, drop"
id=65308 trace_id=20 func=print_pkt_detail line=6005 msg="vd-root:0 received a packet(proto=17, 192.168.1.212:38409->192.168.1.45:161) tun_id=0.0.0.0 from x5. "
id=65308 trace_id=20 func=init_ip_session_common line=6204 msg="allocate a new session-31df8aa5"
id=65308 trace_id=20 func=__vf_ip_route_input_rcu line=1989 msg="find a route: flag=80000000 gw-0.0.0.0 via root"
id=65308 trace_id=20 func=fw_local_in_handler line=620 msg="iprope_in_check() check failed on policy 0, drop"
id=65308 trace_id=21 func=print_pkt_detail line=6005 msg="vd-root:0 received a packet(proto=17, 192.168.1.212:38409->192.168.1.45:161) tun_id=0.0.0.0 from x5. "id=65308 trace_id=21 func=print_pkt_detail line=6005 msg="vd-root:0 received a packet(proto=17, 172.16.1.212:38409->172.16.1.45:161) tun_id=0.0.0.0 from x5. "
Even if I allow this traffic with local-in-policy (I also tried src and service all), the traffic still drops to policy 0.
Any idea what could be the problem?
Thanks,
