Skip to main content
rg_586
New Member
November 4, 2022
Solved

SNMP Traffic not able to poll VDOM (multiple vdom setup)

  • November 4, 2022
  • 17 replies
  • 13945 views

Hello

 

I am working with Fortinet 201E v7.2 1157

Please see diagram in reference to my issue below.

So far, I have setup multiple vdoms. Traffic will go through hit the Root VDOM then it should go to VDOM 1.

To browse to the Firewall I use VDOM 1 - Port 1 sub interface address.

This works fine.

At Global Level I have added SNMP settings and I can see traffic hitting the firewall through packet capture, but then I do not know where it is going.

SNMP polling fails.

 

My question is; how do I link ROOT VDOM to VDOM 1?

I have tried a VDOM - LINK and I created a rule in the rule base of VDOM 1 to SNMP IP, but this failed, no traffic or logs.

 

Do I need a static route on ROOT VDOM context to VDOM 1 context.

 

The setup seems so simple but I am not sure why SNMP cannot talk to VDOM 1 but I can browse to it. Port 1 sub interface is management, I have a HA setup as well, Active-Passive. IMG_2756.jpg

 

 

I do not use the management port, this is for local access only.

 

All help is appreciated, thanks.

 

Best answer by rg_586

This topic can be closed. I have figured out the issue. I changed management VDOM to be Management VDOM 1 as my root and SNMP kicked in and started working. Thanks for everyones help.

17 replies

gfleming
Staff
Staff
November 4, 2022

SNMP is configured in the Global VDOM. You need to define the hosts that have access to the SNMP communities: https://docs.fortinet.com/document/fortigate/7.2.2/administration-guide/547825/snmp-v1-v2c-communities

 

You need to allow SNMP access on the relevant interfaces in each VDOM: https://docs.fortinet.com/document/fortigate/7.2.2/administration-guide/325005/interface-access

 

Is that all done accordingly?

 

rg_586
rg_586Author
New Member
November 4, 2022

@gflemingThanks for your reply, I've configured the hosts in the Global SNMP section, I've got SNMP enabled on Port 1 physically and on the sub-interface.

 

My first thought was to try break down the problem. I'm not 100% sure in a multiple vdom solution where traffic hits first, does it hit the Root VDOM?

If it does hit the Root VDOM, then that's why i think i needed a static route to the vdom sub-interface port 1.

 

gfleming
Staff
Staff
November 4, 2022

If your SNMP polling station is outside of VDOM1 (i.e. it does not connect directly to the sub-interface) then just poll on port1. You don't need to poll the sub interface. SNMPwalk on port1 will give you all the same details.

 

But yes to answer your other concern, you absolutely need routes and fw policies to allow traffic to and from different VDOMs.

gfleming
Staff
Staff
November 5, 2022

Sí, parece que necesita acceder a una interfaz en el VDOM de administración.

 

https://community.fortinet.com/t5/FortiGate/Note-for-configuring-SNMP-when-using-it-with-VDOM-enabled/ta-p/194853

rg_586
rg_586Author
New Member
November 7, 2022

@gflemingI've followed what you have said, and checked my articles. I've now made my VDOM 1 the management VDOM. And I was hoping this would then accept the SNMP queries & traps but it didn't. I may leave this post open to let others see it and share there input.

I have Solarwinds polling the device which is a good start.

gfleming
Staff
Staff
November 7, 2022

This should work. Can you please provide details:

  • IP address of the SNMP polling station (solarwinds)
  • IP address of the interface of the FortiGate
  • Ping from polling station to interface is successful
  • What is the path from polling station to interface on FortiGate?

Can you show output of:

show system interface <subinterface> (interface you want to poll)
show system snmp community 

 

rg_586
rg_586Author
New Member
November 9, 2022

@gfleming 

 

I'm working with this Article now, it was updated yesterday and i will make changes at some point to et vdom in community.

rg_586
rg_586Author
New Member
November 19, 2022

@gflemingapologies I was working on something else, unfortunately I cannot send out any configs which is a real shame hence the diagram and my explanations. 

 

So i've got the right settings, i can ping my sub interface, however the traffic just goes down a black hole from the SNMP server.

I am now on the latest version.

Do I need to setup a VDOM-Link from Root to VDOM 1?

In the root VDOM I have no static routes but when browsing to the firewall it is fine. And I have this all setup on Port1 sub interface 1. Which is really odd why SNMP cannot get out.

I followed the last article I posted in the comment before.

gfleming
Staff
Staff
November 19, 2022

Hi it's still not clear can you please be very clear:

- Can you ping your sub interface from the SNMP server? (It sounds like you can but other traffic goes down a black hole, but I'm not sure exactly what you mean)

- If traffic from your SNMP server is traversing your Root VDOM to VDOM 1 why do you insist on polling the interface in VDOM 1? Why not poll the interface in the Root VDOM?

rg_586
rg_586AuthorAnswer
New Member
December 4, 2022

This topic can be closed. I have figured out the issue. I changed management VDOM to be Management VDOM 1 as my root and SNMP kicked in and started working. Thanks for everyones help.

gfleming
Staff
Staff
December 5, 2022

Glad you figured it out! This solution was presented earlier please consider marking the other reply as solution as well, thank you.

 

https://community.fortinet.com/t5/Fortinet-Forum/SNMP-Traffic-not-able-to-poll-VDOM-multiple-vdom-setup/m-p/229003/highlight/true#M202414

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!