Created on 08-08-2023 01:35 AM Edited on 08-10-2024 06:02 AM By Jean-Philippe_P
Description |
This article describes troubleshooting steps to undertake when an SNMP query from the SNMP manager to the firewall fails. |
Scope | All FortiGate models. |
Solution |
First, verify that there are indeed packets being sent from the SNMP manager to the firewall. To do so, run the following CLI command:
diag sniffer packet any 'host SNMP-manager-ip' 4 0 a
After executing this command, send an SNMP query from the SNMP manager to make sure there are packets reaching the firewall. If the packets do not reach the firewall, validate the internal network.
The SNMP manager IP must be added under System -> SNMP -> SNMP V2 or SNMP V3 settings as shown below:
Also, SNMP should be enabled in the corresponding firewall interface as shown in the image below:
Important: the SNMP community names mentioned in the firewall and the SNMP manager must be the same. For example: in the following SNMP setting, the SNMP community name was configured as 'public', so the same should be defined in the SNMP manager.
Additional Debugs: Conduct a debug flow to verify traffic is being accepted: Reference for debug flow: Troubleshooting Tip: First steps to troubleshoot connectivity problems to or through a FortiGate wit... If the problem persists after verifying all of these settings, contact TAC for further support. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.