Hi
We're currently trying FortiNAC v7.2.5.0101, everything runs smoothly for most of our devices except for Meraki AP.
We follow this guide for configuring/adding the AP https://docs.fortinet.com/document/fortinac-f/7.2.0/network-device-modeling/785561/cisco-meraki-ms-s...
Indeed, even though SNMPv3 is enabled on our Meraki oraganization and so AP ( snmpwalk -v3 is ok) FortiNAC always throws an error while trying to add it using S/N as UserName and API Key as Password as you can see below:
From a firewall perspective we got not deny or any filtering, proof is we can add the same AP using SNMPv2c for instance.
From a FortiNAC perspective, there's no such log or information that may helps to troubleshoot this.
Any of you guys succeed to use SNMPv3 between FortiNAC and Meraki ?
Thanks a lot for your help & advices
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I finally found the solution from here https://support.auvik.com/hc/en-us/articles/204356740-How-to-enable-SNMP-on-Meraki-devices
So credentials to use are those from Network-wide, we agree, but in any case, it has to be SHA1 & DES.
It works pretty smooth, happy to have learnt something today ! :)
I'm on FNAC 7.2 so I don't have access to the previous and real linux shell, but only to the "forti" layer shell.
From another server, the snmpwalk -v3 to my Meraki AP is working as mentionned earlier.
Hello @motorbass ,
Fortinac can access the switch IP address, right?
yes it has, I can also add it through SNMPv2c for instance.
Wait, you can test the snmpwalk -v3 entering on shell:
exec enter-shell
snmpwalk -v3 -l authPriv -u "XXXXX" -a SHA -A "YYYY" -x des -X "YYYY" 10.10.10.10
https://community.fortinet.com/t5/FortiNAC-F/Troubleshooting-tip-Verify-device-support-in-FortiNAC-F...
BR
Yes i'm currently having a look from the Meraki perspective, i'm troubleshooting through wireshark and let you know once I found something interesting, thanks again for your help folks !
Additional information:
https://community.fortinet.com/t5/FortiNAC/Technical-Note-Permission-requirements-for-modeled-device...
Also please what is the OID of Meraki?
BR
Hi, i'm currently reading both of your doc
OID is :
It seems privKey is not well interpreted (don't know if it's from fnac or Meraki) but both are actually communicating
EDIT:
Got the same kind of flows and messages no matter if i use S/N + API key OR the AuthKey Privkey
You can review this article about privKey Unknow.
https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB0748756
Can you try with another protocol and simple PSK?
BR
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.