Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
motorbass
New Contributor III

Can't use SNMPv3 on Meraki AP on FortiNAC

Hi

We're currently trying FortiNAC v7.2.5.0101, everything runs smoothly for most of our devices except for Meraki AP.

 

We follow this guide for configuring/adding the AP https://docs.fortinet.com/document/fortinac-f/7.2.0/network-device-modeling/785561/cisco-meraki-ms-s...

 

Indeed, even though SNMPv3 is enabled on our Meraki oraganization and so AP ( snmpwalk -v3 is ok) FortiNAC always throws an error while trying to add it using S/N as UserName and API Key as Password as you can see below:

fortinac_meraki.png

 

From a firewall perspective we got not deny or any filtering, proof is we can add the same AP using SNMPv2c for instance.

 

From a FortiNAC perspective, there's no such log or information that may helps to troubleshoot this.

 

Any of you guys succeed to use SNMPv3 between FortiNAC and Meraki ?

Thanks a lot for your help & advices

 

FortiNAC  

 

 

 

1 Solution
motorbass
New Contributor III

I finally found the solution from here https://support.auvik.com/hc/en-us/articles/204356740-How-to-enable-SNMP-on-Meraki-devices

 

So credentials to use are those from Network-wide, we agree, but in any case, it has to be SHA1 & DES.

It works pretty smooth, happy to have learnt something today ! :)

View solution in original post

27 REPLIES 27
motorbass
New Contributor III

Just tried for instance with only SHA25 - SNMPv3 AuthNoPriv andresult is same but wireshark changes a little bit.forti3.png

In any case, frame details got some missing parameters so I guess FNAC or Meraki doesn't seems to "talk the same way"

frame_details.png

ozkanaltas

Can you share the Meraki snmp setting with us? 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
motorbass
New Contributor III

For sure :

From the Network-Side :

network_side.png

Username & passphrase configured are those that works when I explained that it works through snmpwalk -v3

 

From the Organisation Side snmpv3 is also enabled with Auth and privkey, but If this one is disabled, snmpwalk -v3 still continue to works :

orga_side.png

motorbass
New Contributor III

I finally found the solution from here https://support.auvik.com/hc/en-us/articles/204356740-How-to-enable-SNMP-on-Meraki-devices

 

So credentials to use are those from Network-wide, we agree, but in any case, it has to be SHA1 & DES.

It works pretty smooth, happy to have learnt something today ! :)

ozkanaltas
Contributor III

I'm glad it worked. However, I shared this document in my first messages. I guess you didn't read :) 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
motorbass
New Contributor III

Hi, i'm so sorry ,indeed you mentionned the url, however my workmate told me he already tried this url that's why I misclick. But thanks again for your help, i do really appreciate it :)

ndumaj
Staff
Staff

I'm glad to hear that it worked.
Well done!

BR

- Happy to help, hit like and accept the solution -
motorbass
New Contributor III

Thanks a lot for your help ! :)

Labels
Top Kudoed Authors