Hi
We're currently trying FortiNAC v7.2.5.0101, everything runs smoothly for most of our devices except for Meraki AP.
We follow this guide for configuring/adding the AP https://docs.fortinet.com/document/fortinac-f/7.2.0/network-device-modeling/785561/cisco-meraki-ms-s...
Indeed, even though SNMPv3 is enabled on our Meraki oraganization and so AP ( snmpwalk -v3 is ok) FortiNAC always throws an error while trying to add it using S/N as UserName and API Key as Password as you can see below:
From a firewall perspective we got not deny or any filtering, proof is we can add the same AP using SNMPv2c for instance.
From a FortiNAC perspective, there's no such log or information that may helps to troubleshoot this.
Any of you guys succeed to use SNMPv3 between FortiNAC and Meraki ?
Thanks a lot for your help & advices
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I finally found the solution from here https://support.auvik.com/hc/en-us/articles/204356740-How-to-enable-SNMP-on-Meraki-devices
So credentials to use are those from Network-wide, we agree, but in any case, it has to be SHA1 & DES.
It works pretty smooth, happy to have learnt something today ! :)
Just tried for instance with only SHA25 - SNMPv3 AuthNoPriv andresult is same but wireshark changes a little bit.
In any case, frame details got some missing parameters so I guess FNAC or Meraki doesn't seems to "talk the same way"
Can you share the Meraki snmp setting with us?
For sure :
From the Network-Side :
Username & passphrase configured are those that works when I explained that it works through snmpwalk -v3
From the Organisation Side snmpv3 is also enabled with Auth and privkey, but If this one is disabled, snmpwalk -v3 still continue to works :
I finally found the solution from here https://support.auvik.com/hc/en-us/articles/204356740-How-to-enable-SNMP-on-Meraki-devices
So credentials to use are those from Network-wide, we agree, but in any case, it has to be SHA1 & DES.
It works pretty smooth, happy to have learnt something today ! :)
I'm glad it worked. However, I shared this document in my first messages. I guess you didn't read :)
Hi, i'm so sorry ,indeed you mentionned the url, however my workmate told me he already tried this url that's why I misclick. But thanks again for your help, i do really appreciate it :)
I'm glad to hear that it worked.
Well done!
BR
Thanks a lot for your help ! :)
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1660 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.