Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Juls
New Contributor

Enabling SNMP on Fortigate 200B FortiOS v4.0,build0672,130904 (MR3 Patch 15)

Hi, I' m trying to enable SNMP on my Fortigate 200B FortiOS v4.0 MR3 Patch 15. I already checked SNMP on its interface and already configured SNMP v3 user. But upon performing port scan It doesn' t show that port 161/SNMP is opened. Here is SNMP v3 configuration: =================================================== name : zbx-fortinet events : cpu-high mem-low log-full intf-ip vpn-tun-up vpn-tun-down ha-switch ha-hb-failure ips-signature ips-anomaly av-virus av-oversize av-pattern av-fragmented fm-if-change ha-member-up ha-member-down ent-conf-change av-conserve av-bypass av-oversize-passed av-oversize-blocked ips-pkg-update faz-disconnect ha-direct : disable notify-hosts : 10.12.x.x notify-hosts6 : queries : enable query-port : 161 security-level : no-auth-no-priv ===================================================
Thanks, Juls
Thanks, Juls
4 REPLIES 4
Dave_Hall
Honored Contributor

Does " get system snmp sysinfo" actually show the SNMP agent running?
 # get system snmp sysinfo
 
 contact-info        : 
 description         : 
 engine-id           : 
 location            : 
 status              : disable 
 trap-high-cpu-threshold: 80
 trap-log-full-threshold: 90
 trap-low-memory-threshold: 80
 

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Juls
New Contributor

Hi,

 

Yes SNMP is enable

=========================

---_Cloud01_~ # get system snmp sysinfo contact-info        : ------ description         : ------ engine-id           : (null) location            : ----- status              : enable trap-high-cpu-threshold: 80 trap-log-full-threshold: 90 trap-low-memory-threshold: 80

Thanks, Juls
Thanks, Juls
Dave_Hall
Honored Contributor

No Admin IP address restriction placed on that interface? No Local-in policy in place? Have you tried snmpwalk? Does triggering an event show up on your SNMP manager?

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Juls
New Contributor

No Admin IP address restriction placed on that interface? - None

No Local-in policy in place? - None

Have you tried snmpwalk? - I just tried to use Getif running on my windows virtual machine on my laptop and there's no response from fortinet. BTW I'm doing all of this remotely and accessing the Fortinet via SSLVPN

Does triggering an event show up on your SNMP manager? - The SNMP manager query on port 161 timesout

Thanks, Juls
Thanks, Juls
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors