Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Zato02
New Contributor II

SNMP No Response After Firmware Update on FortiGate 60F(7.2.2 to 7.2.4) non-managed vdom interface

After updating the firmware of the Fortigate 60F from 7.2.2 to 7.2.4, I encountered that SNMP responses stopped coming from the interface configured on the non-managed VDOM.
The configuration is as follows: SNMP server → Managed VDOM → Non-managed VDOM (SNMP target interface).
The administrator's trusted host is also registered with a /32.
The firewall policies between the VDOMs are verified to be correct. No changes were made during the update.
Additionally, I have configured the set vdoms as described in the URL below, but nothing has changed.

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Configure-SNMP-in-multi-vdom-to-send...

 

When checking the communication logs in the managed VDOM, allowed communication from the SNMP server IP to the SNMP target interface is visible. However, in both send and receive directions, the received byte count is 0B.
Using a sniffer in the managed VDOM, no response packets are observed.
Similarly, a sniffer on the non-managed VDOM shows transmitted packets, but no response packets are received.

The community name is correct, and I have also tried disabling and enabling SNMP.

What configuration adjustments should I consider? Your advice would be greatly appreciated.

 

1 Solution
Zato02
New Contributor II

Ultimately, I couldn't find any issues with the routes or policies (since they were working initially), and based on other articles, it is mentioned that being a managed VDOM is a condition for SNMP monitoring. Therefore, as a test, I changed the managed VDOM to a VDOM that has an SNMP target interface, and the SNMP monitoring was restored.

The operation was simple, but since I wasn't sure what might be affected, I proceeded cautiously. However, the HTTPS GUI management interface remained stable, and I was able to successfully restore the system to the desired state.

Conversely, it seems that in versions 7.0.5 and 7.2.2, SNMP monitoring is possible even on interfaces of unmanaged VDOMs. Thank you very much for your response.

View solution in original post

3 REPLIES 3
funkylicious
SuperUser
SuperUser

have you tried disabling/uncheck SNMP under administrative access on the interface that you are polling and then re-enabling it?

try doing even a diag sniffer packet on it to see what happens with the packets.

"jack of all trades, master of none"
"jack of all trades, master of none"
Zato02
New Contributor II

Thank you for your reply.
I tried toggling the ON/OFF setting, but it made no difference.
I checked with a sniffer, and the traffic is as follows:

 

Tunnel in (SNMP server IP).(port#) -> (SNMP target interface IP).(port 161): UDP
VDOM link 1 out (SNMP server IP).(port#) -> (SNMP target interface IP).(port 161): UDP
VDOM link 2 in (SNMP server IP).(port#) -> (SNMP target interface IP).(port 161): UDP

 

This is the only traffic I see now.
Before the update, the output was:

 

Tunnel in (SNMP server IP).(port#) -> (SNMP target interface IP).(port 161): UDP
VDOM link 1 out (SNMP server IP).(port#) -> (SNMP target interface IP).(port 161): UDP
VDOM link 2 in (SNMP server IP).(port#) -> (SNMP target interface IP).(port 161): UDP

Tunnel out (SNMP target interface IP).(port 161) -> (SNMP server IP).(port#): UDP

Zato02
New Contributor II

Ultimately, I couldn't find any issues with the routes or policies (since they were working initially), and based on other articles, it is mentioned that being a managed VDOM is a condition for SNMP monitoring. Therefore, as a test, I changed the managed VDOM to a VDOM that has an SNMP target interface, and the SNMP monitoring was restored.

The operation was simple, but since I wasn't sure what might be affected, I proceeded cautiously. However, the HTTPS GUI management interface remained stable, and I was able to successfully restore the system to the desired state.

Conversely, it seems that in versions 7.0.5 and 7.2.2, SNMP monitoring is possible even on interfaces of unmanaged VDOMs. Thank you very much for your response.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors