Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
HungDT
New Contributor III

SNMP don't response traffic

Hi Everyone,

I have the problem with configure SNMP. I use a pair fortigates model: 201F, version 7.2.7. I config HA mode Active-Passive. So I want to monitor 2 fortigates, I have enable snmp agent and config community snmp v2, config interface administrator access service: snmp, ping, https. Test ping from NMS to Fortigate is successful but when NMS send SNMP get but not receive response packet from Fortigate. Can you help me ? Thanks a lot.

local trafficlocal traffic

1 Solution
srajeswaran

The debug shows the route lookup is happening on vsys_hamgmt vdom, which is default vdom when ha-mgmt is enabled. The interface port5 will be part of root (default vdom) and thats why the SNMP packet is getting dropped. Can you enable "set ha-direct enable" under SNMP community as below and test?

 

 

 

# show system snmp community
config system snmp community
edit 1
set name "hostmonitor"
config hosts
edit 1
set ip 10.5.0.36 255.255.255.255
set ha-direct enable ------>>>>Here
next
end
next
end

 

Regards,
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.

View solution in original post

27 REPLIES 27
HungDT
New Contributor III

HI @AEK @hbac ,

 

10.200.0.36 is NMS server, query to this port 5 on fortigate. Hope you guys help me solve this problem. Thanks a lot.

snmp.jpg

srajeswaran

The debug shows the route lookup is happening on vsys_hamgmt vdom, which is default vdom when ha-mgmt is enabled. The interface port5 will be part of root (default vdom) and thats why the SNMP packet is getting dropped. Can you enable "set ha-direct enable" under SNMP community as below and test?

 

 

 

# show system snmp community
config system snmp community
edit 1
set name "hostmonitor"
config hosts
edit 1
set ip 10.5.0.36 255.255.255.255
set ha-direct enable ------>>>>Here
next
end
next
end

 

Regards,
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
HungDT
New Contributor III

Thank you so much,

My problem has been solved. Port 5 is configed Mangement Interface Reservation, so that block traffic from fortigate to NMS, is that right. Why don't i see block log on forward traffic and local traffic ? 

srajeswaran

We may have to check from vsys_hamgmt vdom as mentioned in below article.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-HA-Reserved-Management-Interface-s-hidden-...

Regards,
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
AEK
SuperUser
SuperUser

Hi Hung

As a test, can you enable SNMP on port5 and send the SNMP query to port5's IP address?

AEK
AEK
HungDT
New Contributor III

HI @AEK ,

I have enabled SNMP on port5 and send the SNMP query to port5's IP address with the previous picture. Do you detect anything unusual in the log

funkylicious
SuperUser
SuperUser

Something is very strange in your config, because in the debug i can see being specified, vsys_hamgmt which typically refers to a ha cluster interface.

 

Can you show the output of the command, show system ha ?

---------------------------
geek
---------------------------
---------------------------geek---------------------------
mahesh_pm
New Contributor III

Hi,

 

please check snmp index in all the interface. 

config system interface

show

Cheers,
Cheers,
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors