OPNsense Forum

English Forums => General Discussion => Topic started by: martin.schaible on April 04, 2019, 10:17:22 pm

Title: SNMP Support
Post by: martin.schaible on April 04, 2019, 10:17:22 pm
Hello

I have installed "net-SNMP". I enabled the service, i have added a valid "SNMP Community" and the "Listen IP". I learned, that the "Listen IP" is the IP-Address of the Firewall, eg. LAN and NOT the IP-address of the monitoring server.

Do i need to do more?

My monitoring server does not receive data from the Firewall at all.

Thanks!

Title: Re: SNMP Support
Post by: fabian on April 04, 2019, 10:38:54 pm
A firewall rule to pass incoming traffic?
Title: Re: SNMP Support
Post by: mimugmail on April 05, 2019, 06:27:27 am
How should the field "Listen IP" worded so that someone knows it should be the local IP address to listen to, as it would otherwise listen to all IPs (leave blank would also be ok)?
Title: Re: SNMP Support
Post by: franco on April 05, 2019, 10:36:34 am
Hide under advanced?


Cheers,
Franco
Title: Re: SNMP Support
Post by: martin.schaible on April 08, 2019, 11:23:04 pm
"Hide under Advanced" -> where to find?

The monitoring server is in the LAN, therefore no rule is needed. Usualy a SNMP Service has entries like:
- Limit SNMP packets to specific hosts
- Trap Destination
- Send Auth Trap

Thanks!
Title: Re: SNMP Support
Post by: hbc on April 10, 2019, 01:53:27 pm
There is no SNMP trap support in gui and hey: OPNsense is a firewall. To limit SNMP to specific hosts, just create a  rule  ;)
Title: Re: SNMP Support
Post by: FraLem on April 10, 2019, 08:54:31 pm
I would suggest to check with tcpdump -i xxx port 161 if the snmp query is reaching the firewall
In my case I didn`t quite get the meaning of lisening Ip, therefore blanck and rule in the WAN interface.
Title: Re: SNMP Support
Post by: martin.schaible on April 12, 2019, 07:44:20 pm
As i wrote, the monitoring server is in the LAN, not WAN. Therefore no rules needed to access them from LAN.

I think, that SNMP has a general problem on my box, while no data is coming at all.
Title: Re: SNMP Support
Post by: bewue on April 18, 2019, 10:42:50 am
Do you have a rule on the LAN interface to allow SNMP traffic?
In the next step check if the SNMP query is received by the firewall like FraLem was mentioning.
Then we can look further.
Title: Re: SNMP Support
Post by: martin.schaible on April 19, 2019, 12:12:54 pm
Ahh, i really had to add a rule from my Monitoring Server as the "Source" to "This Firewall".

Thank you!