OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • SNMP Support
« previous next »
  • Print
Pages: [1]

Author Topic: SNMP Support  (Read 5269 times)

martin.schaible

  • Newbie
  • *
  • Posts: 14
  • Karma: 0
    • View Profile
SNMP Support
« on: April 04, 2019, 10:17:22 pm »
Hello

I have installed "net-SNMP". I enabled the service, i have added a valid "SNMP Community" and the "Listen IP". I learned, that the "Listen IP" is the IP-Address of the Firewall, eg. LAN and NOT the IP-address of the monitoring server.

Do i need to do more?

My monitoring server does not receive data from the Firewall at all.

Thanks!

Logged

fabian

  • Hero Member
  • *****
  • Posts: 2769
  • Karma: 200
  • OPNsense Contributor (Language, VPN, Proxy, etc.)
    • View Profile
    • Personal Homepage
Re: SNMP Support
« Reply #1 on: April 04, 2019, 10:38:54 pm »
A firewall rule to pass incoming traffic?
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6767
  • Karma: 494
    • View Profile
Re: SNMP Support
« Reply #2 on: April 05, 2019, 06:27:27 am »
How should the field "Listen IP" worded so that someone knows it should be the local IP address to listen to, as it would otherwise listen to all IPs (leave blank would also be ok)?
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17703
  • Karma: 1616
    • View Profile
Re: SNMP Support
« Reply #3 on: April 05, 2019, 10:36:34 am »
Hide under advanced?


Cheers,
Franco
Logged

martin.schaible

  • Newbie
  • *
  • Posts: 14
  • Karma: 0
    • View Profile
Re: SNMP Support
« Reply #4 on: April 08, 2019, 11:23:04 pm »
"Hide under Advanced" -> where to find?

The monitoring server is in the LAN, therefore no rule is needed. Usualy a SNMP Service has entries like:
- Limit SNMP packets to specific hosts
- Trap Destination
- Send Auth Trap

Thanks!
Logged

hbc

  • Hero Member
  • *****
  • Posts: 501
  • Karma: 47
    • View Profile
Re: SNMP Support
« Reply #5 on: April 10, 2019, 01:53:27 pm »
There is no SNMP trap support in gui and hey: OPNsense is a firewall. To limit SNMP to specific hosts, just create a  rule  ;)
Logged
Intel(R) Xeon(R) Silver 4116 CPU @ 2.10GHz (24 cores)
256 GB RAM, 300GB RAID1, 3x4 10G Chelsio T540-CO-SR

FraLem

  • Jr. Member
  • **
  • Posts: 83
  • Karma: 2
    • View Profile
Re: SNMP Support
« Reply #6 on: April 10, 2019, 08:54:31 pm »
I would suggest to check with tcpdump -i xxx port 161 if the snmp query is reaching the firewall
In my case I didn`t quite get the meaning of lisening Ip, therefore blanck and rule in the WAN interface.
Logged

martin.schaible

  • Newbie
  • *
  • Posts: 14
  • Karma: 0
    • View Profile
Re: SNMP Support
« Reply #7 on: April 12, 2019, 07:44:20 pm »
As i wrote, the monitoring server is in the LAN, not WAN. Therefore no rules needed to access them from LAN.

I think, that SNMP has a general problem on my box, while no data is coming at all.
Logged

bewue

  • Newbie
  • *
  • Posts: 35
  • Karma: 3
    • View Profile
Re: SNMP Support
« Reply #8 on: April 18, 2019, 10:42:50 am »
Do you have a rule on the LAN interface to allow SNMP traffic?
In the next step check if the SNMP query is received by the firewall like FraLem was mentioning.
Then we can look further.
Logged

martin.schaible

  • Newbie
  • *
  • Posts: 14
  • Karma: 0
    • View Profile
Re: SNMP Support
« Reply #9 on: April 19, 2019, 12:12:54 pm »
Ahh, i really had to add a rule from my Monitoring Server as the "Source" to "This Firewall".

Thank you!
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • SNMP Support
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2