<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: snmp on fpr 1150 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4415237#M1081399</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you post the configuration for the SNMP in the FTD you mentioned before in order to crosscheck?&lt;/P&gt;</description>
    <pubDate>Wed, 09 Jun 2021 09:17:34 GMT</pubDate>
    <dc:creator>kostasthedelegate</dc:creator>
    <dc:date>2021-06-09T09:17:34Z</dc:date>
    <item>
      <title>snmp on fpr 1150</title>
      <link>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4409188#M1081081</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have an FPR 1150 with FTD 6.6.1 managed locally(FDM)&lt;/P&gt;&lt;P&gt;Does it support SNMP configuration?&lt;/P&gt;&lt;P&gt;Is there a guide?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks and regards,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Konstantinos&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 04:55:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4409188#M1081081</guid>
      <dc:creator>kostasthedelegate</dc:creator>
      <dc:date>2021-05-27T04:55:37Z</dc:date>
    </item>
    <item>
      <title>Re: snmp on fpr 1150</title>
      <link>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4409191#M1081082</link>
      <description>&lt;P&gt;Only via Flexconfig. There's an example buried in this page:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/660/fdm/fptd-fdm-config-guide-660/fptd-fdm-advanced.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/660/fdm/fptd-fdm-config-guide-660/fptd-fdm-advanced.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;They removed that in 6.7 and restricted it to via API - even uglier.&lt;/P&gt;
&lt;P&gt;Generally speaking, FDM and SNMP don't play well together (easily) on 6.x. You can do it but it's likely to leave you frustrated by the very rudimentary support.&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 05:02:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4409191#M1081082</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-05-27T05:02:45Z</dc:date>
    </item>
    <item>
      <title>Re: snmp on fpr 1150</title>
      <link>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4409198#M1081083</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I deployed it and we see if it goes well!!&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 05:28:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4409198#M1081083</guid>
      <dc:creator>kostasthedelegate</dc:creator>
      <dc:date>2021-05-27T05:28:31Z</dc:date>
    </item>
    <item>
      <title>Re: snmp on fpr 1150</title>
      <link>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4409211#M1081085</link>
      <description>&lt;P&gt;You're welcome.&lt;/P&gt;
&lt;P&gt;By the way, the "SNMP config via API-only" constraint remains with FDM-managed FTD 7.0 devices.&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 06:09:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4409211#M1081085</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-05-27T06:09:54Z</dc:date>
    </item>
    <item>
      <title>Re: snmp on fpr 1150</title>
      <link>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4409874#M1081107</link>
      <description>&lt;P&gt;Well I created a Flex object and entered the required config but it did not work&lt;/P&gt;&lt;P&gt;This is the policy&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="snmp.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/121401i62729F64644792F5/image-size/large?v=v2&amp;amp;px=999" role="button" title="snmp.PNG" alt="snmp.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 28 May 2021 05:23:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4409874#M1081107</guid>
      <dc:creator>kostasthedelegate</dc:creator>
      <dc:date>2021-05-28T05:23:26Z</dc:date>
    </item>
    <item>
      <title>Re: snmp on fpr 1150</title>
      <link>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4410135#M1081118</link>
      <description>&lt;P&gt;"it did not work" - how? Did the flexconfig deploy successfully into running-config? If so, are you unable to poll the appliance?&lt;/P&gt;</description>
      <pubDate>Fri, 28 May 2021 13:53:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4410135#M1081118</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-05-28T13:53:34Z</dc:date>
    </item>
    <item>
      <title>Re: snmp on fpr 1150</title>
      <link>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4410797#M1081166</link>
      <description>&lt;P&gt;Yes it deployed successfully&lt;/P&gt;&lt;P&gt;I cannot see only the last command&lt;/P&gt;</description>
      <pubDate>Mon, 31 May 2021 05:08:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4410797#M1081166</guid>
      <dc:creator>kostasthedelegate</dc:creator>
      <dc:date>2021-05-31T05:08:00Z</dc:date>
    </item>
    <item>
      <title>Re: snmp on fpr 1150</title>
      <link>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4410863#M1081172</link>
      <description>&lt;P&gt;So when you poll the device, does it accept the queries from your SNMP manager? Do you not get what you expected? Please provide more information about what doesn't work.&lt;/P&gt;</description>
      <pubDate>Mon, 31 May 2021 08:29:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4410863#M1081172</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-05-31T08:29:10Z</dc:date>
    </item>
    <item>
      <title>Re: snmp on fpr 1150</title>
      <link>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4410880#M1081176</link>
      <description>&lt;P&gt;The FW is the server and the client I get timeout on the management interface of the FW from the SNMP&amp;nbsp;&lt;/P&gt;&lt;P&gt;and when I tried the inside interface I get no response&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will it work on the management interface??&lt;/P&gt;</description>
      <pubDate>Mon, 31 May 2021 09:27:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4410880#M1081176</guid>
      <dc:creator>kostasthedelegate</dc:creator>
      <dc:date>2021-05-31T09:27:05Z</dc:date>
    </item>
    <item>
      <title>Re: snmp on fpr 1150</title>
      <link>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4410891#M1081177</link>
      <description>&lt;P&gt;SNMP will not work to the management interface since you have "snmp-server host inside"... The inside keyword means that is where the SNMP server is allowed to poll. I would suggest a packet capture on your SNMP manager (client) to see what (if anything) the FTD is replying when you query it. I have deployed several using similar commands and they all worked OK.&lt;/P&gt;</description>
      <pubDate>Mon, 31 May 2021 09:42:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4410891#M1081177</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-05-31T09:42:49Z</dc:date>
    </item>
    <item>
      <title>Re: snmp on fpr 1150</title>
      <link>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4411329#M1081201</link>
      <description>&lt;P&gt;Yes you are right&amp;nbsp;&lt;BR /&gt;I have the inside interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Today I used the MIB from Cisco but I get the following&lt;/P&gt;&lt;P&gt;iso.3.6.1.2.1 = No more variables left in this MIB View (It is past the end of the MIB tree)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 09:38:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4411329#M1081201</guid>
      <dc:creator>kostasthedelegate</dc:creator>
      <dc:date>2021-06-01T09:38:46Z</dc:date>
    </item>
    <item>
      <title>Re: snmp on fpr 1150</title>
      <link>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4411344#M1081203</link>
      <description>&lt;P&gt;Hmm.What are you using to query?&lt;/P&gt;
&lt;P&gt;I just tried (using snmpwalk from the cli of a Prime Infrastructure server) on one of my FTD devices with FTD enabled and got the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;ade # snmpwalk -v2c -c &amp;lt;community string redacted&amp;gt; &amp;lt;address redacted&amp;gt; 1.3.6.1.2.1.1
SNMPv2-MIB::sysDescr.0 = STRING: Cisco Firepower Threat Defense, Version 6.7.0.2 (Build 24), ASA Version 9.15(1)15
SNMPv2-MIB::sysObjectID.0 = OID: SNMPv2-SMI::enterprises.9.1.2407
DISMAN-EVENT-MIB::sysUpTimeInstance = Timeticks: (143251900) 16 days, 13:55:19.00
SNMPv2-MIB::sysContact.0 = STRING: null
SNMPv2-MIB::sysName.0 = STRING:&amp;lt;hostname redacted&amp;gt;
SNMPv2-MIB::sysLocation.0 = STRING: null
SNMPv2-MIB::sysServices.0 = INTEGER: 4
ade # 
&lt;/PRE&gt;
&lt;P&gt;If I back up a level like you used I get a whole long list as output (interface info, counters etc.).&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 10:22:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4411344#M1081203</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-06-01T10:22:04Z</dc:date>
    </item>
    <item>
      <title>Re: snmp on fpr 1150</title>
      <link>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4411349#M1081204</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am using these&lt;/P&gt;&lt;P&gt;snmpwalk -M /usr/local/share/snmp/mibs/cisco/ -v1 -c &amp;lt;community string redacted&amp;gt; &amp;lt;address redacted&amp;gt;&lt;/P&gt;&lt;P&gt;snmpwalk -M /usr/local/share/snmp/mibs/cisco/ -v2c -c &amp;lt;community string redacted&amp;gt; &amp;lt;address redacted&amp;gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 10:35:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4411349#M1081204</guid>
      <dc:creator>kostasthedelegate</dc:creator>
      <dc:date>2021-06-01T10:35:22Z</dc:date>
    </item>
    <item>
      <title>Re: snmp on fpr 1150</title>
      <link>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4411578#M1081207</link>
      <description>&lt;P&gt;Only the basic SNMPv2, SNMPv2-SMI and IF MIBs are supported via the dataplane queries. Those generally suffice to ascertain device status and interface statistics.&lt;/P&gt;
&lt;P&gt;To access Cisco-specific MIBs you need to configure and use the Diagnostic interface which allows you to query the LINA (ASA) subsystem using SNMP.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 18:07:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4411578#M1081207</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-06-01T18:07:37Z</dc:date>
    </item>
    <item>
      <title>Re: snmp on fpr 1150</title>
      <link>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4411782#M1081216</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now I am confused actually.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So you say the query I run is complex?&lt;/P&gt;&lt;P&gt;That is why I get timeout?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I saw that management interface won't reply, isn't that correct?&lt;/P&gt;&lt;P&gt;What should I run?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Konstantinos&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 06:11:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4411782#M1081216</guid>
      <dc:creator>kostasthedelegate</dc:creator>
      <dc:date>2021-06-02T06:11:48Z</dc:date>
    </item>
    <item>
      <title>Re: snmp on fpr 1150</title>
      <link>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4411830#M1081225</link>
      <description>&lt;P&gt;Sorry I dd not mean that it is complex - it is just not supported to query the Cisco-specific MIBs via dataplane interface.&lt;/P&gt;
&lt;P&gt;You would need to give an address to the Diagnostic interface from within FDM. Then update your flexconfig to indicate that the SNMP client is allowed to acess using the Diagnostic interface. Once you have done that, you can query using the Cisco MIBs. The FTD device in that case will look pretty much like an ASA since the LINA subsystem will be handling all of that interaction.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 07:48:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4411830#M1081225</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-06-02T07:48:17Z</dc:date>
    </item>
    <item>
      <title>Re: snmp on fpr 1150</title>
      <link>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4411905#M1081230</link>
      <description>&lt;P&gt;Ok the management address I have now to which interface is assigned to?&lt;/P&gt;&lt;P&gt;Could I use the same?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 10:52:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4411905#M1081230</guid>
      <dc:creator>kostasthedelegate</dc:creator>
      <dc:date>2021-06-02T10:52:28Z</dc:date>
    </item>
    <item>
      <title>Re: snmp on fpr 1150</title>
      <link>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4412067#M1081238</link>
      <description>&lt;P&gt;You need to use the &lt;STRONG&gt;Diagnostic&lt;/STRONG&gt; interface. Here is more detail:&lt;/P&gt;
&lt;P&gt;The physical port labeled Management (or for Firepower Threat Defense Virtual, the Management 0/0 virtual interface) actually has two separate interfaces associated with it.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Management virtual interface&lt;/STRONG&gt;—This IP address is used for system communication. This is the address the system uses for Smart Licensing and to retrieve database updates. You can open management sessions to it (Firepower Device Manager and CLI). You must configure a management address, which is defined on when you first setup the system (or later from the cli using "configure network").&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Diagnostic physical interface&lt;/STRONG&gt;—The physical Management port is actually named Diagnostic. You can use this interface to send syslog messages to an external syslog server, send Netflow records or &lt;STRONG&gt;query the LINA subsystem using SNMP&lt;/STRONG&gt;. Configuring an IP address for the Diagnostic physical interface is optional. This interface appears, and is configurable using Firepower Device Manager, under edit physical interface page under Management 1/1. &lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 16:02:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4412067#M1081238</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-06-02T16:02:19Z</dc:date>
    </item>
    <item>
      <title>Re: snmp on fpr 1150</title>
      <link>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4413882#M1081337</link>
      <description>&lt;P&gt;I am trying this query&lt;/P&gt;&lt;P&gt;snmpwalk -v2c -c &amp;lt;communitystring&amp;gt; &amp;lt;address inside&amp;gt; 1.3.6.1.2.1.1&lt;/P&gt;&lt;P&gt;And I get this&lt;/P&gt;&lt;P&gt;iso.3.6.1.2.1.1 = No more variables left in this MIB View (It is past the end of the MIB tree)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also when I give the command&lt;/P&gt;&lt;P&gt;show snmp-server statistics&lt;BR /&gt;Unable to honour this command now. Please try again later.&lt;/P&gt;&lt;P&gt;I get the above&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Should I enable the snmp from flexconfig only or should I perform some setting somewhere else?&lt;/P&gt;&lt;P&gt;How do I set the version?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jun 2021 09:34:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4413882#M1081337</guid>
      <dc:creator>kostasthedelegate</dc:creator>
      <dc:date>2021-06-07T09:34:19Z</dc:date>
    </item>
    <item>
      <title>Re: snmp on fpr 1150</title>
      <link>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4413910#M1081342</link>
      <description>&lt;P&gt;As i noted in my previous reply, "You need to use the &lt;STRONG&gt;Diagnostic&lt;/STRONG&gt; interface."&lt;/P&gt;
&lt;P&gt;So the flexconfig that you posted earlier should work (assuming you first configure an address for the diagnostic interface) if you substitute "Diagnostic" for "inside".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jun 2021 10:26:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-on-fpr-1150/m-p/4413910#M1081342</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-06-07T10:26:34Z</dc:date>
    </item>
  </channel>
</rss>

