<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA Failover Cluster: SNMP configuration was not replicated comple in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-failover-cluster-snmp-configuration-was-not-replicated/m-p/4981333#M1107070</link>
    <description>&lt;P&gt;Hi tvotna,&lt;BR /&gt;&lt;BR /&gt;thanks for your fast reply!&lt;BR /&gt;&lt;BR /&gt;Unfortunately the manual re-enter of teh commands on the active unit did not solve the issue:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;ENAM-ASA01/pri/act(config)# snmp-server user nocuser nocasa4check v3 engineID &amp;lt;engine-ID&amp;gt; encrypted auth sha &amp;lt;key deleted&amp;gt; priv aes 128 &amp;lt;key deleted&amp;gt;
WARNING: This command cannot be replicated because it contains localized keys.
ENAM-ASA01/pri/act(config)# snmp-server host Transfer 10.9.0.15 version 3 nocuser
ENAM-ASA01/pri/act(config)# wr mem
Building configuration...
&lt;/LI-CODE&gt;
&lt;P&gt;Is there any other option I could try?&lt;BR /&gt;&lt;BR /&gt;Thanks a lot!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Bye&lt;BR /&gt;R.&lt;/P&gt;</description>
    <pubDate>Tue, 19 Dec 2023 11:13:21 GMT</pubDate>
    <dc:creator>swscco001</dc:creator>
    <dc:date>2023-12-19T11:13:21Z</dc:date>
    <item>
      <title>ASA Failover Cluster: SNMP configuration was not replicated completely</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-cluster-snmp-configuration-was-not-replicated/m-p/4979936#M1106996</link>
      <description>&lt;P&gt;Hello everybody,&lt;BR /&gt;&lt;BR /&gt;we had to replace the standby-node of a&amp;nbsp;ASA Failover Cluster (9.14(3)18)) because a HW defect.&lt;BR /&gt;&lt;BR /&gt;After cluster re-establishment our monitoring complained because several SNMP values&lt;BR /&gt;could not be requested. On the primary node all is ok.&lt;BR /&gt;&lt;BR /&gt;I checked the failover status:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;ENAM-ASA01/pri/act# sh fa
Failover On
Failover unit Primary
Failover LAN Interface: HEARTBEAT Ethernet1/16 (up)
Reconnect timeout 0:00:00
Unit Poll frequency 1 seconds, holdtime 15 seconds
Interface Poll frequency 5 seconds, holdtime 25 seconds
Interface Policy 1
Monitored Interfaces 1 of 1293 maximum
MAC Address Move Notification Interval not set
Cipher in use: 3DES/AES
Version: Ours 9.14(3)18, Mate 9.14(3)18
Serial Number: Ours JAD2444020W, Mate JAD23130VMN
Last Failover at: 10:00:37 CET Dec 9 2023
        This host: Primary - Active
                Active time: 618451 (sec)
                slot 0: FPR-2130 hw/sw rev (1.4/9.14(3)18) status (Up Sys)
                  Interface Transfer (10.9.0.10): Normal (Not-Monitored)
                  Interface outside (185.247.62.10): Normal (Monitored)
                  Interface management (10.31.131.155): Normal (Not-Monitored)
        Other host: Secondary - Standby Ready
                Active time: 0 (sec)
                slot 0: FPR-2130 hw/sw rev (1.4/9.14(3)18) status (Up Sys)
                  Interface Transfer (10.9.0.11): Normal (Not-Monitored)
                  Interface outside (185.247.62.11): Normal (Monitored)
                  Interface management (10.31.131.153): Normal (Not-Monitored)&lt;/LI-CODE&gt;
&lt;P&gt;Then I compared the SNMP configuration of both nodes:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;Active:

ENAM-ASA01/pri/act# sh run | in snmp
snmp-server group nocasa4check v3 priv
snmp-server user nocuser nocasa4check v3 engineID &amp;lt;engineID deleted&amp;gt; encrypted auth sha &amp;lt;key deleted&amp;gt;
snmp-server host Transfer 10.9.0.15 version 3 nocuser
no snmp-server location
no snmp-server contact
snmp-server community *****
no snmp-server enable oid mempool
class-map class_snmp
 class class_snmp
  inspect snmp

------------------------------------------------------------------------

Standby:

ENAM-ASA01/sec/stby# sh run | in snmp
snmp-server group nocasa4check v3 priv
no snmp-server location
no snmp-server contact
snmp-server community *****
no snmp-server enable oid mempool
class-map class_snmp
 class class_snmp
  inspect snmp&lt;/LI-CODE&gt;
&lt;P&gt;Even if I enter 'wr mem' on the active node the SNMP configuration was not&lt;BR /&gt;replicated to the standby.&lt;BR /&gt;&lt;BR /&gt;All other configuration was replicated.&lt;BR /&gt;&lt;BR /&gt;How can I solve the issue?&lt;BR /&gt;&lt;BR /&gt;Thanks a lot for every hint!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Bye&lt;BR /&gt;R.&lt;/P&gt;</description>
      <pubDate>Sat, 16 Dec 2023 13:17:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-cluster-snmp-configuration-was-not-replicated/m-p/4979936#M1106996</guid>
      <dc:creator>swscco001</dc:creator>
      <dc:date>2023-12-16T13:17:12Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover Cluster: SNMP configuration was not replicated comple</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-cluster-snmp-configuration-was-not-replicated/m-p/4979944#M1106997</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF6600"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - FYI :&lt;/FONT&gt;&amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvy60100" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvy60100&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Dec 2023 14:24:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-cluster-snmp-configuration-was-not-replicated/m-p/4979944#M1106997</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2023-12-16T14:24:23Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover Cluster: SNMP configuration was not replicated comple</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-cluster-snmp-configuration-was-not-replicated/m-p/4979962#M1106998</link>
      <description>&lt;P&gt;This is expected behavior and the mentioned bug is not relevant for you.&lt;/P&gt;&lt;P&gt;Before 9.14 SNMP user information was hashed by the local SNMP engine-id in the configuration. Active and standby ASA exchanged engine-id over failover link and put two instances of the "snmp-server user" command into configuration: each hashed by the corresponding engine-id.&lt;/P&gt;&lt;P&gt;In 9.14 and above behavior was changed again and documented by the CSCvx18878. SNMP engine-id is no longer synchronized over failover link and each unit uses its own local engine-id to hash "snmp-server user". There is only one copy of the "snmp-server user" command in the config.&lt;/P&gt;&lt;P&gt;When the ASA is replaced, the new ASA has new SNMP engine-id and hence cannot accept "snmp-server user" from its peer during config sync, because hashing is a one-way function. Hence, "snmp-server user" is rejected on the new standby unit. You need to re-enter "snmp-server user" and "snmp-server host" manually on the active unit specifying passwords in clear text and then do "write mem". The commands will be synced in clear to standby, local engine-ID applied and resulting configuration saved.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Dec 2023 15:37:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-cluster-snmp-configuration-was-not-replicated/m-p/4979962#M1106998</guid>
      <dc:creator>tvotna</dc:creator>
      <dc:date>2023-12-16T15:37:06Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover Cluster: SNMP configuration was not replicated comple</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-cluster-snmp-configuration-was-not-replicated/m-p/4981333#M1107070</link>
      <description>&lt;P&gt;Hi tvotna,&lt;BR /&gt;&lt;BR /&gt;thanks for your fast reply!&lt;BR /&gt;&lt;BR /&gt;Unfortunately the manual re-enter of teh commands on the active unit did not solve the issue:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;ENAM-ASA01/pri/act(config)# snmp-server user nocuser nocasa4check v3 engineID &amp;lt;engine-ID&amp;gt; encrypted auth sha &amp;lt;key deleted&amp;gt; priv aes 128 &amp;lt;key deleted&amp;gt;
WARNING: This command cannot be replicated because it contains localized keys.
ENAM-ASA01/pri/act(config)# snmp-server host Transfer 10.9.0.15 version 3 nocuser
ENAM-ASA01/pri/act(config)# wr mem
Building configuration...
&lt;/LI-CODE&gt;
&lt;P&gt;Is there any other option I could try?&lt;BR /&gt;&lt;BR /&gt;Thanks a lot!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Bye&lt;BR /&gt;R.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2023 11:13:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-cluster-snmp-configuration-was-not-replicated/m-p/4981333#M1107070</guid>
      <dc:creator>swscco001</dc:creator>
      <dc:date>2023-12-19T11:13:21Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover Cluster: SNMP configuration was not replicated comple</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-cluster-snmp-configuration-was-not-replicated/m-p/4981336#M1107071</link>
      <description>&lt;P&gt;Hi cora9881,&lt;BR /&gt;&lt;BR /&gt;thanks for your reply but this is not an active/active cluster but a normal active/standby.&lt;BR /&gt;&lt;BR /&gt;Thanks a lot!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Bye&lt;BR /&gt;R.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2023 11:15:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-cluster-snmp-configuration-was-not-replicated/m-p/4981336#M1107071</guid>
      <dc:creator>swscco001</dc:creator>
      <dc:date>2023-12-19T11:15:07Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover Cluster: SNMP configuration was not replicated comple</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-cluster-snmp-configuration-was-not-replicated/m-p/4981366#M1107075</link>
      <description>&lt;P&gt;You need to enter passwords on the active unit in this command in clear text and don't specify engine-id. Refer to command reference for exact syntax.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2023 12:39:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-cluster-snmp-configuration-was-not-replicated/m-p/4981366#M1107075</guid>
      <dc:creator>tvotna</dc:creator>
      <dc:date>2023-12-19T12:39:44Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover Cluster: SNMP configuration was not replicated comple</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-cluster-snmp-configuration-was-not-replicated/m-p/4981535#M1107090</link>
      <description>&lt;P&gt;Hi tvotna,&lt;BR /&gt;&lt;BR /&gt;I misunderstood your first reply.&lt;BR /&gt;&lt;BR /&gt;After entering the 'snmp-ser user' command without engine ID and clear-text password the monitoring can&amp;nbsp; request the data again.&lt;BR /&gt;&lt;BR /&gt;Thanks a lot!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Bye&lt;BR /&gt;R.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2023 15:59:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-cluster-snmp-configuration-was-not-replicated/m-p/4981535#M1107090</guid>
      <dc:creator>swscco001</dc:creator>
      <dc:date>2023-12-19T15:59:01Z</dc:date>
    </item>
  </channel>
</rss>

