<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic snmp polling across firewalls in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/snmp-polling-across-firewalls/m-p/2390131#M307368</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello julio,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not getting data. I would have thought it possible for the snmp server to poll the firewall interface. I am not seeing any hits on the rule for the cross site connection i.e the snmp server 1 to firewall 2 or snmp server 2 to firewall 1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 10 Dec 2013 21:54:20 GMT</pubDate>
    <dc:creator>Roy Lindo</dc:creator>
    <dc:date>2013-12-10T21:54:20Z</dc:date>
    <item>
      <title>snmp polling across firewalls</title>
      <link>https://community.cisco.com/t5/network-security/snmp-polling-across-firewalls/m-p/2390129#M307363</link>
      <description>&lt;P&gt;I have an issue with my firewalls polling my snmp stations.&amp;nbsp; The issue is that my smnp server is unable to poll a connected interface on the firewall on a different network. We are using two /24 networks across a managed connection for redundancy purposes. At either end of the managed connection there is an asa firewall, the firewalls are configured with /24 networks. There is a snmp server on one of the /24 network on either side of managed connection, the servers default gateway points to the firewall connected interface i.e snmp server 1 has an IP address of 10.10.30.13/24 and a gateway of 10.10.30.1 (firewall 1) and snmp server 2 on the other side of the managed connection has a ip address of 10.10.31.13/24 and a gateway of 10.10.31.1(firewall 2), the .1 addresses are the physical interfaces on the friewalls. There is a transit network configured between the firewalls to allow for the routing of traffic between the 10.10.30/24 and 10.10.31/24 networks. The transit&amp;nbsp; network has an interface with an IP address 10.10.222.1/31 on the firewall on the left side (firewall 1) of the managed connection and an IP address of 10.10.222.2/31 on the firewall on the right side (firewall 2) of the managed connection. Routes have been set up on the firewalls to the 10.10.30.0/24 and 10.10.31.0/24 via the transit network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem I am having is that the snmp server at 10.10.30.13/24 is not able to poll the firewall interface 10.10.31.1 (firewall 2) and the server at 10.10.31.13 is also not able to poll the firewall interface at 10.10.30.1 (firewall 1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The routing and snmp configuration is listed below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Firewall 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route&lt;/P&gt;&lt;P&gt;10.10.31.0/24 via 10.10.222.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Snmp config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Listerning port 161&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;snmp host access list&lt;/P&gt;&lt;P&gt;interface_name 10.10.30.13, community string, snmp version 2c, poll/trap, port 162&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A any any access rule is used on the transit interface on either side of the connection&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and a access list has been configured on 10.10.30.1 interface which allows snmp traffic from 10.10.31.13&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Firewall 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route &lt;/P&gt;&lt;P&gt;10.10.30.0/24 via 10.10.222.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Snmp config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Listerning port 161&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;snmp host access list&lt;/P&gt;&lt;P&gt;interface_name 10.10.31.13, community string, snmp version 2c, poll/trap, port 162&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A any any access rule is used on the transit interface on either side of the connection&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and a access list has been configured on 10.10.31.1 interface which allows snmp traffic from 10.10.30.13&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have been looking at this problem for sometime without much success, can you kindly help&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:15:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-polling-across-firewalls/m-p/2390129#M307363</guid>
      <dc:creator>Roy Lindo</dc:creator>
      <dc:date>2019-03-12T03:15:25Z</dc:date>
    </item>
    <item>
      <title>snmp polling across firewalls</title>
      <link>https://community.cisco.com/t5/network-security/snmp-polling-across-firewalls/m-p/2390130#M307366</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Roy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you mean it's not able to get data for that interface???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or do you mean you are trying to connect to that IP address?? Cause if that is the case it will never happen as you cannot contact a distant interface (If I am on inside I can ping , ssh, telnet inside but If I will never be able to contac the DMZ interface IP address or outside,etc)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rate all of the helpful posts!!! &lt;BR /&gt; &lt;BR /&gt;Regards, &lt;BR /&gt; &lt;BR /&gt;Jcarvaja &lt;BR /&gt; &lt;BR /&gt;&lt;SPAN&gt;Follow me on &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Dec 2013 17:11:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-polling-across-firewalls/m-p/2390130#M307366</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-12-10T17:11:26Z</dc:date>
    </item>
    <item>
      <title>snmp polling across firewalls</title>
      <link>https://community.cisco.com/t5/network-security/snmp-polling-across-firewalls/m-p/2390131#M307368</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello julio,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not getting data. I would have thought it possible for the snmp server to poll the firewall interface. I am not seeing any hits on the rule for the cross site connection i.e the snmp server 1 to firewall 2 or snmp server 2 to firewall 1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Dec 2013 21:54:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-polling-across-firewalls/m-p/2390131#M307368</guid>
      <dc:creator>Roy Lindo</dc:creator>
      <dc:date>2013-12-10T21:54:20Z</dc:date>
    </item>
  </channel>
</rss>

