<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WLC 2500 - SNMP in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wlc-2500-snmp/m-p/3180093#M110916</link>
    <description>&lt;P&gt;Take a look in packet inspection. Firewall don't like udp cause they have no connection establishment.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 05 Sep 2017 12:55:21 GMT</pubDate>
    <dc:creator>Flavio Miranda</dc:creator>
    <dc:date>2017-09-05T12:55:21Z</dc:date>
    <item>
      <title>WLC 2500 - SNMP</title>
      <link>https://community.cisco.com/t5/wireless/wlc-2500-snmp/m-p/3179011#M110910</link>
      <description>&lt;P&gt;Hi everybody,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm a newbie.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a&amp;nbsp;poller (centreon) in the&amp;nbsp;subnet/VLAN 172.18.96.1/255.255.224.0, i want to supervise my WLC&amp;nbsp;which is the subnet/VLAN 172.18.160.1/255.255.224.0. The WLC&amp;nbsp;subnet contains other&amp;nbsp;switches too. I pass from the first subnet to the second through my ASA 5510.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can succeed snmpget command&amp;nbsp;to WLC from&amp;nbsp;&lt;SPAN&gt;172.18.160.1/255.255.224.0 subnet but not from&amp;nbsp;172.18.96.1/255.255.224.0. So my configuration seems to be ok.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;My first think was the firewall but the rules are permissives, ping, http and https to WLC are ok and snmpget to the&amp;nbsp;switches from&amp;nbsp;172.18.96.1/255.255.224.0 succeeds. There is no issue with ASA packet tracer. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When I try to follow datagram with Wireshark, I can see the get-request and answers packets for the switches but for WLC, I only see the "get-request" packets and&amp;nbsp;no answer.&amp;nbsp;Snmpget give me&amp;nbsp;"timeout"&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I'm using the same snmpv3 configuration for my switches and my wlc.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;snmpget -v 3 -u userrfi -l authPriv -A pass&amp;nbsp;-a MD5 -x DES -X pass&amp;nbsp;172.18.160.100 1.3.6.1.2.1.1.3.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any idea/help would be appreciated.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Merci beaucoup.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 14:36:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-2500-snmp/m-p/3179011#M110910</guid>
      <dc:creator>lambrosx</dc:creator>
      <dc:date>2021-07-05T14:36:13Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 2500 - SNMP</title>
      <link>https://community.cisco.com/t5/wireless/wlc-2500-snmp/m-p/3179197#M110911</link>
      <description>&lt;PRE&gt;debug&amp;nbsp; snmp agent enable&lt;/PRE&gt;&lt;P&gt;snmpwalk from the vlan that does not work and show the output.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 02 Sep 2017 01:33:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-2500-snmp/m-p/3179197#M110911</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2017-09-02T01:33:19Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 2500 - SNMP</title>
      <link>https://community.cisco.com/t5/wireless/wlc-2500-snmp/m-p/3179753#M110912</link>
      <description>&lt;P&gt;To delete&lt;/P&gt;</description>
      <pubDate>Mon, 04 Sep 2017 15:31:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-2500-snmp/m-p/3179753#M110912</guid>
      <dc:creator>lambrosx</dc:creator>
      <dc:date>2017-09-04T15:31:03Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 2500 - SNMP</title>
      <link>https://community.cisco.com/t5/wireless/wlc-2500-snmp/m-p/3179756#M110913</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the same VLAN (IP client : 172.18.160.98) :&lt;/P&gt;&lt;PRE&gt;*SNMPTask: Sep 04 15:55:13.407: SNMPD: Packet from: 172.18.160.98:52901, in_packet_len = 64
*SNMPTask: Sep 04 15:55:13.407: SNMPD: calling srDoSnmp.
*SNMPTask: Sep 04 15:55:13.407: Unknown engine Ids
*SNMPTask: Sep 04 15:55:13.407: SNMPD: Sending SNMP packet to 172.18.160.98:52901, out_packet_len = 107
*SNMPTask: Sep 04 15:55:13.410: SNMPD: Packet from: 172.18.160.98:52901, in_packet_len = 134
*SNMPTask: Sep 04 15:55:13.410: SNMPD: calling srDoSnmp.
*SNMPTask: Sep 04 15:55:13.410: SNMPD: received get pdu
*SNMPTask: Sep 04 15:55:13.410: SNMPD:calling do_response
*SNMPTask: Sep 04 15:55:13.410: Searching for requested instance of sysUpTime
*SNMPTask: Sep 04 15:55:13.411: SNMPD: Sending SNMP packet to 172.18.160.98:52901, out_packet_len = 141&lt;/PRE&gt;&lt;P&gt;On the other (IP client : 172.18.102.5) &amp;nbsp;:&lt;/P&gt;&lt;PRE&gt;*SNMPTask: Sep 04 15:56:06.697: SNMPD: Packet from: 172.18.102.5:50927, in_packet_len = 64
*SNMPTask: Sep 04 15:56:06.697: SNMPD: calling srDoSnmp.
*SNMPTask: Sep 04 15:56:06.697: Unknown engine Ids
*SNMPTask: Sep 04 15:56:06.697: SNMPD: Sending SNMP packet to 172.18.102.5:50927, out_packet_len = 107
*SNMPTask: Sep 04 15:56:07.698: SNMPD: Packet from: 172.18.102.5:50927, in_packet_len = 64
*SNMPTask: Sep 04 15:56:07.698: SNMPD: calling srDoSnmp.
*SNMPTask: Sep 04 15:56:07.698: Unknown engine Ids
*SNMPTask: Sep 04 15:56:07.698: SNMPD: Sending SNMP packet to 172.18.102.5:50927, out_packet_len = 107
*SNMPTask: Sep 04 15:56:08.700: SNMPD: Packet from: 172.18.102.5:50927, in_packet_len = 64
*SNMPTask: Sep 04 15:56:08.700: SNMPD: calling srDoSnmp.
*SNMPTask: Sep 04 15:56:08.700: Unknown engine Ids
*SNMPTask: Sep 04 15:56:08.700: SNMPD: Sending SNMP packet to 172.18.102.5:50927, out_packet_len = 107
*SNMPTask: Sep 04 15:56:09.701: SNMPD: Packet from: 172.18.102.5:50927, in_packet_len = 64
*SNMPTask: Sep 04 15:56:09.701: SNMPD: calling srDoSnmp.
*SNMPTask: Sep 04 15:56:09.701: Unknown engine Ids
*SNMPTask: Sep 04 15:56:09.702: SNMPD: Sending SNMP packet to 172.18.102.5:50927, out_packet_len = 107
*SNMPTask: Sep 04 15:56:10.703: SNMPD: Packet from: 172.18.102.5:50927, in_packet_len = 64
*SNMPTask: Sep 04 15:56:10.704: SNMPD: calling srDoSnmp.
*SNMPTask: Sep 04 15:56:10.704: Unknown engine Ids
*SNMPTask: Sep 04 15:56:10.704: SNMPD: Sending SNMP packet to 172.18.102.5:50927, out_packet_len = 107
*SNMPTask: Sep 04 15:56:11.705: SNMPD: Packet from: 172.18.102.5:50927, in_packet_len = 64
*SNMPTask: Sep 04 15:56:11.705: SNMPD: calling srDoSnmp.
*SNMPTask: Sep 04 15:56:11.705: Unknown engine Ids&lt;/PRE&gt;&lt;P&gt;Thank you for the help.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Sep 2017 14:30:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-2500-snmp/m-p/3179756#M110913</guid>
      <dc:creator>lambrosx</dc:creator>
      <dc:date>2017-09-04T14:30:24Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 2500 - SNMP</title>
      <link>https://community.cisco.com/t5/wireless/wlc-2500-snmp/m-p/3179879#M110914</link>
      <description>&lt;PRE&gt;SNMPD: Sending SNMP packet to 172.18.102.5:50927&lt;/PRE&gt;&lt;PRE&gt;SNMPD: Packet from: 172.18.102.5:50927, in_packet_len = 64&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;According to logs, looks like WLC is receiving the packet and replying it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;SNMP is UDP and works in two ports: 161/162. Make sure you have both allowed and make sure packet inspection is ok on ASA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;I´d say that your problem is Firewall not WLC.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2017 00:54:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-2500-snmp/m-p/3179879#M110914</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2017-09-05T00:54:42Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 2500 - SNMP</title>
      <link>https://community.cisco.com/t5/wireless/wlc-2500-snmp/m-p/3179998#M110915</link>
      <description>&lt;P&gt;Hi Flavio,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your answer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many weird&amp;nbsp;things :&lt;/P&gt;&lt;P&gt;- In the firewall, for both&amp;nbsp;VLAN, Access Rules is Any Any Ip Permit&lt;/P&gt;&lt;P&gt;- Packet tracer VLAN 1 -&amp;gt; VLAN 2 and VLAN 2 -&amp;gt; VLAN 1 for 161/162 is ok&lt;/P&gt;&lt;P&gt;- From WLC, ping to the other VLAN, through Firewall, is ok&lt;/P&gt;&lt;P&gt;- Snmpget to switches in WLC VLAN succeeds (why is ok for switches and not wlc, same rules, same config)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, just one observation, when we install WLC few years ago, we had issues accessing admin pages from other VLAN, very similar issue. We had to configure TCP Bypass.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But here, SNMP uses UDP...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We never have this issues with our Small Business switches.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2017 10:26:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-2500-snmp/m-p/3179998#M110915</guid>
      <dc:creator>lambrosx</dc:creator>
      <dc:date>2017-09-05T10:26:24Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 2500 - SNMP</title>
      <link>https://community.cisco.com/t5/wireless/wlc-2500-snmp/m-p/3180093#M110916</link>
      <description>&lt;P&gt;Take a look in packet inspection. Firewall don't like udp cause they have no connection establishment.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2017 12:55:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-2500-snmp/m-p/3180093#M110916</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2017-09-05T12:55:21Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 2500 - SNMP</title>
      <link>https://community.cisco.com/t5/wireless/wlc-2500-snmp/m-p/3180483#M110917</link>
      <description>&lt;P&gt;Hi Flavio,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Everything looks ok on the firewall except we don't see anwser packet back.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found &lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/7-4/configuration/guides/consolidated/b_cg74_CONSOLIDATED/b_cg74_CONSOLIDATED_chapter_010011111.html" target="_self"&gt;that&lt;/A&gt; :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;Restrictions for Configuring Dynamic Interfaces
The following restrictions apply for configuring the dynamic interfaces on the controller:
Wired clients cannot access management interface of the Cisco WLC 2500 series using the IP address of the AP Manager interface .
For SNMP requests that come from a subnet that is configured as a dynamic interface, the controller responds but the response does not reach the device that initiated the conversation.&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've got one dynamic Interface per VLAN and one SSID (or more) per VLAN.&amp;nbsp;Is it the explanation?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I notice that snmpget succeeds on the IP of the dynamic interface on the good VLAN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for taking time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2017 08:09:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-2500-snmp/m-p/3180483#M110917</guid>
      <dc:creator>lambrosx</dc:creator>
      <dc:date>2017-09-06T08:09:44Z</dc:date>
    </item>
  </channel>
</rss>

