09-02-2011 10:02 AM - edited 03-11-2019 02:20 PM
I have a customer with an ASA5505 where it will not reply to SNMP polls from any source, i have followed the configuration guide
http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/monitor_snmp.html#wp1083795
at and tested another ASA in our internal network and i have that working fine on our LAN, here is the snmp and logging sections of the show-run on the ASA, it there anything obvious im missing to make the SNMP work on this device?
snmp-server host outside 203.XX.75.122 community XXXX
snmp-server host outside 203.XX.84.196 community XXXX
snmp-server host outside 203.XX.86.82 community XXXX
snmp-server host outside 82.XX.244.3 community XXX
snmp-server host outside 87.XX.152.136 community XXX
snmp-server location benoi
snmp-server contact localit
snmp-server community XXXX
snmp-server enable traps snmp authentication linkup linkdown coldstart
snmp-server enable traps syslog
snmp-server enable traps ipsec start stop
snmp-server enable traps entity config-change fru-insert fru-remove
snmp-server enable traps remote-access session-threshold-exceeded
icmp permit any outside
logging enable
logging console informational
logging history notifications
logging asdm informational
Solved! Go to Solution.
09-02-2011 07:49 PM
Hello !
You say that the problem is with polls, have you tried to take captures when the SNMP server tries to connect to the ASA?
Try capturing when you hit the buttom on the server to poll the messages, here is how you can apply captures on the ASA.
https://supportforums.cisco.com/docs/DOC-1222
Mike
09-02-2011 07:49 PM
Hello !
You say that the problem is with polls, have you tried to take captures when the SNMP server tries to connect to the ASA?
Try capturing when you hit the buttom on the server to poll the messages, here is how you can apply captures on the ASA.
https://supportforums.cisco.com/docs/DOC-1222
Mike
09-05-2011 05:46 AM
Yes i have captures from the ASA - it recieves the GET requests from the SNMP server (version 1 and the community strings match ok) but the ASA does not reply it just sends traps to the devices in its hosts list.
09-05-2011 09:39 AM
Have you take the logs form the ASA firewall?
Mike
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide