02-02-2010 01:14 PM - edited 03-11-2019 10:04 AM
I have a third party tool I'm trying to use and it wants to connect through SNMP to gather information. I can connect to my Cisco switches and routers but not my ASAs. They all use the same community 'pubs'.
DAYASA# sh run snmp-server
snmp-server host Inside 192.168.200.13 poll community pubs version 2c
snmp-server host Inside 192.168.200.53 community pubs
snmp-server location Day
no snmp-server contact
snmp-server community pubs
snmp-server enable traps snmp authentication linkup linkdown coldstart
snmp-server enable traps syslog
The 192.168.200.53 IP is my MARS unit and it talks to the ASA so I know SNMP works, at least, in part. The tool I'm trying to use isn't on a specific machine but shouldn't 'snmp-server community pubs' allow anything to connect?
Solved! Go to Solution.
02-02-2010 02:15 PM
what is the IP of your PC ?
YOu need to allow SNMP access from your PC to the ASA...
snmp-server host inside 192.168.x.x poll community public
where 192.168.x.x is the ip address of your PC...
refer to the following URL for more info:
Hope this helps.. all the best..
Raj
02-02-2010 01:42 PM
What is the IP address of your tool ? you can define another snmp-server host inside 192.168.200.x (ip of your tool) to make the tool access the ASA via SNMP..
Raj
02-02-2010 02:08 PM
It is on my laptop which is DHCP so I didn't want to lock it down to a specific IP.
02-02-2010 02:15 PM
what is the IP of your PC ?
YOu need to allow SNMP access from your PC to the ASA...
snmp-server host inside 192.168.x.x poll community public
where 192.168.x.x is the ip address of your PC...
refer to the following URL for more info:
Hope this helps.. all the best..
Raj
02-03-2010 05:23 AM
Thanks for the help. I'll put the tool on one of my utility servers so I don't have to worry about changing the IP in the future.
Just to be clear the statement:
snmp-server community pubs
is not a generic snmp statement to allow any device to connect to the ASA as long as they have the correct community string?
02-03-2010 05:33 AM
You will need to define the SNMP community string on the ASA to martch the string on your SNMP server. A community string acts as a shared secret password that authenticates any management station's SNMP polls that should match between the incoming pools and the firewall itself. Default string on the frewall is "public". Make sure both your NNM and Firewall match..
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide