02-05-2020 11:45 AM - edited 02-21-2020 09:53 AM
Hi Experts,
We are configuring SNMP on our Firepower-2130 from Firepower management Center(FMC) GUI for Integration with NMS tool.
--> Configured SNMP receiver (i.e. NMS Server IP) , SNMP Version : 2 , TRAPs, Assigned a Interface as well.
All details are accepted and showing properly on GUI.
But while checking and verifying the configuration on Firepower CLI, i can't find any SNMP configuration which was configured there on FMC GUI. on CLI there is nothing about snmp-server.
Don't understand what & where i missed.
Please advise.
02-05-2020 08:19 PM
02-05-2020 08:45 PM - edited 02-05-2020 08:50 PM
Hi Francesco,
Ys , platform policy has been configured on FMC GUI. Further
Could u help & share how to chk this whether this is assigned to correct intended device or not.
And one point I forget to mention that problem is with snmp config only, rest all changes like policy etc which we are pushing from FMC is visible in FTD CLI.
02-05-2020 10:22 PM - edited 02-05-2020 10:24 PM
Hi Francesco,
Checked , FTD(FPR-2130) is already there added under the policy in FMC. After then only , we are entering for SNMP configuration.
problem is whatever we are pushing related to SNMP (Device -> platform setting -> policy -> FTD->SNMP) there is nothing replication or visbile on the FTD CLI.
However for rest of the configuration changes eg. security policy from FMC GUI, I can see them all in FPR-2130 CLI as well.
Please suggest.
02-06-2020 06:29 AM
02-07-2020 12:15 AM - edited 02-07-2020 12:27 AM
Hi Francesco,
Please find the FPR version : Version 6.4.0.7 (Build 53) - [Cisco Firepower 2130]
Output for sh run snmp-server
firepower# sh run snmp-server
no snmp-server location
no snmp-server contact
no snmp-server enable traps snmp authentication linkup linkdown coldstart warmstart
firepower#
Screen shot from FMC also attached.
02-07-2020 05:28 AM - edited 02-07-2020 05:36 AM
One twist... with new issue
We have taken a deep dive to NMS and found FTD is available in NMS polling with management interface IP and which is not actually visible to us from CLI even from FMC too (this management IP of FTD is integrated with FMC at backend), This lead to understanding gap and we started trying to integrate FTD with NMS via a Data Interface IP on FTD (as mgmt IP is not visible there on CLI & FMC under FTP interface).
New problem is now is that - At NMS monitoring .... FTD is showing with management interface & few more (probably 3-4) interface with name tun1, tap0, tap0.1, tap0.100 which is of no purpose for us.
The desired state for which we are doing all this exercise is to get trap notification for all IPSec tunnel which are created on this FTP.
Would also like to understand, why snmp configuration are not reflecting there in FTD CLI, which were pushed from FMC
Hope, to get the solution now here in this forum/platform.
02-07-2020 08:07 PM
02-07-2020 09:46 PM
Hi Francesco,
I tried everything, but since this is production environment i can't do much R&D even for SNMP.
Well, i have found other post in forum "https://community.cisco.com/t5/firepower/snmp-to-the-ftd-managment-interface/m-p/3915417/highlight/false#M14743" ....I have requested there to advice for solution.
Meanwhile, please continue to share your inputs Or if anyone having solution fix to problem . please help.
02-08-2020 07:17 PM - edited 02-08-2020 11:11 PM
As I noted in the other thread, you are correct that as of the current Firepower release (6.5.0.2) we still need to assign a separate IP address to the diagnostic interface. That allows the NMS to interact with the LINA code within Firepower which handles SNMP instrumentation of the dataplane. The management interface, while it will respond to SNMP if configured to do so, only handles SNMP instrumentation of the physical appliance as it is based within the FX-OS subsystem.
Expect this to change ca. Firepower 6.6 later this year.
(edited 2020-02-09 to reflect 6.6 info.)
02-08-2020 10:21 PM
Hi Marvin, how are you? Support for SNMP management in the FPR-2100 through the Device Management Interface is coming in 6.6.0 and it will be available via the Platform Settings in FMC and FlexConfig in FDM.
Thank you for rating helpful posts!
02-08-2020 11:13 PM
Hi Neno. I’m doing well. Hope you are too.
Thanks for the correction. I updated my earlier post to reflect that.
I look forward to the improvements coming in the next few releases.
02-08-2020 08:01 PM - edited 02-08-2020 08:04 PM
Ok we are talking about 2 issues. Getting info from the LINA using the diagnostic interface and the 1st pb you bring which is pushing snmp config that's not showing up into your FTD.
What I can propose is to export the platform settings config from the import/export menu and share it in private to see if i can test it on my firepower device. If you can do that, I'll give you my email in a private message.
For the other issue, you need to assign a different ip on the diagnostic as mentioned by @Marvin Rhoads
Still not available on 6.6
02-09-2020 02:29 AM - edited 02-09-2020 09:52 AM
Hi Marvin and Neno,
Thanks very much for response.
Finally, we have to use Diagnostic Interface and configure IP on the same till we have 6.6 version. But can we use IP from same subnet which is there on Management Interface, this is because i am avoiding executing of additional ACL further. NMS server is on same subnet as of management Interface.
believe there would not be any impact of the Production services if i configure IP on Diagnostic interface.
Hi Francesco,
I have share screen shot with you already for configuration, setup and scenario is also explained. You may refer that for your Lab.
Additionally, referring to reply on other post - "The management ip address resides within the firepower part of FTD and not within Lina" .....Trying to understand this statement. is FPR-2130 having two segment inside it Firepower and FTD and what is difference between LINA , snort and FX-OS.
rgds
02-09-2020 06:37 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide