cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

2508
Views
5
Helpful
2
Replies
Highlighted

SNMP does not work on the standby ASA firewalls

Hello Everyone,

I have a pair of 5 pairs of active/standby ASA firewalls running 8.4.4(1)

All the active firewall respond to the SNMP requests, but the standby firewalls do not. I'm using SNMP v3. The configuration of primary and secondary firewalls is replica of each other, apart from the ip addressess.

I want the secondary firewall to respond to SNMP requests coming in from the monitoring server. Can someone please help ?

Thanks,

Rishi

2 REPLIES 2
Highlighted
Advocate

Are you able to reach the SNMP server from the standby firewalls?? What information are you trying to poll from the standby machine?

Thanks,
Varun Rao
Security Team,
Cisco TAC

Thanks, Varun Rao Security Team, Cisco TAC
Highlighted
Beginner

Assuming you can ping both firewalls, the problem is that the firewall pair shares the same config and therefore, the same SNMPv3 engineID. Some NMSs (e.g. WhatsUp Gold) do not support this and therefore only 1 firewall in the pair can be queried.

Doesn't look like this has been fixed yet:

Bug info: CSCtl88556 - ASA5520 failover pair has duplicate snmp v3 engine id

Content for Community-Ad