cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1586
Views
0
Helpful
4
Replies

SNMPv3 support for Assurance telemetry traps

rrrsseta
Level 1
Level 1

Hi,

 

We use DNAC 1.3.1.x and we do discovery of Catalyst 9300 switch running IOS-XE 16.12.1 using SNMPv3 credentials.

Discovery is successful and when we enable telemetry for Assurance (Optimal Visibility) then DNAC provisions the switch with DNAC's IP address as Syslog server and SNMP trap receiver. Unfortunately it uses SNMPv2 version for traps configuration.   

I need to know if DNA Assurance can support SNNMPv3 for traps sent from switches DNAC for Assurance?

 

Regards

1 Accepted Solution

Accepted Solutions

Tomas de Leon
Cisco Employee
Cisco Employee
SNMPv3 is supported for the Cisco DNAC and Network Devices that support SNMPv3.
What is NOT supported is SNMPv3 for Telemetry & Assurance. That said, the Cisco
DNAC will use the username for the SNMPv3 user that is configured on the Cisco DNAC
as the SNMPv2c Community for SNMP Traps for Assurance.

Assurance has two parts:
1. A Polling mechanism is used to collect cpu and memory statistics. Both SNMPv2c
and SNMPv3 are supported. SNMPv3 credentials are given by the user to be configured
during device discovery process.

2. Trap handling is used to report device "issues" through SNMP traps. At this time,
only SNMPv2c is supported on the Cisco DNAC. If SNMPv3 only is configured under device
credentials, the Cisco DNAC will use the username of the SNMPv3 credential for the
SNMPv2c community for SNMP Traps on the device. This also is configured on the
device by by the Cisco DNAC.


SNMPv3 trap support is on the roadmap and should be available in a future "featured" Release for the Cisco DNAC.

View solution in original post

4 Replies 4

Tomas de Leon
Cisco Employee
Cisco Employee
SNMPv3 is supported for the Cisco DNAC and Network Devices that support SNMPv3.
What is NOT supported is SNMPv3 for Telemetry & Assurance. That said, the Cisco
DNAC will use the username for the SNMPv3 user that is configured on the Cisco DNAC
as the SNMPv2c Community for SNMP Traps for Assurance.

Assurance has two parts:
1. A Polling mechanism is used to collect cpu and memory statistics. Both SNMPv2c
and SNMPv3 are supported. SNMPv3 credentials are given by the user to be configured
during device discovery process.

2. Trap handling is used to report device "issues" through SNMP traps. At this time,
only SNMPv2c is supported on the Cisco DNAC. If SNMPv3 only is configured under device
credentials, the Cisco DNAC will use the username of the SNMPv3 credential for the
SNMPv2c community for SNMP Traps on the device. This also is configured on the
device by by the Cisco DNAC.


SNMPv3 trap support is on the roadmap and should be available in a future "featured" Release for the Cisco DNAC.

Tomas, thank you very much for the explanation.
Are you aware of any plans when (which DNAC version) SNMPv3 traps can be available?

I am not aware of which release that this support will added.  The releases and features are fluid so it can change.  The best way to found out is to reach out to your Account Team and they can reach out to the Product Team and they can give you are better timeframe.

 

T.

Thank you very much.