06-15-2022 12:42 PM
We have several Cisco SG series switches and I was wondering if there is any way to capture the source IP of a device that fails SNMP authentication? I see log messages like what I have pasted below. I have the Originator Identifier set to IPv4 Address which I thought would probably capture the source IP for these logs, but it has not. Is there something I am missing or are the logs not capable of capturing the source IP on SNMPAUTHFAIL?
Warning %SNMP-W-SNMPAUTHFAIL: Access attempted by unauthorized NMS
06-15-2022 01:15 PM
Hi
If you failed to see on switch, another option I can see is send switch logs to a syslog server. The problem is that you need a syslog server to see this log.
06-16-2022 07:47 AM
I failed to mention that I do have the remote log server setup and the logs I receive on the remote syslog server are exactly the same as what I see on the device itself. I am getting SNMPAUTHFAIL messages but no source IP address for the device that is causing these.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide