<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SNMP issue with acquiring Cisco MDS switches with OCI 7.1 in Active IQ Unified Manager Discussions</title>
    <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/SNMP-issue-with-acquiring-Cisco-MDS-switches-with-OCI-7-1/m-p/108963#M19221</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm trying to find a bit more information and guidance regarding the below error:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Snmp error code: 43 error message: Error Sending PDU. Failed to authenticate the SecurityParameters for user &amp;lt;username&amp;gt; SnmpEngineEntry not found for address &amp;lt;IP address&amp;gt; port 161"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The switches are located at a remote site, and I've been increasing the timeout to try and accomodate for the distance.&amp;nbsp; Would an RAU assist in acquiring switches?&amp;nbsp; We have an exisiting RAU at this location to assist with acquiring an array, and I'm curious if it can pull double-duty.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;Julia&lt;/P&gt;</description>
    <pubDate>Wed, 04 Jun 2025 23:28:30 GMT</pubDate>
    <dc:creator>JBARBALACE</dc:creator>
    <dc:date>2025-06-04T23:28:30Z</dc:date>
    <item>
      <title>SNMP issue with acquiring Cisco MDS switches with OCI 7.1</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/SNMP-issue-with-acquiring-Cisco-MDS-switches-with-OCI-7-1/m-p/108963#M19221</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm trying to find a bit more information and guidance regarding the below error:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Snmp error code: 43 error message: Error Sending PDU. Failed to authenticate the SecurityParameters for user &amp;lt;username&amp;gt; SnmpEngineEntry not found for address &amp;lt;IP address&amp;gt; port 161"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The switches are located at a remote site, and I've been increasing the timeout to try and accomodate for the distance.&amp;nbsp; Would an RAU assist in acquiring switches?&amp;nbsp; We have an exisiting RAU at this location to assist with acquiring an array, and I'm curious if it can pull double-duty.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;Julia&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 23:28:30 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/SNMP-issue-with-acquiring-Cisco-MDS-switches-with-OCI-7-1/m-p/108963#M19221</guid>
      <dc:creator>JBARBALACE</dc:creator>
      <dc:date>2025-06-04T23:28:30Z</dc:date>
    </item>
    <item>
      <title>Re: SNMP issue with acquiring Cisco MDS switches with OCI 7.1</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/SNMP-issue-with-acquiring-Cisco-MDS-switches-with-OCI-7-1/m-p/108968#M19223</link>
      <description>&lt;P&gt;Hey Julia,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This looks more like a misconfiguration than a timeout / latency issue. Have these datasources ever worked?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From your error message, with username cited, are you using SNMPv3?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SNMPv3 data is identical to v2, what is different is SNMP v1+v2 have a simplistic security model using community strings (functionally shared secrets) whereas v3 allows authentication and encryption.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, since SNMP is UDP based, it can be a bit tricky to troubleshoot, as you are not guaranteed to get a reply if your request doesn't meet the expectations of the receiving device.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;OCI ships a snmpwalk.bat that allows you test snmp outside of a datasource.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you know whether you should or should not be using SNMP v3, I can give you some examples.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cmd prompt&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cd %sanscreen_home%\bin&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;snmpwalk.bat 1.2.3.4 -v2 -cpublic&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you see a ton of stuff scroll past, good. if it times out, that is a sign that "public" is not a valid community string on device 1.2.3.4, or snmp v2 may not be enabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Aug 2015 15:45:57 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/SNMP-issue-with-acquiring-Cisco-MDS-switches-with-OCI-7-1/m-p/108968#M19223</guid>
      <dc:creator>ostiguy</dc:creator>
      <dc:date>2015-08-21T15:45:57Z</dc:date>
    </item>
    <item>
      <title>Re: SNMP issue with acquiring Cisco MDS switches with OCI 7.1</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/SNMP-issue-with-acquiring-Cisco-MDS-switches-with-OCI-7-1/m-p/108970#M19225</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Yes, we are using V3 and no, they have never worked.&amp;nbsp; We do have additional MDS switches that are local and we are acquiring just fine.&amp;nbsp; It is just those at the remote location with the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I specific community string was created for OCI (by the admins, not by me) which seems to work for the local, but not the remote.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I ran the command below, using -v2 and -v3 and using the community string name that was set up, and also with -cpublic...whatever I adjusted for, there was not a lot of scrolling of anything.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Aug 2015 15:56:04 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/SNMP-issue-with-acquiring-Cisco-MDS-switches-with-OCI-7-1/m-p/108970#M19225</guid>
      <dc:creator>JBARBALACE</dc:creator>
      <dc:date>2015-08-21T15:56:04Z</dc:date>
    </item>
    <item>
      <title>Re: SNMP issue with acquiring Cisco MDS switches with OCI 7.1</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/SNMP-issue-with-acquiring-Cisco-MDS-switches-with-OCI-7-1/m-p/108973#M19226</link>
      <description>&lt;P&gt;So, the good news I can offer you is that the reply back , or error you are seeing in the OCI datasource is a pretty good sign that there is no firewall between OCI and the device in question, so I think we can probably eliminate that as a possibility.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Admittedly, our terminology for SNMP is somewhat cryptic&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SNMP community string - this field is the datasource is mandatory, but irrelevant for SNMP v3 configs. So, you need to populate it with something, but the value is not used in v3 configs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;User name - this field is optional, as it is irrelevant for anything *but* SNMP v3 configs. It is functionally mandatory for snmp v3 configs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Password - this field is optional, as it is irrelevant for anything *but* SNMP v3 configs. It it MAY be functionally mandatory for snmp v3 configs, depending on how your device (in this case, a Cisco MDS switch) is configured&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SNMP Auth Protocol - only relevant for v3 configs. MD5 | SHA | NO_AUTH&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SNMP Privacy Protocol - only relevant for v3 configs DES | TRIPLEDES | AES | NONE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SNMP Privacy Password - only relevant for v3 configs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The tricky stuff with snmpv3:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can configure a switch where no authentication or encryption (privacy) is required - in which case, from an OCI perspective, you simply need to:&lt;/P&gt;&lt;P&gt;populate username&lt;/P&gt;&lt;P&gt;set SNMP auth protocol to NO_AUTH&lt;/P&gt;&lt;P&gt;set SNMP privacy protocol to NONE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And you should be in business&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;snmpWalk.bat 1.2.3.4 -v3 -snostiguy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would be a way of testing such a config for user "ostiguy"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At the opposite extreme, authentication and encryption could be required. And separate authentication passwords and encryption passwords could be required. For OCI:&lt;/P&gt;&lt;P&gt;populate username with extreme&lt;/P&gt;&lt;P&gt;populate password with authpasswordhere&lt;/P&gt;&lt;P&gt;set SNMP auth protocol to SHA&lt;/P&gt;&lt;P&gt;set SNMP Privacy Protocol to AES&lt;/P&gt;&lt;P&gt;Set SNMP Privacy Password to privpasswordhere&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To test this with our snmpwalk.bat:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;snmpwalk.bat 1.2.3.4 -v3 -sn&lt;FONT color="#FF0000"&gt;extreme&lt;/FONT&gt; -ua&lt;FONT color="#FF0000"&gt;authpasswordhere&lt;/FONT&gt; -sha -privpc&lt;FONT color="#FF0000"&gt;AES128&lt;/FONT&gt; -privp&lt;FONT color="#FF0000"&gt;privpasswordhere&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;I unfortunately don't have much for notes on SNMP v3 on Cisco. However:&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;It may be worth looking if any policies have been enabled on the switch to force certain levels of auth or encryption - if these have been set, but your user was not create in compliance with them, your user may be functionally unusable (i.e, no encryption password defined, but the switch only allows SNMPv3 usage with AES128).&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;I don't know if Cisco supports any crypto we don't support - OCI doesn't support AES 192 or 256 because Java doesn't, out of the box. &lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;I am kinda over-due to take a look at this stuff on Cisco. We have a strongly Brocade playbook because in Brocade Virtual Fabric environments, you MUST use SNMPv3 to collect performance, or else you cannot get statistics on the non-default Virtual Fabric&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;Matt&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Aug 2015 17:35:33 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/SNMP-issue-with-acquiring-Cisco-MDS-switches-with-OCI-7-1/m-p/108973#M19226</guid>
      <dc:creator>ostiguy</dc:creator>
      <dc:date>2015-08-21T17:35:33Z</dc:date>
    </item>
    <item>
      <title>Re: SNMP issue with acquiring Cisco MDS switches with OCI 7.1</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/SNMP-issue-with-acquiring-Cisco-MDS-switches-with-OCI-7-1/m-p/108974#M19227</link>
      <description>&lt;P&gt;Thanks very much for all those details!&amp;nbsp; I'm going to forward this info over to networking and see what they have to say for themselves.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We do require an authentication, and we are currently using SNMP auth protocol MD5 and SNMP Privacy Protocol DES.&amp;nbsp; It's possible that I'm running the command incorrectly, but what is returned (some items redacted to protect the innocent):&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;D:\SANscreen\bin&amp;gt;snmpwalk.bat 1.2.3.4 -v3 -sn&amp;lt;name&amp;gt; –au&amp;lt;password&amp;gt; -md5 -privpcdes –privp&amp;lt;password&amp;gt;&lt;/P&gt;&lt;P&gt;Host=1.2.3.4:161 Timeout=1000ms Retries=1 Debug=false Version=SNMPv3 Community=public User=&amp;lt;name&amp;gt; AuthProtocol=MD5 sessionName=null_0&lt;/P&gt;&lt;P&gt;End of MIB Reached&lt;/P&gt;&lt;P&gt;Total # of Requests = 0&lt;/P&gt;&lt;P&gt;Total # of Objects = 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you again for your help today!&amp;nbsp;&lt;/P&gt;&lt;P&gt;Julia&lt;/P&gt;</description>
      <pubDate>Fri, 21 Aug 2015 18:55:01 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/SNMP-issue-with-acquiring-Cisco-MDS-switches-with-OCI-7-1/m-p/108974#M19227</guid>
      <dc:creator>JBARBALACE</dc:creator>
      <dc:date>2015-08-21T18:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: SNMP issue with acquiring Cisco MDS switches with OCI 7.1</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/SNMP-issue-with-acquiring-Cisco-MDS-switches-with-OCI-7-1/m-p/109205#M19271</link>
      <description>you MUST use SNMPV3 you MUST have a valid RO Community String you MUST have an SNMP V3 user account and password you MUST set the privacy and auth protocols to match you MUST have an access control entry in the SNMP setup</description>
      <pubDate>Fri, 28 Aug 2015 19:24:15 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/SNMP-issue-with-acquiring-Cisco-MDS-switches-with-OCI-7-1/m-p/109205#M19271</guid>
      <dc:creator>stephen2</dc:creator>
      <dc:date>2015-08-28T19:24:15Z</dc:date>
    </item>
  </channel>
</rss>

