nv-l

RE: [nv-l] netmon and SNMP communities

2003-11-26 13:18:24
Subject: RE: [nv-l] netmon and SNMP communities
From: "Federico Vidal" <fvidal AT tecsystem.com DOT ar>
To: <nv-l AT lists.us.ibm DOT com>
Date: Wed, 26 Nov 2003 15:24:58 -0300
Ok, I didn't know that netmon was using a cache different from the ovsnmp db. 
That was really confusing me. So, now, im clear that netmon is not using the 
communities that it should be using.

The devices im triyng to discover are simple routers and switches form other 
locations which have a location specific community name. In fact, there are no 
Solaris, but thanks for the hint.

Yes, what you say its exactly what happening. After receiving the ping 
response, netmon tries to poll it with snmp, but fails repeatedly until it 
finally quits the snmp polling. As a result, the object is not discovered 
because of my seed file (!@oid 0).


Ok, i recognize the problem as being the netmon using the community cache. How 
do I solve it?

thanks!!


-----Mensaje original-----
De: Barr, Scott [mailto:Scott_Barr AT csgsystems DOT com]
Enviado el: Miércoles, 26 de Noviembre de 2003 02:26 p.m.
Para: nv-l AT lists.us.ibm DOT com
Asunto: RE: [nv-l] netmon and SNMP communities


The thing you have to remember is in v7 NetView there is an snmp community name 
"cache" which netmon uses that is separate from ovsnmp db. There are definately 
problems in this technique but the apars should address that. Netmon (which is 
doing discovery) is not tied to the ovsnmp database and the two can differ. 
What community string is netmon daemon using is the real question and I am 
guessing you will need to snoop/sniff to find that out. It *SHOULD* use the one 
from xnmsnmpconf but the apars I have opened/resolved that was NOT the case.

Another possibility - if the devices you are having trouble discovery are 
Solaris - it is possible for Netview to use "public" on a Solaris box that is 
NOT running with public for a community name. What happens is that netmon does 
an SNMP get on system.sysName.0 and if the public community string answers - 
with any response - netmon assumes its a good community string. This is a bug 
in the solaris agent. I would definately try snmpwalk system.sysName.0 to see 
if that is a problem or not on the devices you can't discover.

Also, what happens if you ping the device? Netmon should add devices to 
discovery if it gets an unsolicited ping response and they meet the seed file 
criteria. I assume that the standard SNMP operations will be tried by netmon 
upon recieving ICMP response from the device you pinged.

-----Original Message-----
From: owner-nv-l AT lists.us.ibm DOT com [mailto:owner-nv-l AT lists.us.ibm DOT 
com]On
Behalf Of Federico Vidal
Sent: Wednesday, November 26, 2003 11:22 AM
To: nv-l AT lists.us.ibm DOT com
Subject: RE: [nv-l] netmon and SNMP communities


Paul:

I viewed the apars you told me:

IY42241: INCCORECT SNMPADDRESS OF OBJECTS LOADED INTO NETVIEW THE LOADHOSTS 
COMMAND.
This apar is about the loadhosts command which is not my case.

IY49090: MODIFY THE ORDER OF SNMP REQUESTS DURING DISCOVERY TO ENSURE THEFIRST 
IS RETRIVED FROM "SYSTEM" OF MIB INFORMATION.
This apar is not the case because I am not using alternate community names. The 
fact is that I get authentication failures.

IY49975: IPMAP NEVER ENDS THE SYNCHRONIZATION AND CORES IF GLOBAL-ACK IS 
ENABLED.
This is not the case.

Thanks Paul, but these (although fixes to the 7.1.3 version) are not really the 
problem im having. 

But, in every case, where can I download these fixes???

Thank you


-----Mensaje original-----
De: Paul Stroud [mailto:pstroud AT bellsouth DOT net]
Enviado el: Miércoles, 26 de Noviembre de 2003 01:41 p.m.
Para: nv-l AT lists.us.ibm DOT com
Asunto: Re: [nv-l] netmon and SNMP communities


Get these additional fixes and your problem should be resolved:

IY42241
IY49090
IY49975

Paul

On Wednesday 26 November 2003 11:40, you wrote:
> Paul:
>
> No, I didn't assign any communities to communityNames.conf becuase I
> already imported the snmp configuration. I could try that, but it would be
> a workaround. Since it is only a secondary Netview, i prefer to reinstall
> it rather than having a faulty installation.
>
> Im running Netview for Linux 7.1.3 with Fixpack 01.
>
> thanks
>
>
> -----Mensaje original-----
> De: Paul Stroud [mailto:pstroud AT bellsouth DOT net]
> Enviado el: Miércoles, 26 de Noviembre de 2003 01:11 p.m.
> Para: nv-l AT lists.us.ibm DOT com
> Asunto: Re: [nv-l] netmon and SNMP communities
>
>
> Have you added any of these community names to the communityNames.conf
> file? Also have you installed any patches? If so, which patches?
>
> Paul
>
> On Wednesday 26 November 2003 11:08, you wrote:
> > Scott:
> >
> > First of all, thanks.
> > I did as you told me to and got the netmon.trace, but it only shows the
> > community used with already discovered nodes... The thing is that,
> > because of my seed file ( !@oid  0), no nodes with communities other than
> > the default were discovered, which are the ones I try to poll AND
> > discover.
> >
> > -----Mensaje original-----
> > De: Barr, Scott [mailto:Scott_Barr AT csgsystems DOT com]
> > Enviado el: Miércoles, 26 de Noviembre de 2003 11:57 a.m.
> > Para: nv-l AT lists.us.ibm DOT com
> > Asunto: RE: [nv-l] netmon and SNMP communities
> >
> >
> > During times of problem - use the netmon -a 175 command and look in
> > /usr/OV/log/netmon.trace to see if the community name is different than
> > the one reported in xnmsnmpconf. Thats the bug Leslie is referring to.
> >
> > -----Original Message-----
> > From: owner-nv-l AT lists.us.ibm DOT com [mailto:owner-nv-l AT lists.us.ibm 
> > DOT com]On
> > Behalf Of Leslie Clark Sent: Wednesday, November 26, 2003 8:42 AM
> > To: nv-l AT lists.us.ibm DOT com
> > Subject: Re: [nv-l] netmon and SNMP communities
> >
> >
> >
> > Do you have maintenance on this 7.1.3? There were problems with
> > communities that were fixed.
> >
> > Cordially,
> >
> > Leslie A. Clark
> > IBM Global Services - Systems Mgmt & Networking
> > Detroit
> >
> >
> >
> >     "Federico Vidal" <fvidal AT tecsystem.com DOT ar>
> > Sent by: owner-nv-l AT lists.us.ibm DOT com
> >
> >
> > 11/26/2003 12:16 PM
> > Please respond to nv-l
> >
> >
> >
> >         To:        "Nv-L (E-mail)" <nv-l AT lists.us.ibm DOT com>
> >         cc:
> >         Subject:        [nv-l] netmon and SNMP communities
> >
> >
> >
> >
> > Hello List:
> >
> > I have a customer with Netview 7.1.3 on Linux who tries to discover his
> > network with it. The thing is that, having a seed file that only
> > discovers SNMP devices ( !@oid 0 ), he can't discover any device beside
> > the ones using the default community. Any device that has another SNMP
> > community different than the default, can't be discovered.
> >
> > I will give full details: Looking into the matter, i found that the SNMP
> > configuration (xnmsnmpconf) is correct because I can manually poll these
> > devices using snmpwalk without specifying community. I found that netmon
> > is the one who is using wrong communities to poll because the cisco
> > agents in the network keep telling that netview causes authentication
> > failure, thus netview doesnt discover any device due to the seed file.
> >
> > This is very strange to me, because i thought that the netview engine
> > used the same snmp configuration that CLI commands.
> >
> > Another detail is that before this problem occurred, my customer changed
> > the netview's IP address, so I ran reset_ci to solve the apparent problem
> > but nothing happenned....
> >
> > What could be happening???? My last resort is to deinstall but I would
> > like to solve this issue as a Netview supporter.
> >
> > Thanks in advance.
> >
> > Federico Vidal
> > IBM Certified Deployment Professional
> > Tecsystem S.R.L.
> > e-mail: fvidal AT tecsystem.com DOT ar
> > Tel: (5411)-4814-2770 ext. 120




<Prev in Thread] Current Thread [Next in Thread>