<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Strange SNMP problems on GAIA in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-SNMP-problems-on-GAIA/m-p/141816#M27025</link>
    <description>&lt;P&gt;Well, we use a monitoring software "LibreNMS", which does a discovery every few hours. For such a discovery, it pulls pretty large MIB ranges (if not ALL available), to fill it´s database.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Strange thing is, most of our firewalls do not have any problems with that...&lt;/P&gt;</description>
    <pubDate>Thu, 17 Feb 2022 17:32:25 GMT</pubDate>
    <dc:creator>NicoSeuss</dc:creator>
    <dc:date>2022-02-17T17:32:25Z</dc:date>
    <item>
      <title>Strange SNMP problems on GAIA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-SNMP-problems-on-GAIA/m-p/141470#M26915</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;since some time (can't tell exactly when it started) we encounter some strange problems with SNMP.&lt;/P&gt;&lt;P&gt;When I do an snmpwalk, it times out after a few hundred lines. Some attempts provide more, some less lines on the same machine.&lt;/P&gt;&lt;P&gt;However, that is not on all machines. E.g. on a cluster one machine answers just fine, the other don't.&lt;/P&gt;&lt;P&gt;All machines are on R80.40.&amp;nbsp;Hardware is&amp;nbsp;Check Point 5800 and Check Point 6200P.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Most of the machines do NOT run VSX.&lt;/P&gt;&lt;P&gt;I made some tests and it looks like every attempt stops around MIB&amp;nbsp;.1.3.6.1.2.1.25.3.2.1.1&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is no special SNMP configuration, and identical on all machines:&lt;/P&gt;&lt;LI-SPOILER&gt;set snmp mode default&lt;BR /&gt;set snmp agent on&lt;BR /&gt;set snmp agent-version v3-Only&lt;BR /&gt;add snmp interface Mgmt&lt;BR /&gt;add snmp interface bond1&lt;BR /&gt;add snmp usm user FWxxxxx security-level authPriv auth-pass-phrase-hashed xxxxxxxx privacy-pass-phrase-hashed xxxxxxxx privacy-protocol DES authentication-protocol MD5&lt;BR /&gt;set snmp traps trap authorizationError disable&lt;BR /&gt;set snmp traps trap biosFailure disable&lt;BR /&gt;set snmp traps trap clusterXLFailover disable&lt;BR /&gt;set snmp traps trap coldStart disable&lt;BR /&gt;set snmp traps trap configurationChange disable&lt;BR /&gt;set snmp traps trap configurationSave disable&lt;BR /&gt;set snmp traps trap fanFailure disable&lt;BR /&gt;set snmp traps trap highVoltage disable&lt;BR /&gt;set snmp traps trap linkUpLinkDown disable&lt;BR /&gt;set snmp traps trap lowDiskSpace disable&lt;BR /&gt;set snmp traps trap lowVoltage disable&lt;BR /&gt;set snmp traps trap overTemperature disable&lt;BR /&gt;set snmp traps trap powerSupplyFailure disable&lt;BR /&gt;set snmp traps trap raidVolumeState disable&lt;BR /&gt;set snmp traps trap vrrpv2AuthFailure disable&lt;BR /&gt;set snmp traps trap vrrpv2NewMaster disable&lt;BR /&gt;set snmp traps trap vrrpv3NewMaster disable&lt;BR /&gt;set snmp traps trap vrrpv3ProtoError disable&lt;BR /&gt;set snmp contact "xxxxxxxxx"&lt;BR /&gt;set snmp location "xxxxxxxxxx"&lt;BR /&gt;set snmp traps advanced coldStart reboot-only off&lt;/LI-SPOILER&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Strange thing is, on machines, where everything works fine, I get around e.g. 14'000 lines of SNMPWALK, on machines where timeouts occure, sometimes I get above 65'000 or even over 100'000 lines back, before the timeout.&lt;/P&gt;&lt;P&gt;This way, one snmpwalk takes over half an hour...&lt;/P&gt;&lt;P&gt;One of the questions is: Why do I get so much different outputs on similar devices of a cluster?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BTW: Increasing the timeout setting of snmpwalk does not help (it simply takes much longer).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Versions are the same between the machines. E.g.&lt;/P&gt;&lt;LI-SPOILER&gt;&lt;P&gt;&lt;BR /&gt;This is Check Point CPinfo Build 914000215 for GAIA&lt;BR /&gt;[CPFC]&lt;BR /&gt;No hotfixes..&lt;/P&gt;&lt;P&gt;[MGMT]&lt;BR /&gt;HOTFIX_R80_40_JUMBO_HF_MAIN Take: 94&lt;/P&gt;&lt;P&gt;[IDA]&lt;BR /&gt;No hotfixes..&lt;/P&gt;&lt;P&gt;[FW1]&lt;BR /&gt;HOTFIX_GOT_TPCONF_AUTOUPDATE&lt;BR /&gt;HOTFIX_R80_40_MAAS_TUNNEL_AUTOUPDATE&lt;BR /&gt;HOTFIX_R80_40_JUMBO_HF_MAIN Take: 94&lt;/P&gt;&lt;P&gt;FW1 build number:&lt;BR /&gt;This is Check Point's software version R80.40 - Build 118&lt;BR /&gt;kernel: R80.40 - Build 104&lt;/P&gt;&lt;P&gt;[SecurePlatform]&lt;BR /&gt;HOTFIX_R80_40_JUMBO_HF_MAIN Take: 94&lt;/P&gt;&lt;P&gt;[PPACK]&lt;BR /&gt;HOTFIX_R80_40_JUMBO_HF_MAIN Take: 94&lt;/P&gt;&lt;P&gt;[CPinfo]&lt;BR /&gt;No hotfixes..&lt;/P&gt;&lt;P&gt;[AutoUpdater]&lt;BR /&gt;No hotfixes..&lt;/P&gt;&lt;P&gt;[CVPN]&lt;BR /&gt;HOTFIX_R80_40_JUMBO_HF_MAIN Take: 94&lt;/P&gt;&lt;P&gt;[CPUpdates]&lt;BR /&gt;BUNDLE_GENERAL_AUTOUPDATE Take: 12&lt;BR /&gt;BUNDLE_CPSDC_AUTOUPDATE Take: 19&lt;BR /&gt;BUNDLE_CORE_FILE_UPLOADER_AUTOUPDATE Take: 11&lt;BR /&gt;BUNDLE_GOT_TPCONF_AUTOUPDATE Take: 97&lt;BR /&gt;BUNDLE_R80_40_JUMBO_HF_MAIN_SC Take: 100&lt;BR /&gt;BUNDLE_HCP_AUTOUPDATE Take: 48&lt;BR /&gt;BUNDLE_R80_40_MAAS_TUNNEL_AUTOUPDATE Take: 44&lt;BR /&gt;BUNDLE_INFRA_AUTOUPDATE Take: 52&lt;BR /&gt;BUNDLE_DEP_INSTALLER_AUTOUPDATE Take: 23&lt;BR /&gt;BUNDLE_R80_40_JUMBO_HF_MAIN Take: 94&lt;/P&gt;&lt;P&gt;[CPDepInst]&lt;BR /&gt;No hotfixes..&lt;/P&gt;&lt;P&gt;[hcp_wrapper]&lt;BR /&gt;HOTFIX_HCP_AUTOUPDATE&lt;/P&gt;&lt;P&gt;[DIAG]&lt;BR /&gt;No hotfixes..&lt;/P&gt;&lt;P&gt;[core_uploader]&lt;BR /&gt;HOTFIX_CHARON_HF&lt;/P&gt;&lt;P&gt;[cpsdc_wrapper]&lt;BR /&gt;HOTFIX_CPSDC_AUTOUPDATE&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;/LI-SPOILER&gt;&lt;P&gt;A while ago everything was fine. We updated to R80.40 from 77.30 in the past, but as far as I see, the problems started a while after that, so I don´t see a correlation here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please let me know, if you need more/special information.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot in advance!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Nico&lt;/P&gt;</description>
      <pubDate>Mon, 14 Feb 2022 19:12:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-SNMP-problems-on-GAIA/m-p/141470#M26915</guid>
      <dc:creator>NicoSeuss</dc:creator>
      <dc:date>2022-02-14T19:12:50Z</dc:date>
    </item>
    <item>
      <title>Re: Strange SNMP problems on GAIA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-SNMP-problems-on-GAIA/m-p/141718#M26916</link>
      <description>&lt;P&gt;Best to open a TAC case here.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Feb 2022 22:59:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-SNMP-problems-on-GAIA/m-p/141718#M26916</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-02-16T22:59:31Z</dc:date>
    </item>
    <item>
      <title>Re: Strange SNMP problems on GAIA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-SNMP-problems-on-GAIA/m-p/141720#M26917</link>
      <description>&lt;P&gt;Is there a reason to walk the whole MIB versus get a specific OID?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Feb 2022 23:13:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-SNMP-problems-on-GAIA/m-p/141720#M26917</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-02-16T23:13:15Z</dc:date>
    </item>
    <item>
      <title>Re: Strange SNMP problems on GAIA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-SNMP-problems-on-GAIA/m-p/141722#M26918</link>
      <description>&lt;P&gt;Hey Nico,&lt;/P&gt;
&lt;P&gt;I know this is older sk, but it might be worth checking. TAC case would not hurt either, as it sure sounds like a very peculiar issue.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk97947" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk97947&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Feb 2022 23:28:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-SNMP-problems-on-GAIA/m-p/141722#M26918</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-02-16T23:28:11Z</dc:date>
    </item>
    <item>
      <title>Re: Strange SNMP problems on GAIA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-SNMP-problems-on-GAIA/m-p/141816#M27025</link>
      <description>&lt;P&gt;Well, we use a monitoring software "LibreNMS", which does a discovery every few hours. For such a discovery, it pulls pretty large MIB ranges (if not ALL available), to fill it´s database.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Strange thing is, most of our firewalls do not have any problems with that...&lt;/P&gt;</description>
      <pubDate>Thu, 17 Feb 2022 17:32:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-SNMP-problems-on-GAIA/m-p/141816#M27025</guid>
      <dc:creator>NicoSeuss</dc:creator>
      <dc:date>2022-02-17T17:32:25Z</dc:date>
    </item>
    <item>
      <title>Re: Strange SNMP problems on GAIA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-SNMP-problems-on-GAIA/m-p/141817#M26919</link>
      <description>&lt;P&gt;Hi Andy,&lt;/P&gt;&lt;P&gt;thanks for the link, but in fact I already found this sk.&lt;/P&gt;&lt;P&gt;However, we do not have VSX running on most of the machines, which have the problems... So this must be another problem...&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Nico&lt;/P&gt;</description>
      <pubDate>Thu, 17 Feb 2022 17:36:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-SNMP-problems-on-GAIA/m-p/141817#M26919</guid>
      <dc:creator>NicoSeuss</dc:creator>
      <dc:date>2022-02-17T17:36:08Z</dc:date>
    </item>
  </channel>
</rss>

