<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SNMP -v:3 on CP gateway in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SNMP-v-3-on-CP-gateway/m-p/249832#M48787</link>
    <description>&lt;P&gt;I agree, I don't like the fact CP remove the ability to use SHA-1 for SNMP when you do a new build, as I think that decision should for the customer and there security policy to decide. &lt;BR /&gt;Do you know how to get SHA-1 available again?&amp;nbsp; If not let me know.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 26 May 2025 12:27:35 GMT</pubDate>
    <dc:creator>genisis__</dc:creator>
    <dc:date>2025-05-26T12:27:35Z</dc:date>
    <item>
      <title>SNMP -v:3 on CP gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SNMP-v-3-on-CP-gateway/m-p/249810#M48778</link>
      <description>&lt;P&gt;hey there&lt;/P&gt;&lt;P&gt;i tried to monitor our VPN connections through SNMP and have some troubles doing that&lt;/P&gt;&lt;P&gt;for testing purposes i use the "Peassler SNMP Tester 5.2.1". I already tried powershell/cmd as well.&lt;/P&gt;&lt;P&gt;we have a cluster, one mgmt and 2 nodes. I created the user on both gateways and added the fw rules to reach them&lt;/P&gt;&lt;P&gt;i then downloaded the paessler snmp tester and implemented all data for the SNMPv3 test&lt;/P&gt;&lt;P&gt;i rechecked username,password and key multiple times and can confirm that they are definitively correct&lt;/P&gt;&lt;P&gt;i got auth fail issues, though&lt;/P&gt;&lt;P&gt;26.05.2025 09:29:15 (115 ms) : Value: Authentication failure (incorrect password, community or key) -35&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What could be wrong here?&lt;/P&gt;&lt;P&gt;thanks in advance&lt;/P&gt;</description>
      <pubDate>Mon, 26 May 2025 07:36:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SNMP-v-3-on-CP-gateway/m-p/249810#M48778</guid>
      <dc:creator>SWBW_Florian</dc:creator>
      <dc:date>2025-05-26T07:36:05Z</dc:date>
    </item>
    <item>
      <title>Re: SNMP -v:3 on CP gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SNMP-v-3-on-CP-gateway/m-p/249814#M48779</link>
      <description>&lt;P&gt;Can you paste your SNMPv3 config please (exclude password).&lt;BR /&gt;Also have you confirm SNMPv2 works first, I generally like to test SNMPv2 if v3 has issue.&amp;nbsp; Also the only thing I've seen is if the NMS supports only SHA-1 but the Checkpoint GW (when its a new build) supports only SHA2 without a workaround.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 May 2025 08:31:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SNMP-v-3-on-CP-gateway/m-p/249814#M48779</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2025-05-26T08:31:51Z</dc:date>
    </item>
    <item>
      <title>Re: SNMP -v:3 on CP gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SNMP-v-3-on-CP-gateway/m-p/249816#M48780</link>
      <description>&lt;P&gt;at gaia its configured as you can see it in the attachment&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 May 2025 09:42:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SNMP-v-3-on-CP-gateway/m-p/249816#M48780</guid>
      <dc:creator>SWBW_Florian</dc:creator>
      <dc:date>2025-05-26T09:42:40Z</dc:date>
    </item>
    <item>
      <title>Re: SNMP -v:3 on CP gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SNMP-v-3-on-CP-gateway/m-p/249818#M48781</link>
      <description>&lt;P&gt;Does the NMS support SHA256?&amp;nbsp; I this is where I've generally found to be a problem.&amp;nbsp; There is away to set the gateway to use SHA-1, if you want to try this.&lt;/P&gt;</description>
      <pubDate>Mon, 26 May 2025 09:57:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SNMP-v-3-on-CP-gateway/m-p/249818#M48781</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2025-05-26T09:57:13Z</dc:date>
    </item>
    <item>
      <title>Re: SNMP -v:3 on CP gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SNMP-v-3-on-CP-gateway/m-p/249823#M48783</link>
      <description>&lt;P&gt;i just would try to switch to sha1. How to do that?&lt;/P&gt;</description>
      <pubDate>Mon, 26 May 2025 10:03:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SNMP-v-3-on-CP-gateway/m-p/249823#M48783</guid>
      <dc:creator>SWBW_Florian</dc:creator>
      <dc:date>2025-05-26T10:03:08Z</dc:date>
    </item>
    <item>
      <title>Re: SNMP -v:3 on CP gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SNMP-v-3-on-CP-gateway/m-p/249832#M48787</link>
      <description>&lt;P&gt;I agree, I don't like the fact CP remove the ability to use SHA-1 for SNMP when you do a new build, as I think that decision should for the customer and there security policy to decide. &lt;BR /&gt;Do you know how to get SHA-1 available again?&amp;nbsp; If not let me know.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 May 2025 12:27:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SNMP-v-3-on-CP-gateway/m-p/249832#M48787</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2025-05-26T12:27:35Z</dc:date>
    </item>
    <item>
      <title>Re: SNMP -v:3 on CP gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SNMP-v-3-on-CP-gateway/m-p/249852#M48790</link>
      <description>&lt;P&gt;This is what I've done based on information from the community.&amp;nbsp; Please note, that this is not supported by Checkpoint and I take no responsibility if there is an issue.&lt;BR /&gt;&lt;BR /&gt;I know on the devices I've managed it works.&amp;nbsp;I've used this on&amp;nbsp; R81.x.&amp;nbsp; I see no reason why it would not work on R82.x&lt;/P&gt;
&lt;P&gt;clish:&lt;BR /&gt;add snmp usm user SNMPUser security-level authPriv auth-pass-phrase &lt;EM&gt;&lt;FONT color="#FF0000"&gt;&amp;lt;Password&amp;gt;&lt;/FONT&gt;&lt;/EM&gt; privacy-pass-phrase &lt;EM&gt;&lt;FONT color="#FF0000"&gt;&amp;lt;Password&amp;gt;&lt;/FONT&gt;&lt;/EM&gt; privacy-protocol AES authentication-protocol SHA256&lt;/P&gt;
&lt;P&gt;expert:&lt;BR /&gt;dbset snmp:v3:user:SNMPUser:auth:proto .1.3.6.1.6.3.10.1.1.3&lt;/P&gt;
&lt;P&gt;clish:&lt;BR /&gt;set snmp usm user SNMPUser vsid all (Only needed if you are using VSX)&lt;BR /&gt;show snmp usm user SNMPUser (Should report SHA-1)&lt;/P&gt;
&lt;P&gt;Need to ensure you reset the password at this final stage&lt;BR /&gt;set snmp usm user SNMPUser security-level authPriv auth-pass-phrase &lt;FONT color="#FF0000"&gt;&lt;EM&gt;&amp;lt;Password&amp;gt;&lt;/EM&gt;&lt;/FONT&gt; privacy-pass-phrase &lt;EM&gt;&lt;FONT color="#FF0000"&gt;&amp;lt;Password&amp;gt;&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;save config&lt;/P&gt;
&lt;P&gt;Note:&lt;BR /&gt;If you upgrade or apply a jumbo, you may have to redo this.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 May 2025 16:35:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SNMP-v-3-on-CP-gateway/m-p/249852#M48790</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2025-05-26T16:35:35Z</dc:date>
    </item>
    <item>
      <title>Re: SNMP -v:3 on CP gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SNMP-v-3-on-CP-gateway/m-p/249854#M48792</link>
      <description>&lt;P&gt;This is also how we do it.&lt;/P&gt;</description>
      <pubDate>Mon, 26 May 2025 16:48:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SNMP-v-3-on-CP-gateway/m-p/249854#M48792</guid>
      <dc:creator>joerivang</dc:creator>
      <dc:date>2025-05-26T16:48:15Z</dc:date>
    </item>
  </channel>
</rss>

