Cisco :: When Below SNMP Trap Type Triggers From Network Devices
Dec 7, 2012
We are implementing fault management tool and for that we need information such as what type of traps are being triggered by router on what events..currently we have BGP, interface,reachability,h/w,syslog,authfail,config, trap types configured..All these are hitting in our fm tool but I need to know when these traps are being triggered by router.more importantly authfail, config, syslog, bgp.
Upgraded LMS to 4.1. Yep basically reinstalled. However I can't remember how I did a couple of thing on the original system.
I am trying to take the traps from the Cisco equipment to the LMS and generate e-mail. How do I take the incoming traps (Crit and Warning) and send an e-mail alarm. I'll plan to control what to trap on at the Cisco Equipment.
SNMP trap is set from a fan fault, the Cisco send a trap to the LMS. Now I want take that trap and forward via an email.
I have been reading the admin documentation on "Notification and Action Setting". I see how to take the Cisco LMS created trap and email alarm. (In this case I need a specific trap that LMS did not have.) I see how to take Cisco Traps and resend them to other NMS.
I want to make my switch send trap when failed SSH login is detected. I found the "login Enhancement" feature and enabled the trap and logging for the failed attempt.
3750# sh run | in login aaa authentication login default local login delay 1
I am in the process of testing VA5(1.2) version of ACE on ACE4710 appliance.I did redundnacy configuration and it is working fine.I have done the snmp configuration and SNMP trap receiver is able to recieve traps like link up/down, so it proves that SNMP configuration is working fine, but i am not able to generate the SNMP trap notification for "clrRedundancyStateChange".I tried two things:
1) Via CLI, ran the command "ft switchover all" and i could see redundancy state changes.
2) Powered down Active 4710 appliance and standby ACE 4710 appliance taking over as Active.
However, none of the above could generate the trap clrRedundancyStateChange. how this trap can be generated? In snmp-server enable traps commands doesn't have any option for enabling FT related traps.
How to prepare my network for snmp,currently i don't have SNMP configured with community,so what is the requirement for that?what server i need to configure in order to receive SNMP traps coz last time i had issue ,one of my tunnels (terminated on asa 5510) goes down for 2 hours and i didn't realized that
I want to be able to send snmp traps to my NMS alerting our NOC to when we reach our configured max-associations on an ap. We currently use both 1130 AG and 1140-2N in autonomous mode, no controller. I have found a debug command "debug dot11 station connection failure" and the output of a test AP shows us the fact that the maximum number was reached. I need to find if it is possible to trap on such information.
Now I'm trying to write software that get information from Syslog message, but I'm facing with the problem about getting statistic of client de-authenticated in a WLC (Software Version: 7.0.98.0), because I cannot find any log about this information on WLC except only this SNMP trap:
Tue Aug 23 09:52:28 2011Client Deauthenticated: MACAddress:00:xx:77:2c:06:db Base Radio MAC:00:xx:5d:0c:fc:30 Slot: 0 User Name: unknown Ip Address: 10.2xx.47.15 Reason:Unspecified ReasonCode: 1
So, is there any way that I can configure WLC to convert this SNMP trap to send to Syslog server as a normal Syslog message?
I have Cisco 2960's, 3750's and 3750x's all running IOS on the access layer. I have Cisco 6504's running IOS on the Distribution and Core layers. I am looking to monitor redundant links through Spectrum by having specific ports send traps but I have run into trouble finding how to configure it. I would like to have:
1. Logging enabled for all links (Fiber and Copper) so that I see all links up/down messages in the syslog 2. SNMP traps sent for linkup/link down messages only for redundant links (ex. Dual Up links from Access Layer or Redundant Ether channel Links on Dist Layer) 3. SNMP traps should be ignored/not sent for all copper ports.
I have a snmp trap sent every 30 seconds from one of my cisco switches (a stack of 3750 to be precise): ccStatusMemberStatusChange. Do you know what it is and why it is sent continuously?
We have two ACE4710 in a failover configuration with Software version A4(2.0). SNMP is setup and the receiver is able to receive SNMP traps.The issue is we are receiving a linkDown trap notification at least once every other day, followed shortly by a linkUp notification a minute later. We have checked all layer 2 devices connected to the ACE and cannot see any evidence that any link actually disconnected. We experienced no traffic lost, but this could be because a couple of the ACE links are bundled. The trap notification does not actually indicate which interface changed status. All links are Gigabits, and there are no packet drops either on the ACE or the layer 2 switch.
i am using cisco LMS 2.6. Is it possible to discover devices through SNMP RW string?as LMS is not doing so. is is deffendable for me to have two strings RO and RW for discovery of the devices ?
I've beating my head against the the above said problem for a quite a while. Our client has a very strict security policy and they require all standard protocol to comply with the expected behaviour. It was discovered that their 3750 switch running c3750-ipservicesk9-mz.122-25.SEE3 software and configured to sync its time with an external public NTP server triggers IPS signature - DNS Info leak. The problem is that the switch initiates the packet on UDP port 53 and not as I would expect on port 123 for NTP. Of course I can tune the IPS sensor and make it not to fire this signature but the client needs to know why it is happening and if it is faulty IOS software that doesn't comply to the rules.
Everytime the console port is plugged in, the alarm contacts (1-4) randomly assert (trigger) and then clear themselves in random orders. Nothing is plugged into the ALARM port and all Alarm setting are default. Below is the syslog message and Alarm Settings:
CGS2520-C#show env allSYSTEM TEMPERATURE is OKSystem Temperature Value: 45 Degree CelsiusPOWER SUPPLY 1A TEMPERATURE is OKPOWER SUPPLY 1B TEMPERATURE is DisabledPOWER SUPPLY 1A Temperature Value: 49 Degree
I have 2 3560 switches that are running 12.2(25)SEE2. Port security is enabled on some of the ports. Whenever there is a power failure, when power is restored, 1 port on each switch goes to err-disabled. The mac address that causes this is a valid address for that port. Below is the configuration on one of the ports.
(my connection is a wired cable/DSL modem btw, using a second temp connection to troubleshoot)Last night, my connection was all fine and dandy until I got up this morning. Instead of having access to it and it being set as a home network, it was set to unidentified and public and I now have no internet access on the network. I can't change the network type either, it's stuck as public.[CODE]
Looking to set up a wireless printer (HP Deskjet 3050 All-in-One Printer - J610a) for use by another computer on the network; at present the printer is wirelessly connected to the router (Linksys e1000) and the software is installed on one computer (Win 7). The router recognizes a Network printer but no details about type.
The printer works correctly with the Win 7 machine but can't be found by the other machine (Win xp). Could it possibly be that I need to install the same software on the Win xp computer in order for it to be connected? Just guessing here as that was the case with another printer I networked but it was a Canon brand.
I have a 5508 wireless lan controller we have two SSID configured Profile Name : Corporate and Guest When I go look at the Most Recent Traps all I see is Client with Mac address blah has joined your corporate, this goes on for sometime. But I am unable to see any of the Guest logs joining the network, I have since then grabbed my laptop and connected to the guest log. I still dont see any logs in Most Recent Traps for the Guest SSID WLAN configuration, I then blocked my Mac address and tried to connect again, No logs. I need to also montior the guest network is there some special tick box I need to apply for this to work? Once the guest is connected I can view them in the clients list but it never shows them on MOST RECENT TRAPS but I want to see the guests account connecting or failing to connect as we currently have a rogue device annoying me.
Which trap we need to enable to monitor FEX module on 5K.If FEX goes down due to link failure/power down we do not receive any trap on SNMP server. Ethernet1/5 is where Fex module in connected on 5K
Some sample log
2013 Jan 4 12:11:32switch1 %FEX-5-FEX_PORT_STATUS_NOTI: Uplink-ID 1 of Fex 103 that is connected with Ethernet1/5 changed its status from Connecting to Active 2013 Jan 4 12:11:32switch1 %ETH_PORT_CHANNEL-5-PORT_UP: port-channel103: Ethernet1/5 is up 2013 Jan 4 12:11:32switch1 %ETH_PORT_CHANNEL-5-FOP_CHANGED: port-channel103: first operational port changed from none to E thernet1/5
As part of troubleshooting a seperate issue, somebody on my 891 router had set logging trap debugging which shows as a line in sh run just above the access-lists. There is no syslog server however so I'd like to remove this entry, however when I do no logging trap debugging I end up with a no logging trap entry replacing the previous logging trap debugging entry. Is there away to be rid of this entry? I tried no no logging trap but of course that's an invalid command.
I have multiple 6509 vss switch. and i notice when the standby chassis reboot I didn't get any snmp trap, but I got when the active one reboot. my question is is there any mib out there for detecting and got a trap when standby reboot?
I wasn't sure where to post this as I'm not using cisco to do the network withwhat happens to a network when it goes over 255 devices that need IP address, how does the IP addressing then work?
My home network currently consists of the following components...
BT Homehub 3 router - B/G/N PC running Windows 7 and using a Edimax wireless pci adaptor - B/G/N XBox 360 with live connection - N Laptop with inbuilt wifi and no slots for another card except via USB - G Various phones - G
Everything in the house is running at ~ 26-54 Mb/s at the moment and the two N devices have a very weak signal due to their distance from the router. Unfortunately, moving the router to somewhere that will benefit one device will have a detrimental effect on the other due to their locations.The router has the option to switch on 40mhz (mbit???) which, I gather, is also known as channel bonding and this should boost the range and speed of the N service but I also gather that doing this will stop all the G devices from connecting at all.I still have the Homehub 2 router that I was using before so I was wondering if there is any way I could make use of this (or anything else) to allow me to use all devices in the house at their fastest speeds.
How to feel about having network devices resolve names? Do you typically do it? No? Why or why not?I feel like I haven't seen it set up a lot, but it could certainly be good for specifying logging hosts and things like that.
Facing issue with 2960G switch , where its do not display "logging trap informational " in show running and show startup .where its showing all other levels from 0 to 5 and 7 after configuration and save commands. [code] after config getting saved , it do not shows in show runn or in show startup while for all other levels it do show the config lines .I tried the same on 12.55.SE release also but its same results . Is this a limitaion of this platform, is there any doc explaining the same for reference. [code]