{"id":1238,"date":"2022-09-25T11:37:55","date_gmt":"2022-09-25T11:37:55","guid":{"rendered":"https:\/\/www.geekmungus.co.uk\/?p=1238"},"modified":"2022-11-05T10:53:18","modified_gmt":"2022-11-05T10:53:18","slug":"extreme-networks-voss-switch-snmpv3-configuration-and-monitoring-configuration","status":"publish","type":"post","link":"https:\/\/geekmungus.co.uk\/?p=1238","title":{"rendered":"Extreme Networks VOSS Switch &#8211; SNMP(v3) Configuration and Monitoring Configuration"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Moniting with SNMPv3 is much like monitoring with SNMPv2 or 1 for that matter, except SNMPv3 offers greater security options. SNMPv1 or v2 offers very little security being based on a plain text community string, of course on the monitored device you can restrict which hosts are allowed to connect to your monitored device via SNMP to improve things, but nowadays SNMPv3 should be used where at all possible.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"ExtremeNetworksVOSSSwitchSNMP(v3)ConfigurationandMonitoringConfiguration-SNMPv3Basics\">SNMPv3 Basics<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">So what is different about SNMPv3, well let&#8217;s run through the basic compoents first.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>MIB Tree<\/strong> &#8211; The MIB Tree is the list of OIDs for the various monitored objects within the device, these are all the values that are exposed in the MIB Tree that you can query for.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>View<\/strong> &#8211; A View is a view of the MIB Tree, this might be the whole of the MIB Tree including all the OIDs within or may just be a subset of the MIB Tree that only includes a small number of OIDs. For example you may want a view that just includes the OIDs for the network interfaces of a switch, but doesn&#8217;t include anything else. Kinda enforcing the &#8220;need to know&#8221; approach, if the View is only ever going to be used to query for the interface statuses, why have it able to see all the power supply statuses as well?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>USM Group (User-Based Security Mode) Group<\/strong> &#8211; Simply put it is a group that contains users (see next), the Group then has a View assigned to it, with various required access levels to the View defined, e.g. Read Only, Read\/Write etc. Users are placed into groups.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>User <\/strong>&#8211; A user is the entity that can access the device via SNMPv3 and based on the USM Group (with its assigned permissions and View) can query the MIB Tree (and\/or a subset of OIDs) based on the specification of the View.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There are also three access levels of the USM Group to be aware of:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>NoAuthNoPriv <\/strong>&#8211; Communication without authentication and privacy<\/li><li><strong>AuthNoPriv <\/strong>&#8211; Communication with authentication (MD5 or SHA) and without privacy<\/li><li><strong>AuthPriv <\/strong>&#8211; Communication with authentication (MD5 or SHA) and privacy (DES or AES)<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">There are sometimes reasons to use <strong>NoAuthNoPriv <\/strong>and <strong>AuthNoPriv <\/strong>(e.g. the overheads in encryption added by AuthPriv may consume more resources on the monitored and monitoring systems) but these in our case are pretty rare, so we should really only use <strong>AuthPriv<\/strong> that provides encryption and privacy of the username, password and payload.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"ExtremeNetworksVOSSSwitchSNMP(v3)ConfigurationandMonitoringConfiguration-ExtremeNetworksVOSSSwitchSNMPv3ConfigurationExample\">Extreme Networks VOSS Switch SNMPv3 Configuration Example<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The following example is for an Extreme Networks VOSS based switch running 8.5.2.0.GA. You&#8217;ll find a complete example configuration below, but first, let&#8217;s step through each line to explain what is going on, firstly these lines are just for reference and add configuration to the switch that you can query to assist in determining the location and function of the switch. You&#8217;ll have done something similar with the switch&#8217;s actual hostname (as it appears at the CLI).<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>snmp-server contact \"helpdesk@domain.com\"\nsnmp-server location \"Site Name - Rack Location\"<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Now we move to the real meat of the configuration, firstly this created a <strong>View <\/strong>called &#8220;ALL&#8221; which starts from 1 in the MIB Tree, i.e. this includes the whole of the MIB Tree within the View. If you want a View that only includes a single OID or a sub-tree you can specify it here, but in our case we want to be able to query the whole thing.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>snmp-server view ALL 1<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Next we create a <strong>USM Group<\/strong> called &#8220;MONITORING&#8221;, which is specified for the GlobalRouter VRF by the two speech marks. We then specify the <strong>auth-priv<\/strong> access level must be used, which means it is expecting both a username\/password and privacy password all of which are encrypted. When then specify the group&#8217;s read-view, i.e. what it has Read Only access to, in this case specifying the &#8220;ALL&#8221; view we just created. Then we specify this group&#8217;s Notify view which again is the &#8220;ALL&#8221; view we just created. You can if you wish also add the Write View (with write-view) that will then specify the view that is used for having write privileges, in our case we are not specifying this, so this group will only allow read only and notify (via SNMP traps).<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>snmp-server group MONITORING \"\" auth-priv read-view ALL notify-view ALL<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Then we need to create the User, so to do this use the following command, this creates the User called &#8220;monitoring-user&#8221; and adds it into the group &#8220;MONITORING&#8221;, it then specifies the Auth password (and hashing type, we picked SHA in this case) and then the Priv password (and encryption cipher type, in our case we picked AES).<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>snmp-server user monitoring-user group MONITORING sha &lt;AUTHPASSWORD&gt; aes &lt;PRIVPASSWORD&gt;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Note: Refer to the Key Store for the <strong>Auth Password<\/strong> and <strong>Priv Password<\/strong> that you should use for your monitoring device.<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There are then these three lines, which specify the host that this switch will send SNMP traps to, the IP from which this switch will send those from which on this version of VOSS did not seem to be required, and finally the command to ensure that SNMP blocking is turned off to ensure that the requests can make it through to the switch.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>snmp-server host 192.168.5.100 v3 authpriv monitoring-user\nsnmp-server sender-ip 192.168.1.10 192.168.5.100 (Does not appear to be required with current VOSS version)\nno boot config flags block-snmp<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"ExtremeNetworksVOSSSwitchSNMP(v3)ConfigurationandMonitoringConfiguration-ExampleConfiguration\">Example Configuration<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The below is an example configuration that can be used to provide access to the SNMP MIB Tree and its OIDs.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>snmp-server contact \"helpdesk@domain.com\"\nsnmp-server location \"Site Name - Rack Location\"\n \nsnmp-server view ALL 1\n \nsnmp-server group MONITORING \"\" auth-priv read-view ALL notify-view ALL\n \nsnmp-server user monitoring-user group MONITORING sha &lt;AUTHPASSWORD&gt; aes &lt;PRIVPASSWORD&gt;\n \nsnmp-server host 192.168.5.100 v3 authpriv monitoring-user\nsnmp-server sender-ip 192.168.1.10 192.168.5.100 (Does not appear to be required with current VOSS version)\nno boot config flags block-snmp<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">For reference if you wanted to include &#8220;write-view&#8221; you&#8217;d use this for the group configuration directive.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>snmp-server group MONITORING \"\" auth-priv read-view ALL write-view ALL notify-view ALL<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/extremeportal.force.com\/ExtrArticleDetail?an=000083460\">https:\/\/extremeportal.force.com\/ExtrArticleDetail?an=000083460<\/a><\/li><li><a href=\"https:\/\/community.extremenetworks.com\/t5\/extremeswitching-vsp-fabric\/snmpv3-voss-solarwinds\/m-p\/80010\">https:\/\/community.extremenetworks.com\/t5\/extremeswitching-vsp-fabric\/snmpv3-voss-solarwinds\/m-p\/80010<\/a><\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"ExtremeNetworksVOSSSwitchSNMP(v3)ConfigurationandMonitoringConfiguration-NagiosXIExampleMonitoringCommand\">NagiosXI Example Monitoring Command<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">When you wish to use SNMPv3 within a monitoring command you need to ensure you are including whatever is required to collect your desired information.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"ExtremeNetworksVOSSSwitchSNMP(v3)ConfigurationandMonitoringConfiguration-Example1-SimpleQueryofVOSSVersion\">Example 1 &#8211; Simple Query of VOSS Version<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">We&#8217;ll perform a very simple check that will just return the <strong>sysDecr.0 (.1.3.6.1.2.1.1.1.0)<\/strong> value, once you have verified this is working you can progress to more complicated (and useful) monitoring commands.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>.\/check_snmp -H &lt;HOSTNAME&gt; -o &lt;OID_STRING&gt; -P 3 -L authPriv -a SHA -x AES -U &lt;USERNAME&gt; -A &lt;AUTHPASSWORD&gt; -X &lt;PRIVPASSWORD&gt;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">So with some real information you might have a command and output that looks like this:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>.\/check_snmp -H switch1.domain.com -o .1.3.6.1.2.1.1.1.0 -P 3 -L authPriv -a SHA -x AES -U mon-user -A T0pS3cr3t! -X D0nt!Tell1\nSNMP OK - \"VSP-7400-48Y-8C (8.5.2.0)\" |<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"ExtremeNetworksVOSSSwitchSNMP(v3)ConfigurationandMonitoringConfiguration-Example2-QueryInterfaceOperatingStatus\">Example 2 &#8211; Query Interface Operating Status<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Perform a query on the operating status of the GigabitEthernet 1\/49 port on the switch, this port has the OID ending in &#8220;256&#8221;, the GigabitEthernet 1\/50 port on the switch has the OID ending in &#8220;257&#8221;.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>.\/check_snmp -H switch1.domain.com -o .1.3.6.1.2.1.2.2.1.8.256 -P 3 -L authPriv -a SHA -x AES -U mon-user -A T0pS3cr3t! -X D0nt!Tell1 -s \"1\"\nSNMP CRITICAL - *2* | iso.3.6.1.2.1.2.2.1.8.256=2\n\n.\/check_snmp -H switch1.domain.com -o .1.3.6.1.2.1.2.2.1.8.257 -P 3 -L authPriv -a SHA -x AES -U mon-user -A T0pS3cr3t! -X D0nt!Tell1 -s \"1\"\nSNMP OK - 1 | iso.3.6.1.2.1.2.2.1.8.257=1<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">As you can see GigabitEthernet 1\/49 is reporting status &#8220;2&#8221; which means Down, and &nbsp;GigabitEthernet 1\/50 is reporting status &#8220;1&#8221; which means is Up!<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Note: SNMP Responses are as follows: INTEGER &nbsp;{ up ( 1 ) , down ( 2 ) , testing ( 3 ) , unknown ( 4 ) , dormant ( 5 ) , notPresent ( 6 ) }&nbsp;<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/unsplash.com\/@thomasjsn\" data-type=\"URL\" data-id=\"https:\/\/unsplash.com\/@thomasjsn\">Image Attribution<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Moniting with SNMPv3 is much like monitoring with SNMPv2 or 1 for that matter, except SNMPv3 offers greater security options. SNMPv1 or v2 offers very little security being based on a plain text community string, of course on the monitored device you can restrict which hosts are allowed to connect to your monitored device via &#8230; <a title=\"Extreme Networks VOSS Switch &#8211; SNMP(v3) Configuration and Monitoring Configuration\" class=\"read-more\" href=\"https:\/\/geekmungus.co.uk\/?p=1238\" aria-label=\"Read more about Extreme Networks VOSS Switch &#8211; SNMP(v3) Configuration and Monitoring Configuration\">Read more<\/a><\/p>\n","protected":false},"author":4,"featured_media":1242,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[17],"tags":[],"class_list":["post-1238","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-networking"],"_links":{"self":[{"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/1238","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1238"}],"version-history":[{"count":1,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/1238\/revisions"}],"predecessor-version":[{"id":1298,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/1238\/revisions\/1298"}],"wp:attachment":[{"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1238"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1238"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1238"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}