{"id":4113,"date":"2024-04-20T08:17:59","date_gmt":"2024-04-20T08:17:59","guid":{"rendered":"https:\/\/geekmungus.co.uk\/?p=4113"},"modified":"2024-04-20T08:18:00","modified_gmt":"2024-04-20T08:18:00","slug":"enable-snmp-on-brocade-san-switch-snmpv1","status":"publish","type":"post","link":"https:\/\/geekmungus.co.uk\/?p=4113","title":{"rendered":"Enable SNMP on Brocade SAN Switch (SNMPv1)"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The Brocade SAN Switches have SNMP capability which can be used for configuration and monitoring. These instructions detail how to configure SNMP on the SAN switches to allow them to have their state be monitored via SNMP from a suitable monitoring platform (e.g. NagiosXI or Opsview etc.).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We are not configuring SNMP Traps, this is purely a SNMP Poll configuration.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Configure SNMPv1 for Polling<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The following configures the SAN switch for SNMPv1 Polling to query for information from the switch&#8217;s SNMP OIDs.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">SNMPv1 is not secure, however to minimise risk, it is configured only for Read-Only (RO) i.e. get\/polling and not set (i.e. changes). Additionally we are specifying an ACL (accessControl) to limit access to just the monitoring platform IP addresses.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Enable SNMPv1<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Configure SNMPv1 with a simple and Read-Only (ro) configuration.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>fc_switch_grn:FID128:admin> snmpConfig --add snmpv1 -index 1 -community &lt;communitystring> -groupname ro\r\nCommitting configuration.....done.<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">Adding ACL or IPFilter<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Depending on the OS version of the switch you may need to use ACL or IPFilter, see the details below to restrict the connections from only the monitoring devices. Later versions require instead of the ACL an IPFilter Policy:\u00a0<a href=\"https:\/\/techdocs.broadcom.com\/us\/en\/fibre-channel-networking\/fabric-os\/fabric-os-administration\/9-2-x\/v26758161\/v26759131.html\">https:\/\/techdocs.broadcom.com\/us\/en\/fibre-channel-networking\/fabric-os\/fabric-os-administration\/9-2-x\/v26758161\/v26759131.html<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">ACL Approach (Earlier OS Versions)<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>fc_bc05a_red:FID128:admin> snmpconfig --set accessControl -index 1 -host 10.0.0.10 -access ro\r\nCommitting configuration.....done.<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">IPFilter Policy (Later OS Versions)<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">You can&#8217;t edit the default policy, you need to clone\/create a new one, then activate that, only one policy can be used at a time, so when you activate your custom one, the default one is disabled (along with any rules it provides).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In this example the monitoring host is on 10.0.0.10, so we need to allow that with an SNMP rule.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>ipfilter --create mypolicy_ipv4 -type ipv4\r\n \r\nipfilter --addrule mypolicy_ipv4-rule 1 -sip any -dp 22 -proto tcp -act permit\r\nipfilter --addrule mypolicy_ipv4-rule 2 -sip any -dp 23 -proto tcp -act permit\r\nipfilter --addrule mypolicy_ipv4-rule 3 -sip any -dp 80 -proto tcp -act permit\r\nipfilter --addrule mypolicy_ipv4 -rule 4 -sip any -dp 443 -proto tcp -act permit\r\nipfilter --addrule mypolicy_ipv4-rule 5 -sip 10.0.0.10 -dp 161 -proto udp -act permit\r\nipfilter --addrule mypolicy_ipv4-rule 8 -sip any -dp 123 -proto udp -act permit\r\nipfilter --addrule mypolicy_ipv4-rule 9 -sip any -dp 600-1023 -proto tcp -act permit\r\nipfilter --addrule mypolicy_ipv4-rule 10 -sip any -dp 600-1023 -proto udp -act permit\r\nipfilter --save mypolicy_ipv4\n \r\nipfilter --activate mypolicy_ipv4<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Verify the configuration is successful with:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>snmpconfig --show snmpv1<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>The Brocade SAN Switches have SNMP capability which can be used for configuration and monitoring. These instructions detail how to configure SNMP on the SAN switches to allow them to have their state be monitored via SNMP from a suitable monitoring platform (e.g. NagiosXI or Opsview etc.). We are not configuring SNMP Traps, this is &#8230; <a title=\"Enable SNMP on Brocade SAN Switch (SNMPv1)\" class=\"read-more\" href=\"https:\/\/geekmungus.co.uk\/?p=4113\" aria-label=\"Read more about Enable SNMP on Brocade SAN Switch (SNMPv1)\">Read more<\/a><\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[51],"tags":[],"class_list":["post-4113","post","type-post","status-publish","format-standard","hentry","category-brocade-san"],"_links":{"self":[{"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/4113","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4113"}],"version-history":[{"count":1,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/4113\/revisions"}],"predecessor-version":[{"id":4114,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/4113\/revisions\/4114"}],"wp:attachment":[{"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4113"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4113"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4113"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}