Unsolved

1 Rookie

 • 

4 Posts

734

October 19th, 2021 14:00

SNMPv3 trap forwarding changing engine ID on every request

Hi There,

The SNMPv3 trap forwarding functionality is unfortunately unusable with OpenManage Enterprise.

The engine ID appears to change on every request - as per the SNMPv3 specification, the trap receiver hashes the authentication and privacy passphrases with the engine ID of the trap originator, which means that it is impossible to create valid credentials for use with trap forwarding.

OpenManage needs to keep the engine ID constant - it's supposed to uniquely and persistently identify an application to the trap receiver. It would also be nice if the engine ID were exposed in the GUI, as at the moment the only way to attempt to configure it is to do a packet capture.

Debug log from the trap receiver
--------------------------------

First Packet from OME:
lcd_set_enginetime: engineID 80 00 13 70 01 A9 FE FF 01 05 19 5D 21 : boots=0, time=0
usm: no match on engineID (80 00 13 70 01 A9 FE FF 01 05 19 5D 21 )

Second Packet from OME:
lcd_set_enginetime: engineID 80 00 13 70 01 A9 FE FF 01 FB 92 FB 91 : boots=0, time=0
usm: no match on engineID (80 00 13 70 01 A9 FE FF 01 FB 92 FB 91 )

On the subject of SNMPv3, it's still not possible to add Dell Networking devices (e.g. S5000) using SNMPv3 - OpenManage essentials had this functionality.

There really should be an way for OpenManage to handle these devices without relying on clear text protocols at this point.

No Responses!
No Events found!

Top