Here's what my log file looks like on one of my core 6509s (imagine about a billion more though):
Jan 25 15:06:19: %SNMP-3-AUTHFAIL: Authentication failure for SNMP req from host 10.16.2.142
Jan 25 15:23:42: %SNMP-3-AUTHFAIL: Authentication failure for SNMP req from host 10.16.2.142
Jan 25 15:35:39: %SNMP-3-AUTHFAIL: Authentication failure for SNMP req from host 10.16.2.142
Jan 25 15:51:28: %SNMP-3-AUTHFAIL: Authentication failure for SNMP req from host 10.16.2.142
Jan 25 16:08:30: %SNMP-3-AUTHFAIL: Authentication failure for SNMP req from host 10.16.2.142
Jan 25 16:20:10: %SNMP-3-AUTHFAIL: Authentication failure for SNMP req from host 10.16.2.142
Jan 25 16:38:33: %SNMP-3-AUTHFAIL: Authentication failure for SNMP req from host 10.16.2.142
The node is perfectly managable via SNMP. BTW 10.16.2.142 is our polling engine.
- At first glance it would seem to be an ACL issue (we have the community ACL'd) but that looks fine.
- Also the "Test" SNMP button in manage nodes works fine.
- I even went as far as to pull out wireshark, and I didn't see any packets at the time of the alert with the wrong community.
- I disabled SNMP subnet scanning in IPAM, no change.
Dunno what else to look at...any thoughts?
APM 4.2.0 SP1, IPAM 2.0.1, IPSLAMGR 3.5.1, NCM 7.0, NPM 10.2.1, NTA 3.8.0