Comments
-
unfortunately, i dont know enough about this stuff to really check anything. i remoted in to both scom and orion and couldnt find anything helpful. But as i said i am in no way a server admin or even junior admin. i will just have to convince the server guys to check it when they get time.
-
oh thank god i understand somewhat. hopefully i can find the traplogs and such.
-
the only ip's ever listed in the traps are the routers and the scom. i dont understand why scom ip is even on there when 1.8 is the polling and trap server, right?
-
i have no idea what yall are talking about. all it shows me is how much data was passed. i dont see anywhere to actually inspect the packets. I am just too unfamiliar with this software to really try to fix this. i appreciate all you trying to help.
-
its an scom, know of anything that might do that? he said he changed the comm strings already.
-
traffice showed udp 161 in green and netbios name service(137) in red
-
yep when i hit Test under node management, its passes. always has, i see what yall are saying about something in SCOM, since that is the IP that is saying its trying to auth to. I may have to wait until the other server admin gets off vacation to ask him about it.
-
there are none
-
its seems like all network devices are doing this. im pretty sure they reset it about 2 days ago. something interesting, in router/switch configs, i have the server as 1.8 which is orion, but in the traps viewer, it shows them trying to authen to the y.y.y.y which is 1.57, why are they different?
-
i was getting the same issue. we tried everything, server guy poured over server to dig out all the comm strings. was still getting authfailures from almost all network devices. the only "solution" i found is to take out the snmp server ip out of the device. not much of a fix but it stopped the traps. first i just disabled…
-
that didn't work
-
also, why does it report the outside IP's of the devices?
-
isn't the authen traps kind of the point in doing it? we managed to get most of the routers to stop showing up, now its all switches. Server admin said the comm strings were buried a million places so i dont think this will be a quick fix.
-
should i change the snmp server in the configs to 1.57?
-
1.57 is our SCOM, in the configs 1.8(NPM) is the snmp server. As you can tell i am a total noob to this. snmpTrapEnterprise = SNMPv2-MIB:snmpTraps experimental.1057.1.0 = device.IP sysUpTime = 116 days 16 hours 42 minutes 53.13 seconds snmpTrapOID = SNMPv2-MIB:authenticationFailure cExtSnmpTargetAuthInetAddr = .1.57…
-
everything looked fine, alot of unknown strings though. 2599583 SNMP packets input 0 Bad SNMP version errors 11258 Unknown community name 0 Illegal operation for community name supplied 0 Encoding errors 5211221 Number of requested variables 0 Number of altered variables 1273382 Get-request PDUs 7736 Get-next PDUs 0…
-
and you are talking about the ACL on the server?
-
its under the proper comm string in orion and is set correctly, i am asking about installing WS now
-
yes we recently changed it network wide. All is correct.
-
do you mean in the orion web console? its under node management then select the node then snmp settings.
-
where do i put this?