Server Management - Systems Insight Manager
1752565 Members
5448 Online
108788 Solutions
New Discussion юеВ

Re: SNMP Required from IM server?

 
Megan Kielman
Advisor

SNMP Required from IM server?

I have been tasked with attempting to configure IM agents that reside in a very restricted DMZ. Everything I have read indicates that not only does the agent initiate SNMP traffic with the IM server, but the IM server initiates traffic with the agent. Is there any way around this? Also, it is a requirement for the IM server to poll or can I do a manual discovery and elimate the need for polling via ping?
5 REPLIES 5
David Claypool
Honored Contributor

Re: SNMP Required from IM server?

The Insight Agents/Systems Management Homepage send SNMP traps to the HP SIM server when a fault condition or other even occurs. HP SIM queries the Insight Agents during Server Status Polling for the ProLiant Status Array, during Device Identification and during Data Collection.

Server Status Polling of ProLiant servers is not an ICMP ping--it is a query via SNMP of the ProLiant Status Array OID.

Automatic discovery can be accomplished via ICMP ping or via an HTTP port inquiry, typically port 80.

If you do not want HP SIM to do an automatic discovery periodically of a subnet, you can manually discover the units either individually or via a hosts file. When you supply information to HP SIM during manual discovery, it will then proceed to interrorgate the device using all configured protocols in an attempt to identify it.

More information is available from the documents "Managing ProLiant Servers with HP SIM through firewalls" and "Understanding HP SIM Security" from http://www.hp.com/go/hpsim --> Information Library
Megan Kielman
Advisor

Re: SNMP Required from IM server?

Thank you so much for your quick response!

Ok so essentially it is required for the IM Server to initiate SNMP traffic to the agent. Correct?

I was also reading about SNMP passthru via iLO but I can't find much information about how this works. Does iLO enscapsulate this traffic via http/https or does it actually send and accept SNMP traps to the IM server?

Thanks again!!!
Martin Smoral
Trusted Contributor

Re: SNMP Required from IM server?

Megan, i successfully configured the ILO snmp passthrough on some servers in a DMZ so that i would not have to open SNMP ports on the firewall. Instead I connected the ILO Ports of the DMZ servers to the Internal Network. Now when there is a Problem, the IM Agent will try to send SNMP trap and it will be passed through the ILO to the SIM CMS Server on a different network. The Servers in the DMZ will still show Unmanaged though in the SIM Console.
David Claypool
Honored Contributor

Re: SNMP Required from IM server?

Martin, there's a couple of other issues with your configuration as well...you can't access the System Management Homepage and there is no data collection, either.

If these are Windows servers, you can allow DCOM traffic across the firewall as it's encrypted and provide WBEM credentials so the WMI mapper can communicate and then you'll get identification working so you'll get product names and a few other details. You'll still be lacking stuff that is unique ProLiant data like the physical drives and Product ID (which is necessary to use Contract and Warranty Lookup in HPSIM).

Also, if you open ports 2301 and 2381, HP SIM can identify the SMH and you'll be able to link off to it to launch out of HP SIM.
Megan Kielman
Advisor

Re: SNMP Required from IM server?

David - Can you explain how DCOM encrypts the traffic if the managed system belongs to a different AD domain than the SIM server? Does it use the certificate?