Server Management (Insight Manager 7)
1819914 Members
2085 Online
109607 Solutions
New Discussion юеВ

Authentication Failure Trap Messages..

 
Ayman Altounji
Valued Contributor

Authentication Failure Trap Messages..

On each server that is being monitored by XE we have the following entries on the SNMP Service Properties:
Security Tab: checked off Send Authentication Trap
Checked off Accept Community Names:
w35t ready only
w35tc0n read write
Checked off Accept SNMP Packets from these Hosts:
172.16.100.91 (ip address of server running XE)
After these settings have been made and you stop and start SNMP
We receive numerous Authentication Failure Messages within XE for the devices that have these settings. WHY?
If we check off Accept SNMP packets from Any Hosts. Stop and Start SNMP. we NO LONGER get the messages
Why is this?
2 REPLIES 2
Ayman Altounji
Valued Contributor

Re: Authentication Failure Trap Messages..

Are you running on NT or Win2k? Certain SNMP settings require that the SNMP service be "cycled" for them to become active - FYI.
Ayman Altounji
Valued Contributor

Re: Authentication Failure Trap Messages..

I've been in this boat myself. If you choose to "Security Tab: checked off Send Authentication Trap Checked off " on a server, your instructing SNMP security on that server to trap anytime there's an attempt to connect via SNMP to this server with community strings that don't match (i.e. possibly someone's hacking your server via SNMP). I discovered in my shop, there's all kinds of SNMP traffic out there I wasn't aware of. My CIM-XE server (as well as the sql db) was being flooded with traps. You can shut of collecting these messages temporarily by turning off the receiving of 'informational events' in CIM-XE. This will allow you to track down where the invalid SNMP contacts are comming from and clean up. You can also just deselect SNMP's "Security Tab: checked off Send Authentication Trap Checked off " and not worry about SNMP security ;-)