SNMPv3 unreliable talking to Fortigate 50E

2.0.0p17 (CFE)
Trial expired

CheckMK error
** [snmp] Cannot fetch system description OID .1.3.6.1.2.1.1.1.0. Please check your SNMP configuration. Possible reason might be: Wrong credentials, wrong SNMP version, Firewall rules, etc.CRIT , Got no information from host, execution time 4.1 sec**

Fortigate error
|Version|SNMP_v3|
|Message|Message authentication or checking failed (USM authentication failure)|

I am new to CheckMK, looking for guidance. Setup this instance some months ago and had little issue getting it running with all device which needed monitoring and for networking devices this was using SNMPv3.

Recently replaced the Vigor router with a Fortigate 50E and have been frustrated that it seems CheckMK cant reliable use SNMPv3 monitor this device.

  • I can configure CheckMK to use SNMPv3 with auth(MD5) and priv(DES) and CheckMK tests ok

  • I can run an snmpwalk test from other unix box’s with the SNMP settings used in CheckMK and it works just fine so credentials are good and configured correctly in firewall

  • Firewall configuration must be OK as snmpwalk is successful

  • I checked DNS. All seems OK

  • I can run “download SNMP walk” from CheckMK and it has thousands of OID including the one the error message states it can not find

Initially after I add this host in CheckMK all appears OK and data for the monitored services is update but after the 2nd or 3rd auto page refresh they all report as stale

Im at a loss what to check next. Is this a bug in CheckMK??

If SNMPwalk works and I use the same creds in CheckMK and I then start seeing auth failures in the firewall is CheckMK losing this config

Thanks for looking

How about starting your troubleshooting from here Monitoring with SNMP: Troubleshooting in God Mode | Checkmk ?

@chauhan_sudhir Thanks for the reply.

Followed the info on the page you provided but it didn’t find any issue.

Checking the Firewall host in Checkmk over several hours and the Checkmk reported this as Flapping.

Removed all SNMPv3 config and re added starting with just MD5 Authentication seemed OK added Privacy SHA it started playing up again.

For now Checkmk SNMPV3 is configured just for authentication and it seems to have settled down.

Going to leave config this way for another week at least before trying again to use privacy as well

This topic was automatically closed 365 days after the last reply. New replies are no longer allowed. Contact an admin if you think this should be re-opened.