Network Management

last person joined: yesterday 

Keep an informative eye on your network with HPE Aruba Networking network management solutions
Expand all | Collapse all

SNMP trap authenticationFailure

This thread has been viewed 16 times
  • 1.  SNMP trap authenticationFailure

    Posted Sep 23, 2015 03:44 AM

    Hi everyone.
    Can anyone give me an advice about AirWave.
    Currently I have installed few aruba controllers and AirWave system to monitor them. From time to time I can see the following snmp traps in AirWave:

    Date and timeSNMP Trap----AuthauthenticationFailure


    What is that type of trap - is it user auth error, administrator auth error or SNMPv3 authentication error?



  • 2.  RE: SNMP trap authenticationFailure
    Best Answer

    EMPLOYEE
    Posted Sep 23, 2015 07:50 AM

    What is the whole message from the trap?

     



  • 3.  RE: SNMP trap authenticationFailure

    Posted Sep 23, 2015 07:57 AM
      |   view attached

    Actually, it's a whole message...here is picture next



  • 4.  RE: SNMP trap authenticationFailure

    EMPLOYEE
    Posted Sep 23, 2015 07:59 AM

    On the controller type "show snmp trap-queue" to see if you can find it.  Usually the message has much more information than that...

     



  • 5.  RE: SNMP trap authenticationFailure

    Posted Sep 23, 2015 08:05 AM

    That is little funny, but the output from cli for "show snmp trap-queue" command is:
    2015-09-23 12:50:23 SNMP Authentication Failed
    2015-09-23 12:50:28 SNMP Authentication Failed



  • 6.  RE: SNMP trap authenticationFailure

    EMPLOYEE
    Posted Sep 23, 2015 08:07 AM

    Okay.  That means something is wrong with the method you are using to poll.  Have you already tried working with snmpv2 successfully?

     

     



  • 7.  RE: SNMP trap authenticationFailure

    Posted Sep 23, 2015 08:15 AM

    Actually, SNMPv2 displays more information...
    Here is output from SNMPv2 trap:
    9/23/2015 8:39 AM    SNMP Trap    -    -    -    -    Auth    wlsxNAuthServerIsDown wlsxTrapAuthServerName.0: #########,
    wlsxTrapTime: 9/23/2015 8:39:32 UTC-3

     

    But it's strange....I thought that SNMPv3 gives the same information as v2. I thought that the only difference is in security parameters..

     

     



  • 8.  RE: SNMP trap authenticationFailure

    EMPLOYEE
    Posted Sep 23, 2015 08:19 AM

    Those look like two different notifications.  One trap is saying that snmp authentication failed.  The other one is reporting an authentication server is down.



  • 9.  RE: SNMP trap authenticationFailure

    EMPLOYEE
    Posted Sep 23, 2015 11:42 AM

    So you have the SNMPv3 informs configured on the controller for SNMPv3 with a user/password that exactly matches the SNMPv3 settings configured for airwave AND you don't have any auto-SNMPvX discovery settings configured on AirWave? I don't have one handy at the moments but so long as the controller is configured for SNMPv3 informs with the same username/password as what is configured for the SNMPv3 settings on Airwave (of which there are two places to configure), it will work fine without any SNMPv1/2 settings needed. 

     

    Remember, two places to configure SNMPv3 for a controller on AirWave:

    1. Within the device-specific communications

    2. Within the "SNMPv3 Informs" on the "Device Setup > Communications" page

     

    The controller should be configured for SNMPv3 Informs on the SNMP settings page.



  • 10.  RE: SNMP trap authenticationFailure

    Posted Sep 25, 2015 09:04 AM

    I checked current situation once more...
    Now I'm pretty sure, that next error exists only in SNMPv3.

     

    Date and timeSNMP Trap----AuthauthenticationFailure


    Also, I suspect that it's authentication error of controller and AirWave communication. I meen, that it's just internal SNMPv3 error.
    As I found, it appears nearly once per hour and makes auth errors for a 10-15 seconds. Despite that, all other SNMPv3 communication works fine. For now, I'm getting all traps, performing device polling...
    What can it be?
    To finalize, I'll say, that I currently successfully using SNMPv3 (for test), but once per hour getting authentication Failure.
    Also, from time to time, I'm getting next logs (which are in different time according authenticationFailure errors):

    Fri Sep 25 13:54:11 2015SystemError in SNMP polling: Unknown user name(interface_error_counter)
    Fri Sep 25 13:54:07 2015SystemError in SNMP polling: Unknown user name(neighbor_client_location)
    Fri Sep 25 13:24:11 2015SystemError in SNMP polling: Unknown user name(interface_error_counter)
    Fri Sep 25 13:24:07 2015SystemError in SNMP polling: Unknown user name(neighbor_client_location)
    Fri Sep 25 13:04:04 2015SystemPoll now complete
    Fri Sep 25 13:03:51 2015xe6752Polling now
    Fri Sep 25 13:03:35 2015SystemConfiguration verification: configuration on device does not match desired configuration
    Fri Sep 25 13:02:02 2015SystemPoll now complete
    Fri Sep 25 13:01:39 2015xe6752Polling now
    Fri Sep 25 12:54:24 2015SystemError in SNMP polling: Unknown user name(thin_ap_dot11)
    Fri Sep 25 12:54:24 2015SystemError in SNMP polling: Unknown user name(thin_ap_discovery)
    Fri Sep 25 12:54:13 2015SystemError in SNMP polling: Unknown user name(thin_ap_usb_interface)
    Fri Sep 25 12:54:11 2015SystemError in SNMP polling: Unknown user name(interface_error_counter)
    Fri Sep 25 12:54:09 2015SystemError in SNMP polling: Unknown user name(interface_bandwidth)
    Fri Sep 25 12:54:07 2015SystemError in SNMP polling: Unknown user name(tunneled_node_client)
    Fri Sep 25 12:54:06 2015SystemError in SNMP polling: Unknown user name(neighbor_client_location)


  • 11.  RE: SNMP trap authenticationFailure

    EMPLOYEE
    Posted Sep 25, 2015 09:10 AM

    What is the SNMPv3 username you are using again? I didn't see it in the above but could have missed it. Is it just a single SNMPv3 username? Also on the controller how many other SNMP users may be configured? Is it JUST the one SNMPv3 user or are there other SNMPv1/2c strings or other SNMPv3 users present?



  • 12.  RE: SNMP trap authenticationFailure

    Posted Sep 25, 2015 09:23 AM

    actually, I tried a few usernames with different credentials and algorithms. I'm working on it for week tried different usernames from "user1" to "d32sfFSD3" - result was all the time the same. At controller exists only one user and only one host as "trap reciever". On the controller is no other instances of SNMPv3 or SNMPv1/2 configs. There is just SNMPv3 with 1 user and one host.



  • 13.  RE: SNMP trap authenticationFailure

    EMPLOYEE
    Posted Sep 25, 2015 09:29 AM

    OK that's good as there is only a finite number of SNMPv3 servers a single controller can support (which I think is 3). Might be good to MAKE SURE in the CLI, but otherwise, TAC needs to get involved to look much closer and likely needs some pcaps possibly when these events occur.