Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Sending SNMP Traps to ClearPass

This thread has been viewed 18 times
  • 1.  Sending SNMP Traps to ClearPass

    Posted Jun 27, 2022 11:40 PM
    Is there any reason to be sending SNMP traps to ClearPass from lets say a Cisco access layer switch? We continually receive log messages about bad traps:

    Ignore v2c trap. Bad security name in trap"

    For the devices we get these errors on, we have confirmed that the SNMP strings configured under Administration/External accounts match what is configured both on the device and under Configuration/Network/Devices yet we constantly received these messages in the Event Viewer, making it easy to miss important log messages.

    Should we configure our devices to send traps to ClearPass or is this maybe not worth the headache?


  • 2.  RE: Sending SNMP Traps to ClearPass

    EMPLOYEE
    Posted Jun 28, 2022 04:48 AM
    SNMP External accounts are used for ClearPass active profiling(Pulling data from switches and for endpoint scan). you can read more about from the tech note :
    https://support.hpe.com/hpsc/doc/public/display?docId=a00100323en_us
    You can remove the snmp trap sent to clearpass from the switch.


  • 3.  RE: Sending SNMP Traps to ClearPass

    Posted Jun 28, 2022 07:01 AM
    You can remove the trap configuration.  SNMP in general is not worth the headache IMHO.  Use other profiling methods such as DHCP relay.


  • 4.  RE: Sending SNMP Traps to ClearPass

    Posted Jun 28, 2022 07:50 AM
    what is ur purpose on sending snmp traps to clearpass ?





  • 5.  RE: Sending SNMP Traps to ClearPass

    Posted Jul 05, 2022 04:22 PM
    Just figured it would add extra profiling information, if I have the correct SNMP information I am not understanding why it does not work. 

    Either way, sounds like I do no need to be using traps.


  • 6.  RE: Sending SNMP Traps to ClearPass

    Posted Jul 06, 2022 12:28 AM
    i am going to use whichever profiling method available in clearpass @ my project here, and when i open a tac case, the tac confirms we no longer need snmp traps to send to clearpass.

    doc ref: 
    1. active profiling pdf
    2. profiling tech note v1.2