Unable to discover Fortinet Generic firewall (867 Views)
Reply
Occasional Advisor
tagrawal
Posts: 22
Registered: ‎05-30-2012
Message 1 of 9 (867 Views)

Unable to discover Fortinet Generic firewall

Hi,

 

I am using NNMi v9.10 p3.

 

I am unable to discover fortinet Generic firewall with sys objectid: enterprises.12356.101.1.1002

Can someone please tell this device is certified in NNMi or not?

 

I have checked in MIB variable, its not showing there.

 

Please tell how i can discover this in NNM.

 

Thanks,

Tarun 

Please use plain text.
HP Expert
iquesada
Posts: 221
Registered: ‎03-07-2012
Message 2 of 9 (858 Views)

Re: Unable to discover Fortinet Generic firewall

First thing to check would be if that device is listed on Device Support Matrix. Let's have a look at:

 

HP Network Node Manager i Software (NNMi) Device Support Matrix->

                http://sg-pro-ovweb.austin.hp.com/nnm/NNM9.10/devicematrix.htm

 

Second, what are the steps you followed to add the device ? Are you using node seeds (ie nnmloadseeds.ovpl)?. You can also use the nnmnoderediscover.ovpl script to add nodes to the NNMi discovery queue. See the nnmnoderediscover.ovpl reference page, or the UNIX manpage, for more information

HP Support
The views expressed in my contributions are my own and do not necessarily reflect the views and strategy of HP.
If you find this or any post resolves your issue, please be sure to mark it as an accepted solution, If you are satisfied with anyone’s response please remember to give them a KUDOS and show your appreciation.
Please use plain text.
Honored Contributor
Ian_4
Posts: 3,738
Registered: ‎10-04-2000
Message 3 of 9 (852 Views)

Re: Unable to discover Fortinet Generic firewall

Did you try to seed it like so  nnmloadseeds.ovpl -n  <Fortinet device>   on some devices auto discovery may not work (see the NNMi release notes) , even if the device is not on the device support list NNMi must discover any device that respond to SNMP  and/or ICMP if you properly configured your discovery rules.

 

Hope this helps.

 

Please use plain text.
Occasional Advisor
tagrawal
Posts: 22
Registered: ‎05-30-2012
Message 4 of 9 (845 Views)

Re: Unable to discover Fortinet Generic firewall

[ Edited ]

Hi, 

 

Device is already certified in device matrix.

I have tried nnmloadseeds.ovpl but still after discovery, device discovered as <non-snmp>.

After configuration poll its showing following message:

 

snmp.JPG

 

I have checked that SNMP is configured at device end for NNM application.

 

Please suggest what is the problem??

 

Thanks,

Tarun

Please use plain text.
Honored Contributor
AndyKemp
Posts: 711
Registered: ‎05-17-2010
Message 5 of 9 (838 Views)

Re: Unable to discover Fortinet Generic firewall

You need to ensure that there is a permit rule defined on the firewall that allows SNMP access via UDP port 161 on an interface that is reachable by your NNMi server.

SNMP need to be enabled on the firewall.

A defined Read Only community on the firewall must match what you have configured in either a communication region or default rule.

Have a nice day :)

Andy Kemp,  CISSP
Please use plain text.
Honored Contributor
Ian_4
Posts: 3,738
Registered: ‎10-04-2000
Message 6 of 9 (833 Views)

Re: Unable to discover Fortinet Generic firewall

The output show “No SNMP” for 10.31.11.60, as Andy suggested you need to make sure that you can talks SNMP to this device.

 

Hope this helps.

 

Please use plain text.
Occasional Advisor
tagrawal
Posts: 22
Registered: ‎05-30-2012
Message 7 of 9 (811 Views)

Re: Unable to discover Fortinet Generic firewall

Hi,

 

For the SNMP communication i have checked with nnmsnmpwalk.ovpl.

 

This command takes around 1 hour in execution, that why in configuration poll its showing 'No SNMP' may be it get Timed out.

I can increase the Timed out and number of retries but it wouldn't solve problem to discover new devices. which i am facing in to discover these fortigate firewalls.

Due to this issue in my enviroment already 40% of devices are in Minor state, showing "No SNMP response"

 even communication is there.

 

Thanks,

Tarun

 

 

Please use plain text.
Honored Contributor
LindsayHill
Posts: 683
Registered: ‎11-16-2011
Message 8 of 9 (801 Views)

Re: Unable to discover Fortinet Generic firewall

If it's taking an hour to complete snmpwalk, and you've got devices in production showing "No SNMP access", then I'd be tempted to push it back to Fortinet, and ask them why it takes so long to get SNMP responses.

 

Does it just slowly keep returning results, or are there certain OIDs that take a long time to respond?

CCIE 36708 | @northlandboy | lkhill.com
Please use plain text.
Valued Contributor
pafreire
Posts: 140
Registered: ‎01-10-2011
Message 9 of 9 (761 Views)

Re: Unable to discover Fortinet Generic firewall

Hi,

 

Assumed that you have access to device and is using correct community, I suggest to you insert the mib for this device (that follows attached with documentation) and do the properly configuration if you need specific data from fortinet.

 

 

Regards,

 

Paulo Freire

 

 

“The greatest challenge to any thinker is stating the problem in a way that will allow a solution.”
Bertrand Russell
Please use plain text.
The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the Terms of Use and Rules of Participation