Comments on: How to configure SNMP v3 on Nortel Ethernet Routing Switches https://blog.michaelfmcnamara.com/2009/10/how-to-configure-snmp-v3-on-nortel-ethernet-routing-switches/ technology, networking, virtualization and IP telephony Tue, 16 Dec 2014 01:15:13 +0000 hourly 1 https://wordpress.org/?v=6.8.3 By: Saleh https://blog.michaelfmcnamara.com/2009/10/how-to-configure-snmp-v3-on-nortel-ethernet-routing-switches/comment-page-1/#comment-21667 Sun, 05 Jan 2014 23:13:36 +0000 http://blog.michaelfmcnamara.com/?p=1068#comment-21667 Dear Michael,

I wan to my Nortel Switch ERS-8610 (5.1.3.1) send syslog traps to one of my server IP 10.67.X.X.
I followed your tips but fails to configure and getting below message

GDPREBS3-COR-4A:5/config/sys/set# snmp sender-ip 10.67.80.70
Not enough required parameters entered
set snmp trap sender Ip
Required parameters:
= ip address {a.b.c.d}
= ip address {a.b.c.d}
Command syntax:
sender-ip

please advice

]]>
By: Shafeeq https://blog.michaelfmcnamara.com/2009/10/how-to-configure-snmp-v3-on-nortel-ethernet-routing-switches/comment-page-1/#comment-17463 Thu, 20 Jun 2013 06:19:53 +0000 http://blog.michaelfmcnamara.com/?p=1068#comment-17463 I am using 8300 series core switch and avaya switches. I am getting the topology of Network in OCM which is the Local area. how can i get the remote topology? can you please write the SNMP commands for this requirement.

I have more than 4 sites and i need to view all the devices Switches and WLCs.. please help me

]]>
By: Bill https://blog.michaelfmcnamara.com/2009/10/how-to-configure-snmp-v3-on-nortel-ethernet-routing-switches/comment-page-1/#comment-8565 Thu, 06 Dec 2012 12:58:29 +0000 http://blog.michaelfmcnamara.com/?p=1068#comment-8565 Yes. I had v3 working….. my management network is 10.10.1.0/24.

Thanks.

Id: 1
Name: default
PolicyEnable: false
Mode: allow
Service: ftp|http|tftp|telnet|ssh|snmpv3
Precedence: 128
NetAddrType: any
NetAddr: N/A
NetMask: N/A
TrustedHostAddr: N/A
TrustedHostUserName: none
AccessLevel: readOnly
AccessStrict: false
Usage: 1

Id: 2
Name: secure
PolicyEnable: true
Mode: allow
Service: ftp|http|tftp|telnet|rlogin|ssh|snmpv3
Precedence: 10
NetAddrType: ipv4
NetAddr: 0.0.0.0
NetMask: 0.0.0.0
TrustedHostAddr: 0.0.0.0
TrustedHostUserName: secure
AccessLevel: readWriteAll
AccessStrict: false
Usage: 1459

Id: 10
Name: policy10
PolicyEnable: true
Mode: allow
Service: ftp|http|tftp|telnet|ssh|snmpv3
Precedence: 10
NetAddrType: ipv4
NetAddr: 10.10.1.0
NetMask: 255.255.255.0
TrustedHostAddr: 0.0.0.0
TrustedHostUserName: none
AccessLevel: readWriteAll
AccessStrict: false
Usage: 27016

mch8610a:5#

]]>
By: Michael McNamara https://blog.michaelfmcnamara.com/2009/10/how-to-configure-snmp-v3-on-nortel-ethernet-routing-switches/comment-page-1/#comment-8556 Thu, 06 Dec 2012 01:38:01 +0000 http://blog.michaelfmcnamara.com/?p=1068#comment-8556 In reply to Bill.

Well you’re not talking about SNMPv3 you’re talking about SNMPv2/SNMPv1 correct? I believe you need to allow SNMPv2/SNMPv1.

Perhaps you could show us your access policy?

show sys access-policy info

You might want to refer to this blog post.

Good Luck!

]]>
By: Bill https://blog.michaelfmcnamara.com/2009/10/how-to-configure-snmp-v3-on-nortel-ethernet-routing-switches/comment-page-1/#comment-8547 Wed, 05 Dec 2012 17:26:40 +0000 http://blog.michaelfmcnamara.com/?p=1068#comment-8547 I do, they are allowing snmpv3.
This is very frustrating. I had v3 configured and working. I am demo’ing an NMS from Path Solutions and they use v2c. The communities were already configured. I’ve deleted them added new ones, created new groups….SNMP speak is Chinese to me….lol

I have started a discussion on the Network Infrastructure forum….no luck getting this to work yet…crazy. http://forums.networkinfrastructure.info/nortel-ethernet-switching/snmpv2c-from-snmpv3-on-an-8610/

Thanks

]]>
By: Michael McNamara https://blog.michaelfmcnamara.com/2009/10/how-to-configure-snmp-v3-on-nortel-ethernet-routing-switches/comment-page-1/#comment-8535 Wed, 05 Dec 2012 03:10:40 +0000 http://blog.michaelfmcnamara.com/?p=1068#comment-8535 In reply to Bill.

Hi Bill,

Do you have any access policies configured?

Cheers!

]]>
By: Bill https://blog.michaelfmcnamara.com/2009/10/how-to-configure-snmp-v3-on-nortel-ethernet-routing-switches/comment-page-1/#comment-8525 Tue, 04 Dec 2012 19:49:57 +0000 http://blog.michaelfmcnamara.com/?p=1068#comment-8525 I have an 8610 that I have successfully configured snmp v3 on. I am demoing an snmp management platform that polls v1 or v2c only. This platform cannot discover the 8610 using the communities I have configured. No response received from device…..
Is there anything I need to do to turn back on v2c?

Communities are there:

show snmp-v3 community

================================================================================
Community Table
================================================================================
Index Name Security Name Context Name Transport Tag
——————————————————————————–
first ******** readView
second ******** writeView

2 out of 2 Total entries displayed
——————————————————————————–

]]>
By: Michael McNamara https://blog.michaelfmcnamara.com/2009/10/how-to-configure-snmp-v3-on-nortel-ethernet-routing-switches/comment-page-1/#comment-6661 Wed, 30 May 2012 03:16:25 +0000 http://blog.michaelfmcnamara.com/?p=1068#comment-6661 In reply to Bill.

Thanks for sharing the solution Bill.

]]>
By: Bill https://blog.michaelfmcnamara.com/2009/10/how-to-configure-snmp-v3-on-nortel-ethernet-routing-switches/comment-page-1/#comment-6631 Wed, 23 May 2012 12:08:21 +0000 http://blog.michaelfmcnamara.com/?p=1068#comment-6631 Forgot your questions.
Ver 6.1.5 on the 5520.
6.3.0 on ESM
6.2.1.2 on DM

]]>
By: Bill https://blog.michaelfmcnamara.com/2009/10/how-to-configure-snmp-v3-on-nortel-ethernet-routing-switches/comment-page-1/#comment-6630 Wed, 23 May 2012 12:06:22 +0000 http://blog.michaelfmcnamara.com/?p=1068#comment-6630 I figured out how to configure it.
Edit/Communities/Password
Insert
IP address ( with the default 0.0.0.0 being v1/2c) I have to add each switch individually until they are all done. Then I can convert 0.0.0.0 to v3.
User Name
Auth Protocol = SHA
Priv Protocol = DES ( to conform the my free version of “The Dude”)
Passwords.
These reflect the configuration of the switch.

You will see an orange lock, on the device, in ESM.

]]>
By: Michael McNamara https://blog.michaelfmcnamara.com/2009/10/how-to-configure-snmp-v3-on-nortel-ethernet-routing-switches/comment-page-1/#comment-6626 Tue, 22 May 2012 23:36:54 +0000 http://blog.michaelfmcnamara.com/?p=1068#comment-6626 In reply to Bill.

Hi Bill,

I don’t believe Enterprise Switch Manager (ESM – which has been retired) supports SNMPv3. I’m guessing you have this problem on all your switches?

What version of software on the ERS 5520? What version of ESM? What version of JDM?

Good Luck!

]]>
By: Bill https://blog.michaelfmcnamara.com/2009/10/how-to-configure-snmp-v3-on-nortel-ethernet-routing-switches/comment-page-1/#comment-6620 Mon, 21 May 2012 19:18:59 +0000 http://blog.michaelfmcnamara.com/?p=1068#comment-6620 I am able to open my 5520 SNMPv3 configured switch with JDM but ESM will discover it, show it by IP Address(when ESM is configured for sysName), but will not open it….

Any ideas?

Thanks,
Bill

]]>
By: Adel https://blog.michaelfmcnamara.com/2009/10/how-to-configure-snmp-v3-on-nortel-ethernet-routing-switches/comment-page-1/#comment-6299 Thu, 22 Mar 2012 21:41:49 +0000 http://blog.michaelfmcnamara.com/?p=1068#comment-6299 Thanks Michael. You’re absolutely right.

I found it documented in the 8600’s SNMP guide from Avaya (Page 22)

http://www.google.ca/url?sa=t&rct=j&q=%22circuitless%22%20%228600%22%20%22trap-sender%22%20site%3Aavaya.com&source=web&cd=1&ved=0CCEQFjAA&url=http%3A%2F%2Fsupport.avaya.com%2Fcss%2FP8%2Fdocuments%2F100123752&ei=n5hrT_n5OeeQiQK0woHCBQ&usg=AFQjCNGQ1x44lcqpJZBgU7BashxeRZ8Kow

]]>
By: Michael McNamara https://blog.michaelfmcnamara.com/2009/10/how-to-configure-snmp-v3-on-nortel-ethernet-routing-switches/comment-page-1/#comment-6294 Thu, 22 Mar 2012 03:04:44 +0000 http://blog.michaelfmcnamara.com/?p=1068#comment-6294 In reply to Adel.

Hi Adel,

Thanks for the kind words. I believe it does need to be a CLIP interface.

Cheers!

]]>
By: Adel https://blog.michaelfmcnamara.com/2009/10/how-to-configure-snmp-v3-on-nortel-ethernet-routing-switches/comment-page-1/#comment-6293 Thu, 22 Mar 2012 02:41:25 +0000 http://blog.michaelfmcnamara.com/?p=1068#comment-6293 Hi Michael,

Thanks for your great blog. It has been very helpful since I started working with Avaya devices.

I just have a question about setting the source of the SNMP traps. Does it work only with the CLIP? I have tried using the following commands to send the traps to our syslog server (SNMP trap receiver as well) from one of the routed VLAN interfaces but it did not work.

config sys set snmp sender-ip
config sys set snmp force-trap-sender true
config sys set snmp force-iphdr-sender true

On the syslog server, I am filtering the traps based on the 8600 source IP I configured above. However, the traps were not emailed to me by the syslog server. I then ran some packet captures and discovered the source IP was not altered. The traps were sent from the 8600 outgoing interface instead (as shown in the routing table).

I then tried using the CLIP as the source IP and it all worked fine.

Do you know if this feature is limited to the CLIP only?

Thanks,

]]>
By: Michael McNamara https://blog.michaelfmcnamara.com/2009/10/how-to-configure-snmp-v3-on-nortel-ethernet-routing-switches/comment-page-1/#comment-5777 Mon, 19 Dec 2011 05:29:39 +0000 http://blog.michaelfmcnamara.com/?p=1068#comment-5777 In reply to Vijay.

Hi Vijay,

You simply follow the instructions I’ve laid out in the past above for the ERS 4500 series switches.

Good Luck!

]]>
By: Vijay https://blog.michaelfmcnamara.com/2009/10/how-to-configure-snmp-v3-on-nortel-ethernet-routing-switches/comment-page-1/#comment-5770 Fri, 16 Dec 2011 19:54:14 +0000 http://blog.michaelfmcnamara.com/?p=1068#comment-5770 Hi Micheal,

I need to update my Nortel 4550T-PWR switches with the new snmp v3 read-only and read-write passwords. Also i need to enable md5 Authentication and AES encryption on it. Currently it is running snmpv2c. How can i do that.

]]>
By: Michael McNamara https://blog.michaelfmcnamara.com/2009/10/how-to-configure-snmp-v3-on-nortel-ethernet-routing-switches/comment-page-1/#comment-5587 Fri, 18 Nov 2011 17:25:30 +0000 http://blog.michaelfmcnamara.com/?p=1068#comment-5587 In reply to Siddharth Bhargava.

Hi Siddharth,

What are you doing via SNMP when the CPU utilization goes to 100%? If you are walking a large MIB then the reaction is expected since you are heavily polling the switch. If I walk the RFC 1493 Bridge MIB I’ll spike my CPUs as well. That’s because I have some 6000 devices in my FDB/MAC tables so that’s a lot of information for the CPU to gather.

Unless you are having performance issues it’s probably safe to ignore.

Cheers!

]]>
By: Siddharth Bhargava https://blog.michaelfmcnamara.com/2009/10/how-to-configure-snmp-v3-on-nortel-ethernet-routing-switches/comment-page-1/#comment-5583 Fri, 18 Nov 2011 12:13:16 +0000 http://blog.michaelfmcnamara.com/?p=1068#comment-5583 When trying to access switch through SNMP, the CPU utilisation is going high to 100%.. :(
Please suggest why it is happening??

]]>
By: Michael McNamara https://blog.michaelfmcnamara.com/2009/10/how-to-configure-snmp-v3-on-nortel-ethernet-routing-switches/comment-page-1/#comment-5398 Sun, 06 Nov 2011 04:05:36 +0000 http://blog.michaelfmcnamara.com/?p=1068#comment-5398 In reply to swin.

Hi Swin,

You most likely have a configuration error. You should review your configuration.

Good Luck!

]]>
By: swin https://blog.michaelfmcnamara.com/2009/10/how-to-configure-snmp-v3-on-nortel-ethernet-routing-switches/comment-page-1/#comment-5373 Fri, 04 Nov 2011 09:41:20 +0000 http://blog.michaelfmcnamara.com/?p=1068#comment-5373 With the JDM Error:

usmStatsDecryptionErrors: The packet can’t be decrypted

]]>
By: swin https://blog.michaelfmcnamara.com/2009/10/how-to-configure-snmp-v3-on-nortel-ethernet-routing-switches/comment-page-1/#comment-5372 Fri, 04 Nov 2011 09:37:35 +0000 http://blog.michaelfmcnamara.com/?p=1068#comment-5372 I have the same problem !

]]>
By: ahmed https://blog.michaelfmcnamara.com/2009/10/how-to-configure-snmp-v3-on-nortel-ethernet-routing-switches/comment-page-1/#comment-4358 Mon, 06 Jun 2011 14:15:32 +0000 http://blog.michaelfmcnamara.com/?p=1068#comment-4358 Dear Michael,

Thanks for your reply.
Below are the relevent sections:

#
# SNMP V3 GROUP MEMBERSHIP CONFIGURATION
#

snmp-v3 group-member create Manager usm admin

#
# SNMP V3 GROUP ACCESS CONFIGURATION
#

snmp-v3 group-access create “admin” “” usm authPriv
snmp-v3 group-access view “admin” “” usm authPriv read “root” write “root” notif
y “root”

#
# SNMP V3 MIB VIEW CONFIGURATION
#

snmp-v3 mib-view create root 1.3 type include

#
# SNMP V3 NOTIFY CONFIGURATION
#

#
# SNMP V3 TARGET ADDRESS CONFIGURATION
#

snmp-v3 target-addr create “HPopenview” 10.0.23.31:162 “TparamV1” tdomain i
pv4_tdomain timeout 1500 retry 3 taglist trapTag mms 484
snmp-v3 target-addr create “Testpc” 172.16.0.222:162 “TparamV1” tdomain ipv4_
tdomain timeout 1500 retry 3 taglist trapTag mms 484

#
# SNMP V3 TARGET PARAMS CONFIGURATION
#

#
# SNMP V3 NOTIFY FILTER CONFIGURATION
#

snmp-v3 ntfy-filter delete profile1 99.3.6.1.6.3.1.1.4.1

#
# SNMP V3 NOTIFY FILTER PROFILE CONFIGURATION
#

#
# SNMPLOG CONFIGURATION
#

snmp snmplog enable true
snmp snmplog maxfilesize 256
#

]]>
By: Michael McNamara https://blog.michaelfmcnamara.com/2009/10/how-to-configure-snmp-v3-on-nortel-ethernet-routing-switches/comment-page-1/#comment-4352 Sun, 05 Jun 2011 00:10:36 +0000 http://blog.michaelfmcnamara.com/?p=1068#comment-4352 In reply to ahmed.

Hi Ahmed,

Can you post the relevant sections of your configuration?

Cheers!

]]>
By: ahmed https://blog.michaelfmcnamara.com/2009/10/how-to-configure-snmp-v3-on-nortel-ethernet-routing-switches/comment-page-1/#comment-4347 Sat, 04 Jun 2011 10:15:54 +0000 http://blog.michaelfmcnamara.com/?p=1068#comment-4347 my switch is ers 8300

]]>