Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SFOS 18 firmware seems to break SNMP via WAN

Hi all.  I have been successfully remotely monitoring a Sophos XG Firewall via SNMP (using MRTG), mainly to monitor incoming and outgoing bandwidth on all 3 Ethernet ports.  To clarify... there is an MRTG server out on the Internet, connecting to the Sophos via the Internet (WAN).  There is a firewall rule that maps the non-standard port I am using on the WAN, to the standard UDP 161 on the LAN.  SNMP is enabled in the Sophos, with a community string set, etc.  This has worked for years.

Recently I upgraded firmware from "SFOS 17.5.15 MR-15" to "SFOS 18.5.3 MR-3-Build408" and this monitoring via SNMP broke.  I was able to duplicate the problem by rolling back to "SFOS 17.5.15 MR-15" and SNMP started to work again.  Again, I booted "SFOS 18.5.3 MR-3-Build408" and it stopped... reverted to SFOS 17.5.15 MR-15" and it started to work again... so left it there.

Has anyone else noticed this problem?  I am not sure, as a 'free' user, if I am able to report the problem to Sophos directly or get any other type of help in identifying the cause?

Thanks!

- Scott



This thread was automatically locked due to age.
Parents
  • Hi : Are you getting any different logs OR errors in snmpd.log in V18.x which is not there in V17.x? Also Is there any difference in terms of packet or TCPDUMP in both versions on the required host IP or Port in both versions? 

    Regards,

    Vishal Ranpariya
    Technical Account Manager | Sophos Technical Support

    Sophos Support Videos | Knowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'This helped me' link.

  • Here is what I see in snmpd.log. I have not tried a packet capture yet, as I do not believe it would be helpful (but if you think so, I can try)

    2022-05-11 03:50:25Z Reconfiguring daemon

    2022-05-11 03:50:25Z NET-SNMP version 5.8.1.pre2 restarted
    2022-05-11 03:50:25Z error finding row index in _ifXTable_container_row_restore
    2022-05-11 03:50:25Z /cfs/system/snmpd.conf: line 5: Error: Blank line following sysDescr token.
    2022-05-11 03:50:25Z /cfs/system/snmpd.conf: line 8: Error: Address family for hostname not supported
    2022-05-11 03:50:25Z /cfs/system/snmpd.conf: line 10: Error: Address family for hostname not supported
    2022-05-11 03:50:25Z /cfs/system/snmpd.conf: line 12: Error: Address family for hostname not supported
    2022-05-11 03:50:25Z /cfs/system/snmpd.conf: line 14: Error: Address family for hostname not supported
    2022-05-11 03:50:25Z duplicate registration: MIB modules ipAddressTable and ipAddressTable (oid .1.3.6.1.2.1.4.34).

Reply
  • Here is what I see in snmpd.log. I have not tried a packet capture yet, as I do not believe it would be helpful (but if you think so, I can try)

    2022-05-11 03:50:25Z Reconfiguring daemon

    2022-05-11 03:50:25Z NET-SNMP version 5.8.1.pre2 restarted
    2022-05-11 03:50:25Z error finding row index in _ifXTable_container_row_restore
    2022-05-11 03:50:25Z /cfs/system/snmpd.conf: line 5: Error: Blank line following sysDescr token.
    2022-05-11 03:50:25Z /cfs/system/snmpd.conf: line 8: Error: Address family for hostname not supported
    2022-05-11 03:50:25Z /cfs/system/snmpd.conf: line 10: Error: Address family for hostname not supported
    2022-05-11 03:50:25Z /cfs/system/snmpd.conf: line 12: Error: Address family for hostname not supported
    2022-05-11 03:50:25Z /cfs/system/snmpd.conf: line 14: Error: Address family for hostname not supported
    2022-05-11 03:50:25Z duplicate registration: MIB modules ipAddressTable and ipAddressTable (oid .1.3.6.1.2.1.4.34).

Children
No Data
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?