Difference between revisions of "TUT:Configuring snmptrapd to receive SNMPv3 notifications"
(make definitions proper.) |
|||
Line 13: | Line 13: | ||
;TRAPs: Sent by an application or daemon but no response is sent or expected by the notification receiver. | ;TRAPs: Sent by an application or daemon but no response is sent or expected by the notification receiver. | ||
;INFORMs: INFORMs are nothing more than an acknowledged TRAP. I.E., when the notification receiver receives an INFORM it sends a response back that indicates "I got it". (An application may be configured to send more than one INFORM message if it failed to receive an acknowledgment) | ;INFORMs: INFORMs are nothing more than an acknowledged TRAP. I.E., when the notification receiver receives an INFORM it sends a response back that indicates "I got it". (An application may be configured to send more than one INFORM message if it failed to receive an acknowledgment) | ||
+ | |||
+ | === SNMPv3 INFORMs vs SNMP TRAPs === | ||
+ | |||
+ | SNMPv3 with the [[User-Based Security Model]] (USM) makes use of an [[EngineID]] identifier for the SNMPv3 application that is ''authoratative'' (meaning the one who controls the flow of information). | ||
+ | |||
+ | With SNMPv3 TRAPs, the ''authoratative'' engine is the engine that sends the trap | ||
+ | |||
+ | With SNMPv3 INFORMs, the ''authoratative'' engine is the engine that receives the trap. | ||
+ | |||
+ | SNMPv3 USM users are uniquely defined by a combination of the authoratative EngineID and the user name. | ||
{{TUT:LIST}} | {{TUT:LIST}} |
Revision as of 16:54, 10 October 2007
SNMPv3 background
Before you can begin to understand how to use snmptrapd with SNMPv3 protected notifications you need to understand some basic concepts. Specifically, please read:
- SNMPv3 Options -- Documents how to use Net-SNMP with SNMPv3 in general
- TUT:snmptrap -- Discussing SNMP notifications and sending them using snmptrap
- TUT:snmptrap SNMPv3 -- Discussing SNMPv3 notifications and sending them using snmptrap
SNMP INFORMs vs SNMP TRAPs Notifications
SNMP supports two types of notifications: TRAPs and INFORMs. (In SNMPv1, there was only TRAPs; SNMPv2c and SNMPv3 support INFORMs too). There is one fundamental difference between SNMP INFORMs and TRAPs:
- TRAPs
- Sent by an application or daemon but no response is sent or expected by the notification receiver.
- INFORMs
- INFORMs are nothing more than an acknowledged TRAP. I.E., when the notification receiver receives an INFORM it sends a response back that indicates "I got it". (An application may be configured to send more than one INFORM message if it failed to receive an acknowledgment)
SNMPv3 INFORMs vs SNMP TRAPs
SNMPv3 with the User-Based Security Model (USM) makes use of an EngineID identifier for the SNMPv3 application that is authoratative (meaning the one who controls the flow of information).
With SNMPv3 TRAPs, the authoratative engine is the engine that sends the trap
With SNMPv3 INFORMs, the authoratative engine is the engine that receives the trap.
SNMPv3 USM users are uniquely defined by a combination of the authoratative EngineID and the user name.
Tutorial Sections
About the SNMP Protocol
These tutorial links talk about SNMP generically and how the protocol itself works. They are good introductory reading material and the concepts are important to understand before diving into the later tutorials about Net-SNMP itself.
- How SNMP Works: About the protocol itself (GETs, GETNEXTs, etc)
- What data is in SNMP: All about SNMP Management Information Bases (MIBs)
- Securing SNMP: How to use the SNMP protocol securely
Net-SNMP Command Line Applications
These tutorial pages discuss the command line tools provided in the Net-SNMP suite of tools. Nearly all the example commands in these tutorials works if you try it yourself, as they're all examples that talk to our online Net-SNMP test agent. Given them a shot!
- snmptranslate: learning about the MIB tree.
- snmpget: retrieving data from a host.
- snmpgetnext: retrieving unknown indexed data.
- snmpwalk: retrieving lots of data at once!
- snmptable: displaying a table.
- snmpset: peforming write operations.
- snmpbulkget: communicates with a network entity using SNMP GETBULK request
- snmpbulkwalk: retrieve a sub-tree of management values using SNMP GETBULK requests.
- snmptrap: Sending and receiving traps, and acting upon them.
- Traps/informs with SNMPv3/USM: Sending and receiving SNMPv3/USM TRAPs and INFORMs
- Sending Traps/Informs via AgentX: Sending notifications from the command line through snmpd
- Common command line options:
- Writing mib2c config files
Application Configuration
All of our applications support configuration to allow you to customize how they behave.
Net-SNMP Daemons
Net-SNMP comes with two long-running daemons: a SNMP agent (snmpd) for responding to management requests and a notification receiver (snmptrapd) for receiving SNMP notifications.
- SNMP Agent (snmpd) Configuration
- SNMP Notification Receiver (snmptrapd)
- Configuring snmptrapd
- Configuring SNMPv3 notifications
- Configuring snmptrapd to understand vendor-specific MIBS (Cisco)
- Agent Monitoring
Coding Tutorials
Net-SNMP comes with a highly flexible and extensible API. The API allows you to create your own commands, add extensions to the agent to support your own MIBs and perform specialized processing of notifications.
- Client / Manager Coding Tutorials
- Agent Coding Tutorials
- The Agent Architecture page might be worth reading before or after the agent coding tutorials, and describes how the Agent Helpers work under the hood.
- Writing a mib module to serve information described by an SNMP MIB, and how to compile it into the net-snmp snmpd agent.
- Writing a Dynamically Loadable Object that can be loaded into the SNMP agent.
- Writing a Subagent that can be run to attach to the snmpd master agent.
- Writing a perl plugin to extend the agent using the NetSNMP::agent module.
- Writing shell scripts to extend the agent
- Using mib2c to help write an agent code template for you
- Header files and autoconf
Debugging SNMP Applications and Agents
All our tools and applications have extensive debugging output. These tutorials talk about how the debugging system works and how you can add your own debugging statements to you code:
- Debugging output printed using the -D command line option
- Using -Ddump to display packet breakdowns
- Debugging using GDB
Operating System Specific Tutorials
- Building With Visual Studio 2005 Express
- Building Net-SNMP 64-bit with Visual C++ 2010 Express
- Net-Snmp on Ubuntu
- Net-SNMP and lm-sensors on Ubuntu 10.04
- Net-SNMP for windows: