Hello,
We have set our SNMP community string. We have also set the firewall to accept ports 161-162. See: https://goo.gl/E6TQbp and https://goo.gl/LUho9u
However, when trying to query SNMP over the internet, it fails.
Can you help? Thanks
Hello,
We have set our SNMP community string. We have also set the firewall to accept ports 161-162. See: https://goo.gl/E6TQbp and https://goo.gl/LUho9u
However, when trying to query SNMP over the internet, it fails.
Can you help? Thanks
Make sure that your accept rules for SNMP protocol is above the drop rule of input chain (if exists).
Make sure too, if your ISP allow SNMP through it.
Yes, the rule is above all others. We are the ISP, so no problem there.
SNMP is answered locally? Can you see the accept rules in input chain, counting packtes?
Here are the firewall settings:
https://goo.gl/OFr9qn
Unfortunately, no way to check SNMP locally, only over the internet.
Your router seems to receiving SNMP packets..
Some applications can use SNMP over TCP. Accept too the TCP rule for ports 161 and 162.
It seems to be receiving a few packets, but I don’t think they are from me. Whenever I have tried to query, it fails. I am using PRTG to specifically monitor bandwidth, and it fails every time.
I did change it to TCP with no change.
My suggestion:
Try using a SNMP Tool (example: PRTG SNMP), running locally (Windows machine directly connected into the router). If SNMP responses are ok, RouterOS is ok. Then, you can run the same tool into your remote PRTG Server.
Funny thing, I am actually using PRTG to try to monitor this router. I’ll try to run it locally and see what happens.
Are you dual homed? With assymetric traffic paths?
Enviado desde mi SAMSUNG-SM-G920A mediante Tapatalk
Not dual homed.
Do you have multiple IPs on the wan interface?
Are you querying to the main IP of the wan interface if the answer to the previous question is yes?
Enviado desde mi SAMSUNG-SM-G920A mediante Tapatalk
Only 1 IP is on that interface. The router does respond to SNMP over the LAN, but not internet.
Taking into account you said it works from the LAN side, are you 100% sure the router is receiving the petition? Did you do a packet capture?
I’ve worked with isp that are really odd and block everything going to well known ports towards their clients, maybe this is your case.
Enviado desde mi SAMSUNG-SM-G920A mediante Tapatalk