NetApp - Fabric OS: SNMP and syslog
NetApp Solution · Config document · referenced from Logging, monitoring and AutoSupport
The SNMP and syslog settings of a Brocade 6505 as they were typed: a first pass that switched SNMPv1 off, a second pass that left it on with private community strings because the ONTAP cluster polls the switches with SNMPv1, and the syslog server.
| Item | Value |
|---|---|
| Runs on | The Fabric OS shell of the switch, as admin |
| Shown here for | DC1-A-SNAS001 |
| Also applied to | DC1-A-SNAS002, DC1-B-SNAS001, DC1-B-SNAS002 |
| Polled by | The cluster management LIFs of DC1-A-XNAS001 and DC1-B-XNAS001, UDP 161 |
| Syslog server | 10.11.17.113 |
The command set
# --- 1. First pass: look at the factory state -------------------------------- # SNMPv1: six default communities, no trap recipients, "SNMPv1:Enabled". # SNMPv3: users snmpadmin1-3 (rw) and snmpuser1-3 (ro), all noAuth/noPriv, # one trap entry to 10.13.13.207 port 162. snmpconfig --show snmpv1 snmpconfig --show snmpv3 # --- 2. First pass: harden --------------------------------------------------- # Switch SNMPv1 off. snmpconfig --disable snmpv1 # Security level: GET needs authentication and privacy (2), SET no access (3). snmpconfig --set secLevel -snmpget 2 -snmpset 3 # Set the SNMPv3 parameters (interactive; the dialogue is not in the notes). snmpconfig --set snmpv3 # --- 3. Second pass, headed "SNMPv1 configuration" --------------------------- configure # Before: "GET security level = 0, SET level = 0", no security at all. snmpconfig --show seclevel # Security level: GET no security (0), SET no access (3). snmpconfig --set secLevel -snmpget 0 -snmpset 3 # Replace the six default community strings (interactive): three read-write, # three read-only, each <SNMP_COMMUNITY_n>; every trap recipient left at # 0.0.0.0. Ends with "Committing configuration.....done." snmpconfig --show snmpv1 snmpconfig --set snmpv1 snmpconfig --show snmpv1 configcommit # --- 4. Syslog ----------------------------------------------------------------- # Before: facility LOG_LOCAL7, one server, 10.13.13.207. syslogadmin --show -facility syslogadmin --show -ip # Remove the configured server, set facility LOG_LOCAL2 and the central server. syslogadmin --remove -ip 10.13.13.207 syslogadmin --set -facility 2 syslogadmin --set -ip 10.11.17.113 # After: "syslog.1 10.11.17.113", "Syslog facility: LOG_LOCAL2". syslogadmin --show -ip syslogadmin --show -facility configcommit
After section 3 the output of snmpconfig --show snmpv1 in the notes still ends with SNMPv1:Enabled, and the cluster reports SNMPv1 for the switches. The cluster side of the community change is in ONTAP: SNMPv3 user for Sensu.
| Difference | Datacenter A | Datacenter B |
|---|---|---|
| Switches | DC1-A-SNAS001, DC1-A-SNAS002 | DC1-B-SNAS001, DC1-B-SNAS002 |
| Name in the cluster | Brocade_10.11.15.45, Brocade_10.11.15.46 | Brocade_10.11.23.45, Brocade_10.11.23.46 |
| Commands | As shown | Identical |
The notes do not name the switch each listing was taken on; they use the generic prompt FC-SW. They hold nothing for site 2.
Checked against Fabric OS 9.2
| As built | Today |
|---|---|
| Brocade 6505 | End of support since 2025-04-30; Fabric OS releases that became generally available after 2023-04-30 are not provided for it |
| Fabric OS 8.0.x | End of support since 2020-07-30. The current streams are 9.2.x and 10.0.x |
| Six default SNMPv1 communities and six default SNMPv3 users with noAuth and noPriv | From Fabric OS 9.0 there are no default SNMPv1 community or SNMPv3 user entries; accounts existing before an upgrade from 8.2.x are carried forward |
snmpconfig --set snmpv3, interactive | In 9.x users are added non-interactively with snmpconfig --add snmpv3 and options for index, user, group, authentication and privacy protocol and passwords. The 8.2.x dialogue offers MD5 or SHA and DES, AES128 or AES256 |
| SNMPv1 left enabled for the cluster's health monitor | From Fabric OS 9.2.2 SNMPv1 configuration is no longer supported, and the secure default configuration of 9.2.0 disables SNMPv1 and SNMPv2. ONTAP monitors switches on Fabric OS 9.0.1 and later with SNMPv3 only |
syslogadmin --set -ip, plain syslog | The security guide recommends secure syslog; the syslogadmin syntax for it was not checked |
The contradiction of this document, SNMPv1 for the cluster against SNMPv3 for everybody else, is gone on current firmware: the cluster uses SNMPv3 too. The 6505 itself is out of support; whether it can run a Fabric OS 9 release at all could not be confirmed.