when i use snmpwalk conmand on the snmp server , it says below
but i can ping and ssh FW with 10.18.133.113 . and system-services snmp is configured on 10.18.133.113
10.18.133.113 is configure on a loopback interface , the snmp traffic comes from reth1.800 . when i check the session .i can see the traffic has arriveed and permit by athe firewall but there is no reply :
...ow session destination-prefix 10.18.133.113 source-prefix 10.1.146.40 node0: -------------------------------------------------------------------------- Flow Sessions on FPC1 PIC0: Session ID: 20493287, Policy name: Policy-NMS-to-FW/23, State: Active, Timeout: 60, Valid In: 10.1.146.40/1633 --> 10.18.133.113/161;udp, If: reth1.800, Pkts: 5, Bytes: 345 Out: 10.18.133.113/161 --> 10.1.146.40/1633;udp, If: .local..5, Pkts: 0, Bytes: 0 Total sessions: 1
when i check traceoptions , i can see infomation below :
Feb 9 18:05:23 17:45:23.747732:CID-01:FPC-01:PIC-00:THREAD_ID-28:RT:Changing out-ifp from .local..5 to lo0.3 for dst: 10.18.133.113 in vr_id:5 Feb 9 18:05:23 17:45:23.747760:CID-01:FPC-01:PIC-00:THREAD_ID-28:RT: routed (x_dst_ip 10.18.133.113) from Zone-Backbone-Network (reth1.800 in 1) to lo0.3, Next-hop: 10.18.133.113 Feb 9 18:05:23 17:45:23.747795:CID-01:FPC-01:PIC-00:THREAD_ID-28:RT:flow_first_policy_search: policy search from zone Zone-Backbone-Network-> zone Zone-FW-Mngt (0x0,0xaff00a1,0xa1) Feb 9 18:05:23 17:45:23.747875:CID-01:FPC-01:PIC-00:THREAD_ID-28:RT: policy has timeout 30 Feb 9 18:05:23 17:45:23.747884:CID-01:FPC-01:PIC-00:THREAD_ID-28:RT: app 25, timeout 60s, curr ageout 60s Feb 9 18:05:23 17:45:23.747897:CID-01:FPC-01:PIC-00:THREAD_ID-28:RT: permitted by policy Policy-NMS-to-FW(23) Feb 9 18:06:35 17:46:36.026776:CID-01:FPC-01:PIC-00:THREAD_ID-28:RT: route lookup: dest-ip 10.1.146.40 orig ifp reth1.800 output_ifp reth1.800 orig-zone 11 out-zone 11 vsd 1 Feb 9 18:06:35 17:46:36.026807:CID-01:FPC-01:PIC-00:THREAD_ID-28:RT: route to 10.18.145.52
her is my snmp cofiguration . is there any one can help me with that ? thank you
set snmp community CCTsnmpRO authorization read-only set snmp community CCTsnmpRO clients 10.1.146.0/24 set snmp community CCTsnmpRO clients 0.0.0.0/0 restrict set snmp trap-options source-address 10.18.133.113 set snmp trap-options enterprise-oid set snmp trap-group INTF-Traps categories authentication set snmp trap-group INTF-Traps categories chassis set snmp trap-group INTF-Traps categories link set snmp trap-group INTF-Traps categories routing set snmp trap-group INTF-Traps categories startup set snmp trap-group INTF-Traps categories services set security zones security-zone Zone-FW-Mngt host-inbound-traffic system-services snmp