DX Unified Infrastructure Management

Expand all | Collapse all

Is that common snmpcollector server trying to connect so many foreign unknown IP address?

  • 1.  Is that common snmpcollector server trying to connect so many foreign unknown IP address?

    Posted Jul 03, 2017 10:58 PM
      |   view attached

    As subject, there are lots of China and USA IP addresses are connected by snmpcollector server, but the server locates at Singapore, does snmpcollector query something such as DNS for communication or other function?



  • 2.  Re: Is that common snmpcollector server trying to connect so many foreign unknown IP address?

    Posted Jul 03, 2017 11:55 PM

    snmpcollector actually queries the Discovery Server for device information for creating the profiles , below is exactly what it does 

     

    snmpcollector Theory of Operations - CA Unified Infrastructure Management Probes - CA Technologies Documentation 

    Interactions with Discovery

    SNMP enabled device information is not automatically added to the snmpcollector device inventory. Import the device data into snmpcollector.

    Import Device Information

    The devices and the information about the devices must be in the main database. How the information is sent to the database occurs during two distinct steps.

    First, you use Discovery Wizard to perform the primary discovery processes to get device topology data on the primary hub. This information includes the device name, IP address, and SNMP credentials. The following diagram shows how device data is collected by USM during the primary device discovery process.

    Primary device discovery process

    Second, you use the snmpcollector Probe configuration GUI to query Discovery Server for devices. The device information that is presented to snmpcollector does not initially contain any subcomponent information. The snmpcollector probe uses the IP addresses and SNMP credentials to run a secondary discovery process. The secondary discovery process finds device component information. This information appears in the probe configuration GUI as device profiles. The following diagram shows how device data is collected by snmpcollector during the secondary device discovery process.

     

    Secondary device discovery process


  • 3.  Re: Is that common snmpcollector server trying to connect so many foreign unknown IP address?

    Posted Jul 05, 2017 09:57 PM

    Hi Phani

    Does above process keeps performing repeated even we not manually discovery devices?

    And will snmpc try so many foreign IPs for update topology info?



  • 4.  Re: Is that common snmpcollector server trying to connect so many foreign unknown IP address?

    Broadcom Employee
    Posted Jul 04, 2017 02:15 AM

    Hello.

    9715 port in the snmpcollector robot is accessible remotely.

    Do you have any information of destination port of coming traffic ?



  • 5.  Re: Is that common snmpcollector server trying to connect so many foreign unknown IP address?

    Posted Jul 05, 2017 09:54 PM

    Hi Yu

     

    Thanks for your reply.

    Is this port open default? Can I close or disable it in probe config?

    And what is port used for?



  • 6.  Re: Is that common snmpcollector server trying to connect so many foreign unknown IP address?

    Broadcom Employee
    Posted Jul 05, 2017 10:00 PM

    We use the port for the below.

     

    http://<snmpcollector IP Address>:9715/metrics

    http://<snmpcollector IP Address>:9715/database

     

    The first one gives you metric reports which is very useful.

    The next one gives you an interface to access H2 database which the probe is using internally.

     

    I am not sure how to turn off completely. I would say that you can safely block this port access from outside via firewall.



  • 7.  Re: Is that common snmpcollector server trying to connect so many foreign unknown IP address?

    Posted Jan 17, 2018 06:07 AM

    Hi Yu,

     

    https://support.ca.com/us/knowledge-base-articles.TEC1613804.html

    We need to access local snmpcollector database.
    Database accessed with " http://10.224.202.45:8715/database "
    Below attached popup will appears.
    We are not able to login.
    Kindly suggest.
    Regards
    Dharmender


  • 8.  Re: Is that common snmpcollector server trying to connect so many foreign unknown IP address?

    Broadcom Employee
    Posted Jan 17, 2018 06:38 AM

    Hello, Dharmender.

    Here is new way to do the same in 3.43.

    Note - This is possible only when the probe is deactivated.

     

    1. Deactivate SNMPcollector probe.

    2. Install JRE and h2 DB Console to SNMPC hub robot.

     

    http://www.h2database.com/html/download.html

     

    3. Open the h2 db console (It will redirect you to the db login page in the browser)

     

    http://www.h2database.com/html/quickstart.html

     

    4. Use URL (suppose UIM default folder in C drive)
    jdbc:h2:C:\Program Files (x86)\Nimsoft\probes\network\snmpcollector\SnmpCollector

     

    We have retired the original facility in 3.43.

    Apologies for this not described in any doc.

    The facility was retired due to reduce the risk of db corruption outside the probe.



  • 9.  Re: Is that common snmpcollector server trying to connect so many foreign unknown IP address?

    Posted Jan 17, 2018 07:57 AM

    Hi Yu, 

     

    Thank you so much for your suggestions.

     

    Also I have one more query.

     

    We are using UIM 8.5.1 and snmpc 3.43

    integrated with Spectrum 10.2.2 and spectrumgtw 8.6

     

    After Integration CA Spectrum GC is sync into CA UIM & Device are visible in UIM Inventory with their SNMP Key.

     

    As per Tech doc

     

    CA Spectrum and CA UIM - CA Spectrum - 10.2 to 10.2.2 - CA Technologies Documentation 

     

    We are able to sync snmp profile while doing query discovery server.

     

    We want to configure cpu & memory utilization on those servers which are sync from CA spectrum to CA UIM.

     

    3 servers snmp profiles got synchronize in snmpc configuration, when we do query discovery servers, 2 are in error state, rest of other snmp profile is in visible in snmpc configuration.

     

    Note: Servers which are sync from CA Spectrum to CA UIM are sysedge servers.

     

    Please Kindly suggest

     

    Regards 

    Dharmender



  • 10.  Re: Is that common snmpcollector server trying to connect so many foreign unknown IP address?

    Broadcom Employee
    Posted Jan 17, 2018 09:07 PM

    Hi, Dharmender.

    Please try to use the latest Spectrum Gateway probe version 8.64

    Recent release in the probe have had a bug community name not imported properly from Spectrum.



  • 11.  Re: Is that common snmpcollector server trying to connect so many foreign unknown IP address?

    Posted Jan 18, 2018 02:08 AM

    Hi Yu,

     

    Actually currently we are using spectrumgtw 8.64 version.



  • 12.  Re: Is that common snmpcollector server trying to connect so many foreign unknown IP address?

    Broadcom Employee
    Posted Sep 18, 2018 09:30 PM

    Feature (facility) of http://<ip or hostname of snmpcollector probe>:8715/database is back with 3.43 hotfix.

    Please use 3.43 hotfix

    CA Unified Infrastructure Management Hotfix Index - CA Technologies 



  • 13.  Re: Is that common snmpcollector server trying to connect so many foreign unknown IP address?

    Posted Jul 05, 2017 04:25 PM

    moving this to the UIM community