- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
snmpv3 for mx
Hi all,
Im trying to configure snmpv3 polling so we can monitor and discover all our branch networks Meraki MX from our NMS. A few things confuse me though. Would we only need to configure this under org settings or does it need to be on both org & network-wide settings? As these MX are all in different networks, would it be the WAN IPs or the VLAN interface IPs that need to be polled from the NMS at the head-end office? And would we need to specifically allow this traffic in the MX firewall rules? Thanks in advance!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SNMP in the org settings allows your to poll the dashboard via SNMP. This is not the local devices directly.
SNMP in the Network-Wide settings configures for devices to be polled directly via SNMP polling from within the network (VLAN IP's) or externally (WAN IP's).
Additional info can be found at the following reference guide
SNMP Overview and Configuration - Cisco Meraki Documentation
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks! I've checked the doc and it seems the info we would need for discovery/monitoring can be polled from the dashboard. One thing though, with polling the dashboard under Org settings, there is no means of configuring username for snmpv3, only auth/priv passwords? Isnt a username required? And it says that the hostname used for all SNMP requests should be snmp.meraki.com instead of org-specific hostnames. How would the NMS identify the correct org to poll if it is just snmp.meraki.com? Thanks!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you look in the little tiny text under org settings, it tells you the username to use.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
As @PhilipDAth advised, a dynamic username and password are generated when you enable the settings. You can then poll the dashboard with those credentials which will only allow extraction of data from your organisation.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks for answering, my problem is solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you're using an application that uses IP addresses and no hostnames, would it work to use the IP address for snmp.meraki.com that comes back with nslookup, which looks like it's:
Name: vch150.meraki.com
Addresses: 2620:12f:c007:100:250:56ff:fe9d:12b8
158.115.136.46
Aliases: snmp.meraki.com
