The Manager → <Admin Domain Name> → Setup → Notification → Faults → SNMP option enables you to specify an SNMP server to which system fault information will be sent from the Manager. You can configure more than one SNMP server where you want to send fault messages. The SNMP Servers page displays the SNMP servers that have been configured. The fields in this page are described within the configuration steps that follow.
To configure an SNMP server to receive system faults from your Manager, do the following:
Task
- Select Manager → <Admin Domain Name> → Setup → Notification → Faults → SNMP.
- Check Enable SNMP Notification (default is Yes) and click Save.
-
Click
.
The SNMP page is displayed..png)
-
Fill in the following fields:
Field Description Admin Domains Select the below options to enable admin domain notification: - Current— Send notifications for alerts in the current domain. Always enabled for the current domain.
- Children— Include alerts for all child domains of the current domain
IP Address IP address of the target SNMP server. This can be an IPv4 or IPv6 address. Target Port Target server's SNMP listening port. The standard port for SNMP, 162, is pre-filled in the field. SNMP Version Version of SNMP running on the target SNMP server. Version options are 1, 2c, and Both 1 and 2c, and 3. Community String Type an SNMP community string to protect your Trellix IPS data. SNMP community strings authenticate access to Management Information Base (MIB) objects and functions as embedded passwords. Forward Faults Choose the severity level for forwarding faults. The options are Critical, Error and above, Warning and above, and Informational and above. Choose the severity of alerts that will have information forwarded. Limiting your alert severities to Critical or Error and above is recommended for focused analysis.
The following fields appear only when SNMP Version 3 is selected. User Name Type a username that will be used for authentication Authoritative Engine ID (Hex Values) The Authoritative (security) Engine ID of the Manager used for sending SNMP version 3 REQUEST messages. The hex value of the Authoritative Engine ID should have only even pairs (For example, you can have hex value of 4 pairs like 00-1B-3F-2C).
Note
MAC address can also be used as Authoritative Engine ID.
Authoritative Peer Engine ID (Hex Values): Note
The Authoritative Peer Engine ID field is available while configuring SNMP version 3 only after successful creation of an MDR pair.
The authoritative (security) engine ID used for SNMP version 3 REQUEST messages by secondary Manager Note
The Authoritative (security) engine ID for any Manager is unique. At any point of time, the Authoritative Engine ID of the Manager is static irrespective of Manager status in case of an MDR pair. That is, when MDR switchover occurs, the authoritative engine ID of the Manager will not change with the status of the Manager. Hence, the alerts generated from the Primary and Secondary Manager will have their respective authoritative engine IDs.
Note
After successful deletion of an MDR pair, the Authoritative Engine IDs are retained by the respective Managers.
Authentication Level This specifies the authentication level and has the following categories: - No Authorization, No Privileges— Uses a user name match for authentication
- Authorization, No Privileges— Provides authentication based on the MD5 or SHA algorithms
- Authorization, Privileges— Provides authentication based on the MD5 or SHA algorithms. It also provides encryption in addition to authentication based on the DES or AES standards.
The following fields appear only when Authorization, No Privileges or Authorization and Privileges is selected in Authentication Level. Authentication Type The authentication protocol (MD5 or SHA) used for authenticating SNMP version 3 messages Authentication Password The authentication pass phrase used for authenticating SNMP version 3 messages Encryption Type The privacy protocol (DES or AES) used for encrypting SNMP version 3 messages Privacy Password The privacy pass phrase used for encrypting SNMP version 3 messages - Click Save.