Spectrum raises "Unknown Alert Received" trap event for Fortinet device
search cancel

Spectrum raises "Unknown Alert Received" trap event for Fortinet device

book

Article ID: 125439

calendar_today

Updated On:

Products

Spectrum Network Observability

Issue/Introduction

A Fortinet device not yet Spectrum certified and discovered in Spectrum as GnSNMPDev is sending traps to Spectrum.

Some of these are failing with the message:

Unknown alert received from device xxxxx of type GnSNMPDev. Device Time 2+18:08:40. (Trap type 1.3.6.1.2.1.15.6.2) Trap var bind data: OID: 1.3.6.1.2.1.1.3.0 Value: 23812084 OID: 1.3.6.1.6.3.1.1.4.1.0 Value: 1.3.6.1.2.1.15.0.2 OID: 1.3.6.1.2.1.15.3.1.7 Value: x.x.x.x OID: 1.3.6.1.2.1.15.3.1.14 Value: 6.3 OID: 1.3.6.1.2.1.15.3.1.2 Value: 1

Environment

All supported DX NetOps Spectrum releases

Cause

The AlertMap file to handle the trap type 1.3.6.1.2.1.15.6.2 and 1.3.6.1.2.1.15.6.1 is present under the folder <$SPECROOT>/SS/CsVendor/Ctron_SNMP_Rtr/BGP4_App. When the trap arrives in Spectrum does not get processed properly due to the device using model type GnSNMPDev. This results in an the  "Unknown alert received" Alarms being raised.

Resolution

Create a copy the AlertMap file from the <$SPECROOT>/SS/CsVendor/Ctron_SNMP_Rtr/BGP4_App directory, placing the copy into the <$SPECROOT>/Custom/Events folder,

Once the file is copied navigate to the VNM model in the OC web UI. In the Information tab for the VNM model expand theSpectroSERVER Control section. Select the Update Event Configuration option.

Once completed new instances of the trap arriving in Spectrum should raise the appropriately defined Alarm.