Unknownt Alert Receive - Fortinet

book

Article ID: 125439

calendar_today

Updated On:

Products

CA Spectrum

Issue/Introduction

A Fortinet device not yet Spectrum certified and discovered in Spectrum as GnSNMPDev is sending traps to Spectrum.
Some of these are failing with the message:
Unknown alert received from device RPPFWXXXXX of type GnSNMPDev. Device Time 2+18:08:40. (Trap type 1.3.6.1.2.1.15.6.2) Trap var bind data: OID: 1.3.6.1.2.1.1.3.0 Value: 23812084 OID: 1.3.6.1.6.3.1.1.4.1.0 Value: 1.3.6.1.2.1.15.0.2 OID: 1.3.6.1.2.1.15.3.1.7 Value: 169.254.4.6 OID: 1.3.6.1.2.1.15.3.1.14 Value: 6.3 OID: 1.3.6.1.2.1.15.3.1.2 Value: 1
Why?

Cause

The AlertMap file to handle the trap type 1.3.6.1.2.1.15.6.2 and 1.3.6.1.2.1.15.6.1 is present under the folder:
<$SPECROOT>\SS\CsVendor\Ctron_SNMP_Rtr\BGP4_App  and when the trap arrives to Spectrum, probably this is not processed because the device was discovered as GnSNMPDev, resulting in an  "Unknown alert received from device RPPFWXXXXX of type GnSNMPDev..."


 

Environment

Spectrum 10.3 on any platform

Resolution

Copy the AlertMap from the <$SPECROOT>\SS\CsVendor\Ctron_SNMP_Rtr\BGP4_App into the <$SPECROOT>\Custom\Events folder, then open the VNM model -> SpectroSERVER Control and click on Update Event Configuration.