Oracle SBC Security Guide
enable-snmp-syslog-notify – enable syslog conversion to SNMP
enable-snmp-monitor-traps – enable unique trap-IDs for each syslog event
The SBC setting to enable environmental monitors may seem advantageous, but is not recommended, and
should remain at the default – disabled. The same traps are already sent as part of the ap-smgmt MIB.
enable-env-monitor-traps – sends traps for environmental issues like temperature, voltage, fan
speeds, etc.
SNMP Traps
The following are a selection of the most common or important traps sent by the SD. The full list of traps
can be found in the MIB Reference Guide and MIB files for the release implemented:
apSwCfgActivateNotification (1.3.6.1.4.1.9148.3.4.3.0.1)
o Generated when the activate-config command is issued at ACLI and configuration has
been changed at run time. This trap may be seen often but is only informational and
doesn’t necessarily mean there is an issue (unless the config changes are service affecting
or the change was not authorized).
apEnvMonStatusChangeNotification (1.3.6.1.4.1.9148.3.3.2.1.0)
o Generated when the environmental state of the SBC changes. Environment traps include
main board PROM temperature, CPU voltage, state of power supplies, fan speeds, etc. To
receive this trap, the system-config parameter enable-env-monitor-traps needs to be
enabled. An example of this trap for voltage state change is found in [4].
apSysMgmtGroupTrap (1.3.6.1.4.1.9148.3.2.3.0.1)
o Generated when an SBC resource threshold or health score is exceeded. For example, if
NAT table usage, ARP table usage, memory usage, or CPU usage reaches 90% or
greater. Also, If the health score for an HA pair falls below 60.
apSysMgmtExpDOSTrap (1.3.6.1.4.1.9148.3.2.8.0.2)
o Generated when an endpoint exceeds configured thresholds and is denied access by the
SD.
apSysMgmtInetAddrWithReasonDOSTrap (1.3.6.1.4.1.9148.3.2.8.0.4)
o This trap is generated when the IDS Reporting Feature Group license (available in S-
CX6.3 and above) is installed. This trap is generated when thresholds are exceeded, and
contains further data on the end-point and reason why the trap was generated. When IDS
Reporting is installed the apSysMgmtExpDOSTrap is disabled.
apSysMgmtInetAddrTrustedToUntrustedDOSTrap (1.3.6.1.4.1.9148.3.2.8.0.5.)
o This trap is available in S-C[xz]6.4.0 and above. It will be generated when the number of
rejected messages exceeds the configured threshold and the endpoint is demoted from the
trusted to untrusted list. The trap-on-demote-to-untrusted setting under media-manager
must be enabled for this trap to be sent.
apSysMgmtRejectedMesagesThresholdExeededTrap (.1.3.6.1.4.1.9148.3.2.6.0.57)
o This trap is available in S-C[xz]6.4.0 and above. A trap will be generated when the
number of rejected messages exceed the configured threshold and the endpoint is put into
the untrusted queue.
apSysMgmtSipRejectionTrap (.1.3.6.1.4.1.9148.3.2.10.0.1)
o Generated when a SIP INVITE or REGISTRATION request fails
apSysMgmtPowerTrap (1.3.6.1.4.1.9148.3.2.6.0.1)
o Generated if a power supply is powered down, powered up, inserted (present) or removed
(not present).
apSysMgmtTempTrap (1.3.6.1.4.1.9148.3.2.6.0.2)
Comentarios a estos manuales