| Title: | DECmcc user notes file. Does not replace IPMT. |
| Notice: | Use IPMT for problems. Newsletter location in note 6187 |
| Moderator: | TAEC::BEROUD |
| Created: | Mon Aug 21 1989 |
| Last Modified: | Wed Jun 04 1997 |
| Last Successful Update: | Fri Jun 06 1997 |
| Number of topics: | 6497 |
| Total number of notes: | 27359 |
Hi !
I tried to set up occurs rules to catch snmp traps. I have one rule for
each generic trap because the linkup and linkdown traps are handled in a
another domain and sent to the rigth interface via the collection_am.
When the traps get's into the mcc system the rigth rule fires but the coldstart
rule also always fires for all types of traps. Please see example below.
When requesting the traps one by one from the notify request window as a
workaround it's ok.
I have reproduced this problem on two different systems with CISCO and Chipcom
equipment generating the traps.
$ man/ent
DECmcc (V1.2.0)
MCC> show mcc 0 tcpip_am sink all count
MCC 0 TCPIP_AM SINK
AT 21-SEP-1992 19:48:09 Counters
Examination of attributes shows:
Current Clients = 6
coldStart Traps Received = 0
warmStart Traps Received = 0
linkDown Traps Received = 0
linkUp Traps Received = 0
authenticationFailure Traps Received = 6
egpNeighborLoss Traps Received = 0
enterpriseSpecific Traps Received = 0
Total Traps Received = 6
Counter Creation Time = 21-SEP-1992 19:32:05.34
MCC> notify domain allen_plan_2
%MCC-S-NOTIFSTART, Notify request 2 started
MCC> ena mcc 0 alarms rule * , in domain allen_plan_2
MCC 0 ALARMS RULE authenticationfailure
AT 21-SEP-1992 19:51:29
Normal operation has begun.
MCC 0 ALARMS RULE Coldstart
AT 21-SEP-1992 19:51:30
Normal operation has begun.
MCC 0 ALARMS RULE Warmstart
AT 21-SEP-1992 19:51:30
MCC> show mcc 0 alarms rule * all attr, in domain allen_plan_2
MCC 0 ALARMS RULE authenticationfailure
AT 21-SEP-1992 19:51:38 All Attributes
NAME = authenticationfailure
State = Enabled
Substate = Running
Result of Last Evaluation = In progress
Current Severity = Critical
Creation Timestamp = 21-SEP-1992 19:51:29.95
Evaluation Error = 0
Evaluation True = 0
Evaluation False = 0
Expression = (OCCURS (SNMP *
authenticationfailure))
Perceived Severity = Critical
Probable Cause = Unknown
MCC 0 ALARMS RULE Coldstart
AT 21-SEP-1992 19:51:39 All Attributes
NAME = Coldstart
State = Enabled
Substate = Running
Result of Last Evaluation = In progress
Current Severity = Critical
Creation Timestamp = 21-SEP-1992 19:51:30.83
Evaluation Error = 0
Evaluation True = 0
Evaluation False = 0
Expression = (OCCURS (SNMP * coldstart))
Perceived Severity = Critical
Probable Cause = Unknown
MCC 0 ALARMS RULE Warmstart
AT 21-SEP-1992 19:51:39 All Attributes
NAME = Warmstart
State = Enabled
Substate = Running
Result of Last Evaluation = In progress
Current Severity = Critical
Creation Timestamp = 21-SEP-1992 19:51:31.00
Evaluation Error = 0
Evaluation True = 0
Evaluation False = 0
Expression = (OCCURS (SNMP * warmstart))
Perceived Severity = Critical
Probable Cause = Unknown
MCC> show snmp tmpsys4 all char, by passw niklas !** wrong password = authentic
ation failure
!!!!!!!!!!!!!! Alarm, 21-SEP-1992 19:53:09 !!!!!!!!!!!!!! [2]
Domain: ANTIK_NS:.ALLEN_PLAN_2 Severity: Critical
Notification Entity: SNMP ANTIK_NS:.TMPSYS4
Event Source: Domain ANTIK_NS:.ALLEN_PLAN_2 Rule Coldstart
Event: OSI Rule Fired
Event Type = QualityofServiceAlarm
Event Time = 21-SEP-1992 19:53:08.00
Probable Cause = Unknown
Additional Info = { (
significance = True,
information = "The last event detected: SNMP
ANTIK_NS:.TMPSYS4
authenticationFailure
21-SEP-1992 19:53:07.43" ),
(
significance = True,
information = "Event: authenticationFailure An
authenticationFailure trap was
received: enterprise =
""1.3.6.1.4.1.49.1.3.1.0""
agent-addr = 16.181.0.204
generic-trap =
authenticationFailure
specific-trap = 0 time-stamp =
29497427" ),
(
significance = True,
information = "(OCCURS (SNMP * coldstart))" ) }
Managed Object = SNMP ANTIK_NS:.TMPSYS4
Perceived Severity = Critical
!!!!!!!!!!!!!! Alarm, 21-SEP-1992 19:53:10 !!!!!!!!!!!!!! [2]
Domain: ANTIK_NS:.ALLEN_PLAN_2 Severity: Critical
Notification Entity: SNMP ANTIK_NS:.TMPSYS4
Event Source: Domain ANTIK_NS:.ALLEN_PLAN_2 Rule authenticationfailure
Event: OSI Rule Fired
Event Type = QualityofServiceAlarm
Event Time = 21-SEP-1992 19:53:08.15
Probable Cause = Unknown
Additional Info = { (
significance = True,
information = "The last event detected: SNMP
ANTIK_NS:.TMPSYS4
authenticationFailure
21-SEP-1992 19:53:07.43" ),
(
significance = True,
information = "Event: authenticationFailure An
authenticationFailure trap was
received: enterprise =
""1.3.6.1.4.1.49.1.3.1.0""
agent-addr = 16.181.0.204
generic-trap =
authenticationFailure
specific-trap = 0 time-stamp =
29497427" ),
(
significance = True,
information = "(OCCURS (SNMP *
authenticationfailure))" ) }
Managed Object = SNMP ANTIK_NS:.TMPSYS4
Perceived Severity = Critical
!!!!!!!!
!!!!!!!! The above notification are repeated two times
!!!!!!!! due to the two UDP retries i think ??
!!!!!!!!
SNMP tmpsys4
AT 21-SEP-1992 19:53:07 Characteristics
No response from entity.
MCC> show mcc 0 tcpip_am sink all count
MCC 0 TCPIP_AM SINK
AT 21-SEP-1992 19:54:37 Counters
Examination of attributes shows:
Current Clients = 6
coldStart Traps Received = 0
warmStart Traps Received = 0
linkDown Traps Received = 0
linkUp Traps Received = 0
authenticationFailure Traps Received = 9
egpNeighborLoss Traps Received = 0
enterpriseSpecific Traps Received = 0
Total Traps Received = 9
Counter Creation Time = 21-SEP-1992 19:32:05.34
/Niklas
| T.R | Title | User | Personal Name | Date | Lines |
|---|---|---|---|---|---|
| 3778.1 | Bug in SNMP AM. | YAHEY::BOSE | Thu Sep 24 1992 10:59 | 9 | |
Niklas, You have uncovered a bug in the SNMP AM. It will be fixed in the next release. Regarding your other question, yes, you get the multiple authentificationFailure traps because of the UDP retries. Rahul. | |||||
| 3778.2 | CSOADM::ROTH | I'm getting closer to my home... | Tue Sep 29 1992 18:28 | 10 | |
> Niklas, > You have uncovered a bug in the SNMP AM. It will be fixed in > the next release. Any idea when this will be available... or a patch to fix this particular problem? It is rather visible at the site I am working at. Thanks- Lee Roth | |||||
| 3778.3 | Which release will fix this known bug?? | ZUR01::FUEGLISTER | Roland Fueglister, 760-2498 | Wed Apr 07 1993 08:33 | 176 |
The following happens with POLYcenter Network Manager 400 V2.3 SSB:
After receiving two WarmStart traps from two different SNMP devices, I got a
notification from alarm rules which are listening to coldstart and linkdown
traps!!
Have a look at the attached LOG.
RE: .1
/ Niklas,
/ You have uncovered a bug in the SNMP AM. It will be fixed in
/ the next release.
/
/ Rahul.
What means "fixed in the next release" ? Which release ?
This nasty bug should be resolved soon.
Best Regards,
Roland
****5-APR-1993 11:01:43.99 SNMP LOCAL_NS:.ch.psi.ip.psth09****
Rule: Domain LOCAL_NS:.mcc_alarm_hidden Rule linkdown_trap
Info1: The last event detected: SNMP LOCAL_NS:.ch.psi.ip.psth09 warmStart 5
-APR-1993 11:01:43.47
Info2: Event: warmStart A warmStart trap was received: enterprise = "1.3.6.
1.4.1.26.22.2" agent-addr = 129.129.120.9 generic-trap = warmStart
specific-trap = 0 time-stamp = 43
****5-APR-1993 11:01:44.93 SNMP LOCAL_NS:.ch.psi.ip.psth09****
Rule: Domain LOCAL_NS:.mcc_alarm_hidden Rule coldstart_trap
Info1: The last event detected: SNMP LOCAL_NS:.ch.psi.ip.psth09 warmStart 5
-APR-1993 11:01:43.47
Info2: Event: warmStart A warmStart trap was received: enterprise = "1.3.6.
1.4.1.26.22.2" agent-addr = 129.129.120.9 generic-trap = warmStart
specific-trap = 0 time-stamp = 43
****6-APR-1993 15:05:44.97 SNMP LOCAL_NS:.ch.psi.ip.psth0c****
Rule: Domain LOCAL_NS:.mcc_alarm_hidden Rule linkdown_trap
Info1: The last event detected: SNMP LOCAL_NS:.ch.psi.ip.psth0c warmStart 6
-APR-1993 15:05:43.91
Info2: Event: warmStart A warmStart trap was received: enterprise = "1.3.6.
1.4.1.26.22.2" agent-addr = 129.129.120.12 generic-trap = warmStart
specific-trap = 0 time-stamp = 43
****6-APR-1993 15:05:45.56 SNMP LOCAL_NS:.ch.psi.ip.psth0c****
Rule: Domain LOCAL_NS:.mcc_alarm_hidden Rule coldstart_trap
Info1: The last event detected: SNMP LOCAL_NS:.ch.psi.ip.psth0c warmStart 6
-APR-1993 15:05:43.91
Info2: Event: warmStart A warmStart trap was received: enterprise = "1.3.6.
1.4.1.26.22.2" agent-addr = 129.129.120.12 generic-trap = warmStart
specific-trap = 0 time-stamp = 43
MCC 0 TCPIP_AM SINK
AT 6-APR-1993 16:19:02 Counters
Examination of attributes shows:
Current Clients = 6
coldStart Traps Received = 0
warmStart Traps Received = 2
linkDown Traps Received = 0
linkUp Traps Received = 0
authenticationFailure Traps Received = 0
egpNeighborLoss Traps Received = 0
enterpriseSpecific Traps Received = 0
Total Traps Received = 2
Counter Creation Time = 2-APR-1993 14:07:26.77
MCC 0 TCPIP_AM SINK
AT 6-APR-1993 16:19:04 Status
Examination of attributes shows:
Sink State = Running
Time when Sink Started = 2-APR-1993 14:07:26.77
Time of Last Event = 6-APR-1993 15:05:43.91
Type of Last Event = warmStart
Domain LOCAL_NS:.mcc_alarm_hidden Rule coldstart_trap
AT 6-APR-1993 16:26:26 Rule Attributes
Name = coldstart_trap
Expression = (OCCURS (snmp * ColdStart))
Description = "This rule is watching for ColdStart Traps from any SNMP objects"
Category = "Trap"
Alarm Fired Procedure = $DISK1:[MCC.ALARMS]OSI_RULE_FIRED.COM;1
Batch Queue = "decmcc$batch"
Severity = Indeterminate
Probable Cause = Unknown
State = Enabled
Substate = Running
Time of Last Evaluation = 6-APR-1993 15:05:45.56
Result of Last Evaluation = True
Current Severity = Indeterminate
Creation Timestamp = 2-APR-1993 14:13:04.37
Evaluation Error = 0
Evaluation True = 2
Evaluation False = 0
Domain LOCAL_NS:.mcc_alarm_hidden Rule warmstart_trap
AT 6-APR-1993 16:26:34 Rule Attributes
Name = warmstart_trap
Expression = (OCCURS (snmp * WarmStart))
Description = "This rule is watching for WarmStart Traps from any SNMP objects"
Category = "Trap"
Alarm Fired Procedure = $DISK1:[MCC.ALARMS]OSI_RULE_FIRED.COM;1
Batch Queue = "decmcc$batch"
Severity = Indeterminate
Probable Cause = Unknown
State = Enabled
Substate = Running
Result of Last Evaluation = In progress
Current Severity = Indeterminate
Creation Timestamp = 2-APR-1993 14:13:06.75
Evaluation Error = 0
Evaluation True = 0
Evaluation False = 0
Domain LOCAL_NS:.mcc_alarm_hidden Rule linkup_trap
AT 6-APR-1993 16:26:47 Rule Attributes
Name = linkup_trap
Expression = (OCCURS (snmp * LinkUp))
Description = "This rule is watching for LinkUp Traps from any SNMP objects"
Category = "Trap"
Alarm Fired Procedure = $DISK1:[MCC.ALARMS]OSI_RULE_FIRED.COM;1
Batch Queue = "decmcc$batch"
Severity = Indeterminate
Probable Cause = Unknown
State = Enabled
Substate = Running
Result of Last Evaluation = In progress
Current Severity = Indeterminate
Creation Timestamp = 2-APR-1993 14:13:04.74
Evaluation Error = 0
Evaluation True = 0
Evaluation False = 0
Domain LOCAL_NS:.mcc_alarm_hidden Rule linkdown_trap
AT 6-APR-1993 16:26:56 Rule Attributes
Name = linkdown_trap
Expression = (OCCURS (snmp * LinkDown))
Description = "This rule is watching for LinkDown Traps from any SNMP objects"
Category = "Trap"
Alarm Fired Procedure = $DISK1:[MCC.ALARMS]OSI_RULE_FIRED.COM;1
Batch Queue = "decmcc$batch"
Severity = Indeterminate
Probable Cause = Unknown
State = Enabled
Substate = Running
Time of Last Evaluation = 6-APR-1993 15:05:44.97
Result of Last Evaluation = True
Current Severity = Indeterminate
Creation Timestamp = 2-APR-1993 14:13:04.46
Evaluation Error = 0
Evaluation True = 2
Evaluation False = 0
| |||||
| 3778.4 | MOLAR::YAHEY::BOSE | Wed Apr 07 1993 09:40 | 5 | ||
The bug was fixed in DECmcc BMS V1.3 (Polycenter Network Manager 200), which has recently gone into SSB. Rahul. | |||||
| 3778.5 | I'm working with DECmcc V1.3 SSB | ZUR01::FUEGLISTER | Roland Fueglister, 760-2498 | Thu Apr 08 1993 04:14 | 14 |
Hi Rahul, You seemed to have overlooked something or maybe I have encountered a NEW bug. RE. .3 / The following happens with POLYcenter Network Manager 400 V2.3 SSB: / DECmcc BMS V1.3 SSB is part of the POLYcenter Network Manager 400 V2.3 SSB! Best regards, Roland | |||||
| 3778.6 | Recreate alarms MIR | STKMCC::LUND | Niklas Lund | Thu Apr 08 1993 08:13 | 7 |
Hi, Roland if you have gone from 1.2 to 1.3 I recommend that you run mcc_alarms_extract_rules.exe and then delete the alarms MIR and recreate it with mcc_alarms_rules.com. /Niklas | |||||
| 3778.7 | I will do it | ZUR01::FUEGLISTER | Roland Fueglister, 760-2498 | Tue Apr 13 1993 12:26 | 12 |
Hi Niklas, I indeed did an update from V1.2 to V1.3 and did not recreate the Alarms MIR. I will try out what you have recommended. Earliest date for testing your workaround solution will be week 18 or 19. Thank you for your answer. Best regards, Roland | |||||