ArubaOS-CX SNMP Traps: From Community to Trap Receiver - 夜莺博客

ArubaOS-CX SNMP Traps: From Community to Trap Receiver

Most ArubaOS-CX SNMP problems are not SNMP problems at all — they are VRF problems. AOS-CX runs the agent inside a VRF you choose, and if the notification path and the polling path sit in different VRFs, polling works while traps vanish. This guide configures SNMP v2c and v3 traps from scratch, picks the right VRF, and verifies the whole chain from the switch's own CLI.

Step 1: Enable SNMP in the Correct VRF

configure terminal
snmp-server vrf mgmt
snmp-server vrf default

Enabling both is normal — management stations usually poll the mgmt VRF while traps may need to exit via default. Document which is which before you continue.

Step 2: Set Identity and Community

snmp-server system-description "DC1-QSFP-Access-01"
snmp-server system-location "DC1 Rack 42"
snmp-server system-contact netops@example.com
snmp-server community public

Replace public. The default community on AOS-CX is public and it is read-only, but it is still a credentialed name on the open wire.

Step 3: Prefer SNMPv3 in Production

snmpv3 user monitor auth sha auth-pass ciphertext <hash>
snmpv3 user monitor priv des priv-pass ciphertext <hash>
snmpv3 context monitor

AOS-CX stores ciphertext credentials; generate them with the CLI ciphertext helper rather than pasting plaintext. Use authPriv so both authentication and encryption are in force.

Step 4: Configure the Trap Receiver

snmp-server host 10.80.2.187 trap version v2c community public vrf mgmt
snmp-server host 10.80.2.187 inform version v2c community public
snmp-server host 10.80.2.187 trap version v3 user monitor vrf mgmt
snmp-server trap-source 10.80.2.1 vrf mgmt

Do not configure the same receiver for both traps and informs on the same UDP port — AOS-CX will accept the configuration but the receiver sees an ambiguous stream. Traps are fire-and-forget; informs are acknowledged and generate retries when the collector is down.

Step 5: Limit Which Traps You Send

snmp-server host 10.80.2.187 trap version v3 user monitor vrf mgmt port-security vsf vsx

Supported notification types include aaa-server, alarm, bgp, card, config, interface, mstp, ospf, port-security, power, power-ethernet, rmon, stp, temperature, vrrp, vsf and vsx. A switch that fires every category at a busy collector is a trap storm; select what your NMS actually alerts on.

Verification

show snmp agent-port
show snmp vrf
show snmp community
show snmp trap
show snmpv3 user
show logging -r

The show snmp trap table is the one to read carefully: it lists host, port, type, version, community or user, and VRF. If the VRF column shows default while your collector is only reachable through mgmt, you have found the bug.

RMON Alarms for Custom Traps

When you need a trap the platform does not emit natively, build it with an RMON alarm rather than polling harder:

rmon alarm index 1 snmp-oid arubaWiredVsfv2MemberStatus rising-threshold 100 falling-threshold -100
rmon alarm index 2 snmp-oid arubaWiredVsfv2MemberStatusChange rising-threshold 100 falling-threshold -100

For VSF member and link state changes the threshold values are effectively ignored, but the CLI requires them — any non-zero pair works.

Related Reading

Deeper dives on the same topics from our archive:

原文链接:https://community.arubanetworks.com/discussion/aos-cx-snmp-simple-steps-to-configure