Quantcast
Channel: All SRX Services Gateway posts
Viewing all articles
Browse latest Browse all 17645

Snmp v3 srx cluster, engine-id

$
0
0

From what i understand the juniper documentation is a bit contradicting regarding this:

 

https://kb.juniper.net/InfoCenter/index?page=content&id=KB27191&actp=RSS here it says:

 

"You must ensure that the engine ID is equal on both of the nodes in the SRX cluster. A common wrong way is to use the MAC address to automatically generate  the engine ID:"

 

But here https://kb.juniper.net/library/CUSTOMERSERVICE/GLOBAL_JTAC/SRX-cluster-monitoring-best-practices.pdf it says:

 

"We recommend that the SNMP engine ID be different for each node. This is because SNMPv3 uses the engine boots value for authentication of the protocol data units (PDUs) and the SNMP engine boots value is different for each node. SNMPv3 might fail after a switchover when the engine boots value does not match the expected value. Most of the protocol stacks will resynchronize if the engine IDs are differen"

 

So whats really recommended?


Viewing all articles
Browse latest Browse all 17645

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>