<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NetSight: Trap Log filling Up with Junk in ExtremeCloud IQ- Site Engine Management Center</title>
    <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netsight-trap-log-filling-up-with-junk/m-p/30284#M3065</link>
    <description>So there are a couple of computers on campus which run software that actively goes out and "seeks" for Multi-Function Printers and gets a status from them using snmp V1 with the public community string.  It runs through the entire network and retrieves responses back from the printers on their health, and more importantly, how many pages they printed for accounting purposes.&lt;BR /&gt;
&lt;BR /&gt;
Since we don't use SNMP V1 on any of our devices, these queries are getting rejected and in turn filling up the trap log with "Incorrect Community Name" messages.  Hundreds of them.&lt;BR /&gt;
&lt;BR /&gt;
Needless to say, this is quite annoying and when we go to look for legitimate traps in the NetSight log they've been overrun by this junk.&lt;BR /&gt;
&lt;BR /&gt;
Any ideas on what to do about this?  The software needs to check so I'm not terribly concerned about the methodology, but I would like them to stop showing up in the trap log so we can get more meaningful information from it.&lt;BR /&gt;
&lt;BR /&gt;
Thank you in advance!</description>
    <pubDate>Tue, 30 Sep 2014 02:42:00 GMT</pubDate>
    <dc:creator>Rich_Upshaw</dc:creator>
    <dc:date>2014-09-30T02:42:00Z</dc:date>
    <item>
      <title>NetSight: Trap Log filling Up with Junk</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netsight-trap-log-filling-up-with-junk/m-p/30284#M3065</link>
      <description>So there are a couple of computers on campus which run software that actively goes out and "seeks" for Multi-Function Printers and gets a status from them using snmp V1 with the public community string.  It runs through the entire network and retrieves responses back from the printers on their health, and more importantly, how many pages they printed for accounting purposes.&lt;BR /&gt;
&lt;BR /&gt;
Since we don't use SNMP V1 on any of our devices, these queries are getting rejected and in turn filling up the trap log with "Incorrect Community Name" messages.  Hundreds of them.&lt;BR /&gt;
&lt;BR /&gt;
Needless to say, this is quite annoying and when we go to look for legitimate traps in the NetSight log they've been overrun by this junk.&lt;BR /&gt;
&lt;BR /&gt;
Any ideas on what to do about this?  The software needs to check so I'm not terribly concerned about the methodology, but I would like them to stop showing up in the trap log so we can get more meaningful information from it.&lt;BR /&gt;
&lt;BR /&gt;
Thank you in advance!</description>
      <pubDate>Tue, 30 Sep 2014 02:42:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netsight-trap-log-filling-up-with-junk/m-p/30284#M3065</guid>
      <dc:creator>Rich_Upshaw</dc:creator>
      <dc:date>2014-09-30T02:42:00Z</dc:date>
    </item>
    <item>
      <title>RE: NetSight: Trap Log filling Up with Junk</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netsight-trap-log-filling-up-with-junk/m-p/30285#M3066</link>
      <description>The traps are expected if someone has your SNMP stations IP address. The best way to handle this is to capture snmp traffic with an sniffer.&lt;BR /&gt;
another way (if using something like a SecureStack or S series) is to put in a manual policy to block SNMP such as the following examples:&lt;BR /&gt;
&lt;BR /&gt;
set policy profile 45 name NoNo                                              &lt;NAME&gt;&lt;BR /&gt;
set policy rule 45 ipsourcesocket 10.26.196.5  mask 32 drop       &lt;DROP snmp="" to="" destination="" 10.26.196.5=""&gt;&lt;BR /&gt;
set policy rule 45 udpdestport 161 drop                                   &lt;DROP snmp=""&gt;&lt;BR /&gt;
set policy rule 45 macsource 00-00-00-00-00-00  mask 48 drop    &lt;DROP all="" macsource="" of="" 00:00:00:00=""&gt;&lt;BR /&gt;
set policy rule 45 ipsourcesocket 10.26.255.255:161  mask 48 drop &lt;DROP all="" snmp="" from="" this="" ip="" range=""&gt;&lt;BR /&gt;
&lt;BR /&gt;&lt;/DROP&gt;&lt;/DROP&gt;&lt;/DROP&gt;&lt;/DROP&gt;&lt;/NAME&gt;</description>
      <pubDate>Tue, 30 Sep 2014 04:55:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netsight-trap-log-filling-up-with-junk/m-p/30285#M3066</guid>
      <dc:creator>Jason_Parker</dc:creator>
      <dc:date>2014-09-30T04:55:00Z</dc:date>
    </item>
    <item>
      <title>RE: NetSight: Trap Log filling Up with Junk</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netsight-trap-log-filling-up-with-junk/m-p/30286#M3067</link>
      <description>Jason, This looks great.  I'll try putting this policy in place.  I'll let you know how it went.  Thanks!&lt;BR /&gt;</description>
      <pubDate>Wed, 01 Oct 2014 20:05:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netsight-trap-log-filling-up-with-junk/m-p/30286#M3067</guid>
      <dc:creator>Rich_Upshaw</dc:creator>
      <dc:date>2014-10-01T20:05:00Z</dc:date>
    </item>
  </channel>
</rss>

