ā11-20-2023 05:37 AM
Hi,
I have on customer site Palo Alto 5200 firewall (PAN OS 10.2) connected to NMS using SNMP V3 (Auth/Priv: SHA/AES) with loaded custom Palo Alto SNMP MIBS for PAN OS 10.2 in MyMibs folder.
In "Port Tree" view I see only a few ports but when I switch to "Interface Summary View" I see a complete device port list (with logical interfaces like aggregation and tunnel as well).
Port Tree view:
Interface Summary view:
As far as I understand if I want to create manually some links in Network Maps with this firewall I need to have device interfaces in "Port Tree" view to be able to do it. Do you have any idea how to fix it?
Solved! Go to Solution.
ā11-21-2023 05:35 AM
You are correct that if you want to be able to manually create links on maps the full port list being available would be necessary.
I do not understand the different why Port View vs Interface Summary produces different results. I would have to see SNMP style traces or model the updates for both to see a difference in behavior.
This would be something I would advise you to open a GTAC case for if necessary.
ā11-24-2023 05:36 AM
SNMPv3 OID Permissions in Firewall for this SNMP user were set with 0x80 mask so it shouldn't be a problem (any 1.X should be available). Now when I moved back to SNMPv2c there is still only limited Port Tree view. I've tried also deleting and re-adding device again to NMS but unfortunately with no success. Next week I'll upgrade this XMC to XIQ-SE and hope it fix the issue
ā11-27-2023 06:05 AM
If you do continue to encounter the issue I would suggest opening a case with GTAC. The screenshots you provided indeed show a discrepancy between the two tables and they should essentially be identical in terms of the # of interfaces/ports shown. SNMP 'tcpdump' traces taken when opening each view would be a good data point to start with.