FineConnection.com

SNMP traps, the Monitor one Trap server with filtering capabilities

Posted On: August 27, 2005 - 16:45 by Admin

About traps

A Trap is an unsolicited message sent by an SNMP agent to an SNMP management system when the agent detects that a certain type of event has occurred locally on the managed host. The SNMP management console that receives a trap message is known as a trap destination. For example, a trap message might be sent on a system restart (Cold- or Warm start trap) event or in case of an eminent disk failure.

Trap versions

The current Monitor one version fully supports decoding, filtering and processing of SNMPv1 and SNMPv2 traps. However, due to the different format of SNMPv2 traps, filtering of SNMPv2 traps slightly differs from filtering of SNMPv1 traps!

Trapreceiver

Trap filtering

In order to prevent you from missing important traps due to the receiving of too many unimportant ones, Monitor one provides a sophisticated trap filtering mechanism. A trap filter’s decision is based on 3 different trap properties:

  1. the Trap type (Generic, Enterprise specific)
  2. the Enterprise (3Com, HP, Cisco, IBM etc..)
  3. the Trap number (value)

Generic Trap filters

The screenshot below shows a simple generic trap filter. All Generic traps are accepted except the Authentication failure trap, LinkUp and LinkDown traps received from HP j4813A switches and the coldStart trap received from D-link systems.

The "PHASE II" rules cannot be added directly into the filtering table above. Monitor one provides another way to let you add PHASE II filtering rules. By default, all Generic traps that pass the PHASE I filter are accepted and displayed in the "Trap control" window. If you are certain that you do not want to see a specific generic trap anymore, right-click the trap in this window and select Block this trap type from now on. A new filtering rule (describing the trap you blocked) is added automatically to the PHASE II table!

Generic trap filtering

Enterprise Specific Trap filters

EnterpriseSpecific Trap filtering slightly differs from Generic Trap filtering. Use the Enterprise box to select an enterprise. New Enterprises and trap descriptions can be made available by compiling the appropriate enterprise specific MIBs!

Enterprise specific trap filtering

Just as with Generic Traps, new rules can be added to the set of Enterprise Specific filtering rules by right-clicking traps in the "Trap control" window and choosing Block this trap type from now on.

News

InfoFineConnection is pleased to announce the availability of the new stable Monitor one version FP1.106.391 (February 2008).
ChartsFor superior trending and long-term analysis, Monitor one can act as a "front end" for RRD. RRD is a system to store and display time-series data. The RRD can also perfectly be used for exporting logged trending data to text files for use in spreadsheets or databases. More...
If you're using HP/Compaq servers with Insight manager agents in your network, click here to learn how they can be monitored with Monitor one.
PDAMonitor one provides an interface to messaging gateway systems, making it easy to send alert messages to pagers, mobile phones, PIMs and wireless devices.
MonitorThe Monitor one "Desktop" option allows you to save Monitor one desktop configurations to the database for quick access later.
CertificateThe new version also comes with a new licensing policy. The required license type is now only determined by the number of device objects on the network map from which you want to monitor uptime. The number of concurrently running Shooters (SNMP monitors) is now "unlimited" in all versions (was dependent of the license type!)
Font_and_ColorThe new version allows you to define the font name, size and color for object labels on the network map.