Asentria SiteBoss 530 User Manual
75
SNMP Trap Capture
The S530 can receive and buffer SNMPv1 traps and
SNMPv2c inform-requests (informs),
collectively referred to
here as “notifications”. Each notification can be subjected to data event evaluation, stored in the Event Log, and
delivered via normal Event Log delivery.
When SNMP Trap Capture is enabled, the S530 listens on port 162 for notifications; those over 1024 bytes are
ignored. The unit responds successfully to informs as soon as they arrive regardless of the content of the inform.
The first task the S530 does upon receiving a notification that is an inform, is to send a response. It then converts
the notification to a multiline record (MLR). A multiline record is an ASCII data packet comprised of 1 or more
lines. In this application each line is terminated by CRLF. A trap that is converted to an MLR is called a trap
MLR; an inform that is converted to an MLR is called an inform MLR. They are generally called notification MLRs
when the difference is irrelevant. There are specific format rules imposed to enable easy use of data events.
1. The first line of the trap MLR specifies the most important common attributes of a trap in this format:
TRAP AA:BBBBB CCCCCCCC DDDDDDDD FROM EEE.EEE.EEE.EEE ENTERPRISE FFF...
where the fields occupied by A - F are:
A. generic trap number (position 6, length 2, padded with 0s) The generic trap number indicates the generic trap
type, of which there are 7:
0: coldStart
1: warmStart
2: linkDown
3: linkUp
4: authenticationFailure
5: egpNeighborLoss
6: enterpriseSpecific
B. specific trap number (position 8, length 5, padded with 0s)
C. date the trap was received (in MM/DD/YY format, position 15, length 8)
D. time the trap was received (in HH:MM:SS (24-hr) format, position 24, length 8)
E. source IP address (position 38, length 15, each octet is padded with 0s)
F. enterprise OID (position 65, variable length)
2. The first line of the inform MLR specifies the following:
INFORMREQUEST CCCCCCCC DDDDDDDD FROM EEE.EEE.EEE.EEE
where the fields occupied by C, D, & E are:
C. date the inform was received (in MM/DD/YY format, position 15, length 8)
D. time the inform was received (in HH:MM:SS (24-hr) format, position 24, length 8)
E. source IP address (position 38, length 15, each octet is padded with 0s)
3. Each additional line in the MLR (for both inform MLRs and trap MLRs) is devoted to 1 varBind in the
notification.
The format of this varBind line is
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA = BBB...
where the fields occupied by A & B are:
A. varBind OID (position 1, length 40, left-justified, truncated or padded with spaces as necessary)
B. varBind value (position 44, variable length, limited to 115 bytes)
Note: Quote marks are never inserted by the unit in varBind values, even if the value type is OCTET STRING.
Содержание SiteBoss 530
Страница 6: ......