SRX Services Gateway
Reply
Contributor
techniq
Posts: 40
Registered: ‎01-14-2009
0
Accepted Solution

SNMP MIB Data for Security Policy Missing in 11.4R1.6

[ Edited ]

In previous versions of code I was able to obtain data from the "jnxJsPolicies" (oid=1.3.6.1.4.1.2636.3.39.1.4) portion of the SRX MIB.  This data seems to no longer be available in 11.4R1.6.  I was specifically getting data from the jnxJsPolicyStatsTable (oid= 1.3.6.1.4.1.2636.3.39.1.4.1.1.3).  Is there now a setting that prevents this data from being made available automatically?  Can it be enabled?

 

Policy Mib: http://www.juniper.net/techpubs/en_US/junos11.4/topics/concept/mib-policy-objects-junos-overview.htm...

 

PolicyStatsTable: http://www.juniper.net/techpubs/en_US/junos11.4/topics/reference/general/jnxjspolicystatstable-nm-mi...

Contributor
techniq
Posts: 40
Registered: ‎01-14-2009
0

Re: SNMP MIB Data for Security Policy Missing in 11.4R1.6

So the second link for the jnxJsPolicyStatsTable contains this statement:

 

"jnxJsPolicyStatsTable, whose object ID is {jnxJsPolicyObjects 3}, exposes the security policy statistics entries listed in Table 1. These statistics can be enabled and disabled by configuration on a per-policy basis."

 

...but I can't find any command on a per-policy basis to support this.  Anyone?

Contributor
techniq
Posts: 40
Registered: ‎01-14-2009
0

Re: SNMP MIB Data for Security Policy Missing in 11.4R1.6

Additional information...

 

I also noted that the mib information is not available directly from the CLI:

 

admin@srx100h> show snmp mib walk decimal .1.3.6.1.4.1.2636.3.39.1.4

Contributor
techniq
Posts: 40
Registered: ‎01-14-2009
0

Re: SNMP MIB Data for Security Policy Missing in 11.4R1.6

Bump!

 

Anyone, this is still not availalbe in 12.1R1.9 or am I misreading the documentation?  Can anyone confirm the same behaviour.

New User
mshehari
Posts: 1
Registered: ‎05-01-2011
0

Re: SNMP MIB Data for Security Policy Missing in 11.4R1.6

I was missing the BGP4 MIB with 11.4R3 but restarting the SNMP daemon fixed the issue for me.

 

> restart snmp

 

 

Contributor
junwbat
Posts: 32
Registered: ‎09-01-2011
0

Re: SNMP MIB Data for Security Policy Missing in 11.4R1.6

I have run into the same issue on my SRXs. I am running 11.4:

 

show snmp mib walk 1.3.6.1.4.1.2636.3.39.1.4

 

This command returns no results. I would expect to see everything in teh jnxJsPolicies mib tree.
 Does anyone know how to enable this MIB, or perhaps update the firewalls MIB?

 

Thanks in Advance!

 

 

Contributor
techniq
Posts: 40
Registered: ‎01-14-2009
0

Re: SNMP MIB Data for Security Policy Missing in 11.4R1.6

Would be nice, but I haven't yet found a solution.  I'm now running 12.1R4.7 and this MIB is still unavailable.

Contributor
junwbat
Posts: 32
Registered: ‎09-01-2011
0

Re: SNMP MIB Data for Security Policy Missing in 11.4R1.6

Is there a way to refresh the supported MIBs on a SRX?

Contributor
junwbat
Posts: 32
Registered: ‎09-01-2011
0

Re: SNMP MIB Data for Security Policy Missing in 11.4R1.6

Bumped - Hopefully we can get an answer on why they are missing. I looked in the docs and they should be available.

Contributor
junwbat
Posts: 32
Registered: ‎09-01-2011
0

Re: SNMP MIB Data for Security Policy Missing in 11.4R1.6

Found answer:

 

Juniper changed how policy SNMP lookups work with logical systems after 11.2. See this KB article: KB23155

The fix is to take your SNMP read community string and add "default@" in front of it. For example default@public. This is for the default logical system.

Copyright© 1999-2013 Juniper Networks, Inc. All rights reserved.