No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search

Reminder

To have a better experience, please upgrade your IE browser.

upgrade

S12700 V200R013C00 Log Reference

This document provides the explanations, causes, and recommended actions of logs on the product.
Rate and give feedback:
Huawei uses machine translation combined with human proofreading to translate this document to different languages in order to help you better understand the content of this document. Note: Even the most advanced machine translation cannot match the quality of professional translators. Huawei shall not bear any responsibility for translation accuracy and it is recommended that you refer to the English document (a link for which has been provided).
SNMP

SNMP

SNMP/6/SNMP_CNFM_CHANGEUDPORT

Message

SNMP/6/SNMP_CNFM_CHANGEUDPORT: When being asked whether to execute the command "[command]", the user chose [Y/N].

Description

The user chose yes or no when being asked whether to execute a command.

Parameters

Parameter Name Parameter Meaning
[command] The command snmp-agent udp-port is executed
[Y/N] Whether to execute a command or not

Possible Causes

The user confirmed whether execute a command or not.

Procedure

  1. The log is informational only, and no action is required.

SNMP/6/CNFM_VERSION_DISABLE

Message

SNMP/6/CNFM_VERSION_DISABLE:The user chose [Y/N] when deciding whether to disable all SNMP versions.

Description

The user decided whether to disable all SNMP versions.

Parameters

Parameter Name Parameter Meaning
[Y/N] Indicates the character input by the user to confirm the action.
  • Indicates that all SNMP versions need be disabled.
  • Indicates that SNMP versions need not be all disabled.

Possible Causes

The user need decide whether to disable all SNMP versions before the command was performed.

Procedure

  1. This log message is informational only, and no action is required.

SNMP/4/SNMP_IPLOCK

Message

SNMP/4/SNMP_IPLOCK: The source IP was locked because of the failure of login through SNMP.(SourceIP=[STRING], VPN=[STRING])

Description

The source IP address was locked due to an SNMP login failure.

Parameters

Parameter Name Parameter Meaning
SourceIP Source IP address

VPN

VPN instance name

Possible Causes

Authentication failed when the NMS attempted to log in to a device. To prevent malicious attacks and brute force attacks, the function to lock the source IP address in the case of an SNMP login failure is enabled by default. This function cannot be disabled. With this function, if a user that attempts to log in to a device through SNMP fails to be authenticated, the IP address of the user is locked for a period of time. In this period, the user cannot log in to the device even if the correct user name and password are entered. The locking period is 8s for the first login failure. It is increased to 16s, 32s, and 5 min, respectively, for the second and subsequent login failures. When the locking period reaches 5 min and the login fails again, the locking period starts from 8s again in a cyclic mode.

Procedure

  1. Check the SNMP version used by the NMS corresponding to the source IP address. If the version is SNMPv1/SNMPv2c, check whether the read/write community name is correct. If the version is SNMPv3, check whether the user name or password is correct.
  2. Check whether the source IP address in the IP address list is valid.

SNMP/4/SNMP_IPLOCKSTAT

Message

SNMP/4/SNMP_IPLOCKSTAT:In the last 5 minutes, [ULONG] IP addresses were locked. (IPList=[STRING])

Description

IP addresses that had been locked in the last 5 minutes were recorded in combined mode.

Parameters

Parameter Name Parameter Meaning
[ULONG] Number of locked IP addresses.
IPList List of locked IP addresses. If one log cannot display all the locked IP addresses, the IP addresses are displayed in multiple logs.

Possible Causes

If there are already three locked IP addresses, the system does not separately generate any new locking log for each newly locked IP address. Instead, the system combines locking logs every 5 minutes and records the IP addresses locked within the 5-minute period.

Procedure

  1. Check the SNMP version used by the NMS corresponding to the source IP address. If the version is SNMPv1/SNMPv2c, check whether the read/write community name is correct. If the version is SNMPv3, check whether the user name or password is correct.
  2. Check whether the source IP address in the IP address list is valid.

SNMP/4/SNMP_IPUNLOCK

Message

SNMP/4/SNMP_IPUNLOCK: The source IP was unlocked.(SourceIP=[STRING], VPN=[STRING])

Description

The locked user who has failed to be authenticated was deleted from the locked user list.

Parameters

Parameter Name Parameter Meaning
SourceIP Source IP address

VPN

VPN instance name

Possible Causes

The locked user who has failed to be authenticated logged in to the system successfully.

The lockout period expired.

Procedure

  1. This log is informational only, and no action is required.

SNMP/4/SNMP_IPUNLOCKSTAT

Message

SNMP/4/SNMP_IPUNLOCKSTAT:In the last 5 minutes, [ULONG] IP addresses were unlocked. (IPList=[STRING])

Description

IP addresses that had been unlocked in the last 5 minutes were recorded in combined mode.

Parameters

Parameter Name Parameter Meaning
[ULONG] Number of unlocked IP addresses.
IPList List of unlocked IP addresses. If one log cannot display all the unlocked IP addresses, the IP addresses are displayed in multiple logs.

Possible Causes

If there are already three unlocked IP addresses, the system does not separately generate any new unlocking log for each newly unlocked IP address. Instead, the system combines unlocking logs every 5 minutes and records the IP addresses unlocked within the 5-minute period.

Procedure

  1. This log is informational only, and no action is required.

SNMP/4/SNMP_LOCK_FULL

Message

SNMP/4/SNMP_LOCK_FULL: SNMP lock queue has been full.

Description

The list table for locked users who failed to be authenticated overflowed.

Parameters

Parameter Name Parameter Meaning
None. None.

Possible Causes

A great number of users who failed to be authenticated accessed the device simultaneously within 5 minutes.

Procedure

  1. Check whether locked unauthorized users have attack source information. If they have attack source information, filter out the information using a firewall.

SNMP/4/SNMP_ALLUNLOCK

Message

SNMP/4/SNMP_ALLUNLOCK: All locks are unlocked.

Description

The locked users who were failed to be authenticated were unlocked.

Parameters

Parameter Name Parameter Meaning
None None

Possible Causes

Information about locked users was deleted.

Procedure

  1. The log is informational only, and no action is required.

SNMP/4/SNMP_MIB_SET

Message

SNMP/4/SNMP_MIB_SET:MIB node set. (UserName=[STRING], SourceIP=[STRING], Version=[STRING], RequestId=[ULONG], [STRING], VPN=[STRING])

Description

The MIB object was set.

Parameters

Parameter Name Parameter Meaning
UserName
Indicates the name of user.
  • For SNMPv1 and SNMPv2c, if a community alias is not configured, UserName is a community in cipher text. If a community alias is configured, UserName is the community alias.
  • For SNMPv3, UserName is a user security mode (USM) user name in cipher text.
SourceIP Indicates the source IP address.
Version Indicates the version.
RequestId Indicates the ID of a request.
[STRING]

Indicates OID and value of a node in a Set request. If the node is a password node, the value is displayed as ******.

If a Set request contains many nodes and the information about these nodes cannot be completely displayed in one log, the information is displayed in multiple logs.

If the length of a node's OID exceeds 512 bytes or the total length of a node's OID and value exceeds 1024 bytes, the last part is displayed as an ellipsis (…).

VPN

Indicates the name of a VPN instance.

Possible Causes

The information about the SET operation on a MIB object was recorded into the log.

Procedure

  • This log message is informational only, and no action is required.

SNMP/4/SNMP_MIB_SET_FAILED

Message

SNMP/4/SNMP_MIB_SET_FAILED:MIB node set failure. (UserName=[STRING], SourceIP=[STRING], Version=[STRING], RequestId=[ULONG], ErrorStatus=[ULONG], ErrorIndex=[ULONG], [STRING], VPN=[STRING])

Description

The MIB object was set failed.

Parameters

Parameter Name Parameter Meaning
UserName Indicates the name of user.
SourceIP Indicates the source IP address.
Version Indicates the version.
RequestId Indicates the ID of a request.
ErrorStatus Indicates error status, including:
  • 0: noError
  • 1: tooBig
  • 2: noSuchName
  • 3: badValue
  • 4: readOnly
  • 5: genError
  • 6: noAccess
  • 7: wrongType
  • 8: wrongLength
  • 9: wrongEncoding
  • 10: wrongValue
  • 11: noCreation
  • 12: inconsistentValue
  • 13: resourceUnavailable
  • 14: commitFailed
  • 15: undoFailed
  • 16: authorizationError
  • 17: notWritable
  • 18: inconsistentName
ErrorIndex Indicates the index of a variable that fails to be set. This log records all variables that need to be set by the NMS. For example, if the fifth variable fails to be set, the value of ErrorIndex is 5.
[STRING]

Indicates OID and value of a node in a Set request. If the node is a password node, the value is displayed as ******.

If a Set request contains many nodes and the information about these nodes cannot be completely displayed in one log, the information is displayed in multiple logs.

If the length of a node's OID exceeds 512 bytes or the total length of a node's OID and value exceeds 1024 bytes, the last part is displayed as an ellipsis (…).

VPN

Indicates the name of a VPN instance.

Possible Causes

The information about the SET operation failed on a MIB object was recorded into the log.

Procedure

  • Determine the cause of the error based on the ErrorStatus field in the log.
  • Locate the error node based on the ErrorIndex field in the log.
  • Determine the cause of the failure to set the node according to the preceding information, and then perform the setting operation again.
  • End.

SNMP/4/SNMP_FAIL

Message

SNMP/4/SNMP_FAIL:Failed to login through SNMP. (Ip=[STRING], Times=[ULONG], Reason=[STRING], VPN=[STRING])

Description

A user failed to log in using SNMP, and the IP address and number of login attempts of the user were recorded.

Parameters

Parameter Name Parameter Meaning
Ip Source IP address
Times Number of login attempts
Reason Reason of the login failure
VPN Name of a VPN instance

Possible Causes

Possible causes are as follows:

  • 1. The SNMP version was incorrect.
  • 2. SNMP messages were over-sized.
  • 3. Messages failed to be added to the message list.
  • 4. A PDU decoding error occurred.
  • 5. The community was incorrect.
  • 6. The ACL filter function was faulty.
  • 7. The value of contextname was incorrect.
  • 8. Authorization failed
  • 9. Access denied

Procedure

  • 1. The SNMP version was incorrect.

    Run the snmp-agent sys-info command to change the SNMP version.

  • 2. SNMP messages were over-sized.

    Run the snmp-agent packet max-size command to increase the size of SNMP messages that can be sent and received.

  • 3. Messages failed to be added to the message list.

    Decrease the rate of sending NMS request messages.

  • 4. A PDU decoding error occurred.

    Change the engine ID for NMS request messages.

  • 5. The community was incorrect.

    Run the snmp-agent community command to configure a correct community.

  • 6. The ACL filter function was faulty.

    Run the snmp-agent acl command to modify the SNMP ACL(This command is supported in V200R005 and later versions).

  • 7. The value of contextname was incorrect.

    Leave contextname empty or enter a hyphen (-) for it.

  • 8: The authorization failed.

    Check whether the SNMP community name or user permissions are correct. If not, run the snmp-agent community or snmp-agent usm-user command to correct the community name or user permissions.

  • 9: The access is denied.

    Check whether the device configurations in the SNMP view are correct and run the snmp-agent mib-view command to reconfigure information in the MIB view.

SNMP/6/TRAPCMDRECORD_YES

Message

SNMP/6/TRAPCMDRECORD_YES:When being asked whether to commit the command "[STRING]", the user chose Y.

Description

The user chose Y when the system prompted the user to confirm whether to execute a global SNMP trap command.

Parameters

Parameter Name Parameter Meaning
STRING Indicates the command that needs to be confirmed by the user.

Possible Causes

The user chose Y when the system prompted the user to confirm whether to execute a global SNMP trap command.

Procedure

  1. This log message is informational only, and no action is required.

SNMP/6/TRAPCMDRECORD_NO

Message

SNMP/6/TRAPCMDRECORD_NO:When being asked whether to commit the command "[STRING]", the user chose N.

Description

The user chose N when the system prompted the user to confirm whether to execute a global SNMP trap command.

Parameters

Parameter Name Parameter Meaning
STRING Indicates the command that needs to be confirmed by the user.

Possible Causes

The user chose N when the system prompted the user to confirm whether to execute a global SNMP trap command.

Procedure

  1. This log message is informational only, and no action is required.
Translation
Download
Updated: 2019-04-09

Document ID: EDOC1100065665

Views: 6224

Downloads: 15

Average rating:
This Document Applies to these Products
Related Documents
Related Version
Share
Previous Next