Hi list,

does anyone of you (or perhaps the CA people) know how Spectrum
handles snmp traps which contain "agent-addr 0.0.0.0" instead of
"agent-addr <trap-src-ip>"?

I think Spectrum simply does... nothing!

The question came up here because we did never generate any
trap-events from our Checkpoint FWs. We traced snmp traffic and
recognized the traps coming in with this 0.0.0.0 as agent-addr.
Spectrum didn't even generate events on VNM model for these traps...

Regarding this I wondered if there's any possibility to debug what
happens if a trap comes in:
- trap comes in
- showing detected model(handle)
- showing used Alertmap
- showing used EventDisp

...do you know if this would be possible?

Many thanks in advance!

Regards,
Marcel

---
To unsubscribe from spectrum, send email to [email protected] with the body: 
unsubscribe spectrum [email protected]

Reply via email to