If a device isn't authorized for SNMP monitoring, use the Discovery Troubleshooting page to identify and resolve the issue.
To authorize a device for SNMP monitoring, all four of the following requirements must be met:
- The device is managed
- The SNMP service is enabled
- SNMP is running and reachable on the device
- Valid SNMP credentials are configured
To begin troubleshooting, navigate to the device dashboard, hover over Discovery, and select Troubleshooting.
Step 1: Verify the device is managed
If the device is unmanaged, Auvik cannot collect data from it.
To manage the device:
- Click Re-enable Management.
- Change the management status from Unmanaged to Managed.
- Click Save.
Once the device is managed, continue to the next step.
Step 2: Verify the SNMP service is enabled
If the SNMP service is disabled, Auvik will not attempt to gather SNMP data from the device.
To enable the SNMP service:
- Click Enable SNMP Service.
- From the Enabled drop-down menu, select Yes, use this service to gather data.
- Click Save.
Verify the device is assigned to the SNMP service
If SNMP is enabled on the device but still appears disabled in Auvik, verify that the device is included in the SNMP service group.
- Click Add this device to the SNMP service group.
- In the Devices to use this service field, add the device by name or device type.
- Review any exclusions and remove any that apply to the device or device type.
- Click Save.
Once the SNMP service is enabled and the device is assigned to the service group, continue to the next step.
Step 3: Verify SNMP is running and reachable
Auvik must be able to communicate with the device using SNMP.
First, verify that:
- SNMP is enabled on the device
- The collector can reach the device over the network
- Firewalls or ACLs are not blocking SNMP traffic
- The device is listening on the expected SNMP port
If you're unsure how to enable SNMP on a device, refer to the device vendor's documentation or Auvik's device setup and configuration articles.
Configure custom SNMP ports
If the device uses a non-default SNMP port, configure the port in Auvik.
- Click Add a new custom port.
- From the Use Default Ports drop-down menu, select No – Custom Ports.
- Enter the required port number.
- To add additional ports, click the + icon.
- Click Save.
Once SNMP is running and reachable, continue to the next step.
Step 4: Verify valid SNMP credentials are configured
Auvik must have credentials that match the device's SNMP configuration.
- Click Add SNMP Credentials.
- Complete the credential form.
- When adding an entity for the credential, you can filter devices as needed.
SNMP v1/v2c
Enter the community string configured on the device.
SNMP v3
Enter:
- Username
- Authentication protocol
- Authentication passphrase
- Privacy protocol (if required)
- Privacy passphrase
- Click Save.
Troubleshoot SNMPv3 unauthorized-user alerts
You may see an alert such as:
Detected an unauthorized user attempting to access the SNMPv3 interface from x.x.x.x
This can occur even when the same SNMPv3 credentials work successfully on other devices. Credentials that are valid elsewhere may not be valid for the affected device or may be applied to the wrong devices.
Check the credential scope
Review the device filters assigned to the SNMPv3 credential. If the credential is scoped too broadly, Auvik may attempt to use it against devices that do not accept that username or security configuration.
Narrow the credential scope to the intended:
- Site
- Subnet
- Device
- Device type
- IP address range
Use specific filters where possible instead of applying one credential to unrelated devices.
Verify the SNMPv3 configuration
Confirm that the following settings match on both Auvik and the device:
- Username
- Security level
- Authentication protocol
- Authentication passphrase
- Privacy protocol
- Privacy passphrase
- Engine ID or context requirements, when applicable
- Source IP addresses permitted to poll the device
A mismatch in any of these values can cause the device to reject the request.
Check collectors and polling source IPs
If multiple collectors can reach the same device, verify which collector is polling it and whether each possible collector IP address is authorized on the device.
If only one collector should poll the device, assign the device or subnet to that collector where appropriate. Otherwise, authorize all possible polling source IP addresses on the device.
Remove duplicate or incorrect credentials
Review the SNMP credentials that apply to the affected device. Remove, disable, or exclude credentials that are obsolete, duplicated, or intended for other devices.
Auvik can try applicable credentials against devices until it finds the correct credential. Overly broad or overlapping credential scopes can therefore result in repeated authorization attempts or unauthorized-user messages.
Retry the credentials
After correcting the credential or its scope:
- Navigate to Discovery > Manage Credentials > SNMP Credentials.
- Select Retry SNMP Credentials, or edit and save the affected credential.
- Return to the device’s Discovery > Troubleshooting page.
- Confirm that the device becomes authorized.
Common causes of SNMP authorization failures
If authorization still fails, verify the following:
- Incorrect SNMP community string
- Incorrect SNMPv3 username
- Authentication protocol mismatch
- Authentication passphrase mismatch
- Privacy protocol mismatch
- Privacy passphrase mismatch
- Incorrect security level
- Engine ID or context mismatch
- SNMP is disabled on the device
- The device is not assigned to the SNMP service
- The collector’s source IP is not permitted
- Firewalls or access control lists are blocking UDP port 161
- Network routing prevents the collector from reaching the device
- An incorrect custom SNMP port is configured
- The wrong credential is being applied because of overlapping filters
- Multiple collectors are polling from unauthorized IP addresses
Test SNMP from the Auvik Collector
If the device remains unauthorized, test the connection directly from the Auvik Collector.
Use the collector’s SNMP troubleshooting commands to verify that:
- The collector can reach the device.
- The SNMPv3 username is accepted.
- The authentication and privacy settings are correct.
- The device returns SNMP data.
Testing directly from the collector can help distinguish between an incorrect credential, a network or ACL problem, and a device-side SNMP configuration issue.
Authorization complete
Once all four requirements are met, Auvik can successfully authenticate to the device using SNMP and begin collecting inventory, monitoring, and performance data.
