This article explains how to enable SNMP monitoring on a Cisco Firepower Threat Defense (FTD) device managed by Firepower Management Center (FMC) for monitoring with Auvik.
Note: Changes made to an FMC Platform Settings Policy must be deployed before they take effect on the managed FTD devices.
Configure a Platform Settings Policy
- In FMC, navigate to Devices > Platform Settings.
- Determine whether a Platform Settings Policy is already assigned to the target FTD device.
- If no policy exists, click New Policy > Threat Defense Settings.
- If a policy already exists for the target FTD, proceed to the next step.
- Enter a name for the policy.
- Add the target FTD device or devices to the Selected Devices field.
- Save the policy.
The Platform Settings Policy will open with additional configuration options available in the navigation pane.
Configure SNMP
- Select SNMP from the left navigation menu.
- Enable SNMP Servers.
- Configure the SNMP settings:
- Select the appropriate SNMP version.
- For SNMPv2c, configure a read-only community string.
- For SNMPv3, configure the required authentication and privacy settings.
- Verify that the listening port is set to 161.
- Click Save.
Recommendation: Cisco recommends using SNMPv3 whenever possible because it provides authentication and encryption. If SNMPv2c is used, choose a unique community string and avoid common values such as "public".
Deploy the Changes
After saving the policy:
- Navigate to Deploy.
- Select the affected FTD device or devices.
- Click Deploy and wait for the deployment to complete successfully.
The SNMP configuration will not become active until the deployment finishes.
Verify Connectivity in Auvik
Once deployment is complete:
- Confirm that the SNMP credentials configured in Auvik match the settings configured in FMC.
- Verify that the Auvik collector can reach the FTD management interface.
- Ensure that any firewalls or access control policies allow SNMP traffic (UDP 161) between the collector and the FTD.
Note: After deployment, it may take longer than usual for SNMP data to appear in Auvik while the collector completes discovery and polling cycles.
Troubleshooting
If Auvik is unable to collect SNMP data from the FTD:
- Verify that the Platform Settings Policy was successfully deployed.
- Confirm the correct SNMP version is configured in both FMC and Auvik.
- Verify that the community string or SNMPv3 credentials match.
- Confirm that UDP port 161 is reachable from the Auvik collector.
- Review FMC deployment status and system health messages for any errors.
For additional troubleshooting information, refer to Cisco's Firepower SNMP documentation.
