SNMPv3 Trap接收器配置问题:Python脚本无法处理SNMPv3陷阱
问题:SNMPv3 Trap可被Python脚本接收但无法处理
当前使用Python配置SNMPv3 Trap接收器,SNMPv1陷阱能正常接收处理,但SNMPv3陷阱虽被receiveSNMPTraps.py接收却无法解析处理。已尝试调整加密/认证口令及协议、添加Engine ID和上下文,问题仍未解决,寻求可行的排查思路与解决建议。
相关配置文件(EXAMPLE-trap.conf)
# # EXAMPLE-trap.conf: # An example configuration file for configuring the Net-SNMP snmptrapd agent. # ############################################################################### # # This file is intended to only be an example. # When the snmptrapd agent starts up, this is where it will look for it. # # All lines beginning with a '#' are comments and are intended for you # to read. All other lines are configuration commands for the agent. # # PLEASE: read the snmptrapd.conf(5) manual page as well! # # Create SNMPv3 user createUser -e 0x5072697374696E65 rberbato SHA "AuthPass" AES "EncPass" snmpTrapdAddr udp:0.0.0.0:1162,udp6:[::]:1162 authUser log,execute,net rberbato authCommunity log,execute,net PUBLIC #authCommunity log,execute,net public # ## send mail when get any events traphandle default /home/rberbato/Pristine/receiveSNMPTraps.py #traphandle default /home/rberbato/Pristine/receiveSNMPTrapsv3.py # ## send mail when get linkDown #traphandle .1.3.6.1.6.3.1.1.5.3 /usr/bin/traptoemail -s smtp.example.org foobar@example.org #doNotLogTraps yes #doNotFork yes #disableAuthorization yes
Python脚本(receiveSNMPTraps.py)
# Python SNMP trap receiver from pysnmp.entity import engine, config from pysnmp.carrier.asyncore.dgram import udp from pysnmp.entity.rfc3413 import ntfrcv import logging snmpEngine = engine.SnmpEngine() user = 'rberbato' AuthPass = 'AuthPass' EncPass = 'EncPass' TrapAgentAddress='0.0.0.0'; # Trap listener address Port=162; # Trap listener port logging.basicConfig(filename='received_traps.log', filemode='w', format='%(asctime)s - %(message)s', level=logging.INFO) logging.info("Agent is listening SNMP Trap on "+TrapAgentAddress+" , Port : " +str(Port)) logging.info('--------------------------------------------------------------------------') print("Agent is listening SNMP Trap on "+TrapAgentAddress+" , Port : " +str(Port)) config.addTransport( snmpEngine, udp.domainName + (1,), udp.UdpTransport().openServerMode((TrapAgentAddress, Port)) ) # Configure community here config.addV1System(snmpEngine, 'PUBLIC', 'PUBLIC') # Configure SNMPv3 user config.addV3User( snmpEngine, user, config.usmHMACSHAAuthProtocol, AuthPass, config.usmAesCfb128Protocol, EncPass, ) def cbFun(snmpEngine, stateReference, contextEngineId, contextName, varBinds, cbCtx): print("Received new Trap message") logging.info("Received new Trap message") for name, val in varBinds: logging.info('%s = %s' % (name.prettyPrint(), val.prettyPrint())) print('%s = %s' % (name.prettyPrint(), val.prettyPrint())) logging.info("==== End of Incoming Trap ====") ntfrcv.NotificationReceiver(snmpEngine, cbFun) snmpEngine.transportDispatcher.jobStarted(1) try: snmpEngine.transportDispatcher.runDispatcher() except: snmpEngine.transportDispatcher.closeDispatcher() raise
解决思路与建议
- 对齐Engine ID配置:在Python脚本的
config.addV3User中,添加与trap.conf一致的Engine ID(0x5072697374696E65),转换为字节格式传入,比如engineID=b'\x50\x72\x69\x73\x74\x69\x6E\x65',否则USM用户匹配会失败。 - 统一监听端口:
trap.conf中snmptrapd监听1162端口,而Python脚本监听162端口。需确认陷阱发送目标端口,要么修改脚本监听1162,要么调整snmptrapd转发配置,避免端口不匹配导致的参数丢失。 - 启用pysnmp调试日志:在脚本开头添加调试代码,查看SNMPv3消息的认证、加密环节细节,定位失败原因:
from pysnmp import debug debug.setLogger(debug.Debug('all')) - 严格匹配USM参数:确认陷阱发送端的认证协议(SHA)、加密协议(AES-128)、口令(AuthPass/EncPass)与脚本完全一致,注意大小写、特殊字符的一致性。
- 验证上下文参数:在回调函数
cbFun中打印contextEngineId和contextName,确认与发送端的配置匹配;若发送端指定了上下文,需在脚本的用户配置中绑定对应上下文。 - 排除snmptrapd转发干扰:临时注释
trap.conf中的traphandle配置,直接用Python脚本监听陷阱端口,测试是否能直接处理SNMPv3陷阱,排除转发环节的参数损坏问题。
内容的提问来源于stack exchange,提问作者Rilind I. Berbatovci
相关产品推荐
相关产品推荐

