Unknownt Alert Receive - Fortinet

Document ID : KB000125439
Last Modified Date : 14/02/2019
Show Technical Document Details
Issue:
A Fortinet device not yet Spectrum certified and discovered in Spectrum as GnSNMPDev is sending traps to Spectrum.
Some of these are failing with the message:
Unknown alert received from device RPPFWXXXXX of type GnSNMPDev. Device Time 2+18:08:40. (Trap type 1.3.6.1.2.1.15.6.2) Trap var bind data: OID: 1.3.6.1.2.1.1.3.0 Value: 23812084 OID: 1.3.6.1.6.3.1.1.4.1.0 Value: 1.3.6.1.2.1.15.0.2 OID: 1.3.6.1.2.1.15.3.1.7 Value: 169.254.4.6 OID: 1.3.6.1.2.1.15.3.1.14 Value: 6.3 OID: 1.3.6.1.2.1.15.3.1.2 Value: 1
Why?
Environment:
Spectrum 10.3 on any platform
Cause:
The AlertMap file to handle the trap type 1.3.6.1.2.1.15.6.2 and 1.3.6.1.2.1.15.6.1 is present under the folder:
<$SPECROOT>\SS\CsVendor\Ctron_SNMP_Rtr\BGP4_App  and when the trap arrives to Spectrum, probably this is not processed because the device was discovered as GnSNMPDev, resulting in an  "Unknown alert received from device RPPFWXXXXX of type GnSNMPDev..."


 
Resolution:
Copy the AlertMap from the <$SPECROOT>\SS\CsVendor\Ctron_SNMP_Rtr\BGP4_App into the <$SPECROOT>\Custom\Events folder, then open the VNM model -> SpectroSERVER Control and click on Update Event Configuration.