Suppress SNMP Authentication Failure Timer

Beginning with FastIron release 09.0.00, a new CLI is introduced to avoid the flooding of SNMP authentication failure logging. A timer starts when an SNMP authentication fails. This timer keeps track of all the authentication attempts from the same IPv4 or IPv6 address. A syslog entry then gets generated after a configurable suppress time interval. If there are no matches within the configured time interval, the timer restarts with the next IPv4 or IPv6 address match.

The following syslog message is generated for an SNMP authentication failure.

SYSLOG: <14> Jul 2 08:52:49 SNMP: Auth. failure, intruder IP: 2::1, 1 event(s).

SYSLOG: <14> Jul 2 08:53:50 SNMP: Auth. failure, intruder IP: 10.198.136.154, 5 event(s).

The snmp-server log-suppress-timer <value> command is used to configure the suppress-timer. The suppress timer can be configured between 1 to 5 minutes and the default value is five minutes.

When the SNMP log suppress timer is configured, the following syslog message is displayed when the snmp authentication failure happens from the intruder ip.

SYSLOG: <14> Jul 2 08:49:09 SNMP: Auth. failure, intruder IP: 10.198.136.154, 1 event(s).

SYSLOG: <14> Jul 2 08:49:09 SNMP: Auth. Failure, intruder IP: 10.198.136.154, suppression started for threshold timer of <configured time> minutes.