sk184379 - SNMPv3 monitoring fails on dplane while succeeding on mplane
SNMPv3 monitoring fails on dplane while succeeding on mplane
Product
Security Gateways
Version
R81.20, R82, R82.10
OS
Gaia
Last Modified
2026-05-26
Symptoms
- When MDPS is enabled and SNMP is configured to version 3 (SNMPv3), SNMP queries succeed on the Management Plane (mplane) but fail on the Data Plane (dplane).
Example:
[Expert@Host:mplane]# snmpwalk -v3 -l authPriv -u USER -a SHA512 -A PASSWORD -x AES256 -X PASSWORD localhost 1.3.6.1.2.1 |grep interface
HOST-RESOURCES-MIB::hrDeviceDescr.262145 = STRING: network interface lo
HOST-RESOURCES-MIB::hrDeviceDescr.262146 = STRING: network interface gre0
HOST-RESOURCES-MIB::hrDeviceDescr.262147 = STRING: network interface gretap0
HOST-RESOURCES-MIB::hrDeviceDescr.262148 = STRING: network interface erspan0
HOST-RESOURCES-MIB::hrDeviceDescr.262155 = STRING: network interface Sync
HOST-RESOURCES-MIB::hrDeviceDescr.262156 = STRING: network interface Mgmt
HOST-RESOURCES-MIB::hrSWRunParameters.21807 = STRING: "--color=auto interface"
[Expert@Host:mplane]# snmpwalk -v3 -l authPriv -u USER -a SHA512 -A PASSWORD -x AES256 -X PASSWORD -n dplane localhost 1.3.6.1.2.1 |grep interface |head -10
Timeout: No Response from localhost
Cause
The SNMP process is missing required bindings in the internal database.
The SNMP process is configured with only the following argument:
process:snmpd:arg:3 /etc/snmp/userDefinedSettings.conf
Instead of:
process:snmpd:arg:3 /etc/snmp/userDefinedSettings.conf,/etc/snmp/vsx-proxy/snmpd.vsx.proxy.conf
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R82.10 starting from Take 19
- Jumbo Hotfix Accumulator for R82 starting from Take 103
- Jumbo Hotfix Accumulator for R81.20 starting from Take 126
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General Status: Approved by TAC Date Created: 2026-01-04 Last Modified: 2026-05-26