SNMPd can register from one keepalived only

Łukasz Margiela <[email protected]>
Newsgroups gmane.linux.keepalived.devel
Message-ID <CAKRdhp_sEbZ=eik9D7vBxhKaQxjuWuT0Hwd-fnMMk-RAMJ4XkA@mail.gmail.com>
Hi,

I'm struggling with a problem when I run multiple keepalived in separated
network namespaces. The first keepalived registers flawlessly and I can
query it without any problem, but when the second one starts I get tons of
errors like:

duplicate registration: MIB modules AgentX subagent 11, session 0xef45d0,
subsession 0xf07cd0 and AgentX subagent 15, session 0xf11540, subsession
0xf4f180 (oid .1.3.6.1.4.1.9586.100.5.3.4.1.26)

After that I still can snmpwalk on KEEPALIVED-MIB::vrrp and get
informations about the first one.

Note that it doesn't matter which of keepalived starts first. The one which
will start first, will get registered.


I'm starting my keepalived with:

keepalived -f /run/conf/keepalived.conf -D -x -n -l

(each network namespace has separated /run directory)



first keepalived.conf:
! Configuration File for keepalived

global_defs {
}

vrrp_instance vrf21 {
    version 3
    native_ipv6
    state BACKUP
    interface net
    use_vmac
    virtual_router_id 1
    priority 101
    advert_int 1
    preempt_delay 0
    enable_snmp_keepalived
    enable_snmp_checker
    enable_traps
    enable_snmp_rfcv3

    virtual_ipaddress {
        fe80::100:1/127
        2001:41d0:3::1/56
    }
    mcast_src_ip fe80::1588:1
    unicast_src_ip fe80::1588:1
}

second keepalived.conf:
! Configuration File for keepalived

global_defs {
}

vrrp_instance vrf22 {
    state BACKUP
    interface net
    use_vmac
    virtual_router_id 2
    priority 100
    advert_int 1
    preempt_delay 0
    enable_snmp_keepalived
    enable_snmp_checker
    enable_traps
    enable_snmp_rfcv3

    virtual_ipaddress {
        10.0.1.254/24
    }
    mcast_src_ip 10.0.1.254
    unicast_src_ip 10.0.1.254
}

snmpd.conf:
###############################################################################
#
# EXAMPLE.conf:
#   An example configuration file for configuring the Net-SNMP agent
('snmpd')
#   See the 'snmpd.conf(5)' man page for details
#
#  Some entries are deliberately commented out, and will need to be
explicitly activated
#
###############################################################################
#
#  AGENT BEHAVIOUR
#

#  Listen for connections from the local system only
#agentAddress  udp:127.0.0.1:161
#  Listen for connections on all interfaces (both IPv4 *and* IPv6)
agentAddress udp:161,udp6:[::1]:161



###############################################################################
#
#  SNMPv3 AUTHENTICATION
#
#  Note that these particular settings don't actually belong here.
#  They should be copied to the file /var/lib/snmp/snmpd.conf
#     and the passwords changed, before being uncommented in that file
*only*.
#  Then restart the agent

#  createUser authOnlyUser  MD5 "remember to change this password"
#  createUser authPrivUser  SHA "remember to change this one too"  DES
#  createUser internalUser  MD5 "this is only ever used internally, but
still change the password"

#  If you also change the usernames (which might be sensible),
#  then remember to update the other occurances in this example config file
to match.



###############################################################################
#
#  ACCESS CONTROL
#

                                                 #  system + hrSystem
groups only
view   systemonly  included   .1.3.6.1.2.1.3
view   systemonly  included   .1.3.6.1.2.1.25.1

                                                 #  Full access from the
local host
#rocommunity public  localhost
                                                 #  Default access to basic
system info
 rocommunity public
 rwcommunity private

                                                 #  Full access from an
example network
                                                 #     Adjust this network
address to match your local
                                                 #     settings, change the
community string,
                                                 #     and check the
'agentAddress' setting above
#rocommunity secret  10.0.0.0/16

                                                 #  Full read-only access
for SNMPv3
 rouser   authOnlyUser
                                                 #  Full write access for
encrypted requests
                                                 #     Remember to activate
the 'createUser' lines above
#rwuser   authPrivUser   priv

#  It's no longer typically necessary to use the full
'com2sec/group/access' configuration
#  r[ou]user and r[ow]community, together with suitable views, should cover
most requirements



###############################################################################
#
#  SYSTEM INFORMATION
#

#  Note that setting these values here, results in the corresponding MIB
objects being 'read-only'
#  See snmpd.conf(5) for more details
sysLocation    Sitting on the Dock of the Bay
sysContact     Me <[email protected]>
                                                 # Application + End-to-End
layers
sysServices    72


#
#  Process Monitoring
#
                               # At least one  'mountd' process
proc  mountd
                               # No more than 4 'ntalkd' processes - 0 is OK
proc  ntalkd    4
                               # At least one 'sendmail' process, but no
more than 10
proc  sendmail 10 1

#  Walk the UCD-SNMP-MIB::prTable to see the resulting output
#  Note that this table will be empty if there are no "proc" entries in the
snmpd.conf file


#
#  Disk Monitoring
#
                               # 10MBs required on root disk, 5% free on
/var, 10% free on all other disks
disk       /     10000
disk       /var  5%
includeAllDisks  10%

#  Walk the UCD-SNMP-MIB::dskTable to see the resulting output
#  Note that this table will be empty if there are no "disk" entries in the
snmpd.conf file


#
#  System Load
#
                               # Unacceptable 1-, 5-, and 15-minute load
averages
load   12 10 5

#  Walk the UCD-SNMP-MIB::laTable to see the resulting output
#  Note that this table *will* be populated, even without a "load" entry in
the snmpd.conf file



###############################################################################
#
#  ACTIVE MONITORING
#

trapcommunity public
                                    #   send SNMPv1  traps
#trapsink     localhost public
                                    #   send SNMPv2c traps
trap2sink    localhost:162
                                    #   send SNMPv2c INFORMs
#informsink   localhost public

#  Note that you typically only want *one* of these three lines
#  Uncommenting two (or all three) will result in multiple copies of each
notification.


#
#  Event MIB - automatically generate alerts
#
                                   # Remember to activate the 'createUser'
lines above
iquerySecName   internalUser
rouser          internalUser
                                   # generate traps on UCD error conditions
defaultMonitors          yes
                                   # generate traps on linkUp/Down
linkUpDownNotifications  yes



###############################################################################
#
#  EXTENDING THE AGENT
#

#
#  Arbitrary extension commands
#
 extend    test1   /bin/echo  Hello, world!
 extend-sh test2   echo Hello, world! ; echo Hi there ; exit 35
#extend-sh test3   /bin/sh /tmp/shtest

#  Note that this last entry requires the script '/tmp/shtest' to be
created first,
#    containing the same three shell commands, before the line is
uncommented

#  Walk the NET-SNMP-EXTEND-MIB tables (nsExtendConfigTable,
nsExtendOutput1Table
#     and nsExtendOutput2Table) to see the resulting output

#  Note that the "extend" directive supercedes the previous "exec" and "sh"
directives
#  However, walking the UCD-SNMP-MIB::extTable should still returns the
same output,
#     as well as the fuller results in the above tables.


#
#  "Pass-through" MIB extension command
#
#pass .1.3.6.1.4.1.8072.2.255  /bin/sh       PREFIX/local/passtest
#pass .1.3.6.1.4.1.8072.2.255  /usr/bin/perl PREFIX/local/passtest.pl

# Note that this requires one of the two 'passtest' scripts to be installed
first,
#    before the appropriate line is uncommented.
# These scripts can be found in the 'local' directory of the source
distribution,
#     and are not installed automatically.

#  Walk the NET-SNMP-PASS-MIB::netSnmpPassExamples subtree to see the
resulting output


#
#  AgentX Sub-agents
#
                                           #  Run as an AgentX master agent
 master          agentx
                                           #  Listen for network
connections (from localhost)
                                           #    rather than the default
named socket /var/agentx/master
#agentXSocket    tcp:localhost:705

------------------------------------------------------------------------------
What NetFlow Analyzer can do for you? Monitors network bandwidth and traffic
patterns at an interface-level. Reveals which users, apps, and protocols are 
consuming the most bandwidth. Provides multi-vendor support for NetFlow, 
J-Flow, sFlow and other flows. Make informed decisions using capacity planning
reports.http://sdm.link/zohodev2dev

_______________________________________________
Keepalived-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/keepalived-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.