RE: Third party walk gives error with snmpd(net-snmp) daemon

"Manish Gupta" <[email protected]>
Newsgroups gmane.network.net-snmp.user
Message-ID <[email protected]>
Dave,

Now I ran the single part of the command and following are the various
outputs, I am trying to describe the issue as much as possible. 

1. pkt dump of snmp daemon (snmpd -f -Le -d with other option) , this is the
last output

Connection from UDP: [10.60.50.116]:1858
Received SNMP packet(s) from UDP: [10.60.50.116]:1858
  GETBULK message, non-rep=0, max_rep=19
    -- IP-MIB::ip

Sending 506 bytes to UDP: [10.60.50.116]:1858
0000: 30 82 01 F6  02 01 01 04  06 70 75 62  6C 69 63 A2    0........public.
0016: 82 01 E7 02  02 13 92 02  01 00 02 01  00 30 82 01    .............0..
0032: D9 30 19 06  0D 2B 06 01  02 01 04 14  01 01 0A 3C    .0...+.........<
0048: 03 73 40 08  0A 3C 03 73  00 00 00 00  30 19 06 0D    .s@..<.s....0...
0064: 2B 06 01 02  01 04 14 01  01 7F 00 00  01 40 08 7F    +............@..
0080: 00 00 01 00  00 00 00 30  12 06 0D 2B  06 01 02 01    .......0...+....
0096: 04 14 01 02  0A 3C 03 73  02 01 02 30  12 06 0D 2B    .....<.s...0...+
0112: 06 01 02 01  04 14 01 02  7F 00 00 01  02 01 05 30    ...............0
0128: 19 06 0D 2B  06 01 02 01  04 14 01 03  0A 3C 03 73    ...+.........<.s
0144: 40 08 FF FF  00 00 00 00  00 00 30 19  06 0D 2B 06    @.........0...+.
0160: 01 02 01 04  14 01 03 7F  00 00 01 40  08 FF 00 00    ...........@....
0176: 00 00 00 00  00 30 12 06  0D 2B 06 01  02 01 04 14    .....0...+......
0192: 01 04 0A 3C  03 73 02 01  01 30 12 06  0D 2B 06 01    ...<.s...0...+..
0208: 02 01 04 14  01 04 7F 00  00 01 02 01  01 30 12 06    .............0..
0224: 0D 2B 06 01  02 01 04 14  01 05 0A 3C  03 73 02 01    .+.........<.s..
0240: FF 30 12 06  0D 2B 06 01  02 01 04 14  01 05 7F 00    .0...+..........
0256: 00 01 02 01  FF 30 19 06  0D 2B 06 01  02 01 04 15    .....0...+......
0272: 01 01 00 00  00 00 40 08  00 00 00 00  00 00 00 00    ......@.........
0288: 30 19 06 0D  2B 06 01 02  01 04 15 01  01 0A 3C 00    0...+.........<.
0304: 00 40 08 0A  3C 00 00 00  00 00 00 30  19 06 0D 2B    .@..<......0...+
0320: 06 01 02 01  04 15 01 01  0A 3C 00 01  40 08 0A 3C    .........<..@..<
0336: 00 01 00 00  00 00 30 19  06 0D 2B 06  01 02 01 04    ......0...+.....
0352: 15 01 01 0A  3C 00 08 40  08 0A 3C 00  08 00 00 00    ....<..@..<.....
0368: 00 30 1A 06  0E 2B 06 01  02 01 04 15  01 01 0A 3C    .0...+.........<
0384: 00 81 3D 40  08 0A 3C 00  BD 00 00 00  00 30 1A 06    ..=@..<......0..
0400: 0E 2B 06 01  02 01 04 15  01 01 0A 3C  00 81 62 40    .+.........<..b@
0416: 08 0A 3C 00  E2 00 00 00  00 30 19 06  0D 2B 06 01    ..<......0...+..
0432: 02 01 04 15  01 01 0A 3C  02 35 40 08  0A 3C 02 35    .......<.5@..<.5
0448: 00 00 00 00  30 19 06 0D  2B 06 01 02  01 04 15 01    ....0...+.......
0464: 01 0A 3C 03  6F 40 08 0A  3C 03 6F 00  00 00 00 30    ..<.o@..<.o....0
0480: 19 06 0D 2B  06 01 02 01  04 15 01 01  0A 3C 03 73    ...+.........<.s
0496: 40 08 0A 3C  03 73 00 00  00 00                       @..<.s....

2. Following is decode of communication of client and server from wireshark
(wireshark shows the error for the response packet as )

[Dissector bug, protocol SNMP: proto.c:1153: failed assertion "length == 4"]
Expert Info (Error/Malformed): proto.c:1153: failed assertion "length == 4"
Message: proto.c:1153: failed assertion "length == 4"
Severity level: Error
Group: Malformed


3. Debug output of the snmpwalk command which we ran.(sm_snmpwalk -c public
--fmt=walk -d -t 2000 10.60.3.115)

+++ getBulk(.1.3.6.1.2.1.2.2.1.15.5, 19) -->
   .1.3.6.1.2.1.2.2.1.16.1 = 344
   .1.3.6.1.2.1.2.2.1.16.2 = 53257191
   .1.3.6.1.2.1.2.2.1.16.3 = 0
   .1.3.6.1.2.1.2.2.1.16.4 = 0
   .1.3.6.1.2.1.2.2.1.16.5 = 2148359115
   .1.3.6.1.2.1.2.2.1.17.1 = 0
   .1.3.6.1.2.1.2.2.1.17.2 = 111649
   .1.3.6.1.2.1.2.2.1.17.3 = 0
   .1.3.6.1.2.1.2.2.1.17.4 = 0
   .1.3.6.1.2.1.2.2.1.17.5 = 7050854
   .1.3.6.1.2.1.2.2.1.18.1 = 4
   .1.3.6.1.2.1.2.2.1.18.2 = 3
   .1.3.6.1.2.1.2.2.1.18.3 = 0
   .1.3.6.1.2.1.2.2.1.18.4 = 0
   .1.3.6.1.2.1.2.2.1.18.5 = 0
   .1.3.6.1.2.1.2.2.1.19.1 = 0
   .1.3.6.1.2.1.2.2.1.19.2 = 0
   .1.3.6.1.2.1.2.2.1.19.3 = 0
   .1.3.6.1.2.1.2.2.1.19.4 = 0
+++ getBulk(.1.3.6.1.2.1.2.2.1.19.4, 19) -->
   .1.3.6.1.2.1.2.2.1.19.5 = 0
   .1.3.6.1.2.1.2.2.1.20.1 = 0
   .1.3.6.1.2.1.2.2.1.20.2 = 0
   .1.3.6.1.2.1.2.2.1.20.3 = 0
   .1.3.6.1.2.1.2.2.1.20.4 = 0
   .1.3.6.1.2.1.2.2.1.20.5 = 0
   .1.3.6.1.2.1.3.1.1.1.2.1.10.60.0.1 = 2
   .1.3.6.1.2.1.3.1.1.1.2.1.10.60.0.8 = 2
   .1.3.6.1.2.1.3.1.1.1.2.1.10.60.0.189 = 2
   .1.3.6.1.2.1.3.1.1.1.2.1.10.60.0.226 = 2
   .1.3.6.1.2.1.3.1.1.1.2.1.10.60.2.53 = 2
   .1.3.6.1.2.1.3.1.1.1.2.1.10.60.3.111 = 2
   .1.3.6.1.2.1.3.1.1.1.2.1.10.60.3.115 = 2
   .1.3.6.1.2.1.3.1.1.1.2.1.10.60.6.6 = 2
   .1.3.6.1.2.1.3.1.1.1.2.1.10.60.8.6 = 2
   .1.3.6.1.2.1.3.1.1.1.2.1.10.60.8.24 = 2
   .1.3.6.1.2.1.3.1.1.1.2.1.10.60.8.77 = 2
   .1.3.6.1.2.1.3.1.1.1.2.1.10.60.50.116 = 2
   .1.3.6.1.2.1.3.1.1.1.2.1.10.60.50.213 = 2
SNMP-N-EPARSER-Mangled or incorrect packet; parsing aborted and data
discarded


Here you can see the walk is not over and it gives the error of parsing
aborted. Let me know if you need any other information ?


Thanks,
Manish

-----Original Message-----
From: [email protected] [mailto:[email protected]] On
Behalf Of Dave Shield
Sent: Tuesday, August 04, 2009 8:00 AM
To: Manish Gupta
Cc: net-snmp-users
Subject: Re: Third party walk gives error with snmpd(net-snmp) daemon

2009/8/4 Manish Gupta <[email protected]>:
>                           we have a different
> snmp walk command from SMARTS group of tools and it gives the following
> error after running the walk as follows

> Saving MIB walk to file(s) '10.60.0.177.walk' '10.60.0.177.mimic'
'10.60.0.177.snap' ...

Do any of these files exist?
If so, what are the contents?


> SNMP-N-EPARSER-Mangled or incorrect packet;
>       parsing aborted and data discarded
>
>
> It seems the packet format is not correct, can you please give some
insight
> on this what can be the problem , is it the deamon or the snmp walk
command?

I have no idea - I've never used this particular suite of tools.

I'd suggest you try using a single-shot tool (equivalent to our "snmpget")
rather than a full SNMP walk, if they include such a thing.   See if there's
a way of turning on debugging, or a raw packet dump.

Failing that, try restarting the agent using
     snmpd -f -Le -d
             (plus any other necessary options), and run a single
query against it.
What does the packet dump look like?

Dave



------------------------------------------------------------------------------
Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
trial. Simplify your report design, integration and deployment - and focus on 
what you do best, core application coding. Discover what's new with 
Crystal Reports now.  http://p.sf.net/sfu/bobj-july
_______________________________________________
Net-snmp-users mailing list
[email protected]
Please see the following page to unsubscribe or change other options:
https://lists.sourceforge.net/lists/listinfo/net-snmp-users
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.