FortiNAC
NOTE: FortiNAC is now named FortiNAC-F. For post-9.4 articles, see FortiNAC-F. FortiNAC is a zero-trust network access solution that provides users with enhanced visibility into the Internet of Things (IoT) devices on their enterprise networks.
FortiKoala
Staff
Staff
Article Id 192724
Description
Differences Between SNMP and CLI Methods for L2/L3 Polling Cisco Devices

Scope
Version:   Network Sentry 7 & 8
Solution
Version:  Network Sentry 7 and 8

Network Sentry collects ARP information via L3 Polling.  When modeling Cisco devices, there are two methods available for polling:  SNMP and CLI.  There are advantages and disadvantages to each method.  

CLI (default method)
Advantage:  IP Address information is more accurate using this method.  ARP entries are timestamped which allows Network Sentry to determine which IP address is the most recent if duplicate entries exist.      
Disadvantage: Full read/write access is required.


SNMP
Advantage: Full read/write privileges are not required to collect L2 and L3 information.  Read only privileges are sufficient.
Disadvantage:  Duplicate ARP entries cannot be differentiated by time (SNMP mib does not provide an age for the entries). This inability to differentiate duplicate entries by time can lead to Network Sentry having inaccurate IP information.


To enable SNMP for L2/L3 Polling:

Navigate to Network Devices > Topology.
Click on the L3 Cisco device in the left panel and click the Element tab.
Click the Advanced checkbox.
Select the Use SNMP to read L2/L3 data from the device check box.
Click Save.

Contributors