APC and SNMP Attack

jpro
Mega Contributor

When discovery encounters our APC UPS devices it detects and adds the device. Then the administrators call due to the "Unauthorized" SNMP access attempts. I can see the credentials in the affinity table but it appears that each time there are five additional attempts during the discovery of each APC unit (and generating an e-mail to the admins for each).

I am not sure how to debug this issue and locate the cause. Is it possible that the sensor/probe has a portion that is not using the affinity table? The IP addresses are static so I understand during the first scan but thought subsequent scans would avoid the unauthorized attempts.

Any suggestions would be great.

Jim

12 REPLIES 12

jrmckins
Kilo Expert

Was this ever fixed? I'm on Paris and am hitting it. Hard to believe it's been around (NINE) years.

Lakshmi Prabha
Giga Expert

I am facing the same issue. Is this fixed? I'm on ROME and facing the same issue? Please advice.

Madhava B
Tera Contributor

We encountered same issue with our Client. Finally we found that in APC UPS devices, MID Servers IPs needs to be white listed using x.x.x.255 to allow multiple MID Servers to be allowed to hit UPS devices. Also, need to configure SNMP V3 credentials instead of V1. Please try this, you can also involve UPS Support for this.

 

Let me know if your issue resolved with this.