SNMP sysUpTime OID 在"显示系统信息"中不会返回与系统正常运行时间相同的时间值。

SNMP sysUpTime OID 在"显示系统信息"中不会返回与系统正常运行时间相同的时间值。

3785
Created On 11/12/20 08:44 AM - Last Modified 11/29/23 03:44 AM


Symptom


在帕洛阿尔托网络防火墙上, SNMP 系统UpTime(1.3.6.1.2.1.1.3) OID 在"显示系统信息"中不会返回与系统正常运行时间相同的时间值。
 
admin@Lab-FW> show system info

hostname: Lab-FW
ip-address: 10.1.1.1
public-ip-address: unknown
netmask: 255.255.255.0
default-gateway: 10.1.1.254
ip-assignment: static
ipv6-address: unknown
ipv6-link-local-address: fe80::a66:1fff:fe02:1eb3/64
ipv6-default-gateway:
mac-address: 08:66:1f:02:1e:b3
time: Thu Nov 12 00:12:29 2020
uptime: 8 days, 1:56:55
family: 3200
model: PA-3260
serial: 016xxxxxxxxx
cloud-mode: non-cloud
sw-version: 8.1.15-h3
global-protect-client-package-version: 5.1.5
app-version: 8320-6305
app-release-date: 2020/09/15 11:51:02 PDT
av-version: 0
av-release-date:
threat-version: 8320-6305
threat-release-date: 2020/09/15 11:51:02 PDT
wf-private-version: 0
wf-private-release-date: unknown
url-db: paloaltonetworks
wildfire-version: 0
wildfire-release-date:
url-filtering-version: 0000.00.00.000
global-protect-datafile-version: unknown
global-protect-datafile-release-date: unknown
global-protect-clientless-vpn-version: 88-203
global-protect-clientless-vpn-release-date:
logdb-version: 8.1.8
platform-family: 3200
vpn-disable-mode: off
multi-vsys: off
operational-mode: normal
device-certificate-status: None

admin@Lab-FW>
 
user@linux->  snmpwalk -v 2c -c public 10.1.1.1 sysUpTime
DISMAN-EVENT-MIB::sysUpTimeInstance = Timeticks: (69512883) 8 days, 1:05:28.83

 


Environment


帕洛阿尔托网络防火墙监控 SNMP

Cause


  • sysUpTime 是一个定义 OID 为"自系统网络管理部分上次重新初始化以来的时间(以百分之一秒为百分之一秒)" 的标准。 这意味着此值不等于系统正常运行时间,但等于 snmp 进程正常运行时间。(rfc3418)
  • 您可以 firewall 通过小时系统更新时间(1.3.6.1.2.1.1.25.1.1.0)获得实际系统正常运行时间

 


Resolution


  • 预期系统正常运行时间值与系统正常运行时间不同
  • 重新启动 snmpd 进程时,将重置 sysUpTime。
    admin@Lab-FW> debug software restart process snmpd
    
    Process snmpd was restarted by user admin
    admin@Lab-FW>
    !! before restart snmpd process
    user@linux->  snmpwalk -v 2c -c public 10.1.1.1 sysUpTime
    DISMAN-EVENT-MIB::sysUpTimeInstance = Timeticks: (69586212) 8 days, 1:17:42.12
    
    !! after restart snmpd process
    user@linux->  snmpwalk -v 2c -c public 10.1.1.1 sysUpTime
    DISMAN-EVENT-MIB::sysUpTimeInstance = Timeticks: (555) 0:00:05.55
    
    [~]
    user@linux->  snmpwalk -v 2c -c public 10.1.1.1 sysUpTime
    DISMAN-EVENT-MIB::sysUpTimeInstance = Timeticks: (1561) 0:00:15.6
    
  • 您可以 firewall 通过小时系统更新时间(1.3.6.1.2.1.1.25.1.1.0)获得实际系统正常运行时间
    admin@Lab-FW> show system info | match uptime
    uptime: 8 days, 2:19:12
    admin@Lab-FW>
    user@linux->  snmpwalk -v 2c -c public 10.1.1.1 1.3.6.1.2.1.25.1.1.0
    HOST-RESOURCES-MIB::hrSystemUptime.0 = Timeticks: (69955383) 8 days, 2:19:13.83

 


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HBdZCAW&lang=zh_CN&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language