Dave Shield wrote:
> On 27 May 2012 08:46, Jan Willamowius <j...@willamowius.de> wrote:
> > The Unix implementation of the agent uses Net-SNMP and sets the OID as
> > type ASN_UNSIGNED. When I look at the GET response with Wireshark, it
> > decodes it as a "Gauge32" value. That made sense at first sight,
> > because according to RFC 1902 Unsigned32 and Gauge32 are the same.
> >
> > The Windows implementation is based on Windows' SnmpAPI.lib and sets
> > the OID as ASN_UNSIGNED32 and when I look at the GET response with
> > Wireshark, it decodes it as "Unsigned32". That looks even better to me.
> >
> > How come the 2 implementations produce different results on the wire ?
> 
> First question - are they actually different,
> or are they simply being reported differently?

They actually are slighly different.

> The Net-SNMP tools support a '-d' flag, to display the raw
> packet dumps.   Try sending a simple query to the two agents
> using this option, and compare the two dumps.
> 
> What do they look like?

>From Net-SNMP based agent: (decoded as Gauge32 by Wireshark)

Received 48 byte packet from UDP: [192.168.1.189]:161->[0.0.0.0]:54767
0000: 30 2E 02 01  01 04 06 70  75 62 6C 69  63 A2 21 02    0......public¢!.
0016: 04 7A CB 78  0E 02 01 00  02 01 00 30  13 30 11 06    .zËx.......0.0..
0032: 0C 2B 06 01  04 01 81 DA  22 0B 01 03  00 42 01 00    .+.....Ú"....B..

.1.3.6.1.4.1.27938.11.1.3.0 = Gauge32: 0

>From the Windows agent: (decoded as Unsigned32 by Wireshark)

Received 48 byte packet from UDP: [192.168.1.100]:161->[0.0.0.0]:40864
0000: 30 2E 02 01  01 04 06 70  75 62 6C 69  63 A2 21 02    0......public¢!.
0016: 04 6A 67 E6  37 02 01 00  02 01 00 30  13 30 11 06    .jgæ7......0.0..
0032: 0C 2B 06 01  04 01 81 DA  22 0B 01 03  00 47 01 00    .+.....Ú"....G..

.1.3.6.1.4.1.27938.11.1.3.0 = 0

As you can see, the packets are slighly different.

Regards,
Jan

-- 
Jan Willamowius, j...@willamowius.de, http://www.gnugk.org/

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
Net-snmp-users mailing list
Net-snmp-users@lists.sourceforge.net
Please see the following page to unsubscribe or change other options:
https://lists.sourceforge.net/lists/listinfo/net-snmp-users

Reply via email to