snmp
: Manage the Net-SNMP and Net-SNMP trap daemon package, service, and configuration.snmp::client
: Manage the Net-SNMP client package and configuration.
snmp::snmpv3_user
: Creates a SNMPv3 user with authentication and encryption paswords.
snmp::snmpv3_usm_hash
: snmpv3_usm_hash.rb --- Calculate SNMPv3 USM hash for a passphrase
Manage the Net-SNMP and Net-SNMP trap daemon package, service, and configuration.
class { 'snmp':
com2sec => [ 'notConfigUser default PassW0rd' ],
manage_client => true,
}
# Only configure and run the snmptrap daemon:
class { 'snmp':
ro_community => 'SeCrEt',
service_ensure => 'stopped',
trap_service_ensure => 'running',
trap_handlers => [
'default /usr/bin/perl /usr/bin/traptoemail [email protected]',
'IF-MIB::linkDown /home/nba/bin/traps down',
],
}
The following parameters are available in the snmp
class:
agentaddress
snmptrapdaddr
ro_community
ro_community6
rw_community
rw_community6
ro_network
ro_network6
rw_network
rw_network6
contact
location
sysname
services
com2sec
com2sec6
groups
views
accesses
dlmod
extends
pass
pass_persist
snmpd_config
disable_authorization
do_not_log_traps
do_not_log_tcpwrappers
trap_handlers
trap_forwards
snmptrapd_config
manage_client
manage_snmptrapd
snmp_config
ensure
autoupgrade
package_name
snmptrapd_package_name
snmpd_options
sysconfig
trap_sysconfig
trap_service_config
service_config
service_config_perms
service_config_dir_path
service_config_dir_owner
service_config_dir_group
service_config_dir_perms
service_ensure
service_name
service_enable
service_hasstatus
service_hasrestart
snmptrapd_options
trap_service_ensure
trap_service_name
trap_service_enable
trap_service_hasstatus
trap_service_hasrestart
openmanage_enable
master
agentx_perms
agentx_ping_interval
agentx_socket
agentx_timeout
agentx_retries
snmpv2_enable
var_net_snmp
varnetsnmp_perms
varnetsnmp_owner
varnetsnmp_group
Data type: Array[String[1]]
An array of addresses, on which snmpd will listen for queries.
Default value: ['udp:127.0.0.1:161', 'udp6:[::1]:161']
Data type: Array[String[1]]
An array of addresses, on which snmptrapd will listen to receive incoming SNMP notifications.
Default value: ['udp:127.0.0.1:162', 'udp6:[::1]:162']
Data type: Variant[Undef, String[1], Array[String[1]]]
Read-only (RO) community string or array for agent and snmptrap daemon.
Default value: 'public'
Data type: Variant[Undef, String[1], Array[String[1]]]
Read-only (RO) community string or array for IPv6 agent.
Default value: 'public'
Data type: Variant[Undef, String[1], Array[String[1]]]
Read-write (RW) community string or array agent.
Default value: undef
Data type: Variant[Undef, String[1], Array[String[1]]]
Read-write (RW) community string or array for IPv6 agent.
Default value: undef
Data type: Variant[Array, Stdlib::IP::Address::V4, Stdlib::IP::Address::V4::CIDR]
Network that is allowed to RO query the daemon. Can be string or array.
Default value: '127.0.0.1'
Data type: Variant[Array, Stdlib::IP::Address::V6, Stdlib::IP::Address::V6::CIDR]
Network that is allowed to RO query the daemon via IPv6. Can be string or array.
Default value: '::1'
Data type: Variant[Array, Stdlib::IP::Address::V4, Stdlib::IP::Address::V4::CIDR]
Network that is allowed to RW query the daemon. Can be string or array.
Default value: '127.0.0.1'
Data type: Variant[Array, Stdlib::IP::Address::V6, Stdlib::IP::Address::V6::CIDR]
Network that is allowed to RW query the daemon via IPv6. Can be string or array.
Default value: '::1'
Data type: String[1]
Responsible person for the SNMP system.
Default value: 'Unknown'
Data type: String[1]
Location of the SNMP system.
Default value: 'Unknown'
Data type: String[1]
Name of the system (hostname).
Default value: $facts['networking']['fqdn']
Data type: Integer
For a host system, a good value is 72 (application + end-to-end layers).
Default value: 72
Data type: Array[String[1]]
An array of VACM com2sec mappings. Must provide SECNAME, SOURCE and COMMUNITY. See http://www.net-snmp.org/docs/man/snmpd.conf.html#lbAL for details.
Default value: ['notConfigUser default public']
Data type: Array[String[1]]
An array of VACM com2sec6 mappings. Must provide SECNAME, SOURCE and COMMUNITY. See http://www.net-snmp.org/docs/man/snmpd.conf.html#lbAL for details.
Default value: ['notConfigUser default public']
Data type: Array[String[1]]
An array of VACM group mappings. Must provide GROUP, <v1|v2c|usm|tsm|ksm>, SECNAME. See http://www.net-snmp.org/docs/man/snmpd.conf.html#lbAL for details.
Default value: [ 'notConfigGroup v1 notConfigUser', 'notConfigGroup v2c notConfigUser', ]
Data type: Array[String[1]]
An array of views that are available to query. Must provide VNAME, TYPE, OID, and [MASK]. See http://www.net-snmp.org/docs/man/snmpd.conf.html#lbAL for details.
Default value: [ 'systemview included .1.3.6.1.2.1.1', 'systemview included .1.3.6.1.2.1.25.1.1', ]
Data type: Array[String[1]]
An array of access controls that are available to query. Must provide GROUP, CONTEXT, <any|v1|v2c|usm|tsm|ksm>, LEVEL, PREFX, READ, WRITE, and NOTIFY. See http://www.net-snmp.org/docs/man/snmpd.conf.html#lbAL for details.
Default value: [ 'notConfigGroup "" any noauth exact systemview none none', ]
Data type: Optional[Array[String[1]]]
Array of dlmod lines to add to the snmpd.conf file. Must provide NAME and PATH (ex. "cmaX /usr/lib64/libcmaX64.so"). See http://www.net-snmp.org/docs/man/snmpd.conf.html#lbBD for details.
Default value: undef
Data type: Optional[Array[String[1]]]
Array of extend lines to add to the snmpd.conf file. Must provide NAME, PROG and ARG. See http://www.net-snmp.org/docs/man/snmpd.conf.html#lbBA for details.
Default value: undef
Data type: Optional[Array[String[1]]]
Array of pass lines to add to the snmpd.conf file. Must provide MIBOID and PROG. See http://www.net-snmp.org/docs/man/snmpd.conf.html#lbBB for details.
Default value: undef
Data type: Optional[Array[String[1]]]
Array of pass_persist lines to add to the snmpd.conf file. Must provide MIBOID and PROG. See http://www.net-snmp.org/docs/man/snmpd.conf.html#lbBB for details.
Default value: undef
Data type: Optional[Array[String[1]]]
Safety valve. Array of lines to add to the snmpd.conf file. See http://www.net-snmp.org/docs/man/snmpd.conf.html for all options.
Default value: undef
Data type: Enum['yes','no']
Disable all access control checks.
Default value: 'no'
Data type: Enum['yes','no']
Disable the logging of notifications altogether.
Default value: 'no'
Data type: Enum['yes','no']
Disable the logging of tcpwrappers messages, e.g. "Connection from UDP: " messages in syslog.
Default value: 'no'
Data type: Optional[Array[String[1]]]
An array of programs to invoke on receipt of traps. Must provide OID and PROGRAM (ex. "IF-MIB::linkDown /bin/traps down"). See http://www.net-snmp.org/docs/man/snmptrapd.conf.html#lbAI for details.
Default value: undef
Data type: Optional[Array[String[1]]]
An array of destinations to send to on receipt of traps. Must provide OID and DESTINATION (ex. "IF-MIB::linkUp udp:1.2.3.5:162"). See http://www.net-snmp.org/docs/man/snmptrapd.conf.html#lbAI for details.
Default value: undef
Data type: Optional[Array[String[1]]]
Safety valve. Array of lines to add to the snmptrapd.conf file. See http://www.net-snmp.org/docs/man/snmptrapd.conf.html for all options.
Default value: undef
Data type: Boolean
Whether to install the Net-SNMP client package.
Default value: false
Data type: Boolean
Weheter to install the Net-SNMP snmptrapd package
Default value: true
Data type: Optional[Array[String[1]]]
Safety valve. Array of lines to add to the client's global snmp.conf file. See http://www.net-snmp.org/docs/man/snmp.conf.html for all options.
Default value: undef
Data type: Enum['present','absent']
Ensure if present or absent.
Default value: 'present'
Data type: Boolean
Upgrade package automatically, if there is a newer version.
Default value: false
Data type: String[1]
Name of the package. Only set this if your platform is not supported or you know what you are doing.
Default value: 'net-snmp'
Data type: Optional[String[1]]
Name of the package provinding snmptrapd. Only set this if your platform is not supported or you know what you are doing.
Default value: undef
Data type: Optional[String[1]]
Commandline options passed to snmpd via init script.
Default value: undef
Data type: Stdlib::Absolutepath
Path to sysconfig file for snmpd.
Default value: '/etc/sysconfig/snmpd'
Data type: Stdlib::Absolutepath
Path to sysconfig file for snmptrapd.
Default value: '/etc/sysconfig/snmptrapd'
Data type: Stdlib::Absolutepath
Path to snmptrapd.conf.
Default value: '/etc/snmp/snmptrapd.conf'
Data type: Stdlib::Absolutepath
Path to snmpd.conf.
Default value: '/etc/snmp/snmpd.conf'
Data type: Stdlib::Filemode
Set permissions for the service configuration file.
Default value: '0600'
Data type: Stdlib::Absolutepath
Path to services configuration directory.
Default value: '/usr/local/etc/snmp'
Data type: String[1]
Owner for the service configuration directory.
Default value: 'root'
Data type: String[1]
Set group ownership for the service configuration directory.
Default value: 'root'
Data type: String[1]
Mode of the service configuration directory.
Default value: '0755'
Data type: Stdlib::Ensure::Service
Ensure if service is running or stopped.
Default value: 'running'
Data type: String[1]
Name of SNMP service. Only set this if your platform is not supported or you know what you are doing.
Default value: 'snmpd'
Data type: Boolean
Start service at boot.
Default value: true
Data type: Boolean
Service has status command.
Default value: true
Data type: Boolean
Service has restart command.
Default value: true
Data type: Optional[String[1]]
Commandline options passed to snmptrapd via init script.
Default value: undef
Data type: Stdlib::Ensure::Service
Ensure if service is running or stopped.
Default value: 'stopped'
Data type: String[1]
Name of SNMP service Only set this if your platform is not supported or you know what you are doing.
Default value: 'snmptrapd'
Data type: Boolean
Start service at boot.
Default value: false
Data type: Boolean
Service has status command.
Default value: true
Data type: Boolean
Service has restart command.
Default value: true
Data type: Boolean
Adds the smuxpeer directive to the snmpd.conf file to allow net-snmp to talk with Dell's OpenManage
Default value: false
Data type: Boolean
Include the master option to enable AgentX registrations.
Default value: false
Data type: Optional[Stdlib::Filemode]
Defines the permissions and ownership of the AgentX Unix Domain socket.
Default value: undef
Data type: Optional[Integer]
This will make the subagent try and reconnect every NUM seconds to the master if it ever becomes (or starts) disconnected.
Default value: undef
Data type: Optional[String[1]]
Defines the address the master agent listens at, or the subagent should connect to.
Default value: undef
Data type: Integer[0]
Defines the timeout period (NUM seconds) for an AgentX request.
Default value: 1
Data type: Integer[0]
Defines the number of retries for an AgentX request.
Default value: 5
Data type: Boolean
Disable com2sec, group, and access in snmpd.conf
Default value: true
Data type: Stdlib::Absolutepath
Path to snmp's var directory.
Default value: '/var/lib/net-snmp'
Data type: Stdlib::Filemode
Mode of var_net_snmp
directory.
Default value: '0755'
Data type: String[1]
Owner of var_net_snmp
directory.
Default value: 'root'
Data type: String[1]
Group of var_net_snmp
directory.
Default value: 'root'
Manage the Net-SNMP client package and configuration.
class { 'snmp::client':
snmp_config => [
'defVersion 2c',
'defCommunity public',
],
}
The following parameters are available in the snmp::client
class:
Data type: Enum['present', 'absent']
Ensure if present or absent.
Default value: 'present'
Data type: Optional[Array[String[1]]]
Array of lines to add to the client's global snmp.conf file. See http://www.net-snmp.org/docs/man/snmp.conf.html for all options.
Default value: undef
Data type: Boolean
Upgrade package automatically, if there is a newer version.
Default value: false
Data type: Optional[String[1]]
Name of the package. Only set this if your platform is not supported or you know what you are doing.
Default value: undef
Data type: Stdlib::Absolutepath
Path to snmp.conf
.
Default value: '/etc/snmp/snmp.conf'
Creates a SNMPv3 user with authentication and encryption paswords.
snmp::snmpv3_user { 'myuser':
authtype => 'MD5',
authpass => '1234auth',
privpass => '5678priv',
}
The following parameters are available in the snmp::snmpv3_user
defined type:
Data type: String[8]
Authentication password for the user.
Data type: Enum['SHA','MD5']
Authentication type for the user. SHA or MD5
Default value: 'SHA'
Data type: Optional[String[8]]
Encryption password for the user.
Default value: undef
Data type: Enum['AES','DES']
Encryption type for the user. AES or DES
Default value: 'AES'
Data type: Enum['snmpd','snmptrapd']
Which daemon file in which to write the user. snmpd or snmptrapd
Default value: 'snmpd'