→ 🚀What's New? Explore Lansweeper's Fall 2024 Updates! Fall Launch Blog !

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
MBI
Engaged Sweeper II

hi,

We install a new scan server and the credencial attach to a specific subnet are not used

when i use the old scanner with the same creds  / subnet it work 

any idea about what is causing it ?

both scan server are o the same subnet 192.168.11.xxx 

 

MBI_0-1696609733956.png

regards

 

 

1 ACCEPTED SOLUTION
Brown_Dog_NG
Champion Sweeper

MBI,
It sounds like you may not have the credentials assigned to the new Scan Server. It shows that you are attempting to leverage SSH so there may be rules on the endpoint that are preventing the New Scan Server from connecting to the device via SSH as well. Confirm that the credentials are assigned by going to the Scanning drop down and then Scanning Credentials. From there you'll look for either the IP Address or Range where the device resides and ensure that the New Scan Server has the credentials assigned to it as well.

-Don't forget to hand out Kudos and mark Solutions to replies you receive!-
LS Tech Support Email: Support@lansweeper.com
LS Tech Support KB: https://www.lansweeper.com/contact-support/

View solution in original post

6 REPLIES 6
MBI
Engaged Sweeper II

the end point is my fortgate 100f

 

the endpoint is set to accept the new scan (snmp print screen )

MBI_0-1696951663352.png

 

new scan server is able to ping the end point 

MBI_1-1696951833031.png

 

 

MBI_2-1696952120368.png

 

regards

 

Brown_Dog_NG
Champion Sweeper

Thanks. The Firewall rules are permitting SNMP v1 and v2 from what I see. So you will want to ensure that the Fortigate is permitting SNMPv2.c with the correct community string. I'd suggest testing with the Lansweeper Device Tester app (C:\Program Files (x86)\Lansweeper\Actions\Devicetester.exe). If that passes, then create a new set of credentials with the successful username and password and assign it to the new scan server. I'm not too familiar with Fortigate but I'm assuming you should be able to console into the unit and run a debug for SNMP to see if the unit is rejecting access from the New Scan Server while you are testing. Would it be possible that Fortigate has a limit to the number of devices that can communicate with a specific SNMP string? May be worth considering creating new credentials for testing/implementation.

Alternatively, you may also use "Paessler SNMP Tester" for testing. I will not post the link here.

I've located the below KB that may be of help in testing SNMP.

Fortigate KB 195334 

If the above information does not help, then I would suggest reaching out to Lansweeper support directly by emailing them at support@lansweeper.com. Here is their KB containing what information they'll need from you. It would probably be helpful for you to apply the below settings to your environment via the Lansweeper Config Editor ("C:\Program Files (x86)\Lansweeper\Tools\ConfigEditor.exe")(Within the app, click Advanced at the top and then import app settings) and then test before you open the case so that they have all their desired information, thus minimizing your wait time. Though, you may want to wait on their instructions as they are the professionals and I'm just an end user.

<?xml version="1.0" encoding="utf-8"?>
<exportDebug>
  <appSetting>
    <key>Debug</key>
    <value>1</value>
  </appSetting>
  <appSetting>
    <key>LogSnmp</key>
    <value>7</value>
  </appSetting>
    <appSetting>
    <key>LogSnmpPass</key>
    <value>7</value>
  </appSetting>    
  <appSetting>
    <key>LogDeviceDuplicates</key>
    <value>7</value>
  </appSetting>
  <appSetting>
    <key>LogSsh</key>
    <value>7</value>
  </appSetting>
  <appSetting>
    <key>LogIpMain</key>
    <value>7</value>
  </appSetting>
  <appSetting>
    <key>LogDeviceUpdate</key>
    <value>7</value>
  </appSetting>
</exportDebug>

 

-Don't forget to hand out Kudos and mark Solutions to replies you receive!-
LS Tech Support Email: Support@lansweeper.com
LS Tech Support KB: https://www.lansweeper.com/contact-support/
MBI
Engaged Sweeper II

i test with devicetester.exe it work with snmp 

so i recreate cred with the one who work with devicetester and still get this error :

No credentials entered for this asset. Please provide credentials to allow Lansweeper scanning server to deliver better results and information about this asset.

 

so i will open a case with support 

 

tks for your help !

 

Brown_Dog_NG
Champion Sweeper

MBI,
It sounds like you may not have the credentials assigned to the new Scan Server. It shows that you are attempting to leverage SSH so there may be rules on the endpoint that are preventing the New Scan Server from connecting to the device via SSH as well. Confirm that the credentials are assigned by going to the Scanning drop down and then Scanning Credentials. From there you'll look for either the IP Address or Range where the device resides and ensure that the New Scan Server has the credentials assigned to it as well.

-Don't forget to hand out Kudos and mark Solutions to replies you receive!-
LS Tech Support Email: Support@lansweeper.com
LS Tech Support KB: https://www.lansweeper.com/contact-support/
MBI
Engaged Sweeper II

both scanner have the same creds on the same subnet  only the old one is working 

i also disable subnet on old scanner without succes 

regards

Brown_Dog_NG
Champion Sweeper

Would you be able to include a screenshot of your scanning config?

Were you able to check the firewall settings on the endpoints to permit the new scan server for SSH? Is the new scan server able to ping the endpoints?

-Don't forget to hand out Kudos and mark Solutions to replies you receive!-
LS Tech Support Email: Support@lansweeper.com
LS Tech Support KB: https://www.lansweeper.com/contact-support/

New to Lansweeper?

Try Lansweeper For Free

Experience Lansweeper with your own data.
Sign up now for a 14-day free trial.

Try Now