Using Junos SNMP utility MIB on Juniper SRX¶
Although good old Junos SNMP MIB is very rich on every platform, occasionally some specific stats could have been handy. For example, number of sessions per IP protocol on SRX. No problem! Blast from the past Junos utility MIB tooling allows expansion of MIB by anything retrievable using RPCs. This short Tech Post aims to give a good starting point for daily use of this simple yet powerful approach.
Using utility MIB from on-box Python¶
In this specific example script in background will be automatically collecting SRX session counts for specific IP protocol followed by load to utility MIB. Related RPC summarizing number of connections in SRX firewall session table is represented on CLI by:
Following on-box Python skeleton code loads session counts for individual IP protocols defined by item values of ip_proto_session_counts dictionary, key is used for naming the SNMP counter:
Script is placed for manual execution (handy for testing changes) in /var/db/scripts/op folder and for periodic execution also in /var/db/scripts/event. Good practice may be simply to create a hard-link instead of making and maintaining a copy:
Then the Junos configuration side for both manual and periodic execution (every 60s in sample below):
Finally, to execute the script manually for a test-drive on CLI and retrieve counters from utility MIB:
For any expansions, to reveal RPC with parameters and corresponding XML data representation using Junos CLI (reduced output for specific example):
Notice the "_" character usage in Python code instead of non-allowed "-" in RPC name above. A common pitfall is to copy paste the RPC as-is into Python code.
And related output XML data structure where from data are extracted:
Notes
- Of course, when doing similar things for a real-world system, then security, exception handling, logging and RE/PFE load imposed by executed code MUST be considered.
- Parameters can be passed to the script from Junos config and CLI. E.g., the ip_proto_session_counts data structure in some string form as parameter to have Junos config driven counter definition instead of script contained variable. Handy is Python split() method to create a list from string.
- To avoid nagging in Junos logs about execution of unsigned script, SHA-256 checksum of the script file needs to be part of Junos config:
- Simple trick for clearing counters when starting over in development environment:
- Generally, there may be better ways for close to real-time data collection use-cases, e.g., if there are appropriate telemetry sensors.
Useful links¶
- Junos Scripting: https://www.juniper.net/documentation/us/en/software/junos/automation-scripting/topics/concept/junos-script-automation-overview.html
- Utility MIB: https://www.juniper.net/documentation/en_US/junos/topics/task/operational/security-snmp-best-practices-utility-mib-using.html
- PyEZ developer guide: https://www.juniper.net/documentation/us/en/software/junos-pyez/junos-pyez-developer/index.html
Glossary¶
- CLI: Command Line Interface
- MIB: Management Information Base
- PFE: Packet Forwarding Engine
- RE: Routing Engine
- RPC: Remote Procedure Call
- SNMP: Simple Network Management Protocol