From 629822c055d70ef53e9359cf13b3d7d3410c33b0 Mon Sep 17 00:00:00 2001 From: Christian Manivong Date: Sat, 20 Jun 2026 03:46:48 +0200 Subject: [PATCH] fix: set listen IP in _action_fix_snmp so snmpd binds to management IF Without an explicit listen address, os-net-snmp on OPNsense may not respond on non-loopback interfaces. The fix sets listen = {self.hostname: {"selected": 1}} which is always the management IP used to reach this device in netOrk. Co-Authored-By: Claude Sonnet 4.6 --- napalm_opnsense/opnsense.py | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/napalm_opnsense/opnsense.py b/napalm_opnsense/opnsense.py index 4c61e01..528ce76 100644 --- a/napalm_opnsense/opnsense.py +++ b/napalm_opnsense/opnsense.py @@ -1579,6 +1579,12 @@ class OPNsenseDriver(FirewallDriver): lines.append("[install] os-net-snmp already installed — skipping reinstall") # 2. Configure SNMP + # The listen field must contain the management IP so that snmpd binds + # to the correct interface. Without it snmpd may not respond on any + # non-loopback address. + # The API expects {"": {"selected": 1}} — we use self.hostname + # which is always the device's management IP in netOrk. + listen_val: dict = {self.hostname: {"selected": 1}} try: self._post("/api/netsnmp/general/set", { "general": { @@ -1588,9 +1594,10 @@ class OPNsenseDriver(FirewallDriver): "location": "Managed by netOrk", "sysobjid": "", "bindip": "", + "listen": listen_val, } }) - lines.append("[config] SNMP enabled with community 'public'.") + lines.append(f"[config] SNMP enabled with community 'public', listen={self.hostname}.") except Exception as exc: logger.debug("SNMP config failed: %s", exc) lines.append(f"[config] error: {exc}")