We can not use wireshark on that network. I would believe the message is coming to the server the way it should be. We use Splunk for other logs and if I use Splunk to receive the traps, they come out readable with default MIBS being used (NOT the correct Cisco MIBS).
I think the first part of my original question might be the key: Why am I receiving the traps ONLY if I enable UDP inputs? If I uncheck SNMP Trap inputs, the messages still come in. If I uncheck UDP input and check SNMP Trap inputs, the messages stop. Its as if the server does not understand to read the incomming message as a SNMP trap.
Thanks again.
Ray