Skip to main content

SNMP Devices

Switches, routers, firewalls and access points run no Selvara agent. An agent on a host in the same network polls them over SNMP instead, and each device appears as a system of its own: in the systems list, with its own status, alerts, events and charts. The host doing the polling is the device's poller.

Adding a device​

Open the poller's page and its SNMP tab. The tab is there on every host with an agent for administrators and managers, and for everyone else once the host polls at least one device. Add device asks for:

FieldMeaning
NameThe device's name in every list. The device's own sysName is shown as its hostname once it has been polled.
AddressIP address or DNS name, as the poller reaches it.
PortUDP port, 161 unless the device listens elsewhere.
SNMP versionSNMPv3 (the default) or SNMPv2c.
Communityv2c only.
User, security level, authentication and encryptionv3 only. The level decides which of the two keys are needed.

Credentials are stored encrypted and are sent only to the poller's agent. In the edit dialog they show as dots; leaving the dots saves the stored value unchanged.

The poller's agent picks the device up with its next report, polls it right away and then every minute. The device takes the poller's customer and stays with it: moving the poller to another customer moves its devices along, and a device cannot be moved on its own.

Deleting a device, from the tab or from the systems list, deletes the system with everything recorded about it.

Which version​

Use SNMPv3 with authentication and encryption wherever the device offers it. A v2c community crosses the network in clear text, and anyone who reads it can query the device.

SNMPv1 is not supported. It has no 64-bit counters, and a 32-bit octet counter on a gigabit port runs over about every half a minute.

Reaching the device​

The poller sends UDP to port 161 of the device, and the device answers from it. On the way that needs:

  • the device's SNMP agent switched on, with the user or community entered here and, where the device restricts it, the poller's address allowed;
  • a firewall rule for UDP 161 from the poller to the device, in any firewall between them.

From the poller, snmpget -v2c -c <community> <address> 1.3.6.1.2.1.1.5.0, or the matching -v3 call, answers with the device's name when all of that is in place.

What is read​

Only standard MIBs, which every managed device implements:

SourceWhat the dashboard shows
SNMPv2-MIB system grouphostname (sysName), device description (sysDescr), location, contact, uptime and reboots
IF-MIBper port: link state, speed, received and sent bytes per second, errors and discards per second; traffic in total
HOST-RESOURCES-MIBCPU and memory, where the device offers them; many switches do not

Ports are Ethernet ports of every speed and link aggregates. VLAN interfaces, loopbacks and tunnels are left out, and so is any port switched off by its admin. A port is named by ifName, which stays the same when a switch reboots; the port description (ifAlias) is shown beside it.

Temperature, fans and power supplies are not standardised and are not read.

On the device's page the Interfaces card lists every port, and two charts show received and sent traffic per port.

Status and alerts​

SituationDevice showsAlerts
The poller reads itOnlinethe usual rules
It stops answering while the poller reportsOffline after two minutesSystem offline, like any host
The poller itself stops reportingPolling interruptednone for the device: the poller's own System offline covers it

A port whose link goes down records an interface.down event, and one that comes back interface.up. The Interfaces card shows a port without link as No link, in grey, and no default rule alerts on it: on most switches that is a port with nothing plugged in. For an uplink that must stay up, add a rule on interface_up below 1 scoped to that device.

How much data a device is​

A device is polled once a minute. A 24-port switch with every port in use reports about 150 series; a 48-port switch about 300. That is roughly what two to four hosts report. Ports that are admin-down cost nothing, which is the simplest way to keep an access switch's unused ports out.

On the poller​

The poller's agent lists itself with the service SNMP poller and the addresses it polls. It polls at most eight devices at a time and gives a device four seconds per request, with one retry. Its log carries one line when polling starts or its device list changes, and one per device that cannot be reached at all:

[SNMP] 10.0.0.1:161: connect 10.0.0.1:161: …

A device that is reachable but refuses the credentials shows the reason on its own page, under the SNMP service.

Related: Customers and Systems for how devices appear in the lists, Alert Rules for scoping a rule to a device, and Agent Collectors for what the poller collects about its own host.