SNMP Devices
Switches, routers, firewalls and access points run no Selvara agent. An agent on a host in the same network polls them over SNMP instead, and each device appears as a system of its own: in the systems list, with its own status, alerts, events and charts. The host doing the polling is the device's poller.
Adding a device
Open the poller's page and its SNMP tab. The tab is there on every host with an agent for administrators and managers, and for everyone else once the host polls at least one device. Add device asks for:
| Field | Meaning |
|---|---|
| Name | The device's name in every list. The device's own sysName is shown as its hostname once it has been polled. |
| Address | IP address or DNS name, as the poller reaches it. |
| Port | UDP port, 161 unless the device listens elsewhere. |
| SNMP version | SNMPv3 (the default) or SNMPv2c. |
| Community | v2c only. |
| User, security level, authentication and encryption | v3 only. The level decides which of the two keys are needed. |
Credentials are stored encrypted and are sent only to the poller's agent. In the edit dialog they show as dots; leaving the dots saves the stored value unchanged.
The poller's agent picks the device up with its next report, polls it right away and then every minute. The device takes the poller's customer and stays with it: moving the poller to another customer moves its devices along, and a device cannot be moved on its own.
Deleting a device, from the tab or from the systems list, deletes the system with everything recorded about it.
Which version
Use SNMPv3 with authentication and encryption wherever the device offers it. A v2c community crosses the network in clear text, and anyone who reads it can query the device.
SNMPv1 is not supported. It has no 64-bit counters, and a 32-bit octet counter on a gigabit port runs over about every half a minute.
Reaching the device
The poller sends UDP to port 161 of the device, and the device answers from it. On the way that needs:
- the device's SNMP agent switched on, with the user or community entered here and, where the device restricts it, the poller's address allowed;
- a firewall rule for UDP 161 from the poller to the device, in any firewall between them.
From the poller, snmpget -v2c -c <community> <address> 1.3.6.1.2.1.1.5.0, or
the matching -v3 call, answers with the device's name when all of that is
in place.
What is read
Only standard MIBs, which every managed device implements:
| Source | What the dashboard shows |
|---|---|
| SNMPv2-MIB system group | hostname (sysName), device description (sysDescr), location, contact, uptime and reboots |
| IF-MIB | per port: link state, speed, received and sent bytes per second, errors and discards per second; traffic in total |
| HOST-RESOURCES-MIB | CPU and memory, where the device offers them; many switches do not |
Ports are Ethernet ports of every speed and link aggregates. VLAN
interfaces, loopbacks and tunnels are left out, and so is any port switched
off by its admin. A port is named by ifName, which stays the same when a
switch reboots; the port description (ifAlias) is shown beside it.
Temperature, fans and power supplies are not standardised and are not read.
On the device's page the Interfaces card lists every port, and two charts show received and sent traffic per port.
Status and alerts
| Situation | Device shows | Alerts |
|---|---|---|
| The poller reads it | Online | the usual rules |
| It stops answering while the poller reports | Offline after two minutes | System offline, like any host |
| The poller itself stops reporting | Polling interrupted | none for the device: the poller's own System offline covers it |
A port whose link goes down records an interface.down event, and one that
comes back interface.up. The Interfaces card shows a port without link
as No link, in grey, and no default rule alerts on it: on most switches
that is a port with nothing plugged in. For an uplink that must stay up, add
a rule on interface_up below 1 scoped to that device.
How much data a device is
A device is polled once a minute. A 24-port switch with every port in use reports about 150 series; a 48-port switch about 300. That is roughly what two to four hosts report. Ports that are admin-down cost nothing, which is the simplest way to keep an access switch's unused ports out.
On the poller
The poller's agent lists itself with the service SNMP poller and the addresses it polls. It polls at most eight devices at a time and gives a device four seconds per request, with one retry. Its log carries one line when polling starts or its device list changes, and one per device that cannot be reached at all:
[SNMP] 10.0.0.1:161: connect 10.0.0.1:161: …
A device that is reachable but refuses the credentials shows the reason on its own page, under the SNMP service.
Related: Customers and Systems for how devices appear in the lists, Alert Rules for scoping a rule to a device, and Agent Collectors for what the poller collects about its own host.