SNMP Basics: Versions, Communities, OIDs and MIBs
What is SNMP
SNMP (Simple Network Management Protocol) is the standard protocol for monitoring and managing network equipment. Switches, routers, servers, PDUs, UPS units, environmental sensors — almost anything with a network port can run an SNMP agent.
The model is simple. A manager sends requests to an agent running on the device, and the agent replies with the requested values.
┌────────────┐ GET / GET-NEXT ┌──────────┐
│ Manager │ ────────────────────► │ Agent │
│ (monitoring│ ◄──────────────────── │ (switch) │
│ system) │ RESPONSE │ │
└────────────┘ ◄──── TRAP ────────── └──────────┘
(unsolicited notification)
SNMP versions
| Version | Authentication | Encryption | Recommendation |
|---|---|---|---|
| v1 | Community string (plaintext) | None | Legacy — avoid |
| v2c | Community string (plaintext) | None | Acceptable on isolated internal networks |
| v3 | Username + auth password (MD5/SHA) | Yes (DES/AES) | Recommended for production |
A community string is a shared password sent in clear text with every v1/v2c request. Anyone who can capture the traffic can read it. If the network path is not fully trusted, use SNMPv3 with both authentication and privacy (authPriv) enabled.
OIDs and MIBs
Every value a device exposes is identified by an OID (Object Identifier), a hierarchical sequence of numbers:
1.3.6.1.2.1.1.1.0 → sysDescr (system description)
1.3.6.1.2.1.2.2.1.10 → ifInOctets (bytes received per interface)
1.3.6.1.2.1.2.2.1.16 → ifOutOctets (bytes sent per interface)
MIBs (Management Information Bases) are files that translate those numbers into readable names and describe their meaning and data type. Standard MIBs (like MIB-II) cover the basics; each vendor publishes its own MIBs for hardware-specific data.
Common OIDs in a datacenter
| OID | Name | What it measures |
|---|---|---|
.1.3.6.1.2.1.1.3.0 | sysUpTime | Time since last reboot |
.1.3.6.1.2.1.2.2.1.10 | ifInOctets | Inbound traffic per interface |
.1.3.6.1.2.1.2.2.1.16 | ifOutOctets | Outbound traffic per interface |
.1.3.6.1.2.1.2.2.1.8 | ifOperStatus | Interface state (up/down) |
.1.3.6.1.4.1.* | Enterprise subtree | Vendor-specific data (CPU, temperature, PSUs…) |
SNMP operations
- GET — read the value of one specific OID.
- GET-NEXT — read the next OID in the tree; used to walk tables.
- GET-BULK (v2c/v3) — read many values in one request; much more efficient than repeated GET-NEXT.
- SET — change a value on the device (requires write access; rarely enabled).
- TRAP / INFORM — the device notifies the manager when something happens, without being asked.
SNMP in CreaRack
CreaRack Observatory uses SNMP as its main polling protocol. You enter the SNMP credentials (community string or v3 user) when you set up monitoring for a device — see [[crearack—monitoring—configurar-snmp]] — and Observatory then polls it on a schedule for traffic, interface status, CPU, memory and temperature.
The [[crearack—network—auto-provision-wizard]] also relies on SNMP: it scans a range, reads each device’s sysDescr, and identifies vendor and model so you can onboard equipment quickly. Vendor-specific OIDs are handled through [[crearack—network—mibs-and-vendor-profiles]].
Good practices
- Use SNMPv3 whenever the device supports it.
- Change the default community strings (
public,private) — they are the first thing attackers try. - Restrict SNMP access by source IP with an ACL on the device.
- Poll only what you need — walking thousands of OIDs on every cycle loads the device’s CPU.
- Load the vendor’s MIBs so metrics show readable names instead of raw numbers.
Related
- [[crearack—monitoring—configurar-snmp]] — set up SNMP monitoring for a device
- [[crearack—monitoring—que-es-observatory]] — the module that consumes SNMP data
- [[crearack—monitoring—metricas]] — metrics collected via SNMP
- [[crearack—network—mibs-and-vendor-profiles]] — vendor MIBs and profiles in CreaRack
- [[crearack—network—auto-provision-wizard]] — SNMP-based device discovery
- [[crearack—redes-infra—switches-routers]] — the equipment you monitor
Véase también
- [[crearack—monitoring—configurar-snmp]]
- [[crearack—monitoring—que-es-observatory]]
- [[crearack—monitoring—metricas]]
- [[crearack—network—mibs-and-vendor-profiles]]
- [[crearack—network—auto-provision-wizard]]
- [[crearack—redes-infra—switches-routers]]