Volver a la wiki

SNMP Basics: Versions, Communities, OIDs and MIBs

What is SNMP

SNMP (Simple Network Management Protocol) is the standard protocol for monitoring and managing network equipment. Switches, routers, servers, PDUs, UPS units, environmental sensors — almost anything with a network port can run an SNMP agent.

The model is simple. A manager sends requests to an agent running on the device, and the agent replies with the requested values.

┌────────────┐    GET / GET-NEXT     ┌──────────┐
│   Manager  │ ────────────────────► │  Agent   │
│ (monitoring│ ◄──────────────────── │ (switch) │
│   system)  │       RESPONSE        │          │
└────────────┘ ◄──── TRAP ────────── └──────────┘
            (unsolicited notification)

SNMP versions

VersionAuthenticationEncryptionRecommendation
v1Community string (plaintext)NoneLegacy — avoid
v2cCommunity string (plaintext)NoneAcceptable on isolated internal networks
v3Username + auth password (MD5/SHA)Yes (DES/AES)Recommended for production

A community string is a shared password sent in clear text with every v1/v2c request. Anyone who can capture the traffic can read it. If the network path is not fully trusted, use SNMPv3 with both authentication and privacy (authPriv) enabled.

OIDs and MIBs

Every value a device exposes is identified by an OID (Object Identifier), a hierarchical sequence of numbers:

1.3.6.1.2.1.1.1.0     →  sysDescr   (system description)
1.3.6.1.2.1.2.2.1.10  →  ifInOctets (bytes received per interface)
1.3.6.1.2.1.2.2.1.16  →  ifOutOctets (bytes sent per interface)

MIBs (Management Information Bases) are files that translate those numbers into readable names and describe their meaning and data type. Standard MIBs (like MIB-II) cover the basics; each vendor publishes its own MIBs for hardware-specific data.

Common OIDs in a datacenter

OIDNameWhat it measures
.1.3.6.1.2.1.1.3.0sysUpTimeTime since last reboot
.1.3.6.1.2.1.2.2.1.10ifInOctetsInbound traffic per interface
.1.3.6.1.2.1.2.2.1.16ifOutOctetsOutbound traffic per interface
.1.3.6.1.2.1.2.2.1.8ifOperStatusInterface state (up/down)
.1.3.6.1.4.1.*Enterprise subtreeVendor-specific data (CPU, temperature, PSUs…)

SNMP operations

SNMP in CreaRack

CreaRack Observatory uses SNMP as its main polling protocol. You enter the SNMP credentials (community string or v3 user) when you set up monitoring for a device — see [[crearack—monitoring—configurar-snmp]] — and Observatory then polls it on a schedule for traffic, interface status, CPU, memory and temperature.

The [[crearack—network—auto-provision-wizard]] also relies on SNMP: it scans a range, reads each device’s sysDescr, and identifies vendor and model so you can onboard equipment quickly. Vendor-specific OIDs are handled through [[crearack—network—mibs-and-vendor-profiles]].

Good practices

  1. Use SNMPv3 whenever the device supports it.
  2. Change the default community strings (public, private) — they are the first thing attackers try.
  3. Restrict SNMP access by source IP with an ACL on the device.
  4. Poll only what you need — walking thousands of OIDs on every cycle loads the device’s CPU.
  5. Load the vendor’s MIBs so metrics show readable names instead of raw numbers.

Véase también

Subir