|
| 1 | +# SNMP |
| 2 | + |
| 3 | +An SNMP agent is available for monitoring the system from an existing network |
| 4 | +management system. It is read-only: the agent answers GET and GETNEXT, and |
| 5 | +there is no way to configure write access. Changing configuration is done |
| 6 | +over NETCONF, RESTCONF or the CLI, where NACM controls who may do what. |
| 7 | + |
| 8 | +The agent is disabled by default and has no community configured, so enabling |
| 9 | +it is a deliberate act. |
| 10 | + |
| 11 | +> [!IMPORTANT] |
| 12 | +> SNMPv1 and v2c carry the community string in clear text on the wire, and |
| 13 | +> anyone who can read it can read everything the community's view allows. |
| 14 | +> Restrict access by source address, and prefer a management VLAN or firewall |
| 15 | +> zone that is not reachable from the outside. Another alternative is to set |
| 16 | +> up a [WireGuard](vpn-wireguard.md) tunnel for management until SNMPv3 |
| 17 | +> support is added. |
| 18 | +
|
| 19 | +## What is served |
| 20 | + |
| 21 | +| MIB | Contents | |
| 22 | +|--------------------|--------------------------------------------------------------------------------| |
| 23 | +| SNMPv2-MIB | `sysDescr`, `sysObjectID`, `sysUpTime`, `sysName`, `sysContact`, `sysLocation` | |
| 24 | +| IF-MIB | `ifTable` and `ifXTable` for every interface | |
| 25 | +| HOST-RESOURCES-MIB | storage, processors, running software | |
| 26 | +| UCD-SNMP-MIB | load average, memory, disk usage | |
| 27 | +| LLDP-MIB | neighbors, when LLDP is enabled | |
| 28 | + |
| 29 | +Every port is an interface, including ports offloaded to a switch fabric, so |
| 30 | +they all appear in the `ifTable`. The `ifIndex` an NMS sees is the same as |
| 31 | +the `if-index` reported under `/interfaces/interface[name='eth0']/if-index`, |
| 32 | +which makes it easy to correlate SNMP data with the operational datastore. |
| 33 | + |
| 34 | +We recommend using `ifName` from `ifXTable` as the stable key for a port, not |
| 35 | +`ifIndex`. Interface indices are assigned by the kernel and may shift when |
| 36 | +configuration creates or removes VLANs, bridges and other virtual interfaces. |
| 37 | + |
| 38 | +> [!NOTE] |
| 39 | +> The counters are the ones the interface itself reports, the same values |
| 40 | +> `show interface` shows. On a port whose traffic is forwarded by the switch |
| 41 | +> fabric, how much of that traffic the counters account for depends on the |
| 42 | +> switch and its driver. |
| 43 | +
|
| 44 | +`sysContact` and `sysLocation` come from `/system/contact` and |
| 45 | +`/system/location`, and `sysName` follows `/system/hostname`. See |
| 46 | +[Contact and Location][contact] for what to put in them. |
| 47 | + |
| 48 | +## Configuration |
| 49 | + |
| 50 | +The data model is [RFC 7407][], `ietf-snmp`. Two things are needed: the |
| 51 | +engine enabled, and a community to answer for. |
| 52 | + |
| 53 | +<pre class="cli"><code>admin@example:/> <b>configure</b> |
| 54 | +admin@example:/config/> <b>set snmp engine enabled</b> |
| 55 | +admin@example:/config/> <b>set snmp community monitor security-name public</b> |
| 56 | +admin@example:/config/> <b>leave</b> |
| 57 | +</code></pre> |
| 58 | + |
| 59 | +That is the whole thing. `monitor` is just a name for the list entry; the |
| 60 | +community string on the wire is `public`, taken from the security name because |
| 61 | +no separate `text-name` was given. Set `text-name` when the two should |
| 62 | +differ: |
| 63 | + |
| 64 | +<pre class="cli"><code>admin@example:/> <b>set snmp community monitor text-name s3cret</b> |
| 65 | +</code></pre> |
| 66 | + |
| 67 | +<pre class="cli"><code>admin@example:/> <b>show snmp</b> |
| 68 | +Enabled : yes |
| 69 | +Versions : v1, v2c (default) |
| 70 | +Listen : 0.0.0.0:161, [::]:161 (default) |
| 71 | + |
| 72 | +COMMUNITY SECURITY NAME SOURCE |
| 73 | +public public any |
| 74 | +</code></pre> |
| 75 | + |
| 76 | +Leaving `version` or `listen` unset means the agent serves every version it |
| 77 | +supports, on every address, port 161. Narrow them when you want something |
| 78 | +tighter: |
| 79 | + |
| 80 | +<pre class="cli"><code>admin@example:/> <b>configure</b> |
| 81 | +admin@example:/config/> <b>set snmp engine version v2c</b> |
| 82 | +admin@example:/config/> <b>edit snmp engine listen mgmt udp</b> |
| 83 | +admin@example:/config/snmp/engine/listen/mgmt/udp/> <b>set ip 192.168.1.10</b> |
| 84 | +admin@example:/config/snmp/engine/listen/mgmt/udp/> <b>leave</b> |
| 85 | +</code></pre> |
| 86 | + |
| 87 | +Every community reads the whole MIB tree, and nothing can write. There is no |
| 88 | +view or group to configure. Limit *who* may ask instead, with a source |
| 89 | +restriction. |
| 90 | + |
| 91 | +### Restricting by source address |
| 92 | + |
| 93 | +A community with no restriction answers anyone who knows the string. To limit |
| 94 | +it, define a target holding the permitted prefix, tag it, and point the |
| 95 | +community at that tag: |
| 96 | + |
| 97 | +<pre class="cli"><code>admin@example:/> <b>configure</b> |
| 98 | +admin@example:/config/> <b>edit snmp target nms</b> |
| 99 | +admin@example:/config/snmp/target/nms/> <b>set udp ip 192.168.1.0</b> |
| 100 | +admin@example:/config/snmp/target/nms/> <b>set udp prefix-length 24</b> |
| 101 | +admin@example:/config/snmp/target/nms/> <b>set tag nms</b> |
| 102 | +admin@example:/config/snmp/target/nms/> <b>set target-params nms</b> |
| 103 | +admin@example:/config/snmp/target/nms/> <b>end</b> |
| 104 | +admin@example:/config/> <b>set snmp community monitor target-tag nms</b> |
| 105 | +admin@example:/config/> <b>leave</b> |
| 106 | +</code></pre> |
| 107 | + |
| 108 | +> [!IMPORTANT] |
| 109 | +> If no target carries the tag, the community is dropped rather than left |
| 110 | +> answering any source. Check `show snmp` after setting it: the community |
| 111 | +> disappears from the table if the tag matched nothing. |
| 112 | +
|
| 113 | +### Firewall |
| 114 | + |
| 115 | +The agent listens on UDP port 161. Permit the `snmp` service in the zone |
| 116 | +facing the management network: |
| 117 | + |
| 118 | +<pre class="cli"><code>admin@example:/> <b>configure</b> |
| 119 | +admin@example:/config/> <b>edit firewall zone mgmt</b> |
| 120 | +admin@example:/config/firewall/zone/mgmt/> <b>set service snmp</b> |
| 121 | +admin@example:/config/firewall/zone/mgmt/> <b>leave</b> |
| 122 | +</code></pre> |
| 123 | + |
| 124 | +## Reading the data |
| 125 | + |
| 126 | +From a management host: |
| 127 | + |
| 128 | +<pre class="cli"><code>linux-pc:# <b>snmpwalk -v2c -c public 192.168.1.10 IF-MIB::ifXTable</b> |
| 129 | +IF-MIB::ifName.1 = STRING: lo |
| 130 | +IF-MIB::ifName.2 = STRING: eth0 |
| 131 | +IF-MIB::ifName.3 = STRING: eth1 |
| 132 | +IF-MIB::ifHCInOctets.2 = Counter64: 20748536 |
| 133 | +IF-MIB::ifHCOutOctets.2 = Counter64: 1332378 |
| 134 | +</code></pre> |
| 135 | + |
| 136 | +> [!TIP] |
| 137 | +> Poll over SNMPv2c, not v1. SNMPv1 has no `Counter64`, so the whole of |
| 138 | +> `ifXTable` is unreadable over v1 and only the 32-bit counters in `ifTable` |
| 139 | +> remain. Those wrap in well under an hour on a busy gigabit port, which is |
| 140 | +> not enough for useful throughput graphs. Set `snmp engine version v2c` to |
| 141 | +> refuse v1 outright. |
| 142 | +
|
| 143 | +The device itself carries no MIB text files, so the `snmpwalk` and `snmpget` |
| 144 | +on it work with numeric OIDs only. That is enough for a quick check from the |
| 145 | +console: |
| 146 | + |
| 147 | +<pre class="cli"><code>admin@example:~$ <b>snmpwalk -v2c -c public 127.0.0.1 .1.3.6.1.2.1.31.1.1.1.1</b> |
| 148 | +.1.3.6.1.2.1.31.1.1.1.1.1 = STRING: lo |
| 149 | +.1.3.6.1.2.1.31.1.1.1.1.2 = STRING: eth0 |
| 150 | +</code></pre> |
| 151 | + |
| 152 | +## Community strings are secrets |
| 153 | + |
| 154 | +`ietf-snmp` marks the community name and the security name |
| 155 | +`nacm:default-deny-all`, which sysrepo honours, so they are unreadable by |
| 156 | +default. An operator or guest sees that a community exists but not what it is |
| 157 | +called. |
| 158 | + |
| 159 | +## Not yet supported |
| 160 | + |
| 161 | +SNMPv3 (USM), notifications (traps and informs), view-based access control, |
| 162 | +the BRIDGE-MIB and the ENTITY-MIB are not implemented. |
| 163 | + |
| 164 | +[contact]: system.md#contact-and-location |
| 165 | +[RFC 7407]: https://www.rfc-editor.org/rfc/rfc7407 |
0 commit comments