NetBlade
Android Step 5 of 6 ~15 min Intermediate

Read your router, switch or printer over SNMP on Android

Enable SNMP on your network gear, then use NetBlade on Android to recover hidden MAC addresses, read device details and map your switches.

SNMP is the protocol network gear uses to describe itself: routers, switches, printers and NAS boxes can answer questions about their interfaces, tables and state. NetBlade uses it read-only, so nothing is ever changed on the device. This article shows how to enable SNMP in general terms, then how to use it in NetBlade to recover MAC addresses, read device details and draw your network map.

Before you start

  • A device that supports SNMP. Many business routers, managed switches, printers and NAS boxes do; many ISP-supplied home routers do not expose it.
  • Access to the device’s admin page to enable SNMP.
  • What is free: reading the router’s table with “Devices from router (SNMP)” and MAC recovery during scans. “SNMP details” on a device is an advanced feature, unlocked for 24 hours with a video or permanently with “Remove ads”.

1. Enable SNMP on the device

Every manufacturer puts it somewhere different, but the steps are similar. In the admin page, look for “SNMP”, often under “Administration”, “Management”, “System” or “Services”. Then choose one of two options.

SNMP v1/v2c with a community

The community is a shared word that works like a read password. Set it up as:

  1. Enable SNMP, version v2c if offered.
  2. Set a read-only community. Avoid public, the default everyone tries.
  3. If the device allows it, restrict access to your local network or to specific addresses.
  4. Never enable a read-write community for NetBlade: it only reads.

SNMP v3 with a user

v3 adds a user name, authentication and encryption, and is the better choice where available:

  1. Create a v3 user with read-only access.
  2. Authentication: MD5 or SHA. NetBlade supports these two.
  3. Privacy (encryption): DES or AES (AES-128). Prefer SHA and AES.

Warning: If your device only offers SHA-256 or AES-256 for v3, NetBlade cannot use that profile. Pick SHA and AES-128, or fall back to v2c with a strong community restricted to your LAN.

Warning: Do not expose SNMP to the internet. If a scan shows port 161 open on a device you did not configure, NetBlade’s security assessment flags it for this reason.

2. Recover MAC addresses during scans

Since Android 10 the system hides most MAC addresses from apps. The router knows them all, in its ARP table.

  1. In the “LAN” tab open ⋮ → “Name network” (or edit the saved network).
  2. Turn on “Devices from router (SNMP)”.
  3. Pick the version and enter the “Community”, or for v3 the “v3 username”, “Authentication”, “Auth password”, “Privacy” and “Privacy password”.
  4. Tap “Save”.
  5. If MACs do not appear straight away, use ⋮ → “Retry SNMP MAC lookup”.

From now on every scan of this network reads the router’s table, and the “Scan summary” reports the result under “SNMP MAC recovery”.

Note: SNMP credentials are stored unencrypted in the app’s database, so they are also included in your Google account backup and in exported backup files. That is a deliberate trade-off: a restore brings them back without re-entering them.

3. Query the router table directly

For a one-off check, without saving a network:

  1. “Tools” → “Devices from router (SNMP)”.
  2. Enter the community or v3 credentials and start.

You get the IP and MAC pairs the router knows, with vendors. It is the most direct answer to “who is really on this network”.

4. Read a device’s SNMP details

  1. Open any device’s details after a scan.
  2. Open “SNMP details”.
  3. If this device uses different credentials from the network, tap the ⚙ icon and fill in “SNMP for this device”, then “Apply”.

What you see depends on the device:

  • All: name, location, contact, uptime and description.
  • Printers: toner, page count and serial number.
  • NAS boxes and servers: CPU, RAM, storage, processes and users.
  • Switches and routers: interfaces, switch ports, VLANs, IP addresses and IP forwarding.
  • Hardware and firmware where the device reports them.

Tap an interface for its live traffic graph, refreshed every 2 seconds. It is a quick way to find the port that is saturating an uplink.

5. Map your network from the switches

If you have managed switches, SNMP lets NetBlade draw how the network is wired.

  1. Make sure the switches answer SNMP with the network’s credentials, or set “SNMP for this device” on each.
  2. After a scan, in the “LAN” tab switch from “List view” to “Map view”.
  3. Tap “Rebuild” to redo the graph from the switches’ tables.
  4. Correct anything by hand: tap a node and choose “Mark as switch”, “Connect to…” or “Detach”.

Without SNMP on the switches, the network appears as a single segment and the structure is only what you draw.

Check that it worked

  • The “Scan summary” shows “Router answered” with a number of ARP entries under “SNMP MAC recovery”.
  • Devices that said “Not recovered” now show a MAC and a vendor.
  • “SNMP details” on the router shows its name and uptime.

If something goes wrong

  • “No SNMP response” or “no reply from …:161”. SNMP is off, the credentials are wrong, or the device only accepts queries from certain addresses. Check each on the device.
  • “Router replies but the ARP table is empty”. Some routers need the IP/ARP part of their SNMP support enabled separately. Look for an option about MIBs or ARP in the SNMP settings.
  • The summary says the default community public was tried. You have not set SNMP up for this network yet. Enter the community in the network settings.
  • An interface has no traffic graph. It does not expose traffic counters.
  • A device without MAC is missing from the map. A device can only be placed on the map once its MAC is known.

Next

← All how-to guides Feature guide → The product: NetBlade Android →