NetBlade
iPhone · iPad Step 2 of 5 ~15 min Intermediate

Get MACs and vendors from your router over SNMP on iPhone

Enable SNMP on your router and connect NetBlade on iPhone or iPad to it, for free, so every device shows its MAC address and vendor.

iOS never shows an app the MAC addresses of other devices, so after a first scan many devices in NetBlade have no MAC and no vendor. Your router knows them all, in its ARP table, and can share that table over SNMP. This article explains how to enable SNMP on a typical router, how to connect NetBlade to it with a community or with SNMP v3, and how to check the result. It is free.

Before you start

  • A saved network, or be ready to save one. See Get started with NetBlade on iPhone and iPad.
  • A router that supports SNMP. Many business routers, firewalls and managed switches do; many ISP-supplied home routers do not expose it.
  • Access to the router’s admin page. Tools › Router › «Open web interface» takes you there.

Note: NetBlade only reads over SNMP. It never changes anything on the router.

1. Enable SNMP on the router

Every manufacturer places it differently, but the idea is the same. In the admin page look for “SNMP”, often under “Administration”, “Management”, “System” or “Services”. Then choose one of the two options below.

Option A: v1/v2c with a community

The community is a shared word that acts as a read password.

  1. Enable SNMP, v2c if the router offers it.
  2. Set a read-only community. Avoid public: it is the default every tool tries first.
  3. If the router allows it, limit SNMP access to your local network.
  4. Never create a read-write community for NetBlade. It does not need one.

Option B: v3 with a user

v3 adds a user name, authentication and encryption. Use it when the router offers it.

  1. Create a read-only v3 user.
  2. Authentication: MD5 or SHA.
  3. Privacy (encryption): DES or AES. Prefer SHA with AES.

Warning: NetBlade supports SHA (SHA-1) and AES (AES-128) for v3. If the router only offers SHA-256 or AES-256, choose SHA and AES-128 for this user, or use v2c with a strong community limited to your LAN.

Warning: Make sure SNMP is reachable only from inside your network, never from the internet.

2. Enter the credentials in NetBlade

  1. On the LAN tab open the ⋯ menu and choose «Save this network». If it is already saved, tap the amber «SNMP» chip under the title, or open Saved › your network › «Credentials».
  2. Turn on «Devices from router (SNMP)».
  3. Pick the «Version»: v1, v2c or v3.
  4. For v1 or v2c enter the «Community».
  5. For v3 enter the «Username», pick «Auth» and type the «Auth key», then pick «Privacy» and type the «Privacy key».
  6. Save. NetBlade immediately retries fetching the MACs.

From now on every scan of this network reads the router’s ARP table.

Where the credentials live

SNMP credentials are kept in the iOS Keychain, on this device only. They are not put in NetBlade’s backup file, so after restoring on another device you enter them again.

3. Try a direct query

For a quick test, or for a router on another network you have not saved:

  1. Tools › «Devices from the router».
  2. Enter the router’s IP (usually the gateway) and the community.
  3. Tap «Query».

You get the IP and MAC pairs the router knows. If this works, the saved network will work too.

Tip: Tools › SNMP queries any device the same way and shows its system information, interfaces with live traffic, VLANs, storage, CPU and, for printers, toner and pages. It is free on iPhone as well.

Check that it worked

  • The «SNMP» chip under the LAN tab’s title is green.
  • The «Scan summary» says the router answered over SNMP.
  • Devices in the list now show a MAC address and a vendor.
  • Settings › «LAN scan» › «Look up vendor from MAC» is on: it only affects devices whose MAC arrives over SNMP.

If some MACs are still missing after the scan, use ⋯ › «Retry MAC (SNMP)».

If something goes wrong

  • The chip stays amber. Check that SNMP is enabled, that the version matches, and that the community or v3 user is spelled exactly as on the router. Communities are case-sensitive.
  • The router answers but few MACs arrive. The ARP table only holds devices that recently talked to the router. Scan again: the scan itself makes devices talk.
  • v3 fails but v2c works. The authentication or privacy protocol probably does not match. Check for SHA-256 or AES-256 on the router, which NetBlade does not support.
  • The router has no SNMP option. Many ISP routers do not. Devices that announce their own MAC, such as AirPlay devices, still show it; for the rest the list stays without MACs, and NetBlade says so rather than guess.
  • A single device uses different SNMP credentials from the network. Open its details and set them in «Credentials (this device)».

Next

← All how-to guides Feature guide → The product: NetBlade iPhone · iPad →