Read switches, printers, NAS and routers over SNMP
Turn on SNMP on your network devices, file v2c or v3 credentials in NetBlade, and read model, firmware, ports, VLANs, PoE, toner and more, safely.
Switches, printers, NAS units, UPSs and routers do not accept a Windows login, but almost all of them speak SNMP, the standard protocol for asking network equipment about itself. With SNMP turned on and one credential filed, NetBlade reads their model, serial and firmware, every port with its VLANs and PoE, the MAC addresses learned on each port, printer supplies and page counts. It is also what the network map is built from. This article walks you through doing it without opening a new hole.
Before you start
- The devices in Devices after a scan (Get started).
- Administrator access to each device’s web interface or console, to turn SNMP on.
- The IP address of the PC running NetBlade, to restrict SNMP access to it where the device allows.
1. Choose the SNMP version
NetBlade supports SNMP v1, v2c and v3.
- v1 and v2c authenticate with a community, a single shared string that works like a password. It travels in the clear: every device on the way can read it. v2c is the one to use if you must choose between the two.
- v3 has a user, an authentication password and an encryption password. It is the only version that protects the exchange.
Use v3 wherever the device supports it; keep v2c for older gear that does not. In NetBlade, v3 offers MD5 or SHA for authentication and DES or AES for encryption. NetBlade’s SHA is SHA-1 and its AES is AES-128, so choose those on the device where it offers several variants.
Warning: With v3 you must pick the algorithms the device is really set to. A device expecting SHA does not refuse an MD5 request, it ignores it, so a wrong choice looks exactly like a device that is switched off.
2. Turn SNMP on, on each device
Every brand places it differently, but the steps are almost always the same (this is general advice, not NetBlade-specific):
- Open the device’s web interface and find the SNMP page, usually under Management, System or Network services.
- Enable the SNMP agent.
- For v2c, replace the factory community with a long random string and make it read-only. For v3, create a user with read-only access, SHA authentication and AES encryption, each with its own password.
- If the device lets you restrict which addresses may query it, allow only the PC running NetBlade.
- Fill in contact and location (sysContact, sysLocation). NetBlade reads them and shows them on the card, which turns “a switch” into “the switch in the second-floor rack, managed by you”.
- On switches, turn on LLDP too if you plan to build the network map.
- Save, and on switches that need it, save the running configuration.
Warning: Never enable a write (read-write) community or v3 user for NetBlade. It only reads, so write access would give nothing to NetBlade and everything to whoever finds the string. And never let UDP port 161 be reachable from the internet.
3. File the SNMP credential
- Open Credentials and press Add….
- Set Protocol to SNMP and choose the SNMP version.
- For v1 or v2c, type the Community. For v3, fill in User, Authentication and Authentication password, Encryption and Encryption password.
- Choose Where it applies. One site is the usual choice. If your network gear lives in a management range you saved with Keep this scope on the Scan page, These scan scopes limits the credential to exactly those devices.
- Label it, for example “Office A - switches v3”, and press File.
- Type a switch’s address in Machine to try and press Test. LAST TEST should say «Works».
If different devices use different communities, file one credential each and order them with Try earlier and Try later: NetBlade tries them in order and stops at the first that answers. A device with its own string can get an Override for this device from its card’s Credentials tab.
4. Read the devices
- Open Devices, filter by Type if you want only network gear, and press Deep inventory. Or, in Sites, press Read every device.
- Open a switch’s card. The read status says «Read … via …».
What comes back over SNMP:
- Summary and Hardware: model, serial, firmware and hardware revision, what the device calls itself and how it describes itself, uptime, contact and location.
- Interfaces tab: every port with its state (up, down, disabled by an administrator), speed, VLANs (tagged and untagged), Power over Ethernet per port, and Seen on each port: the MAC addresses the switch has learned behind each port, matched to devices in your catalog where possible.
- Printers: supplies (toner, drum, fuser, waste toner and so on, with their level), status and Pages printed.
- NAS and servers that publish it: memory and storage.
A device answers with what its SNMP agent publishes, and there is nothing more to ask for. The card says so plainly: «Read over SNMP. The device answers with what its agent publishes — model, serial, interfaces, consumables — and there is no more to ask for here.»
5. Ask a device for everything
The inventory asks a fixed list of questions. When you need something else, a UPS runtime, a NAS disk temperature, a switch’s exact firmware string, use the card’s Published tab:
- Open the device’s card and the Published tab.
- Press Ask for everything. NetBlade walks the device’s whole SNMP tree, the standard part and the vendor’s own subtree.
- Type in filter by name, OID or value to find what you need.
It is slow, one round trip per value, and it is not stored: most values are counters that were true for a second.
6. Check a device quickly without filing anything
The Tools page has an SNMP tool that asks the system group of any address (name, description, model, serial, uptime, contact, location) with a community you type. It is handy on the phone with someone who is holding the box. If the device answers the factory community, the tool says so: «It answers to the factory community. Anyone who can reach this address can read everything it publishes.»
7. Close the factory communities
Identification (Identify on a card, or Identify every device in Sites) tries public SNMP. Any device still answering its factory community gets a finding on To fix, «SNMP answers the factory password», and breaks the compliance rule «SNMP without the factory community».
For each one:
- Open the device’s web interface.
- Change the community to a long string, or better, move to v3. If nothing needs SNMP on that device, turn it off.
- In NetBlade, update your credential (see rotation) and read the device again.
- On To fix, press Check now.
Check that it worked
- The switch’s card says «Read … via …» and the Interfaces tab lists ports, VLANs and learned MAC addresses.
- The printer’s card shows supplies and Pages printed.
- To fix no longer lists «SNMP answers the factory password» for devices you changed.
If something goes wrong
- «no answer to an SNMP … request: the agent is off, set to a different version, or expecting another community». Check, in this order: SNMP enabled on the device, the version in NetBlade matches, the community or v3 user is right, and the device allows queries from the NetBlade PC’s address.
- v3 does not answer, but v2c does. Almost always the algorithms. Match Authentication and Encryption exactly to the device’s settings (SHA-1 and AES-128 for NetBlade’s SHA and AES).
- The Published tab says only an SNMP device publishes a tree. File an SNMP credential that applies to that device.
- A MAC address behind a router is missing. A scan only sees MAC addresses on the local segment. Beyond a router, MAC addresses are visible only over SNMP, from the gear that learned them.
Next
With your switches answering SNMP, you can draw how everything is wired: Build the network map. If you also run Linux servers, see Linux machines over SSH.
← All how-to guides Feature guide → The product: NetBlade Windows →