Skip to main content

SNMP Configuration

Device Monitor can tell you whether a device is reachable without any configuration at all. To get CPU, memory, temperature, interface status, and throughput out of it, the device needs an SNMP agent and EmberCORE needs credentials for it.

Once saved, secrets are never sent back to the browser: EmberCORE shows only whether a community string or SNMPv3 keys are set.

RequirementDetail
ProtocolUDP
Port161 on the device
DirectionPlatform to device, outbound only
VersionsSNMPv2c (community string) and SNMPv3 (user-based security). SNMPv1 is not supported.

Allow UDP 161 from the platform's address range to your device management VLAN.

Step 1: Enable the agent on the device​

The specifics vary by vendor, but the shape is always the same: turn the agent on, set a credential, and restrict which source addresses may query it.

Cisco IOS:

configure terminal
snmp-server community <read-only-community> ro
snmp-server location "Building A, Rack 3"
snmp-server contact "ops@example.com"
exit
write memory

On Cisco, one extra line makes interface data far more useful over time, because it stops interface indexes from renumbering across reboots:

snmp-server ifindex persist

FortiGate:

config system snmp sysinfo
set status enable
set location "Building A"
end
config system snmp community
edit 1
set name "<read-only-community>"
set status enable
config hosts
edit 1
set ip <platform-cidr>
next
end
next
end

Linux hosts and industrial PCs:

sudo apt install snmpd snmp -y

Then in /etc/snmp/snmpd.conf:

rocommunity <read-only-community> <platform-cidr>
syslocation "Building A, Rack 5"
syscontact "ops@example.com"
sudo systemctl enable --now snmpd

Appliances with a web UI (Palo Alto, pfSense, UPS and PDU controllers) all follow the same path: find SNMP under device or network settings, enable the agent, set the v2c community or v3 credentials, and apply.

PLCs and industrial cameras vary by vendor and runtime, and many implement SNMP partially or not at all. Check the vendor's documentation for what the agent actually populates before relying on it.

Step 2: Add the credentials​

In EmberCORE, open the device, go to its SNMP configuration, choose the version, and enter the credentials:

  • SNMPv2c: the community string.
  • SNMPv3: the username, an authentication protocol (MD5 or SHA) and key, and a privacy protocol (DES or AES) and key. Supplying both keys gives you authPriv.

Save it, and the device is polled on the next cycle, within a minute. There is no separate connection test, so check the device's metrics after the first poll. If nothing arrives, the cause is a firewall or the agent roughly nine times out of ten, not the credential.

What gets polled​

Devices are polled every 60 seconds, five at a time, with a 10-second timeout and one retry. What is read depends on the device type you gave it:

DataOIDsPolled for
UptimesysUpTimeEvery SNMP device
InterfacesIF-MIB ifName, ifDescr, ifOperStatus, ifSpeed, 64-bit in and out octets, in and out errorsNetwork, compute, and other devices; not PLCs, robots, or sensors
CPU and memoryHOST-RESOURCES-MIB hrProcessorLoad, hrStorageSize, hrStorageUsedEverything except sensors and cameras
TemperatureENTITY-SENSOR-MIB sensors reporting in CelsiusManaged switches, firewalls, industrial PCs, servers, nodes, and edge AI devices
SessionsTCP established connections (tcpCurrEstab)Firewalls without a vendor session counter
GPUNVIDIA enterprise MIB, or values published through Net-SNMP extendDevices that expose them

Unmanaged switches have no agent and are skipped.

Some vendors get their own OIDs, chosen from the device's vendor field:

VendorExtra data
CiscoCPU over 1 and 5 minutes, memory pool used and free
Fortinet FortiGateCPU, memory, and session count
Siemens SCALANCETemperature
NVIDIAGPU temperature, utilization, memory, power, and fan

The OID set is fixed; you cannot add your own OIDs per device. EmberCORE polls only; it does not receive SNMP traps.

Security​

For v2c, never leave the community string at public, and restrict source addresses on the device itself rather than relying on the network to do it. v2c sends the community string in clear text, so treat it as an access control, not a secret.

For v3, use authPriv with SHA and AES, so traffic is both authenticated and encrypted, and rotate credentials on a schedule. EmberCORE's SNMPv3 supports SHA (SHA-1) and MD5 for authentication, and AES-128 and DES for privacy.

Either way, keep SNMP on a management VLAN with ACLs restricting who can reach port 161.

Troubleshooting​

SymptomLikely causeWhat to do
SNMP unreachableUDP 161 blockedCheck firewall rules along the path
Authentication failureWrong community or v3 credentialsRe-enter them; confirm the version matches the agent
No data after savingAgent not actually runningVerify the SNMP service on the device
Stale dataIntermittent connectivityCheck the network path and round-trip time
TimeoutsLatency or a loaded deviceCheck device CPU and the path; a poll waits 10 seconds

Next steps​