SNMP Configuration
Device Monitor can tell you whether a device is reachable without any configuration at all. To get CPU, memory, temperature, interface status, and throughput out of it, the device needs an SNMP agent and EmberCORE needs credentials for it.
Once saved, secrets are never sent back to the browser: EmberCORE shows only whether a community string or SNMPv3 keys are set.
| Requirement | Detail |
|---|---|
| Protocol | UDP |
| Port | 161 on the device |
| Direction | Platform to device, outbound only |
| Versions | SNMPv2c (community string) and SNMPv3 (user-based security). SNMPv1 is not supported. |
Allow UDP 161 from the platform's address range to your device management VLAN.
Step 1: Enable the agent on the device
The specifics vary by vendor, but the shape is always the same: turn the agent on, set a credential, and restrict which source addresses may query it.
Cisco IOS:
configure terminal
snmp-server community <read-only-community> ro
snmp-server location "Building A, Rack 3"
snmp-server contact "ops@example.com"
exit
write memory
On Cisco, one extra line makes interface data far more useful over time, because it stops interface indexes from renumbering across reboots:
snmp-server ifindex persist
FortiGate:
config system snmp sysinfo
set status enable
set location "Building A"
end
config system snmp community
edit 1
set name "<read-only-community>"
set status enable
config hosts
edit 1
set ip <platform-cidr>
next
end
next
end
Linux hosts and industrial PCs:
sudo apt install snmpd snmp -y
Then in /etc/snmp/snmpd.conf:
rocommunity <read-only-community> <platform-cidr>
syslocation "Building A, Rack 5"
syscontact "ops@example.com"
sudo systemctl enable --now snmpd
Appliances with a web UI (Palo Alto, pfSense, UPS and PDU controllers) all follow the same path: find SNMP under device or network settings, enable the agent, set the v2c community or v3 credentials, and apply.
PLCs and industrial cameras vary by vendor and runtime, and many implement SNMP partially or not at all. Check the vendor's documentation for what the agent actually populates before relying on it.
Step 2: Add the credentials
In EmberCORE, open the device, go to its SNMP configuration, choose the version, and enter the credentials:
- SNMPv2c: the community string.
- SNMPv3: the username, an authentication protocol (MD5 or SHA) and key, and a privacy protocol (DES or AES) and key. Supplying both keys gives you authPriv.
Save it, and the device is polled on the next cycle, within a minute. There is no separate connection test, so check the device's metrics after the first poll. If nothing arrives, the cause is a firewall or the agent roughly nine times out of ten, not the credential.
What gets polled
Devices are polled every 60 seconds, five at a time, with a 10-second timeout and one retry. What is read depends on the device type you gave it:
| Data | OIDs | Polled for |
|---|---|---|
| Uptime | sysUpTime | Every SNMP device |
| Interfaces | IF-MIB ifName, ifDescr, ifOperStatus, ifSpeed, 64-bit in and out octets, in and out errors | Network, compute, and other devices; not PLCs, robots, or sensors |
| CPU and memory | HOST-RESOURCES-MIB hrProcessorLoad, hrStorageSize, hrStorageUsed | Everything except sensors and cameras |
| Temperature | ENTITY-SENSOR-MIB sensors reporting in Celsius | Managed switches, firewalls, industrial PCs, servers, nodes, and edge AI devices |
| Sessions | TCP established connections (tcpCurrEstab) | Firewalls without a vendor session counter |
| GPU | NVIDIA enterprise MIB, or values published through Net-SNMP extend | Devices that expose them |
Unmanaged switches have no agent and are skipped.
Some vendors get their own OIDs, chosen from the device's vendor field:
| Vendor | Extra data |
|---|---|
| Cisco | CPU over 1 and 5 minutes, memory pool used and free |
| Fortinet FortiGate | CPU, memory, and session count |
| Siemens SCALANCE | Temperature |
| NVIDIA | GPU temperature, utilization, memory, power, and fan |
The OID set is fixed; you cannot add your own OIDs per device. EmberCORE polls only; it does not receive SNMP traps.
Security
For v2c, never leave the community string at public, and restrict source
addresses on the device itself rather than relying on the network to do it. v2c
sends the community string in clear text, so treat it as an access control, not a
secret.
For v3, use authPriv with SHA and AES, so traffic is both authenticated and encrypted, and rotate credentials on a schedule. EmberCORE's SNMPv3 supports SHA (SHA-1) and MD5 for authentication, and AES-128 and DES for privacy.
Either way, keep SNMP on a management VLAN with ACLs restricting who can reach port 161.
Troubleshooting
| Symptom | Likely cause | What to do |
|---|---|---|
| SNMP unreachable | UDP 161 blocked | Check firewall rules along the path |
| Authentication failure | Wrong community or v3 credentials | Re-enter them; confirm the version matches the agent |
| No data after saving | Agent not actually running | Verify the SNMP service on the device |
| Stale data | Intermittent connectivity | Check the network path and round-trip time |
| Timeouts | Latency or a loaded device | Check device CPU and the path; a poll waits 10 seconds |
Next steps
- Device Monitor: where the polled data appears
- Connectivity: getting devices onto the network first
- Alerts & Notifications: alerting on what SNMP reports