Routelearn.net
Course menu

Unit 7: TCP, UDP and PortsLesson 7.3.7 (19 of 20 in this unit)52 of 84 in the Network Fundamentals course

SNMP and Syslog

How monitoring systems poll devices and how devices report their own events.

Intermediate · 8 min read

SNMP (Simple Network Management Protocol) and Syslog are network monitoring protocols. SNMP lets a management station read, and optionally change, values in a device’s MIB (Management Information Base) and receive unsolicited alerts called traps; Syslog sends a device’s event messages, each tagged with a severity level, to a central log server.

In simple terms: They let you monitor the whole network from one place. SNMP collects values such as traffic levels and link status, and Syslog collects every device’s event messages on one server.

A situation

At 2 a.m., the uplink on a branch router goes down. Nobody is logged in. You only find out in the morning, when unhappy users start to call. A monitoring system could have told you within seconds. Two protocols make that possible: SNMP and Syslog.

What SNMP is

SNMP (Simple Network Management Protocol) lets a monitoring server, called the NMS (network management station), read information from devices. Each device runs an SNMP agent. The agent keeps its data in the MIB (Management Information Base): a tree of values such as interface status, traffic counters and CPU load. Each value has a numeric identifier called an OID (object identifier).

Step 1 of 4 · Get
NMS
192.168.50.10
Management network
R1 (agent)
10.1.1.1

Polls go to UDP 161 on the device. Traps (and Informs, which are traps the NMS must acknowledge) go to UDP 162 on the NMS.

SNMP versions

Older versions control access with a community string, which is simply a shared password sent in clear text. SNMPv3 adds real security (user authentication and encryption), so it is the version to use.

VersionSecurityNotes
SNMPv1Community string, clear textThe original; obsolete
SNMPv2cCommunity string, clear textAdds GetBulk and Informs; still common
SNMPv3Usernames, authentication and encryptionRecommended. Levels: noAuthNoPriv, authNoPriv, authPriv

What Syslog is

Syslog is the standard way devices send their log messages to a central Syslog server, usually over UDP port 514. Each message has a severity level from 0 (most severe) to 7. When you set a logging level, the device sends that level and every more severe level (the lower numbers).

LevelNameExample
0EmergencySystem is unusable
1AlertAction needed now, for example overheating
2CriticalHardware failure
3ErrorAn interface changed state to down
4WarningA configured limit was reached
5NotificationLine protocol up or down, configuration changed
6InformationalAn ACL matched a packet
7DebuggingOutput of debug commands

💡 A common memory aid: Every Awesome Cisco Engineer Will Need Ice-cream Daily.

Why use both

SNMP is good for values over time, such as how busy a link is or how much memory is free. Syslog is good for events described in words, such as who changed the configuration or which interface went up and down. Most networks send both to their monitoring tools.

R1branch routerCore switchNMS192.168.50.10Syslog server192.168.50.20
  1. 1. Every 5 minutes: the NMS polls R1's interface counters to build traffic graphs.
  2. 2. Something breaks: R1 sends a linkDown trap to the NMS right away.
  3. 3. It is also logged: the same event goes to the Syslog server as a level 3 message.

Configure it

These commands are based on Cisco documentation, not run on a lab device.

snmp-server group NMS-GROUP v3 priv

An SNMPv3 group that requires authentication and encryption (authPriv).

snmp-server user nms-user NMS-GROUP v3 auth sha Auth-Pass-123 priv aes 128 Priv-Pass-123

A user in that group with SHA authentication and AES encryption.

snmp-server host 192.168.50.10 version 3 priv nms-user

Send traps to the NMS using that user.

snmp-server enable traps snmp linkdown linkup

Turn on the link up and link down traps.

logging host 192.168.50.20

Send log messages to the Syslog server.

logging trap informational

Send levels 0 to 6 to that server (debugging stays local).

How to verify it

These outputs are based on Cisco documentation, not run on a lab device.

Example output · based on Cisco documentation; exact format varies by platform and software version
Oct  5 02:04:11.317: %LINK-3-UPDOWN: Interface GigabitEthernet0/0/1, changed state to down
Oct  5 02:04:12.318: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0/0/1, changed state to down
What to look for: read %LINK-3-UPDOWN as facility (LINK), severity (3, Error) and mnemonic (UPDOWN). The second message, %LINEPROTO-5-UPDOWN, is level 5 (Notification). The timestamps only help if the clock is set correctly, ideally with NTP.
Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show logging | include Trap|Logging to
    Trap logging: level informational, 58 message lines logged
        Logging to 192.168.50.20  (udp port 514, audit disabled,
What to look for: Trap logging: level informational means levels 0 to 6 are sent to the server, and Logging to 192.168.50.20 (udp port 514 confirms the Syslog server address and port.
show snmp user

List SNMPv3 users with their authentication and privacy settings.

Check yourself

Predict · scenario 1

You configure logging trap warning on a router. Which messages reach the Syslog server?

Predict · scenario 2

An interface on R1 goes down, and R1 tells the NMS at once, without being polled. Which SNMP message does it send?

Predict · scenario 3

Your security policy says monitoring traffic must be encrypted. Which SNMP version must you use?