A situation
At 2 a.m., the uplink on a branch router goes down. Nobody is logged in. You only find out in the morning, when unhappy users start to call. A monitoring system could have told you within seconds. Two protocols make that possible: SNMP and Syslog.
What SNMP is
SNMP (Simple Network Management Protocol) lets a monitoring server, called the NMS (network management station), read information from devices. Each device runs an SNMP agent. The agent keeps its data in the MIB (Management Information Base): a tree of values such as interface status, traffic counters and CPU load. Each value has a numeric identifier called an OID (object identifier).
Polls go to UDP 161 on the device. Traps (and Informs, which are traps the NMS must acknowledge) go to UDP 162 on the NMS.
SNMP versions
Older versions control access with a community string, which is simply a shared password sent in clear text. SNMPv3 adds real security (user authentication and encryption), so it is the version to use.
| Version | Security | Notes |
|---|---|---|
| SNMPv1 | Community string, clear text | The original; obsolete |
| SNMPv2c | Community string, clear text | Adds GetBulk and Informs; still common |
| SNMPv3 | Usernames, authentication and encryption | Recommended. Levels: noAuthNoPriv, authNoPriv, authPriv |
What Syslog is
Syslog is the standard way devices send their log messages to a central Syslog server, usually over UDP port 514. Each message has a severity level from 0 (most severe) to 7. When you set a logging level, the device sends that level and every more severe level (the lower numbers).
| Level | Name | Example |
|---|---|---|
| 0 | Emergency | System is unusable |
| 1 | Alert | Action needed now, for example overheating |
| 2 | Critical | Hardware failure |
| 3 | Error | An interface changed state to down |
| 4 | Warning | A configured limit was reached |
| 5 | Notification | Line protocol up or down, configuration changed |
| 6 | Informational | An ACL matched a packet |
| 7 | Debugging | Output of debug commands |
💡 A common memory aid: Every Awesome Cisco Engineer Will Need Ice-cream Daily.
Why use both
SNMP is good for values over time, such as how busy a link is or how much memory is free. Syslog is good for events described in words, such as who changed the configuration or which interface went up and down. Most networks send both to their monitoring tools.
- 1. Every 5 minutes: the NMS polls R1's interface counters to build traffic graphs.
- 2. Something breaks: R1 sends a linkDown trap to the NMS right away.
- 3. It is also logged: the same event goes to the Syslog server as a level 3 message.
Configure it
These commands are based on Cisco documentation, not run on a lab device.
snmp-server group NMS-GROUP v3 privAn SNMPv3 group that requires authentication and encryption (authPriv).
snmp-server user nms-user NMS-GROUP v3 auth sha Auth-Pass-123 priv aes 128 Priv-Pass-123A user in that group with SHA authentication and AES encryption.
snmp-server host 192.168.50.10 version 3 priv nms-userSend traps to the NMS using that user.
snmp-server enable traps snmp linkdown linkupTurn on the link up and link down traps.
logging host 192.168.50.20Send log messages to the Syslog server.
logging trap informationalSend levels 0 to 6 to that server (debugging stays local).
How to verify it
These outputs are based on Cisco documentation, not run on a lab device.
Oct 5 02:04:11.317: %LINK-3-UPDOWN: Interface GigabitEthernet0/0/1, changed state to down Oct 5 02:04:12.318: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0/0/1, changed state to down
%LINK-3-UPDOWN as facility (LINK), severity (3, Error) and mnemonic (UPDOWN). The second message, %LINEPROTO-5-UPDOWN, is level 5 (Notification). The timestamps only help if the clock is set correctly, ideally with NTP.R1#show logging | include Trap|Logging to Trap logging: level informational, 58 message lines logged Logging to 192.168.50.20 (udp port 514, audit disabled,
show snmp userList SNMPv3 users with their authentication and privacy settings.
Check yourself
You configure logging trap warning on a router. Which messages reach the Syslog server?
An interface on R1 goes down, and R1 tells the NMS at once, without being polled. Which SNMP message does it send?
Your security policy says monitoring traffic must be encrypted. Which SNMP version must you use?