SNMP Discovery for Industrial Asset Inventory

Overview

SNMP supplies identity, interface, physical-component, VLAN, and topology data across managed switches, controllers, servers, and other networked equipment. It is enabled by default and uses SNMPv2c with community public when no settings are configured.

How OTserver discovers assets with SNMP

OTserver connects to UDP port 161 with SNMPv1, v2c, or v3 settings from the snmp block of executable-adjacent otter.json. It starts with a multi-value GET for system description, object ID, name, and location, then walks selected bounded MIB tables. SNMP probes configured IPv4 targets even when Layer 2 discovery found nothing, but creates an asset only after obtaining a valid interface, bridge, or LLDP chassis MAC.

SNMPv3 supports MD5 and SHA-family authentication plus DES or AES privacy options. Settings can be edited in the GUI and credentials are never written to scan exports or logs. Opt-in auto mode tries usable v3 settings, then v2c, then v1 within the per-target timeout; explicit version selections never fall back.

Evidence extracted

OTserver evidenceMIB source
Description and operating-system hintsysDescr.0
NamesysName.0
LocationsysLocation.0
InterfacesIF-MIB description, MTU, speed, MAC, admin state, and operational state
High-speed interfacesIF-MIB ifHighSpeed
Firmware, serial, vendor, and modelENTITY-MIB physical inventory
Ports and VLANsBRIDGE-MIB and Q-BRIDGE-MIB
Siemens identityAUTOMATION-SYSTEM-MIB identity scalars
Additional network evidenceIP-MIB address and forwarding tables

Ordinary table walks are limited to 512 rows, forwarding tables to 4,000 rows, and SNMPv1 forwarding tables to 128 rows. Queries are bounded to 30 seconds per target, and optional tables that a device does not expose are skipped without discarding valid system evidence.

Security and read-only safety

OTserver uses SNMP GET and WALK only; it never sends SNMP SET. Prefer SNMPv3 authentication and privacy where devices support it, give the scanner a read-only account, and restrict access with device ACLs. SNMP inventory and LLDP topology discovery have independent scanner toggles even though both use the same settings.

Frequently asked questions

Can OTserver scan SNMP without configuring credentials?

Yes. Without SNMP settings, the scanner uses SNMPv2c with community public, so SNMP does not block a scan. Keep otter.json out of source control and restrict its permissions when it contains credentials.

Does OTserver use vendor-specific MIBs?

The scanner uses standard system, IF-MIB, IP-MIB, BRIDGE-MIB, Q-BRIDGE-MIB, ENTITY-MIB, and LLDP trees, plus generic Siemens AUTOMATION-SYSTEM-MIB identity scalars. It preserves returned OIDs as raw evidence and does not perform vendor-specific writes or control operations.

Compare all supported discovery protocols or configure the scanner.