SNMP (Simple Network Management Protocol)
is a standard communication protocol used to monitor
and manage network devices, computer systems, and various
industrial devices.
SNMP allows a central system to monitor device operating
status, network connections, CPU and memory utilization,
temperature, energy values, fault conditions, and other
information provided by the device manufacturer.
SNMP stands for Simple Network Management Protocol.
It is a standard communication protocol used to monitor and
manage devices and systems within a network.
The primary purpose of SNMP is to collect information about
the status of devices and systems and, when required, allow
specific management information to be modified. The protocol
provides communication between a central management system
and an SNMP agent running on a device.
SNMP was originally developed for managing TCP/IP-based
networks. Today, it is widely used to monitor switches,
routers, firewalls, servers, UPS systems, printers,
energy devices, communication equipment, PLCs, RTUs,
and various industrial devices.
One of the important features of SNMP is that it allows
devices from different manufacturers to be monitored through
a standardized management model. The information provided
by a device is defined in a
MIB (Management Information Base) and
addressed using unique identifiers called
OIDs (Object Identifiers).
An SNMP architecture basically consists of two main sides:
the SNMP Manager and the
SNMP Agent.
SNMP Manager
The SNMP Manager is the central application that
monitors devices within a network or industrial
system. It can request information from devices,
modify supported values, and receive notifications
sent by devices.
- Reading data from devices
- Monitoring device status
- Receiving alarms and notifications
- Changing supported parameters
- Centralized device management
SNMP Agent
The SNMP Agent is a software component running
on the monitored device that provides access to
the device's management information. The agent
processes requests received from the Manager
and returns the corresponding information.
- Providing device information
- Providing OID values
- Processing GET and SET requests
- Sending Trap and Inform notifications
- Making device status available for monitoring
In simple terms, an SNMP system can be described as:
the Manager asks, the Agent responds.
In some cases, the Agent can also send a notification
to the Manager when an important event occurs.
SNMP Data Addressing for EOS Software (S#)
In the EOS SCADA SNMP client, the data address
is specified using the SNMP Object Identifier,
or OID.
The address starts with the S# prefix.
S#OID
For example:
S#1.3.6.1.2.1.2.2.1.11.10
The SNMP OID must consist of numerical sections
separated by period characters.
The concepts of MIB and
OID are fundamental to understanding
which information can be accessed from SNMP devices.
MIB
MIB (Management Information Base)
is a structure containing definitions of the
management information provided by an SNMP device.
MIB files are used to describe what specific OIDs
represent, their data types, and how they are
intended to be used.
OID
OID (Object Identifier) is a
hierarchical numerical identifier used to
identify a specific object or piece of information
within SNMP.
For example,
1.3.6.1.2.1.1.3.0
corresponds to a specific SNMP object.
OIDs are organized in a tree structure. Therefore, accessing
a data point in SNMP means querying a specific OID, similar
in principle to the addressing methods used in SCADA systems.
Manufacturers can also provide device-specific information
through their own MIB definitions. Therefore, a manufacturer's
MIB file may be required to read information such as
temperature, power, fan status, or error codes that are
specific to a particular device.
SNMP uses various operation types to read management
information, modify supported values, and report events.
The most common SNMP operations are described below.
GET
Used to read the current value of a specific OID.
For example, device temperature, system uptime,
or port status can be retrieved using a GET request.
GETNEXT
Used to retrieve the next object in the OID tree.
It is particularly useful for traversing tables
and objects within a MIB.
GETBULK
Allows multiple management objects to be retrieved
more efficiently. It is particularly useful for
reading large tables in SNMPv2c and SNMPv3
applications.
SET
Allows authorized users to modify the value of
a supported management object on a device.
However, which values can be changed depends
on the configuration of the device's SNMP agent.
TRAP
Allows a device to automatically notify an SNMP
Manager when an important event occurs.
For example, a communication link failure or
device restart can be reported using a Trap.
INFORM
Similar to a Trap, Inform is used to report events.
However, unlike a Trap, an Inform message can be
acknowledged by the receiver. It can therefore
be preferred when a more reliable notification
mechanism is required.
Different versions of SNMP have been developed over time.
Today, SNMPv2c is widely encountered, while SNMPv3 is preferred
when stronger security capabilities are required.
SNMPv1
The first widely deployed version of SNMP.
It has a simple architecture and supports basic
operations such as GET, GETNEXT, SET, and Trap.
It can still be found in legacy devices and
existing systems.
SNMPv2c
Provides more advanced protocol operations than
SNMPv1. In particular, the GETBULK
operation allows large amounts of management
information to be retrieved more efficiently.
However, community string-based
SNMPv2c does not provide strong security mechanisms.
SNMPv3
SNMPv3 introduces more advanced security mechanisms
to the SNMP management architecture. It can provide
authentication, integrity, and privacy features.
For systems with higher security requirements,
SNMPv3 may be a more appropriate choice than
SNMPv1 and SNMPv2c.
SNMP applications traditionally use UDP-based communication.
UDP 161 is commonly used for requests sent
to SNMP Agents, while UDP 162 is used for
receiving Traps and similar notifications.
UDP 161
The standard port on which an SNMP Agent listens
for normal SNMP requests. Operations such as GET,
GETNEXT, GETBULK, and SET can be performed through
this port.
UDP 162
The standard port used by an SNMP Manager or
Trap Receiver to receive Trap and notification
messages.
Therefore, for a SCADA or centralized monitoring application
to access SNMP devices, the relevant UDP ports must be
reachable through the network and firewall configuration.
How Is SNMP Used in Industrial Systems?
SNMP is primarily used for monitoring and managing devices
and communication infrastructure rather than as a process
control protocol. Nevertheless, it can play an important
role as a complementary communication protocol in many
industrial facilities.
Network Device Monitoring
Switches, routers, firewalls, and other network
devices can be monitored for port status,
traffic values, error counters, temperature,
and similar information.
UPS and Energy Systems
Voltage, current, load, battery status,
operating status, and alarm information can
be obtained from UPS systems, power supplies,
and certain energy devices.
Servers and Computer Systems
Operating status, system resources, network
interfaces, and various manufacturer-specific
parameters can be monitored on servers and
computer systems.
Industrial Devices
PLCs, RTUs, communication devices, industrial
switches, and other field equipment supporting
SNMP can be monitored from centralized systems.
Alarm and Event Notifications
Trap or Inform notifications received from
devices can be forwarded to SCADA, alarm
management, or centralized monitoring systems.
Performance Monitoring
SNMP data collected over time can be archived
and used for trend analysis, performance
monitoring, and capacity planning.
A SCADA system can use SNMP not only to monitor conventional
PLC and RTU data, but also to centrally monitor a wide range
of information related to the facility's communication
infrastructure and auxiliary systems.
For example, in a power generation facility, a SCADA system
can collect process data from PLCs, measurements from energy
devices, and communication status information from network
switches within the same platform.
This approach can help identify problems in the communication
infrastructure at an early stage, even when a device itself
appears to be operating normally.
SNMP data can be used within SCADA systems together with
trending, alarm management, event logging, and reporting
mechanisms. This allows network and device management
information to be evaluated alongside other operational
data of the facility.
Widely Adopted Standard
A standard management protocol supported by
a wide range of network and industrial devices.
Centralized Monitoring
Makes it easier to monitor large numbers of
devices from different manufacturers through
a centralized application.
Simple and Lightweight
Its simple protocol structure makes it useful
for device management and periodic data
collection applications.
Event Notifications
Trap and Inform mechanisms allow devices to
report important events to centralized systems.
Data Archiving
Information collected through SNMP can be
archived as time-series data and later used
for performance analysis.
SNMPv3 Security
SNMPv3 can provide advanced security mechanisms
such as authentication, integrity, and privacy.
Things to Consider When Using SNMP
Although SNMP is a highly useful protocol, it is not by
itself suitable as a process communication protocol for
every application.
-
SNMP was not designed to replace conventional
process control protocols.
-
SNMP support on a device does not necessarily mean
that all device information is accessible through SNMP.
-
Manufacturer-specific information may require the
manufacturer's MIB file.
-
Security requirements should be carefully evaluated
when SNMPv1 or SNMPv2c is used.
-
For critical systems, more advanced security features
such as SNMPv3 should be considered whenever possible.
-
Excessively frequent polling can create unnecessary
traffic and load on devices and networks. Polling
intervals should therefore be determined according
to the application's requirements.
Assume that an SNMP device has the IP address
192.168.1.100.
An SNMP Manager that wants to read a specific OID
from the device can send a GET request for that OID.
For example:
SNMP Agent
IP Address : 192.168.1.100
Port : 161
OID : 1.3.6.1.2.1.1.3.0
When the Manager sends a GET request for this OID,
the SNMP Agent retrieves the corresponding value
and returns it to the Manager in a Response message.
Similarly, when an important event occurs on the device,
the Agent can send a Trap to the Trap Receiver of the Manager.
This means that two basic operating models can be used
together with SNMP:
periodic polling and
event-based notification.
SNMP is a standard communication protocol
developed for network and system management and is supported
by a very wide range of devices.
Through its MIB and OID structure, management information
within devices can be addressed in a standardized manner.
GET, GETNEXT, GETBULK, and SET operations can be used to
query information or modify supported parameters.
Trap and Inform mechanisms allow devices to report events
to centralized systems.
Particularly in SCADA and industrial monitoring systems,
SNMP is an important complementary protocol that allows
network infrastructure, UPS systems, energy devices,
communication equipment, and auxiliary systems to be
monitored alongside PLC and process data within the same
centralized platform.