Open In App

SNMP in Wireshark

The Internet Architecture Board (IAB) defined the Simple Network Management Protocol (SNMP) as an application-layer protocol for transmitting management data between network devices in RFC1157. It belongs to the TCP/IP (Transmission Control Protocol/Internet Protocol) protocol family. One of the extensively used network protocols for managing and watching over network components is SNMP. The majority of network components of professional qualifications include an integrated SNMP agent. To connect with the network monitoring tools or network management system, these agents must be activated and set up (NMS). UDP is frequently used by SNMP as its transport protocol. 161 (SNMP) and 162 are well-known UDP ports for SNMP traffic (SNMP TRAP). Additionally, it is compatible with TCP, Ethernet, IPX, and other protocols. The ILMI (Integrated Local Management Interface) protocol used by ATMs is SNMP.

SNMP Protocol Versions:

SNMP version 1: Developed in the 1980s, this is the standard version of SNMP. It is regarded as the least reliable choice. Low-level security is supported by SNMP v1, which transfers data “clearly” without encryption. The type of data that can be returned is constrained by the fact that this version was created to handle 32-bit counters.



SNMPv2: Developed in the 1990s, SNMPv2 is an update to version 1 that boosts security and performance but does not employ encryption. Additionally, it included a choice for 64-bit counters to accommodate larger interfaces and additional ways for Getbulkrequest to retrieve greater amounts of data (e.g., 10Gb).

The most recent version, SNMP v3, leverages the capability of the base protocol with the addition of cryptographic security to improve data privacy and authenticity capabilities. This offers a more improved variation of the protocol that is best suited to secure device access and optimize performance.



SNMP Basic Components:

SNMP Fundamental Commands:

The following are the basic commands of SNMP-

SNMP Configuration Types:

There are two different SNMP Configuration Types: Read-only and read-write community strings are used by SNMP to exchange data. Both of them can be set up to allow public access or to forbid unauthorized alterations.

Display SNMP in Wireshark:

Following are the steps to display SNMP in Wireshark

SNMP Enterprise Specific Trap Type in Wireshark:

This table is used by Wireshark to map certain trap values to user-defined descriptors in a Trap PDU. The packet details specific-trap elements, and the description is displayed. This is a user table consisting of the following fields:

Captured Traffic on Wireshark:

 

Article Tags :