Showing posts with label SNMP. Show all posts
Showing posts with label SNMP. Show all posts

Tuesday, September 5, 2017

Managed Switch Port Mapping Tools v2.77.1 released August 30, 2017

Version 2.77.1 followed closely behind the release of 2.77. This minor release adds serial and model retrieval from Adtran switches. It also fixes some minor issues with importing devices from a text file in Switch List editor. SQLite was updated as well.

Version 2.77 was a huge release.

Managed Switch Port Mapping Tool v2.77 adds several features to enhance the user experience plus new features including one that has been requested a number of times for several years.

One of the most requested features (for years) is this: a way to compare two mappings of the same switch to see what has changed. It is now there under Review History (left control panel):




Select at mapping from the left list, then select one from the right list. Press ‘Show Added & Removed’ to see a list of what is present only in the first mapping (green) and the second mapping (blue) as shown below.



To see a list of devices moved from one port to another between mappings, press Show Moved. The final port that the device was moved to is shown in the list.



Another major addition is the ‘Test’ button. You can find it in the device settings. It give you a way to see if the device (switch or router or other) can be pinged and communicated with using the SNMP settings you have entered. See below:



Do you have Juniper, Ubiquiti and Force10 switches? We improved support for those switches and we even found that some models of Adtran switches can be mapped – but not all.

Full list of changes in this revision.

2.77 August 18, 2017

-Added button in Review History for comparing and displaying the differences between two mappings of the same switch at different times. One selection shows the difference between information present on the first switch mapping vs the second switch mapping. The other selection shows movement of a device from one port to a new port. The results of the comparisons may be saved/exported/printed.


-Added Test button to Device Settings. Use it to verify the device is reachable with Ping and verify your SNMP settings are correct. It also can tell you if it is a switch or a different kind of SNMP enabled device.

-The target switch is now tested near the start of the mapping to see if it really is a switch, if not a 'do you want to continue' question is asked.

-Additional sources of warning messages during SNMP single parameter retrievals were identified and the warning suppressed. The warnings were sometimes interpreted by users as errors and slowed the mapping process.

-New Command Line option (-txt) to save the results of a mapping to a hybrid tab/CSV delimited text file. Columns are represented by tabs and rows within a multi-row cell are represented by commas.

-Improved export to 10SCAPE. If required columns are missing, a warning is now shown at export.

-Column Order and Visibility Editor: the 10SCAPE defaults button now turns off the Ping Sweep warning (see Global Settings to reactivate it).

-Global Settings: the Display Ping Sweep Not Configured warning message is now disabled by default.

-Global Settings: when switch group specific settings (like MAC limit per port) are changed, the changes are now saved to the currently shown left panel switch group.

-Switch List Editor: show final report and show individual reports are now unchecked by default.

-Framework: menu and toolbar are now fixed in place and not dockable.

-Framework: top titlebar is now correctly updated to show the switch info when the mapping is complete.

-Juniper, Force10 and Ubiquiti switches are now processed correctly and manufacturer specific details are now retrieved.

-Some models of Adtran switches are now supported.

-Juniper switches now show the vlan name, internal vlan number and vlan tag as follows with the tag in curly braces: MYVLAN(5){100}. Other switch brands will continue to show MYLAN(5) or 5 where 5 is the vlan number.

-In order to speed up the switch list mapping process, the column widths are no longer automatically resized in list mode.

-VLAN identification for older 3COM switches was improved.

-Improvements to data shown in vlan columns.

-Fixed SQL syntax problem in lldpLocChassisId when subtypes 1-7 are present.

-Fixed usability problem with device settings editor where selections from existing community names would not appear to 'stick'.

-Fixed XML export where switch information is added in the left column.

-Added System Description to CDP data.

-New information added to SNMP Error Report.

-Changed Review History icon.

-Updated SQLite to version 3.20.0

-Updated MAC address/Manufacturer database.

Download the ‘installed’ version 2.77 from SwitchPortMapper.com and install it over the top of your current installed version.


USB version users need to use the Help Menu/Check for Update selection to obtain the upgrade patch.

Wednesday, January 15, 2014

How to send SNMP Traps from a Netgear GS724T switch

Getting your Netgear GS724T switch to send SNMP Traps requires several steps beyond the obvious enabling of traps and defining where the traps are being sent to. Here are the steps. This procedure works with Software Version 5.4.2.9 or .10.

Use your web browser to connect to the switch. Enter the password to login. The default password is password

1. Make sure you turn off the Port Authentication settings you may have enabled.

1a. Security\Port Authentication\Advanced\802.1X Configuration: "Disable" all options, then click apply (lower right corner of window).



1b. Security\Port Authentication\Advanced\Port Authentication: Select all ports and set Port Control = "Auto", then click apply.



2. Security\Traffic Control\Port Security\Port Security Configuration: Click Enable, then click apply.



3. Security\Traffic Control\Port Security\Interface Configuration

a. Select all ports
b. Port Security = "Enabled"
c. Max Allowed Dynamically Learned MAC = "600"
d. Max Allowed Statically Locked MAC = "20"
e. Enable Violation Traps = "Yes"
f. Click Apply


4. Enable Trap Flags. System\SNMP\ SNMPv1/v2\Trap Flags: select the trap types you want to be sent, then click apply.


5. Select the trap destination IP addresses. System\SNMP\ SNMPv1/v2\Trap Configuration: Enter the receiver's IP address, version of SNMP, community string and enable, then click Add, then Apply in the lower right corner.


6. Your switch should now be sending traps. You do not have to reboot it.

You can test whether the traps are being sent or not by using Wireshark on the receiving machine and look for SNMP trap packets (use the filters). Disconnect and reconnect an active device on the switch to force it to send link up/down and mac address change traps. You can also review the trap log by going to Monitoring\Logs\Trap Logs:


This was not an intuitive procedure, I will not take credit for it - the procedure came from their Tech Support - but it does work - have fun with it!

Saturday, December 21, 2013

Managed Switch Port Mapping Tool v2.21 released December 20, 2013

This is an important release - especially if you rely on the history database (history.db3) for anything. There was a problem writing multirow mac address, IP address, hostname and interface manufacturer cells (ports with several devices attached to them, like other switches) to the history database. This has been corrected along with several other minor changes. I also move to address an issue with SQLITE_BUSY message handling, so if you are on a slow computer with a slow hard drive, it should work better for you.

You can download this release from http://www.SwitchPortMapper.com/ or from NetScanTools.com. We've also recently added an FTP link for those of you with a strange problem downloading using older versions of Internet Explorer. FTP seems to work, while HTTP on old IE sometimes results in a corrupted zip file. I have no idea why that's happening because the problem shows up for those people no matter which site they download from. Strange.

This release has been fully tested on Windows 8.1, 7 and XP. Other operating systems newer than XP should work fine.

Here is the list of detailed changes:
-Corrected problem saving multirow cells (ports with 2 or more attached mac addresses) to the history database. This affects MAC Address, IP Address, Hostname and Interface Manufacturer columns.
-Changes to SQLite interface to better handle the rare occurrence of SQLITE_BUSY messages.
-Improved retrieval of serial number, model number and software versions from Netgear switches.
-Added analysis of used/unused Gigabit Ethernet (type 117) ports on a switch.
-Added new table to history database saving the dot1dBasePortIfIndex for future use.
-Added checkboxes to control the visibility of the auth and priv passwords in the SNMPv3 settings window.
-Added warning to SNMPv3 settings window regarding AuthPriv mode when the database is unprotected.
-Improved SNMPManager utility to better check versions of libeay32.dll.
-Updated SQLite to version 3.8.2
-Updated MAC address/Manufacturer database.

Wednesday, July 10, 2013

Configuring Cisco IOS Switches to work with SNMPv1 or v2c

In order to use Cisco switches with the Managed Switch Port Mapping tool, you need to have at least SNMPv1 or v2c running. You can do this with one line in the running-config.

1. from CLI, type enable followed by enter. You may need to enter a password.
2. switch# config term
3. switch(config)# snmp-server community public ro
^this makes it read only with the community name public, you can add rw at the end for read/write. You can use any community name that makes better sense, but remember that SNMPv1 and SNMPv2c are plaintext packets meaning they can be captured and read in Wireshark or any packet capture tool.
4. switch(config)# end or use CTRL-Z
5. switch# write memory

You should be able to map the switch immediately.

Friday, April 8, 2011

NetScanTools Pro 11 finally released!

After a year+ of work, NetScanTools Pro version 11 was released. There are many new and improved things in this release that I'm sure you will be interested in. This is a true major release.

New Interface - completely update and it is still an 'outlook' style interface, there is a left panel control bar and tools appear on the right side. This new interface gives us the ability to bring back 'Favorites' - something that was present in the old 'tabbed' interface of the earlier versions of NetScanTools Pro. You can see a slideshow of it in the screenshot section of the product grid on http://www.netscantools.com/.

The goal of this release was to enhance yet simplify by clearly showing the intended use of each tool. This meant that some tools were split into two parts, for example the ARP tool became the ARP Cache Tool and the ARP Scan Tool. Some tools and things within tools were renamed to conform to industry standard conventions, for example 'Setup' was a more common term when NetScanTools was first released, but now 'Settings' is more common and better understood.

New Tools - Connection Monitor, MAC Address to Manufacturer, Network Interfaces - Wireless, Routing Table - IPV4, and SNMP Scanner Tool.

Additions to current tools:

DNS Tools - Core now has IPv6 Simple Query lookups, Get Basic DNS Records now retrieves the IPv6 AAAA records, we added Flush Default DNS Cache and Edit DNS HOSTS File.

DNS Tools - Advanced has three new tools, IPv4 or Hostname to ASN, Get VOIP SRV Records and Get Misc SRV Records.

Packet Generator now supports sending ARP/RARP packets and RAW packets. RAW packets means that you craft the whole packet from the destination and source ethernet header MAC addresses all the way to the end. And we've added a new tool to help you do that: a Hex Editor.

Ping now supports IPv6 addresses.

Ping Scanner (AKA NetScanner) has the ability to translate IPv4 addresses using either the Default System DNS or a specific DNS. We also added Scan Delay Time to slow it down if necessary and added a way to import an IPv4 list into it. To simplify results, we made the columns dynamic in other words they appear and disappear according to the additional scan tasks settings.

Port Scanner was completely rewritten and works much better than the v10.x predecessor. It's much faster and more accurate. We've added a section for scanning commonly used ports and there's an editor for that list in case you need to change it.

Promiscuous Mode Scanner adds the Multicast Address 3 test.

Service Lookup replaces the old Database Tests.

SMTP Server Tests now supports STARTTLS and you can select the Protocol (TLS1, SSL2, SSL3), Algorithm (DES, 3 DES, MD5, RC4, SHA) and Minimum Key (40-256 bit) Preferences (not all settings are supported in all operating systems).

SNMP was split in two for clarity, Core and Advanced. It now supports all modes of SNMPv3 (you may need to obtain the OpenSSL libeay32.dll for support the authPriv encrypted mode - we cannot distribute that). We have added WalkBulk, GetNext and GetBulk to the Core tool. The Advanced tool has a launcher for both the Dictionary Attack Tool and the new SNMP Scanner Tool. The Dictionary Attack tool is much faster than before in terms of loading a list of IPs and clearing the display.

Whois now supports IPv6 input queries and if you enter a domain, we attempt to do an IPv6 and IPv4 address resolution on the 'www.' prefixed hostname. History buttons have been added so that you can view previous whois queries made during the current session.

This brings us to overall design considerations. Favorites was a common request during the lifetime of version 10. It was not easily done in version 10, but it was a priority goal in version 11. You can now check a box on each manual tool to add it to the left panel Favorites group. As in NetScanTools LE, we now have a mandatory results database. This is required so that we can bring up historical reports from each tool both manual and automated. Automated Tools was completely rewritten. The Automated Tools use an engine to operate each manual tool given the input and the results are saved to the database. In previous versions, the Automated tools were actually a duplicate of the manual tool that did the same action - not efficient. Running more than one tool at a time is important to some customers, so this new program shell gave us the methods for doing so. As in 10.x, reports are shown in the web browser - the database gives us the method to be able to show old reports from other sessions. The left panel now has tool groupings like DNS Tools, Packet Tools etc. This helps users find tools they need quickly. IPv6 will be a focus of version 11. We have some support in there now, but as version evolves, more IPv6 compatibility will be added - stay tuned!

Please review the video and image gallery on the main netscantools.com page. More information will be posted shortly along with new images and videos.

Tuesday, January 11, 2011

Managed Switch Port Mapping Tool v1.99.2 Released

Last night I released a new minor revision to the Managed Switch Port Mapping Tool. "Minor" is in the eye of the beholder. In reality, there were some big internal changes:

The SNMP engine was upgraded to v5.5. The complete effects of this are unknown, but may help out some mappings due to different SNMP implementations. I've been using this version of the SNMP engine for several months in the development of NetScanTools Pro v11.

The SQLite DLL was upgraded to 3.7.4. SQLite is arguably the most widely distributed non-client/server database engine. It's in your iPhone, Firefox and more.

Other changes were also important but less recognizable. We had one user who had problems with the Switch Port Mapper hanging up. Together we found that it was a corrupted snmp.tmp file. This new version deletes that file automatically when you exit the software and also deletes the html report .tmp file.

Another user had a strange problem a couple weeks ago and it was what accelerated this release. Someone at his university had a MAC with a dynamically updated DNS name of "John's MAC" (with the double quotes). First of all DNS names are not to have single quotes or spaces in them - it is a violation of DNS RFCs - why the DNS accepts them I have no idea. When our software tried to execute the SQL command with that extra quote, it failed because single quotes are used to define strings in SQL. So now our software removes single and double quotes returned by DNS.

The final important change was to the way VLANs were handled. The change corrected the VLAN results shown when you map a Cisco Small Business SF 300-08 switch. Previously there were 'extra' VLANs noted like vlan 0 which doesn't exist.

In case you are wondering, the Managed Switch Port Mapping Tool is Windows compatible software used to discover MAC and IPv4 addresses of devices connected to an SNMP managed network switch. If any of this interests you, please visit http://www.switchportmapper.com/ or http://www.netscantools.com/spmapmain.html

Friday, September 24, 2010

Week Recap

It's been a busy week. I spent alot of time dealing with CRT issues moving the SNMP tool set into NetScanTools Pro 11. The final set of SNMP tools will be put in there today, then I have to finish up a few tools that were left unfinished.

Yesterday I ordered a new Cisco 300 Series Managed Switch from Newegg to see how it performs with the Managed Switch Port Mapping Tool. This is a new series of switch that Cisco announced on Wednesday. The documentation says that it supports SNMP v1, 2c and 3, so I want to see if it can be mapped from the switch port mapper. I should be getting it on Tuesday, so I'll replace an old Linksys Etherfast 4116 with it, then we'll see what happens. I'm curious to know if the SNMP implementation follows the Cisco codebase or is a continuation of the old Linksys code. I guess I'll find out.

I'm also looking for boxshot software - I don't know which is the best, so I'll take any comments.

Monday, January 11, 2010

SNMP Scanning


What do we mean by SNMP Scanning? For the purposes of this article, it means scanning a range of IP addresses to see what devices are running SNMP servers. Some people call this SNMP Community Name guessing or bruteforcing.

What is SNMP and what is it used for? SNMP stands for Simple Network Management Protocol. It's used by network devices like routers and switches to report information about the device. Even a Windows computer can be made to divulge information using SNMP! (Windows does not install it by default). This information can be device information like temperature, packet counts or packet statistics or even IP addresses of devices connected to the device. The info is arranged in a heirarchical order somewhat like directories on a hard drive.

SNMP comes in 3 flavors or versions: 1, 2c and 3. Most devices support 1 and 2c, while newer devices will support v3 and usually have backwards compatibility with versions 1 and 2c. Versions 1 and 2c are very similar and report data to a client if the client includes a simple plain text password-like phrase called a 'community name'. We're going to limit our discussion to v1 and v2c.

SNMP usually runs on UDP port 161. Some people like to put it on an alternate UDP port to avoid what we are going to do in this article. Since it's a UDP based protocol, there is no full connection, so when we talk to an SNMP server it won't respond to us unless the question we are asking is correct. There are two essential parts of the question: the MIB item we are asking for and the community name (password) to get it. Both have to be correct to get a good response.

Back to the point of this article. How do you find the devices in your network running SNMP? One way is to do a Port Scan of every device in the IP range on port 161. This might work, but since SNMP is UDP you are depending on the targets returning an ICMP Port Unreachable message to you if the device is NOT running SNMP. This is a lot to ask, especially if the devices have a firewall or are set to not reply with ICMP. You run the risk of lots of false positives with port scanning.

Another way is to use a specialized tool called SNMP Dictionary Attack which is part of NetScanTools Pro. This tool can make an SNMP query to each IP address and it can send known or common community names to the devices. If you are a network administrator, you already know what the community names of your devices are, so here's a shortcut that you may want to try (if not, then skip this). Locate dctnry.txt in your NetScanTools Pro installation directory and open it with notepad. Enter your common community names at the beginning of the list, one per line and save it (we are going to improve this soon).

Using NetScanTools Pro to scan for SNMP servers on devices. Start NetScanTools Pro and locate the SNMP tools under the Tools left panel group. Select Dictionary Attack under the dropdown list labeled Select SNMP Action. Press Perform Action (no other settings are necessary). This opens the tool.

Now press the Target List Editor button on the left panel to open the editor. You can do one of several things here. You can enter IP addresses one at a time or you can define a range of IPs or you can import a list of IPs. The bigger the list, the longer the scan takes - recommend 256 or less IPs. Once you have created your list press OK and then press Setup. In Setup you can define the SNMP version(s) you want to use. If you choose both v1/v2c, it takes twice as long to scan. You can also adjust the time to wait for an SNMP response. Once you are satisfied with the values, press OK and now we are ready. Put the 'Attack Speed' in the middle range and press the 'Attack' button.

The scan proceeds with the results being presented in the grid as they are found. If the device responds to the SNMP queries, you will see 'Community Name Found' along with the community name, version and system name. If not, you will see 'No SNMP on this device' if an ICMP message came back. You may also see a definitive 'No route to device' if you are on the same subnet as the device. If you edited the dictionary list first, this process will go pretty quickly if you are on the same subnet, but it may take awhile if you are scanning devices outside your subnet.

You can watch the scan status on the lower bar. This tool will work best on the same subnet as the devices, but it is not limited to that subnet (the demo version is limited to the local subnet). While you watch it scan, if the device status is blank, it will continue to try community names until it exhausts the list or the device responds.

When you are done or when you feel the scan has gone on long enough, you can review the results. You should be able to see which devices are running SNMP and their community names.

This is a brute force password guessing tool that will show SNMP responses if the device is running SNMP and you have the correct community name. It scans a list of IP addresses and tests them with multiple SNMP queries in an attempt to get a response. It can take awhile and the community name may not be in the dictionary, so you may not be able to find the community name. We have created a fairly comprehensive list and it does cover many common passwords like the default 'public' and 'private'. Try out the tool in our demo or if you have the full version, give it a try. The demo is here: http://www.netscantools.com/nstprodemorequest.html

As with all scanning tools, we must warn you that your actions may be construed as hostile and may violate local laws. So you need to limit your scans to your own systems or have the permission of the IP address range owner before scanning. There will be lots of traffic directed toward the SNMP port, so intrusion detection systems (IDS) will see it. This is not a stealthy scan operation.

Monday, October 12, 2009

SNMP Snooping, Adding MIBs and other stuff

Those of you who perhaps use Wireshark on a regular basis are aware that SNMP traffic randomly occurs on your network, particularly from printers. On October 7 Laura Chappell posted a short article called "SNMP Snooping". In the article Laura talks about using NetScanTools Pro to have a look at the SNMP information available from a wireless HP printer. She talks about pulling out reams of statistics including Wireless SSIDs and WLAN signal strength. This is all done by simply 'Walking' the .1.3.6.1 OID. Even more interesting are the printer's listening ports - also something reported by the NetScanTools Pro SNMP Tool (he is how: set the IP and community name, select Advanced Queries, press Perform Action, then press Listening Ports Report).

Laura will be talking about SNMP and NetScanTools Pro during her Summit '09 Conference in December. The article is here (at least until Weds, Oct 14):
http://www.chappellseminars.com/index.html

Laura also mentions that she had to add MIBs to the SNMP tool in order to understand the data from the printer. Without the printer MIBs translating the numbers to human readable information, the Walk results are just numbers or strings and don't really look too interesting. Today we added a new video explaining why you need to do this and how to add a MIB to NetScanTools Pro. This even works with the NetScanTools Pro Demo:
http://www.netscantools.com/videos/snmpaddamib/snmpaddamib.html

Friday, January 16, 2009

Next Switch Port Mapper Version almost ready

1.96 is almost ready. I've almost finished the documentation -- quite a few changes there especially in the new expanded "Getting Started" section.

The biggest thing about this version is the change from global setting of the SNMP parameters to individualized settings saved for each SNMP device. That way one can use SNMP v1 and another can use SNMP v2c or maybe even be on a non-standard port number -- whatever. Another significant change is in the look of the left side control panel. It's more organized now and hopefully easier to understand. The final significant change is in the XML export. It now conforms better to the XML standards Microsoft uses for Excel. After all the results are in a spreadsheet. The column widths are correct and the font is now supplied. It just plain looks better when you import it into Excel. If you don't have Excel, that's not a problem -- it also works with OpenOffice 3's Calc. It imports in just fine if you select the MS Excel 2003 XML import filter.

Look for it early next week. And one more thing, this is probably the last 1.x version. The internal and visible changes made in 1.96 were necessary to support the new cool things coming in 2.0...

Thursday, December 18, 2008

New NetScanTools (TM) Pro Version 10.80

The newest release of NetScanTools Pro is finally done. This is the long form (or long-winded) explanation of some of the changes made in 10.80.

Several major changes have been made and they are mostly in the area of DNS Tools because that is where customer interest has been taking us. Current users take note -- the Name Server Lookup manual tool is GONE: but don't worry, it was reworked and renamed DNS Tools - Core. A few of the tools formerly on the Name Server Lookup tool were move to the new DNS Tools - Advanced tool, along with new tools. We have brought back the manual Zone Transfer tool where you specify the authoritative DNS to retrieve the zone from. New DNS Tools have been added including a DNS Version tool that retrieves the software version of the DNS, an Auth Serial Check used to compare the zone serial numbers of primary and secondary DNS, a new SPF/Domain Keys record retrieval tool and both DNS Tools groups have a new Batch Processing function. Batch Processing allows you to run the tools with a list of IPs, domain names or hostnames which is really handy if you have a group of queries to make. Autosave is included in both DNS Tools groups. There will be even more additions to the DNS Tools groups in future releases.

Speaking of Autosave, it has been added SNMP and to Traceroute. What is Autosave? It is a simple method of saving the results of all queries from a tool to a single user-defined text file. That way you can review all the data you have done in SNMP or Traceroute or the DNS Tools. Eventually we would like to put Autosave into every place it makes sense and SNMP and Traceroute were two that needed it the most right away.

SNMP has also had a minor facelift. The annoyingly short width OID entry field was made wider -- alot wider so that you can see what was entered before. The list of SNMP actions has been labeled too. The setup window has been improved.

Traceroute has the autosave function in setup and we also added a main tool quick select of the five kinds of traceroute (ICMP (MS), ICMP WinPcap, UDP variable port, UDP fixed port, and TCP). This means you don't have to go back into setup to change the traceroute mode.

Network Statistics also had a minor facelift mostly in the TCP/UDP connection endpoint list. More columns are visible. We split the Process:PID column into two and also split the IP/Port columns into two. A bit easier to read especially since it is now wider.

That's a few of the major changes, there are lots of other changes. The USB version will be done in a few days and the demo will be updated after Christmas to reflect 10.80 changes.

If you have an active Maintenance Plan, click on the Online left panel group, then click on Check for New Version, login and download the new version. Comments on the new version are appreciated and if you have any feature suggestions, let us know. If you don't have an active maintenance plan, go to our netscantools.com main page and look at the End of 2008 Special.