Home Support Blog

Zabbix switch port monitoring

Release date:2026-09-15

Zabbix monitors an industrial switch by polling it over SNMPv3 every 30–60 seconds and receiving asynchronous traps on UDP 162, then graphing port traffic, CPU, temperature, and — on SFP-equipped models — digital diagnostic (DDM) optical power. Rayin industrial switches speak standard MIB-II / IF-MIB and SNMPv3, so they drop straight into an existing Zabbix instance without custom agents — the same SNMP interface also covers Rayin mini OLTs, so a campus network is monitored from access switch to OLT on one screen.

image

Why SNMP-Based Monitoring Belongs in Every Industrial Deployment

  • Scale: beyond ~10 devices, manual ping checks do not scale; SNMP polls automatically and draws trends.

  • Real-time: polling is pull, but a trap (UDP 162) is push — link down or over-temperature is reported the moment it happens.

  • Visibility: SFP DDM reads Rx optical power and temperature, catching a failing fiber patch before users notice.

SNMP has three versions; v1/v2c send the community string in clear text, while v3 (RFC 3414 USM) adds SHA authentication and AES encryption — mandatory on an industrial network.

KEY TAKEAWAYS
  • Use SNMPv3 (RFC 3414) with AES; never leave v1/v2c open.

  • Poll every 30–60s and enable traps (UDP 162) for instant fault push.

  • Watch DDM Rx power: alarm below −28 dBm, overload above −3 dBm.

Step 1: Enable the SNMP Agent and Create a v3 User

  • Enable the SNMP agent on UDP 161.

  • Create an SNMPv3 user with SHA authentication and AES encryption (DES optional); disable v1/v2c.

  • Limit the source IP to the NMS segment (e.g. 192.168.99.0/24).

  • Move Web/SSH/SNMP onto the dedicated management VLAN 99, physically separate from business domains.

Rayin industrial switches expose standard MIB-II, so Zabbix can read them through the built-in template set.

Step 2: Add the Host in Zabbix and Enter the USM

  • Create a Host; under Interfaces choose SNMP and enter the switch management IP and port 161.

  • Set SNMP version to v3, then enter the username, auth/encrypt algorithms, and keys — the context and engine ID must match the switch exactly.

  • Verify with snmpwalk against sysDescr (MIB-II RFC 1213, OID 1.3.6.1.2.1.1.1) before linking templates.

Step 3: Link Templates (Ports, CPU, Memory, Optics)

  • IF-MIB: per-port bytes in/out, errors, discards, utilization — auto-graphed.

  • CPU / Memory: alert at CPU >80% and memory >85%.

  • SFP DDM: read Rx power; normal window −3 to −28 dBm, alarm below −28 dBm (approaching receive sensitivity).

  • LLDP (IEEE 802.1AB): auto-discovers neighbors and draws topology.

Step 4: Configure Trap Receiving and Thresholds

  • Point Zabbix at an snmptrapd receiver so a link OperStatus down alerts immediately.

  • Key thresholds: port packet loss >1%, temperature >70°C, optical Rx <−28 dBm or >−3 dBm (overload).

  • Route alerts to email / DingTalk / Webhook so the on-call engineer is paged, not the morning report.

    image

Step 5: Verify Polling and History

  • Confirm Latest Data refreshes continuously (polling works).

  • Pull a week of traffic to find busy-hour peaks and plan capacity.

  • Shut one port and confirm a trap fires within a minute.

Taking Zabbix Further in Industrial Sites

  • Templates: package items, triggers, and graphs; assign to a host and it is monitored. Official Template Net covers common MIBs; Rayin switches map cleanly to MIB-II / IF-MIB.

  • Low-Level Discovery (LLD): auto-create items for every up port and SFP via IF-MIB ifDescr/ifIndex; new line cards need no manual registration.

  • Trigger functions beyond thresholds: last(), avg(5m), min(10m)/max(10m), count(10m,"down"), and forecast(1h)/timeleft() — the last predicts when Rx power will cross −28 dBm so you swap the patch first.

  • Value mapping & user macros: map IF-MIB OperStatus 1/2/3 to up/down/testing; set {$IF.UTIL.MAX}=80, {$TEMP.MAX}=70 so one template fits every workshop by changing macros only.

  • Dashboard & Maps: LLDP auto-draws "Switch A ↔ OLT B" links; a red link locates the break faster than log digging.

  • Zabbix Proxy: a remote factory runs a Proxy in active mode, caching and batching back to the HQ server — bandwidth-friendly and outage-safe.

  • Autoregistration + API: new switches with SNMPv3 auto-classify and link templates by IP/LLDP; the Zabbix API (JSON-RPC) syncs CMDB changes with zero manual entry.

  • Maintenance & Escalation: silence alerts during planned upgrades; escalate unacknowledged faults from DingTalk to email to phone.

FAQ

What polling interval should I use?

Typically 30–60 seconds. Core devices can go to 10–15s, but do not over-poll or you load the agent's CPU.

Do I need both traps and polling?

Yes. Polling shows trends; traps catch sudden changes. They complement each other.

What if DDM optical readings are unavailable?

Some older transceivers lack DDM; swap in a DDM-capable SFP. Most modern managed switches expose DDM on their SFP ports, so the reading appears once the IF-MIB DDM template is linked.

What happens if the SNMPv3 engine ID is wrong?

Authentication fails and Zabbix reports timeouts. The engine ID must match the switch configuration exactly.

How do I bring many switches under monitoring at once?

Use templates + Low-Level Discovery + Autoregistration; new devices self-register, and the Zabbix API can sync CMDB entries automatically.

Related Reading

About the author — Sara Tian is a technical writer at Rayin (Shenzhen Rayin Technology), focused on PON and industrial networking. Connect with Sara on LinkedIn.

About Rayin → Rayin company profile

Get A Quote

You have agreed to this website’s《Privacy Policy》