Files
oott/examples/sample_oott.toml
T
rzuastiandClaude Opus 4.8 2987f66363 Add SNMP scanner that polls a gateway's ARP table
Introduce a sixth scanner that periodically queries an SNMP agent
(typically the router/firewall) for its ARP/neighbour cache via
SNMPv2c and feeds discovered devices into the shared devices, events
and notifications pipeline. Unlike the ARP scanner it generates no
traffic on the local segment and can surface devices across all
subnets the agent routes.

Scope is intentionally minimal: SNMPv2c only, a single target, and the
ipNetToMediaTable (ARP) only. SNMPv3 and switch MAC/forwarding-table
polling are left as follow-ups in TODO.md.

- backend: csnmp dependency; SnmpScanner config (opt-in, off unless a
  [snmp_scanner] section is present); DeviceEventScanner::Snmp;
  scanners/snmp/{finder,scanner,status}; main.rs wiring; status API
  endpoint wired into OpenAPI
- frontend: SNMP scanner status model, card, API method, status screen
  and summary card rows, and device-event label
- docs/config: sample TOML, README options, NixOS module option, and
  setup notes for enabling SNMP on pfSense/OPNsense

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-02 08:03:20 -04:00

52 lines
3.1 KiB
TOML

[database]
path = "/db/oott.db" # Database path. For the Docker image this must be "/db/oott.db" (the mounted volume); make sure it's writeable for the user running this process
[networking]
# interface = "eno1" # Optional: network interface to use for scans. If not set, the first non-loopback connected interface is used.
[log]
level = "info" # off, error, warn, info, debug, trace
[arp_scanner]
enabled=true # Set to false to disable the ARP scanner
wait_between_scans="30m" # Wait time between scans. This does not include the scan time
sender_timeout="1m" # If the ARP sender process takes longer than this it will be stopped (for a class C network - 254 IPs - it should take less than a minute)
scan_duration="10m" # How long to wait for response packets on each scan (5m to 10m is a good timeframe for a class B or C network)
[mdns_scanner]
enabled=true # Set to false to disable the mDNS/Bonjour scanner
probe_timeout="2s" # When an mDNS-discovered IP is not in the OS ARP cache, how long to wait for a targeted ARP probe reply to resolve its MAC address
[ssdp_scanner]
enabled=true # Set to false to disable the SSDP/UPnP scanner
probe_timeout="2s" # When an SSDP/UPnP-discovered IP is not in the OS ARP cache, how long to wait for a targeted ARP probe reply to resolve its MAC address
[dhcp_scanner]
enabled=true # Set to false to disable the DHCP scanner
# [snmp_scanner] # Optional: poll a router/firewall's ARP table over SNMP. Disabled unless this section is present.
# enabled=true # Set to false to disable the SNMP scanner without removing this section
# target="192.168.1.1:161" # SNMP agent to poll, as host:port. Point this at your gateway (router/firewall).
# community="public" # SNMPv2c read-only community string. Use a read-only community; never commit a real secret here.
# wait_between_scans="2m" # Wait time between polls. Keep this well under the agent's ARP cache timeout so active devices aren't missed.
# timeout="3s" # Per-poll SNMP request timeout.
# Note: SNMP must be enabled on the target. On pfSense: Services > SNMP (v2c; the mibII module exposes the ARP table).
# On OPNsense: install the os-net-snmp plugin, then Services > Net-SNMP. In both cases add a firewall rule allowing
# UDP/161 from the host running OOTT.
[notifications]
method="pushover" # For now just pushover, you can set this to "none" to avoid sending notifications (it will just log)
notify_when_not_seen_for="1w" # Send a notification if a device comes back online after not being seen for this timeframe
[notifications.pushover]
token="" # Your pushover token goes here, just copy&paste from their website after creating the app
user_key="" # User key goes here, this is the account wide code for pushover
[web_server]
ip_address="0.0.0.0" # IP to bind the web server for the API and web UI to, use 0.0.0.0 to bind it to all interfaces
port=3000 # Port to listen on
api_key="CHANGE_ME" # API Key to use the system's API, change this!
[retention]
window="365d" # How long to keep device events and notifications. Records older than this are deleted daily. Supports: d (days), w (weeks), h (hours), m (minutes)