mirror of
https://github.com/rzuasti/oott.git
synced 2026-07-08 19:21:54 +02:00
Introduce a sixth scanner that periodically queries an SNMP agent
(typically the router/firewall) for its ARP/neighbour cache via
SNMPv2c and feeds discovered devices into the shared devices, events
and notifications pipeline. Unlike the ARP scanner it generates no
traffic on the local segment and can surface devices across all
subnets the agent routes.
Scope is intentionally minimal: SNMPv2c only, a single target, and the
ipNetToMediaTable (ARP) only. SNMPv3 and switch MAC/forwarding-table
polling are left as follow-ups in TODO.md.
- backend: csnmp dependency; SnmpScanner config (opt-in, off unless a
[snmp_scanner] section is present); DeviceEventScanner::Snmp;
scanners/snmp/{finder,scanner,status}; main.rs wiring; status API
endpoint wired into OpenAPI
- frontend: SNMP scanner status model, card, API method, status screen
and summary card rows, and device-event label
- docs/config: sample TOML, README options, NixOS module option, and
setup notes for enabling SNMP on pfSense/OPNsense
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
52 lines
3.1 KiB
TOML
52 lines
3.1 KiB
TOML
[database]
|
|
path = "/db/oott.db" # Database path. For the Docker image this must be "/db/oott.db" (the mounted volume); make sure it's writeable for the user running this process
|
|
|
|
[networking]
|
|
# interface = "eno1" # Optional: network interface to use for scans. If not set, the first non-loopback connected interface is used.
|
|
|
|
[log]
|
|
level = "info" # off, error, warn, info, debug, trace
|
|
|
|
[arp_scanner]
|
|
enabled=true # Set to false to disable the ARP scanner
|
|
wait_between_scans="30m" # Wait time between scans. This does not include the scan time
|
|
sender_timeout="1m" # If the ARP sender process takes longer than this it will be stopped (for a class C network - 254 IPs - it should take less than a minute)
|
|
scan_duration="10m" # How long to wait for response packets on each scan (5m to 10m is a good timeframe for a class B or C network)
|
|
|
|
[mdns_scanner]
|
|
enabled=true # Set to false to disable the mDNS/Bonjour scanner
|
|
probe_timeout="2s" # When an mDNS-discovered IP is not in the OS ARP cache, how long to wait for a targeted ARP probe reply to resolve its MAC address
|
|
|
|
[ssdp_scanner]
|
|
enabled=true # Set to false to disable the SSDP/UPnP scanner
|
|
probe_timeout="2s" # When an SSDP/UPnP-discovered IP is not in the OS ARP cache, how long to wait for a targeted ARP probe reply to resolve its MAC address
|
|
|
|
[dhcp_scanner]
|
|
enabled=true # Set to false to disable the DHCP scanner
|
|
|
|
# [snmp_scanner] # Optional: poll a router/firewall's ARP table over SNMP. Disabled unless this section is present.
|
|
# enabled=true # Set to false to disable the SNMP scanner without removing this section
|
|
# target="192.168.1.1:161" # SNMP agent to poll, as host:port. Point this at your gateway (router/firewall).
|
|
# community="public" # SNMPv2c read-only community string. Use a read-only community; never commit a real secret here.
|
|
# wait_between_scans="2m" # Wait time between polls. Keep this well under the agent's ARP cache timeout so active devices aren't missed.
|
|
# timeout="3s" # Per-poll SNMP request timeout.
|
|
# Note: SNMP must be enabled on the target. On pfSense: Services > SNMP (v2c; the mibII module exposes the ARP table).
|
|
# On OPNsense: install the os-net-snmp plugin, then Services > Net-SNMP. In both cases add a firewall rule allowing
|
|
# UDP/161 from the host running OOTT.
|
|
|
|
[notifications]
|
|
method="pushover" # For now just pushover, you can set this to "none" to avoid sending notifications (it will just log)
|
|
notify_when_not_seen_for="1w" # Send a notification if a device comes back online after not being seen for this timeframe
|
|
|
|
[notifications.pushover]
|
|
token="" # Your pushover token goes here, just copy&paste from their website after creating the app
|
|
user_key="" # User key goes here, this is the account wide code for pushover
|
|
|
|
[web_server]
|
|
ip_address="0.0.0.0" # IP to bind the web server for the API and web UI to, use 0.0.0.0 to bind it to all interfaces
|
|
port=3000 # Port to listen on
|
|
api_key="CHANGE_ME" # API Key to use the system's API, change this!
|
|
|
|
[retention]
|
|
window="365d" # How long to keep device events and notifications. Records older than this are deleted daily. Supports: d (days), w (weeks), h (hours), m (minutes)
|