100

Another post in the records for the tech blog, this time all about opensource network monitoring with LibreNMS!

top 17 comments
sorted by: hot top new old
[-] possiblylinux127@lemmy.zip 5 points 1 year ago

Works in a enterprise setting as well

[-] starkzarn@infosec.pub 2 points 1 year ago

Absolutely! I'd happily take any comments you have from running it in an enterprise setting, if you care to share.

[-] vfsh@lemmy.blahaj.zone 1 points 1 year ago

My college system is working on implementing it as our network monitoring utility, so far so good

[-] slazer2au@lemmy.world 4 points 1 year ago* (last edited 1 year ago)

I only have one issue with the post.

The conclusion says use long random SNMP community strings.

Ideally you should be using SNMPv3 because snmp1/2/2c are all clear text.

Apart from that, nice article

[-] starkzarn@infosec.pub 7 points 1 year ago

You are absolutely correct, thank you. Sadly a bunch of devices still don't support it, even in 2025 (like my microtik switch) for example. I will absolutely add a note about that though, thank you!

[-] starkzarn@infosec.pub 5 points 1 year ago

Updated the post to reflect your feedback here. Thank you!

[-] slazer2au@lemmy.world 1 points 1 year ago

Really? SNMPv3 was ratified in 1998. How does anyone take them seriously without it?

[-] starkzarn@infosec.pub 6 points 1 year ago

And IPv6 was codified in RFCs and first addresses issued in 1999 but look where we are now. I'd bet your corporate network doesn't use IPv6 still. It's unfortunate, but sometimes the wheels of change are slow.

[-] slazer2au@lemmy.world 2 points 1 year ago

My home, work, and mobile networks are all dual stacked.

This is a difference in kind. IPv4 live was extended with Nat and cgnat, but nothing equivalent came for snmp.

[-] starkzarn@infosec.pub 6 points 1 year ago

Hey good for you, that's awesome! My home network is also dual stacked.

You're right about the apples to oranges comparison, but it's not so wildly off, because the commentary is on adoption of new standards, regardless of bolt-on "fixes." Unauthenticated SNMP went through three revisions prior to adding authentication and encryption support.

[-] haroldfinch@feddit.nl 3 points 1 year ago

@StarkZarn@infosec.pub have you heard of NixOS? If you'd become a contributor with these bitesized posts that you're doing you'd be increasing the repeatability of your work immensely.

No pressure. Just doing some evangelization ๐Ÿ™‚

[-] starkzarn@infosec.pub 3 points 1 year ago

I absolutely have and used it for a while before landing on opensuse microos primarily. I absolutely see the benefit and enjoyed the git-centric nature, keeping flakes in repos with a flavor for each machine. What I didn't enjoy, however, was the seemingly poor documentation. Quite frankly too, the drama surrounding the community doesn't inspire confidence either. I decided I ought to try out guix but haven't gotten to it yet. I do actually still have one nixos VM that hosts some services for me and is built entirely on the concept of the impermanence flake. That was pretty cool.

[-] possiblylinux127@lemmy.zip 1 points 1 year ago

Nix OS is way more pain than it is worth for me.

There are plenty of alternatives that are much simpler. I prefer just a Debian install managed with tools like Ansible and pyinfra

[-] jagged_circle@feddit.nl 3 points 1 year ago

Isnt nagios and a dozen others also GPL?

[-] starkzarn@infosec.pub 5 points 1 year ago

Nagios is a premium offering. They have some open source components, but the software model is absolutely not built around the spirit of GPL.

Zabbix is the obvious alternative in my mind, and it is AGPLv3, so absolutely in the same spirit as the LibreNMS license. It's a slightly different tool though, and less network-specific. Having used both, I prefer LibreNMS for specifically network monitoring, it's laid out to cater more to an ISP-type entity running it, and I like that. Zabbix still gets my wholehearted stamp of approval though.

[-] paerrin@midwest.social 2 points 1 year ago

Thanks! Adding to my list to check out. Grabbed the RSS feed for your blog as well!

[-] starkzarn@infosec.pub 2 points 1 year ago

Excellent! Let me know if there are specific things you'd like to hear about.

this post was submitted on 13 May 2025
100 points (98.1% liked)

Selfhosted

61708 readers
863 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS