NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
DavidHuen
Sep 08, 2026Aspirant
The SNMP service is occasionally unavailable
Hi all, My customer is currently facing occasional SNMP unavailability. I have checked uptime ot the switch and found that CPU and memory are normal. After reset snmp, the snmp service resumed. H...
schumaku
Sep 09, 2026Guru - Experienced User
It's not about the service becoming U/S - it dos stop responing for reasons...
Netgear smart managed switches have built-in CPU protection mechanisms that can and do limit aggressive or recursive SNMP polling, which is sometimes flagged or dropped if mistaken for anomalous or resource-intensive traffic.
SNMP Polling Limitations & Security
- CPU Protection: Netgear switches restrict mass, recursive OID (Object Identifier) polling to prevent high CPU loads or lockups from monitoring tools.
- Rate Limiting: High-frequency polling intervals (such as querying every few seconds across hundreds of ports) can overwhelm the limited management CPU on Smart Managed switches.
- Mitigation: Increase polling intervals (e.g., to 60 seconds or more) and use targeted OIDs rather than bulk walk commands.
Intrusion Prevention and Management
Lack of Deep IPS: Netgear smart managed switches operate at Layer 2/3 and do not feature full inline Intrusion Prevention Systems (IPS) or deep packet inspection (DPI) like dedicated firewalls or UTM appliances.
Built-in Attack Mitigation: They offer basic security features such as DoS prevention, Access Control Lists (ACLs), and port security to drop malformed packets or limit unauthorized management access.
Interaction: Heavy SNMP polling combined with security features like DoS or storm control can occasionally cause the switch management interface to become unresponsive or drop ICMP/SNMP packets if CPU thresholds are crossed.
Intrusion Prevention & Security Triggers
While the switch does not feature active inline Intrusion Prevention (IPS), it utilizes specific built-in defensive configurations that can flag heavy SNMP traffic as a threat:
- Denial of Service (DoS) Protection: If you have enabled global DoS protection in the management portal under Security > Management Security, the switch tracks high packet rates destined for its own IP address. Aggressive, multithreaded polling can easily look like a management-plane UDP flood or a brute-force sweep, causing the switch to drop the polling packets entirely.
- Auto-Protection Engine (Storm Control): If your monitoring server sits on a port where Broadcast/Multicast/Unknown Unicast Storm Control is strictly limited, high bursts of discovery packets can result in the switch rate-limiting or blocking the monitoring port altogether.
Have no such switch at hand, so please check
Management > Denial of Service > Auto-DOS Configuration
Security > Traffic Control
Better, more promising with less effort? Start here:
Optimize Your Network Management System (NMS)
If you prefer not to lower the switch’s security posture, you can adapt your monitoring software to respect the low-power microcontrollers inside Smart Managed units:
-
Increase Polling Intervals: Switch from 1-minute intervals to a minimum of 3 to 5 minutes.
Restrict OID Scope: Stop bulk-walking the entire MIB tree. Explicitly configure the pollers to only query essential OIDs (like specific port traffic statistics) to keep CPU overhead minimized. -
Implement a Polling Delay: Set a small delay (e.g., 20–50ms) between consecutive OID requests in your monitoring profile to prevent packet bursts.
Related Content
NETGEAR Academy
Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!