Articles setup, SNMP, updated 2026-09-28

DrayTek Vigor: watching the internet connections

DrayTek Vigor routers (the 2860, 2862, 2865, 2866, 2927, 2962 and 3910 families) are watched with SNMP and Ping. There is no local API an Oversight sensor can use: the web interface needs a form login and a session cookie, which a single request cannot do. SNMP covers what matters on a Vigor, which is whether its internet connections are up, how well a DSL line is holding its sync, and whether it has restarted.

What a Vigor does not report is just as important to know. There are no power supply, fan or internal temperature readings, no BGP or high-availability state, and no DSL error counters. The only temperature is from DrayTek's optional USB thermometer.

Setting up SNMP

SNMP is off on a new Vigor. In the router's web interface, open System Maintenance >> SNMP:

SettingWhat to put
Enable SNMP AgentTicked
Enable SNMPv2C AgentTicked. Leave v3 unticked; Oversight's probes use v2c.
Get CommunityA long random value, up to 23 characters. Never leave it as public.
Set CommunityAnother long random value. Oversight never writes, but the router answers writes with this community, and some of its objects can drop a VPN tunnel. The default, private, must go.
Manager Host IPThe probe's address, with a mask of 255.255.255.255. Up to three. Left blank, any device on the LAN can read the router.

Older firmware has a single Enable SNMP Agent box covering v1 and v2c. From the command line the same is mngt snmp -e 1 -g <get-community> -s <set-community> -m <probe-address>.

In Oversight, save an SNMP credential with version 2c and the get community, on the device or anywhere above it. See Credentials.

From the LAN, not the internet

Poll the router from a probe on its own LAN or across a VPN. To poll it from the internet you would have to tick SNMP Server under System Maintenance >> Management >> Internet Access Control, which puts the SNMP agent, and its community in plain text, on the internet. DrayTek routers have a record of internet-facing management flaws, and DrayTek's own advice is to turn remote management off where it is not needed. If it truly must be done, set both the Manager Host IP and the Management page's Access List to the probe's fixed address only.

Finding the right port numbers

SNMP reads one value per sensor, and a WAN's readings are found by its interface number (its ifIndex) on the end of the OID. That number differs between models, and LTE models shift it again, so look once on each router before building sensors:

snmpwalk -v2c -c <community> <router> 1.3.6.1.2.1.2.2.1.2
snmpwalk -v2c -c <community> <router> 1.3.6.1.2.1.2.2.1.3

The first lists each interface's name, the second its type. On a Vigor2862, for example:

ifIndexNameWhat it is
1LANThe LAN as a whole
4VDSL 07-07-09-05-01-07WAN1, the built-in VDSL port (type 251)
5, 6, 7WAN2, WAN3, WAN4Ethernet WANs
14 to 18LAN_PORT1 to LAN_PORT5The physical LAN ports

Two things to notice. The DSL port's name includes the modem firmware version, so it changes after an upgrade: find the DSL port by its type, 251, not its name. And a WAN that is switched off in the router's WAN settings is still listed, but reads as down: only watch WANs that are in use.

Sensors worth having

All of these are SNMP sensors typed as a number in the OID box, except the last. <wan> is the WAN's ifIndex from the walk; the examples use 4, the 2862's DSL port.

WhatOIDSettingsRules
WAN up1.3.6.1.2.1.2.2.1.8.<wan> (ifOperStatus)GAUGE; labels {"1":"up","2":"down","7":"lowerLayerDown"}SV01 not equal to 1 gives CRIT
Rebooted1.3.6.1.2.1.1.3.0 (sysUpTime)GAUGE, multiplier 0.01, unit sLess than 900 gives WARN: it restarted in the last fifteen minutes
DSL sync, downstream1.3.6.1.2.1.10.251.1.2.2.1.2.4.1GAUGE, multiplier 0.000001, unit Mbit/sLess than 1 gives CRIT; less than about 70% of the line's normal sync gives WARN
DSL sync, upstream1.3.6.1.2.1.10.251.1.2.2.1.2.4.2As aboveAs above, against the upstream figure
DSL noise margin, first1.3.6.1.2.1.10.94.1.1.2.1.4.4GAUGE, multiplier 1, unit dBLess than 3 gives WARN, less than 1 gives CRIT
DSL noise margin, second1.3.6.1.2.1.10.94.1.1.3.1.4.4As aboveAs above
DSL in sync1.3.6.1.2.1.10.94.1.1.2.1.6.4TEXTSD01 not containing SHOWTIME gives CRIT
CPU1.3.6.1.2.1.25.3.3.1.2.0GAUGE, unit %Greater than 90 gives WARN. Optional.
Each VPN tunnelA Ping sensor to a fixed address on the far LANDefault settingsNone needed: no reply is CRIT

The DSL sensors apply to models with a built-in DSL port (the 2860, 2862, 2865 and 2866). In the OIDs above, the .4 is the DSL port's ifIndex and the final .1 and .2 choose downstream and upstream; change the .4 if the walk showed a different number. On a 2927, 2962 or 3910, leave the DSL sensors out and add a WAN up sensor for each Ethernet WAN in use.

Notes on the DSL readings

  • Whole decibels. The standard says noise margin and attenuation are in tenths of a decibel. DrayTek reports whole decibels: a healthy line reads 12 or 15. Leave the multiplier at 1.
  • Which margin is which way. The two noise margin readings are one per direction, but DrayTek does not follow the standard's naming closely enough to say for certain which is downstream on every model. Give both the same thresholds and call them first and second, or compare them once with Online Status >> Physical Connection in the router's web interface and name them to match.
  • In sync is text. The line state is reported as the word SHOWTIME when the line is trained and passing traffic, hence a text rule. On some models and firmware the word turns up in the second row, 1.3.6.1.2.1.10.94.1.1.3.1.6.4, instead: tick Store raw response once and see which row carries it.
  • Firmware 3.9.1 moved things. On a 2860, firmware up to 3.9.0 reported sync rates in the older ADSL objects, which now read 0. The VDSL objects above are the ones to use on current firmware.
  • A modem on an Ethernet WAN, such as a Vigor 130 on WAN2, is only an Ethernet port to the router's SNMP. The modem's own line figures are not reported; watch the modem directly if it has SNMP.

When a line drops

The WAN up sensor is the one to rely on for an outage. When a DSL line loses sync, some DSL readings may stop being reported altogether rather than reading zero, and Oversight treats an object the router says it does not have as a settings fault: that sensor is suspended and shows UNKNOWN until it is saved again. So the DSL sensors are for the line's health while it is up, and WAN up is what raises the alarm when it goes. Clear Counts towards its parent's state on the DSL sensors if a suspended one would otherwise sit on the device's state after the line comes back.

Whether a WAN reads down when the line is still in sync but the PPPoE session behind it has failed has not been confirmed. Pair it with a Ping of the router's public address from a probe outside, where the site allows it: Disable PING from the Internet is ticked by default under System Maintenance >> Management, and can be limited to the probe with the Access List's Apply Access List to PING.

VPN tunnels

DrayTek's MIB does describe VPN tunnels, but its objects only exist while at least one tunnel is up, and on most models they give a count rather than the state of a named tunnel. When the last tunnel drops the objects vanish, and a sensor reading them is suspended as described above, so the outage you wanted to hear about never raises an alarm. Per-profile tunnel status exists only on the 2962 and 3910.

So watch each tunnel with a Ping sensor from a probe on this site's LAN to a fixed address on the far LAN; the far router's LAN address is the obvious one. That tests the tunnel end to end, the way the traffic uses it, on any model and any firmware.

What not to alarm on

  • Memory. DrayTek's own memory figure, 1.3.6.1.4.1.7367.3.7.0, reads 80 to 93 on healthy routers. A high number is normal, not a fault.
  • Interface errors. They read 0 on every interface of the routers tested, even under load, so a rule on them would never fire.
  • Traffic. A figure, not a fault. If you do chart it, use the 64-bit counter on the DSL WAN, 1.3.6.1.2.1.31.1.1.1.6.<wan> (in) and .10.<wan> (out), COUNTER64, change per second, multiplier 8 for bit/s. The 32-bit counters wrap every few minutes at DSL speeds, and the 64-bit counters on the LAN side read 0 or nonsense.
  • LTE signal. On LTE models DrayTek reports signal strength as text, not a number, so it cannot be given a threshold. Watch the LTE WAN's WAN up instead.

Other routes

  • The web interface. A plain HTTP(S) sensor on /weblogin.htm with a REGEX row for /Vigor Login Page/ shows the management side is alive, but nothing about the connections. It is rarely worth the credits.
  • Webhook. Firmware 4.4.3 and later (4.4.5 on the 2927 and 2865) can send a status report out on a timer, under System Maintenance >> Webhook, including WAN states. It is in DrayTek's own format and pushes rather than being asked, so it does not fit a sensor as it stands. If a site would benefit, raise a ticket and GEN can look at receiving it as a pushed reading.
  • VigorACS, DrayTek's management server, has an API, but it is not publicly documented and only helps where VigorACS is already in use.

A starting set

  1. WAN up for each WAN in use. Where a backup WAN is expected to sit down until it is needed, make its rule WARN, or leave it out.
  2. Rebooted.
  3. DSL sync downstream and both noise margins, on DSL models.
  4. A Ping across each VPN tunnel.
  5. A Ping of the public address from outside, where allowed.

At the default 60 seconds from one probe group, an SNMP sensor costs about £1.73 a month and a Ping about 86p.

MIBs

Every OID above works typed as a number; no MIB needs loading to poll a Vigor. To pick them by name from the MIB list, these would need importing through Files:

MIBForWhere from
IF-MIB, HOST-RESOURCES-MIB, ADSL-LINE-MIBInterfaces, CPU, DSL margins and line stateAlready loaded
VDSL2-LINE-MIB, VDSL2-LINE-TC-MIBDSL sync ratesRFC 5650, or any standard MIB collection
DRAYTEK-MIBDrayTek's own objects: model, firmware, memory, USB thermometer, VPN counts, LTELinked from DrayTek's knowledge base article 5517, Which SNMP OIDs does Vigor Routers support?