RE: SNMP service
- From: k levinson <levinson_k@xxxxxxxxx>
- Date: Fri, 10 Feb 2006 10:46:44 -0800 (PST)
That all sounds pretty standard. There are still a
few risks you want to be aware of and either accept or
mitigate.
SNMP v2 and previous were not encrypted, so the
community "password" and data could be discovered by
an attacker via sniffing. If this concerns you, you
could get around this by using SNMP v3, tunneling
through IPSec, SSL or SSH, etc.
SNMP is largely over UDP where spoofing the source IP
is trivial, so the source IP restrictions only buys
you so much assurance. The encrypted tunneling
methods above also give you improved ability to
confirm the identity of the remote system and more
assurance.
With many SNMP implementations, there is often little
audit logging done to detect intrusions. Host-based
and/or network IDS / IPS may be one way to try to
improve on the logging if desired.
Software vulnerabilities are discovered in SNMP
implementations from time to time, so you may also
want to consider what patch management options you
have or need in order to be able to rapidly push
software updates for various OSes.
All of this is optional, depending on your tolerance
for risk.
regards,
karl levinson
-----Original Message-----the
From: kathy.kirk@xxxxxxxxxxxxxx
We could us some guidance regarding SNMP. Below is
requirements we weredo you
given and our proposed approach. What if any issues
see with ourin your
approach? Have you implemented something like this
environment,to a similar
and if so, how many devices do you have conforming
requirement?enable SNMP read
Requirements: Using one standard community name,
capabilities on all devices supportingSNMP services
throughout the corporate network,while
mitigating risk ofSolaris,
any known vulnerability.
Approach: On all supported platforms (i.e. Windows,
Linux, AIX,unique
etc.) configure the SNMP Service using a
community namecommunity
with read only rights and configure the
.name to accept
packets from specified trusted hosts.
__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around
http://mail.yahoo.com
---------------------------------------------------------------------------
---------------------------------------------------------------------------
- Prev by Date: RE: SNMP service
- Next by Date: RE: SNMP service
- Previous by thread: RE: SNMP service
- Next by thread: SecurityFocus Microsoft Newsletter #277
- Index(es):
Relevant Pages
|
|