Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Enabling snmp securely on a router

Status
Not open for further replies.

Adesh001

MIS
Feb 25, 2005
40
TT
Hi Everyone,

I plan to enabled snmp on my cisco 2600 router using the following command:

Rtr(config)# snmp-server community public RO
Rtr(config)# snmp-server community private RW

Is that all it is to securely enable snmp on my router? Are there other procedures that need to be followed. Please advise.

Thanks
Adesh
 
Obviously, change the community names. You can also employ an access list.
 
It all depends upon how you define "securely enable."

If you use the commands you suggest then you will enable SNMPv1. That's OK as long as no one is able to capture and see your SNMP packets. SNMPv1 sends everthing in clear text including the community string (password).

If you want everything encrypted, then you have to use SNMPv3. Not all SNMP tools can speak SNMPv3 and not all IOS images can speak SNMPv3. And SNMPv3 is much more complicted to set up on both ends to get it to do what you want. But that would be the "most secure" way to use SNMP.

HTH,
Patrick
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top