-
1
- #1
BFreshour
Programmer
- Mar 20, 2002
- 84
I have Motorola Surfboard SB3100 and whenever I create the DOCSIS CPE Configuration file with the correct SNMP strings to disable the public and private community strings it never seems to work and I'm still able to 'walk' into my modem using 'Docsdiag'. Is it possible for SNMP configuration to be stored in firmware and not be over-writable such as the case here? Or do I have something done incorrectly?
These are the strings I added to my configuration file:
docsDevNmAccessStatus.1 = 5
docsDevNmAccessIp.1 = 255.255.255.255
docsDevNmAccessIpMask.1 = 0.0.0.0
docsDevNmAccessCommunity.1 = "Public"
docsDevNmAccessControl.1 = 2
docsDevNmAccessInterfaces.1 = "0xc0"
docsDevNmAccessStatus.1 = 2
docsDevNmAccessStatus.2 = 5
docsDevNmAccessIp.2 = 10.0.0.0
docsDevNmAccessIpMask.2 = 255.0.0.0
docsDevNmAccessCommunity.2 = "Private"
docsDevNmAccessControl.2 = 2
docsDevNmAccessInterfaces.2 = "0x40"
docsDevNmAccessStatus.2 = 2
Also, would it be easier for me just to block port 161 (used for SNMP transmissions) with something like:
docsDevFilterIpDefault.0 = 2
docsDevFilterIpStatus.1 = 5
docsDevFilterIpControl.1 = 1
docsDevFilterIpIfIndex.1 = 0
docsDevFilterIpDirection.1 = 3
docsDevFilterIpBroadcast.1 = 2
docsDevFilterIpSaddr.1 = 0.0.0.0
docsDevFilterIpSmask.1 = 0.0.0.0
docsDevFilterIpDaddr.1 = 0.0.0.0
docsDevFilterIpDmask.1 = 0.0.0.0
docsDevFilterIpProtocol.1 = 6
DocsDevFilterIpSourcePortLow.1 = 0
DocsDevFilterIpSourcePortHigh.1 = 65535
docsDevFilterIpDestPortLow.1 = 161
DocsDevFilterIpDestPortHigh.1 = 161
docsDevFilterIpStatus.1 = 1
docsDevFilterIpStatus.1 = 5
docsDevFilterIpControl.1 = 1
docsDevFilterIpIfIndex.1 = 0
docsDevFilterIpDirection.1 = 3
docsDevFilterIpBroadcast.1 = 2
docsDevFilterIpSaddr.1 = 0.0.0.0
docsDevFilterIpSmask.1 = 0.0.0.0
docsDevFilterIpDaddr.1 = 0.0.0.0
docsDevFilterIpDmask.1 = 0.0.0.0
docsDevFilterIpProtocol.1 = 17
DocsDevFilterIpSourcePortLow.1 = 0
DocsDevFilterIpSourcePortHigh.1 = 65535
docsDevFilterIpDestPortLow.1 = 161
DocsDevFilterIpDestPortHigh.1 = 161
docsDevFilterIpStatus.1 = 1
These are the strings I added to my configuration file:
docsDevNmAccessStatus.1 = 5
docsDevNmAccessIp.1 = 255.255.255.255
docsDevNmAccessIpMask.1 = 0.0.0.0
docsDevNmAccessCommunity.1 = "Public"
docsDevNmAccessControl.1 = 2
docsDevNmAccessInterfaces.1 = "0xc0"
docsDevNmAccessStatus.1 = 2
docsDevNmAccessStatus.2 = 5
docsDevNmAccessIp.2 = 10.0.0.0
docsDevNmAccessIpMask.2 = 255.0.0.0
docsDevNmAccessCommunity.2 = "Private"
docsDevNmAccessControl.2 = 2
docsDevNmAccessInterfaces.2 = "0x40"
docsDevNmAccessStatus.2 = 2
Also, would it be easier for me just to block port 161 (used for SNMP transmissions) with something like:
docsDevFilterIpDefault.0 = 2
docsDevFilterIpStatus.1 = 5
docsDevFilterIpControl.1 = 1
docsDevFilterIpIfIndex.1 = 0
docsDevFilterIpDirection.1 = 3
docsDevFilterIpBroadcast.1 = 2
docsDevFilterIpSaddr.1 = 0.0.0.0
docsDevFilterIpSmask.1 = 0.0.0.0
docsDevFilterIpDaddr.1 = 0.0.0.0
docsDevFilterIpDmask.1 = 0.0.0.0
docsDevFilterIpProtocol.1 = 6
DocsDevFilterIpSourcePortLow.1 = 0
DocsDevFilterIpSourcePortHigh.1 = 65535
docsDevFilterIpDestPortLow.1 = 161
DocsDevFilterIpDestPortHigh.1 = 161
docsDevFilterIpStatus.1 = 1
docsDevFilterIpStatus.1 = 5
docsDevFilterIpControl.1 = 1
docsDevFilterIpIfIndex.1 = 0
docsDevFilterIpDirection.1 = 3
docsDevFilterIpBroadcast.1 = 2
docsDevFilterIpSaddr.1 = 0.0.0.0
docsDevFilterIpSmask.1 = 0.0.0.0
docsDevFilterIpDaddr.1 = 0.0.0.0
docsDevFilterIpDmask.1 = 0.0.0.0
docsDevFilterIpProtocol.1 = 17
DocsDevFilterIpSourcePortLow.1 = 0
DocsDevFilterIpSourcePortHigh.1 = 65535
docsDevFilterIpDestPortLow.1 = 161
DocsDevFilterIpDestPortHigh.1 = 161
docsDevFilterIpStatus.1 = 1