Solved

Comunity string question.

Posted on 2004-09-07
3
296 Views
Last Modified: 2010-04-17
I am going to be installing SNPM on 10 Servers, 2 Dell GB Managed Switches and 2 Dell Managed Fast Ethernet Switches.
I am new at this and have a few questions.

Should it also be installed on the Router providing WAN access to our other sites?

Question about the community string, I understand it is like a password. I think of a string as a line between 2 objects. Can I create a single string (password) for all the devices, or do I need 1 per device?

Urgent...

Thanks in Advance… Michael
0
Comment
Question by:Linux_Hawk
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 34

Accepted Solution

by:
PsiCop earned 200 total points
ID: 12000204
Most folx use one SNMP community string for read access on all devices, and a different one for Read-Write. Whether or not you should use a different R/W community string on each device is something only you can answer - depends on the importance of security in your environment. But then if security were a critical concern, you wouldn't be using SNMP, since its fairly insecure.

Do make sure SNMP traffic is not permitted outside your network to the Internet. If possible, you should use a tool such as VLANs to limit the SNMP traffic's visibility. That will help address the issue of any host on the network being able to sniff the SNMP packets and see the community strings.

Remember, the "S" in SNMP stands for "Simple". This is not a robust, secure or particularly scalable technology. While it can be useful for monitoring general network health, I would caution against relying on it for actual management.
0
 
LVL 28

Assisted Solution

by:mikebernhardt
mikebernhardt earned 200 total points
ID: 12000429
The critical piece of information to worry about is the SNMP read-write string. Anyone who has the read-write string for a device can control that device to the degreee that SNMP will let them. On a Cisco router at least, this essentially means full control- you can change the configuration and everything.

The problem is that SNMP community strings are sent clear-text, so anyone with a sniffer can find the community string and then use it. SNMP v3 isn't, but most versions of Cisco IOS don't support it. What you can do on a Cisco router is use and access list to control who the router will respond to when it receives SNMP packets. In addition, do as PsiCop said and make sure that SNMP traffic isn't even sent or received by untrusted networks such as the Internet. These are essential tasks if you choose to use SNMP.

A string by the way, is a programming term which basically means a line of text.
0
 
LVL 4

Assisted Solution

by:net_sec_guru
net_sec_guru earned 100 total points
ID: 12000537
Yep, like PsiCop stated, have a separate string for your public and your private. But you can have the same strings for all your devices.

You can also look into using something like AAA on devices (TACACS+ or Radius) as they are supported according to Dell:
http://www1.us.dell.com/content/products/productdetails.aspx/pwcnt_5324?c=us&cs=04&l=en&s=bsd

0

Featured Post

Simple, centralized multimedia control

Watch and learn to see how ATEN provided an easy and effective way for three jointly-owned pubs to control the 60 televisions located across their three venues utilizing the ATEN Control System, Modular Matrix Switch and HDBaseT extenders.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

In this tutorial I will show you with short command examples how to obtain a packet footprint of all traffic flowing thru your Juniper device running ScreenOS. I do not know the exact firmware requirement, but I think the fprofile command is availab…
This article is a guide to configure bridging on Cisco Routers.  This is something I never knew was possible until after making a few phone calls to Cisco.  Using bridging saved our company money by not requiring us to purchase a new switch.  Bridgi…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

737 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question