Comunity string question.

Posted on 2004-09-07
Last Modified: 2010-04-17
I am going to be installing SNPM on 10 Servers, 2 Dell GB Managed Switches and 2 Dell Managed Fast Ethernet Switches.
I am new at this and have a few questions.

Should it also be installed on the Router providing WAN access to our other sites?

Question about the community string, I understand it is like a password. I think of a string as a line between 2 objects. Can I create a single string (password) for all the devices, or do I need 1 per device?


Thanks in Advance… Michael
Question by:Linux_Hawk
LVL 34

Accepted Solution

PsiCop earned 200 total points
ID: 12000204
Most folx use one SNMP community string for read access on all devices, and a different one for Read-Write. Whether or not you should use a different R/W community string on each device is something only you can answer - depends on the importance of security in your environment. But then if security were a critical concern, you wouldn't be using SNMP, since its fairly insecure.

Do make sure SNMP traffic is not permitted outside your network to the Internet. If possible, you should use a tool such as VLANs to limit the SNMP traffic's visibility. That will help address the issue of any host on the network being able to sniff the SNMP packets and see the community strings.

Remember, the "S" in SNMP stands for "Simple". This is not a robust, secure or particularly scalable technology. While it can be useful for monitoring general network health, I would caution against relying on it for actual management.
LVL 28

Assisted Solution

mikebernhardt earned 200 total points
ID: 12000429
The critical piece of information to worry about is the SNMP read-write string. Anyone who has the read-write string for a device can control that device to the degreee that SNMP will let them. On a Cisco router at least, this essentially means full control- you can change the configuration and everything.

The problem is that SNMP community strings are sent clear-text, so anyone with a sniffer can find the community string and then use it. SNMP v3 isn't, but most versions of Cisco IOS don't support it. What you can do on a Cisco router is use and access list to control who the router will respond to when it receives SNMP packets. In addition, do as PsiCop said and make sure that SNMP traffic isn't even sent or received by untrusted networks such as the Internet. These are essential tasks if you choose to use SNMP.

A string by the way, is a programming term which basically means a line of text.

Assisted Solution

net_sec_guru earned 100 total points
ID: 12000537
Yep, like PsiCop stated, have a separate string for your public and your private. But you can have the same strings for all your devices.

You can also look into using something like AAA on devices (TACACS+ or Radius) as they are supported according to Dell:


Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Tired of waiting for your show or movie to load?  Are buffering issues a constant problem with your internet connection?  Check this article out to see if these simple adjustments are the solution for you.
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

773 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question