Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17


Comunity string question.

Posted on 2004-09-07
Medium Priority
Last Modified: 2010-04-17
I am going to be installing SNPM on 10 Servers, 2 Dell GB Managed Switches and 2 Dell Managed Fast Ethernet Switches.
I am new at this and have a few questions.

Should it also be installed on the Router providing WAN access to our other sites?

Question about the community string, I understand it is like a password. I think of a string as a line between 2 objects. Can I create a single string (password) for all the devices, or do I need 1 per device?


Thanks in Advance… Michael
Question by:Linux_Hawk
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
LVL 34

Accepted Solution

PsiCop earned 800 total points
ID: 12000204
Most folx use one SNMP community string for read access on all devices, and a different one for Read-Write. Whether or not you should use a different R/W community string on each device is something only you can answer - depends on the importance of security in your environment. But then if security were a critical concern, you wouldn't be using SNMP, since its fairly insecure.

Do make sure SNMP traffic is not permitted outside your network to the Internet. If possible, you should use a tool such as VLANs to limit the SNMP traffic's visibility. That will help address the issue of any host on the network being able to sniff the SNMP packets and see the community strings.

Remember, the "S" in SNMP stands for "Simple". This is not a robust, secure or particularly scalable technology. While it can be useful for monitoring general network health, I would caution against relying on it for actual management.
LVL 28

Assisted Solution

mikebernhardt earned 800 total points
ID: 12000429
The critical piece of information to worry about is the SNMP read-write string. Anyone who has the read-write string for a device can control that device to the degreee that SNMP will let them. On a Cisco router at least, this essentially means full control- you can change the configuration and everything.

The problem is that SNMP community strings are sent clear-text, so anyone with a sniffer can find the community string and then use it. SNMP v3 isn't, but most versions of Cisco IOS don't support it. What you can do on a Cisco router is use and access list to control who the router will respond to when it receives SNMP packets. In addition, do as PsiCop said and make sure that SNMP traffic isn't even sent or received by untrusted networks such as the Internet. These are essential tasks if you choose to use SNMP.

A string by the way, is a programming term which basically means a line of text.

Assisted Solution

net_sec_guru earned 400 total points
ID: 12000537
Yep, like PsiCop stated, have a separate string for your public and your private. But you can have the same strings for all your devices.

You can also look into using something like AAA on devices (TACACS+ or Radius) as they are supported according to Dell:


Featured Post

On Demand Webinar: Networking for the Cloud Era

Ready to improve network connectivity? Watch this webinar to learn how SD-WANs and a one-click instant connect tool can boost provisions, deployment, and management of your cloud connection.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article is a guide to configure bridging on Cisco Routers.  This is something I never knew was possible until after making a few phone calls to Cisco.  Using bridging saved our company money by not requiring us to purchase a new switch.  Bridgi…
Shadow IT is coming out of the shadows as more businesses are choosing cloud-based applications. It is now a multi-cloud world for most organizations. Simultaneously, most businesses have yet to consolidate with one cloud provider or define an offic…
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

715 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question