Tech or Treat! Write an article about your scariest tech disaster to win gadgets!Learn more


Difference between public and private strings

Posted on 2004-09-07
Medium Priority
Last Modified: 2012-06-27
I am implementing SNMP on our Servers and Switches, I am new to this but learning a great deal from this wonderful site.
I have read and been told to change the public and private strings (which are like passwords.)

Can someone please explain in laymans terms what exactly public and private strings, and how they would likly be used?

I am a bit rushed to get this projesct started, so I need a quick heads up and basic understanding.

Thanks in advance... Michael.
Question by:Linux_Hawk
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions

Accepted Solution

pedrow earned 2000 total points
ID: 12003791
snmp uses 'community strings' the same way one would use a password.

public is the default community string for RO (read only), which is used for things like monitoring, reading MIB values etc...

private is the default community string for RW (read-write), which would be used to do things like push config changes.

These strings can (and most definitely should) be changegd so that the snmp management stations and the network devices use something that no one knnows about. Further, it's also best practice to restrict the source addresses from where you can make these sorts of transactions.

for instance, on a cisco router you might want something like this:

snmp-server community ThePasswordIsSecret RO 10

access-list 10 permit

This way only machines addressed within this range that know the community string can grab information about your gear.

Does this help?

Author Comment

ID: 12006614
This does help a great deal

Featured Post

Simple, centralized multimedia control

Watch and learn to see how ATEN provided an easy and effective way for three jointly-owned pubs to control the 60 televisions located across their three venues utilizing the ATEN Control System, Modular Matrix Switch and HDBaseT extenders.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

New Server  was moved from behind Router R2 f0/1 to behind router R1 int f/01 and has now address But we want users still to be able to connected to it by old IP. How to do it ? We can used destination NAT (DNAT).  In DNAT…
Getting hacked is no longer a matter or "if you get hacked" — the 2016 cyber threat landscape is now titled "when you get hacked." When it happens — will you be proactive, or reactive?
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses

647 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question