Solved

Configuring Read/Write Community String through Group Policy

Posted on 2008-06-24
8
5,351 Views
Last Modified: 2009-01-21
Is there any way of configuring the Read/Write community strings trhough Group Policy?  We have Windows 2003 and what to configure all servers with the same SNMP community settings.  Some of our monitoring tools require Read/Write such as HP System Management.
0
Comment
Question by:madhour
8 Comments
 
LVL 26

Expert Comment

by:MidnightOne
ID: 21856022
For HP Systems management, we've discovered it requires at least two community strings with read-only access: public and private, with the loopback address being a trap destination. Without it, HP Insight Manager tends to fail rather badly - the front page will not load properly.

THAT said, you can configure SNMP via group policy. Try this:

In the left pane, go to:
Computer Configuration
      Administrative Templates
            Network
                  SNMP
                  
In the right pane, right click Communities and choose Properties
Click the radiobutton Enabled
Click the button Show
Click the button Add...
add the SNMP community strings

In the right pane, right click Permitted Managers and choose Properties
Click the radiobutton Enabled
Click the button Show
Click the button Add...
add the Ip addresses or hostnames for the managers of this device

In the right pane, right click Traps for public community and choose Properties
Click the radiobutton Enabled
Click the button Show
Click the button Add...
Add the trap destinations
0
 

Author Comment

by:madhour
ID: 21856844
This does not seem to be working.  I thought a Public community string is not great for Server Security.

This is my settings:

Traps tab
Community Name:  public
Trap destinations:  blah

Security tab
Accepted community names:  
blah        READ ONLY
myCmtName    READ ONLY

Accept SNMP packet
localhost
myserver
                                                 
0
 
LVL 26

Expert Comment

by:MidnightOne
ID: 21857082
Using public and private for community strings isn't good, but unfortunately they're a requirement for HSIM to function properly.
0
Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

 

Author Comment

by:madhour
ID: 21857214
I don't think I will use HP System Management then.  Is there anyway to add read/write community string via Group Policy?
0
 
LVL 26

Expert Comment

by:MidnightOne
ID: 21858104
As far as I've been able to determine, the default SNMP GPO only adds READ-ONLY community strings.
0
 

Author Comment

by:madhour
ID: 21858264
Yes.  That is correct.  I was hoping someone can post if there is an alternative way to put the read/write entry
0
 

Accepted Solution

by:
WTDC earned 250 total points
ID: 22615196
0
 

Expert Comment

by:Felicity_Harte
ID: 23428289
Comment:

With HP Sim although it is a requirement to use snmp community names they can be either read or write, but you can choose anynames you want and not just have to use the default Public and Private.
0

Featured Post

Live: Real-Time Solutions, Start Here

Receive instant 1:1 support from technology experts, using our real-time conversation and whiteboard interface. Your first 5 minutes are always free.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This is a little timesaver I have been using for setting up Microsoft Small Business Server (SBS) in the simplest possible way. It may not be appropriate for every customer. However, when you get a situation where the person who owns the server is i…
Setting up a Microsoft WSUS update system is free relatively speaking if you have hard disk space and processor capacity.   However, WSUS can be a blessing and a curse. For example, there is nothing worse than approving updates and they just have…
This video Micro Tutorial explains how to clone a hard drive using a commercial software product for Windows systems called Casper from Future Systems Solutions (FSS). Cloning makes an exact, complete copy of one hard disk drive (HDD) onto another d…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

815 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now