RE: How to deny access from only some hosts usinf vacm

This is a discussion on RE: How to deny access from only some hosts usinf vacm within the SNMP Users forums, part of the Networking and Network Related category; > From: net-snmp-users-bounces@lists.sourceforge.net > [mailto:net-snmp-users-bounces@lists.sourceforge.net] On > ...


Go Back   Usenet Forums > Networking and Network Related > SNMP Users

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 01-04-2008
Mike Ayers
 
Posts: n/a
Default RE: How to deny access from only some hosts usinf vacm


> From: net-snmp-users-bounces@lists.sourceforge.net
> [mailto:net-snmp-users-bounces@lists.sourceforge.net] On
> Behalf Of arijit
> Sent: Friday, January 04, 2008 4:09 AM


> If I were to prevent access from only a few specific hosts
> (or subnets) to the agent, is there any way to do it using
> VACM? If not, what would be a preferred way of implementing the same?


Host based access is not supported by VACM, which is a good thing, because hosts are so spoofable. Suggested improvements:

- For general read only access, create a user with a well known password. Block this user from reading VACM and USM, as well as any other MIBs or objects which may contain sensitive information.

- For read/write access, create users for each person that will be granted access. From a security standpoint it does not matter which host they are working from, but who they are.

- If you are addressing traffic flow issues, use traffic flow tools. Your firewall can prevent or restrict all contact with the SNMP port(s) based on source host.


HTH,

Mike

-------------------------------------------------------------------------
This SF.net email is sponsored by: Microsoft
Defy all challenges. Microsoft(R) Visual Studio 2005.
http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/
_______________________________________________
Net-snmp-users mailing list
Net-snmp-users@lists.sourceforge.net
Please see the following page to unsubscribe or change other options:
https://lists.sourceforge.net/lists/...net-snmp-users
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 03:49 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0