<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SNMP Question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/snmp-question/m-p/836975#M1020024</link>
    <description>&lt;P&gt;The following command snmp-server host 1.1.1.1 means that it will send the traps to NMS 1.1.1.1 only &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Should i use the following too for more security&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 50 permit 1.1.1.1  &lt;/P&gt;&lt;P&gt;access-list 50 deny any log    &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;snmp-server community CISCORO RO 50&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 09:45:16 GMT</pubDate>
    <dc:creator>welcomeccie</dc:creator>
    <dc:date>2020-02-21T09:45:16Z</dc:date>
    <item>
      <title>SNMP Question</title>
      <link>https://community.cisco.com/t5/network-security/snmp-question/m-p/836975#M1020024</link>
      <description>&lt;P&gt;The following command snmp-server host 1.1.1.1 means that it will send the traps to NMS 1.1.1.1 only &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Should i use the following too for more security&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 50 permit 1.1.1.1  &lt;/P&gt;&lt;P&gt;access-list 50 deny any log    &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;snmp-server community CISCORO RO 50&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 09:45:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-question/m-p/836975#M1020024</guid>
      <dc:creator>welcomeccie</dc:creator>
      <dc:date>2020-02-21T09:45:16Z</dc:date>
    </item>
    <item>
      <title>Re: SNMP Question</title>
      <link>https://community.cisco.com/t5/network-security/snmp-question/m-p/836976#M1020027</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is always good to add that too...it means that only 1.1.1.1 will be able to poll the RO community string of the device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have a RW string I would suggest an ACL on that as well.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Oct 2007 14:01:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-question/m-p/836976#M1020027</guid>
      <dc:creator>David Stanford</dc:creator>
      <dc:date>2007-10-31T14:01:49Z</dc:date>
    </item>
    <item>
      <title>Re: SNMP Question</title>
      <link>https://community.cisco.com/t5/network-security/snmp-question/m-p/836977#M1020028</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;But with this command snmp-server host 1.1.1.1 I ensure that the traps will go to that host only so why should i use the ACL with community command and what does Poll the communlty mean?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Oct 2007 14:49:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-question/m-p/836977#M1020028</guid>
      <dc:creator>welcomeccie</dc:creator>
      <dc:date>2007-10-31T14:49:12Z</dc:date>
    </item>
    <item>
      <title>Re: SNMP Question</title>
      <link>https://community.cisco.com/t5/network-security/snmp-question/m-p/836978#M1020029</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The host command ensures that traps goes to this IP only, but an NMS station can still query the router via the RO comm string.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any NMS that knows the RO community string can query the device for information. This is why you want an ACL on your RO comm string to limit who can query your router. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Traps are different as they are set from the router...polls are snmpgets and snmpwalks looking for response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/iosswrel/ps5207/products_command_reference_chapter09186a00801a809e.html#wp1153489" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/iosswrel/ps5207/products_command_reference_chapter09186a00801a809e.html#wp1153489&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Oct 2007 17:36:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-question/m-p/836978#M1020029</guid>
      <dc:creator>David Stanford</dc:creator>
      <dc:date>2007-10-31T17:36:03Z</dc:date>
    </item>
  </channel>
</rss>

