<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 4507 signature with SNMPv3 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/4507-signature-with-snmpv3/m-p/2190417#M53991</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, I had already checked that information but it doesn't seem to answer these questions.&lt;/P&gt;&lt;P&gt;- Would SNMPv3 traffic normally cause an "error in decoding the SNMP protocol" as indicated in the documentation?&lt;/P&gt;&lt;P&gt;- Do the 4507/x signatures understand &amp;amp; work with SNMPv3?&lt;/P&gt;&lt;P&gt;- Are there any known issues with the 4507/x signatures working with SNMPv3 traffic?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 11 Mar 2013 22:28:17 GMT</pubDate>
    <dc:creator>mark.barrett</dc:creator>
    <dc:date>2013-03-11T22:28:17Z</dc:date>
    <item>
      <title>4507 signature with SNMPv3</title>
      <link>https://community.cisco.com/t5/network-security/4507-signature-with-snmpv3/m-p/2190415#M53989</link>
      <description>&lt;P&gt;Are there any known issues with the 4507/x signatures working with SNMPv3 traffic? I'm getting a lot of 4507/6 alarms related to a new server which is using SNMPv3 to talk to various devices. I haven't found anything documented, but I'm speculating that since the IDS is seeing encrypted traffic on UDP 161 it's just generating the alarm because it's not able to figure out what the traffic actually is.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:55:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/4507-signature-with-snmpv3/m-p/2190415#M53989</guid>
      <dc:creator>mark.barrett</dc:creator>
      <dc:date>2019-03-10T12:55:02Z</dc:date>
    </item>
    <item>
      <title>4507 signature with SNMPv3</title>
      <link>https://community.cisco.com/t5/network-security/4507-signature-with-snmpv3/m-p/2190416#M53990</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/security/center/viewIpsSignature.x?signatureId=4507&amp;amp;signatureSubId=6&amp;amp;softwareVersion=5.1&amp;amp;releaseVersion=S17"&gt;http://tools.cisco.com/security/center/viewIpsSignature.x?signatureId=4507&amp;amp;signatureSubId=6&amp;amp;softwareVersion=5.1&amp;amp;releaseVersion=S17&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Mar 2013 22:02:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/4507-signature-with-snmpv3/m-p/2190416#M53990</guid>
      <dc:creator>jocamare</dc:creator>
      <dc:date>2013-03-11T22:02:07Z</dc:date>
    </item>
    <item>
      <title>4507 signature with SNMPv3</title>
      <link>https://community.cisco.com/t5/network-security/4507-signature-with-snmpv3/m-p/2190417#M53991</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, I had already checked that information but it doesn't seem to answer these questions.&lt;/P&gt;&lt;P&gt;- Would SNMPv3 traffic normally cause an "error in decoding the SNMP protocol" as indicated in the documentation?&lt;/P&gt;&lt;P&gt;- Do the 4507/x signatures understand &amp;amp; work with SNMPv3?&lt;/P&gt;&lt;P&gt;- Are there any known issues with the 4507/x signatures working with SNMPv3 traffic?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Mar 2013 22:28:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/4507-signature-with-snmpv3/m-p/2190417#M53991</guid>
      <dc:creator>mark.barrett</dc:creator>
      <dc:date>2013-03-11T22:28:17Z</dc:date>
    </item>
    <item>
      <title>4507 signature with SNMPv3</title>
      <link>https://community.cisco.com/t5/network-security/4507-signature-with-snmpv3/m-p/2190418#M53992</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On 4507/6, if you look at the sig itself on a sensor, the sig states that it fires on invalid community length. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; So that is where I would start.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Would SNMPv3 traffic normally cause an "error in decoding the SNMP protocol" as indicated in the documentation?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No, at least not for signature 4507/6.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Do the 4507/x signatures understand &amp;amp; work with SNMPv3?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Are there any known issues with the 4507/x signatures working with SNMPv3 traffic?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a bug [CSCef60726] saying that 4507/3 will incorrectly fire for SNMPv3 ttraffic.&lt;/P&gt;&lt;P&gt;The rest of them should work just fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Mar 2013 23:20:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/4507-signature-with-snmpv3/m-p/2190418#M53992</guid>
      <dc:creator>jocamare</dc:creator>
      <dc:date>2013-03-11T23:20:36Z</dc:date>
    </item>
  </channel>
</rss>

