<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: blocking snmp v1 &amp; 2c but allow snmp version 3 on ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/blocking-snmp-v1-2c-but-allow-snmp-version-3-on-asa/m-p/976854#M939911</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes,you can do this by "SNMP Inspection". The software later than 7.01 can support the feature,I wrote an example as followed:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list snmp-acl permit udp any any eq 161&lt;/P&gt;&lt;P&gt;access-list snmp-acl permit udp any any eq 162&lt;/P&gt;&lt;P&gt;class-map snmp-port&lt;/P&gt;&lt;P&gt;--&amp;gt; match access-list snmp-acl&lt;/P&gt;&lt;P&gt;snmp-map inbound_snmp&lt;/P&gt;&lt;P&gt;--&amp;gt; deny version 1&lt;/P&gt;&lt;P&gt;--&amp;gt; deny version 2&lt;/P&gt;&lt;P&gt;policy-map inbound_policy&lt;/P&gt;&lt;P&gt;--&amp;gt; class snmp-port&lt;/P&gt;&lt;P&gt;------&amp;gt; inspect snmp inbound_snmp&lt;/P&gt;&lt;P&gt;service-policy inbound_policy interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Verify:&lt;/P&gt;&lt;P&gt;show service-policy inspect snmp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Of course you can use default "global_policy" which applies to all interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 03 Apr 2008 19:02:07 GMT</pubDate>
    <dc:creator>pengfang</dc:creator>
    <dc:date>2008-04-03T19:02:07Z</dc:date>
    <item>
      <title>blocking snmp v1 &amp; 2c but allow snmp version 3 on ASA</title>
      <link>https://community.cisco.com/t5/network-security/blocking-snmp-v1-2c-but-allow-snmp-version-3-on-asa/m-p/976853#M939910</link>
      <description>&lt;P&gt;I have a customer, due to cost saving, recently migrated from&lt;/P&gt;&lt;P&gt;a checkpoint NGx firewall over to Cisco ASA 5510 &lt;/P&gt;&lt;P&gt;firewall with 8.0(3).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a Linux host on the internal network that supports &lt;/P&gt;&lt;P&gt;snmp version 1, 2c and 3.  I want host Linux_internal to querry&lt;/P&gt;&lt;P&gt;host SNMP_Server with snmp version 1 or 2c; however, Linux_vendors&lt;/P&gt;&lt;P&gt;has to use snmp version 3 to querry the SNMP_Server host because &lt;/P&gt;&lt;P&gt;they are going across the Internet and that I want the snmp&lt;/P&gt;&lt;P&gt;traffic to be encrypted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to know how it can be done with ASA5510.  Prior to the&lt;/P&gt;&lt;P&gt;migration over to the ASA5510, I used Checkpoint firewall&lt;/P&gt;&lt;P&gt;integrated SmartDefense to make this work.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible with ASA to block access snmp version 1 and 2c&lt;/P&gt;&lt;P&gt;over the Internet and allow only snmp version 3?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:26:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-snmp-v1-2c-but-allow-snmp-version-3-on-asa/m-p/976853#M939910</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2019-03-11T12:26:07Z</dc:date>
    </item>
    <item>
      <title>Re: blocking snmp v1 &amp; 2c but allow snmp version 3 on ASA</title>
      <link>https://community.cisco.com/t5/network-security/blocking-snmp-v1-2c-but-allow-snmp-version-3-on-asa/m-p/976854#M939911</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes,you can do this by "SNMP Inspection". The software later than 7.01 can support the feature,I wrote an example as followed:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list snmp-acl permit udp any any eq 161&lt;/P&gt;&lt;P&gt;access-list snmp-acl permit udp any any eq 162&lt;/P&gt;&lt;P&gt;class-map snmp-port&lt;/P&gt;&lt;P&gt;--&amp;gt; match access-list snmp-acl&lt;/P&gt;&lt;P&gt;snmp-map inbound_snmp&lt;/P&gt;&lt;P&gt;--&amp;gt; deny version 1&lt;/P&gt;&lt;P&gt;--&amp;gt; deny version 2&lt;/P&gt;&lt;P&gt;policy-map inbound_policy&lt;/P&gt;&lt;P&gt;--&amp;gt; class snmp-port&lt;/P&gt;&lt;P&gt;------&amp;gt; inspect snmp inbound_snmp&lt;/P&gt;&lt;P&gt;service-policy inbound_policy interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Verify:&lt;/P&gt;&lt;P&gt;show service-policy inspect snmp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Of course you can use default "global_policy" which applies to all interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Apr 2008 19:02:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-snmp-v1-2c-but-allow-snmp-version-3-on-asa/m-p/976854#M939911</guid>
      <dc:creator>pengfang</dc:creator>
      <dc:date>2008-04-03T19:02:07Z</dc:date>
    </item>
    <item>
      <title>Re: blocking snmp v1 &amp; 2c but allow snmp version 3 on ASA</title>
      <link>https://community.cisco.com/t5/network-security/blocking-snmp-v1-2c-but-allow-snmp-version-3-on-asa/m-p/976855#M939912</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks.  I will give it a try today. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One more question.  Can ASA have the ability &lt;/P&gt;&lt;P&gt;to block ssh verison 1 through, NOT to, the&lt;/P&gt;&lt;P&gt;firewall with the same scenario?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Apr 2008 12:52:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-snmp-v1-2c-but-allow-snmp-version-3-on-asa/m-p/976855#M939912</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2008-04-04T12:52:13Z</dc:date>
    </item>
    <item>
      <title>Re: blocking snmp v1 &amp; 2c but allow snmp version 3 on ASA</title>
      <link>https://community.cisco.com/t5/network-security/blocking-snmp-v1-2c-but-allow-snmp-version-3-on-asa/m-p/976856#M939913</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't think you can do that.ASA only supports very limited Application Layer Protocol Inspection, SSH is not in the list.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Apr 2008 16:51:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-snmp-v1-2c-but-allow-snmp-version-3-on-asa/m-p/976856#M939913</guid>
      <dc:creator>pengfang</dc:creator>
      <dc:date>2008-04-04T16:51:36Z</dc:date>
    </item>
  </channel>
</rss>

