04-02-2011 03:12 AM - edited 03-11-2019 01:16 PM
hi experts
i was going through the asa documentation for snmp inspection and it doesnot mention much about snmp inspection . if the traffic is going from one snmp host to a destination snmp server passing asa , will inspect snmp required ? if yes , will it nat the IP header or the payload also just like dynamic protocols like sip and ftp .
04-02-2011 03:32 AM
ASA by itself, does NOT inspect snmp inspection. In order to inspect SNMP, I think you will need the add-on SSM module to perform this kind of function. But that's my guess.
I come from Checkpoint environment and Checkpoint behaves the same way. In order to inspect snmp on Checkpoint, an addition IPS blade (aka SmartDefence prior to NGx R70) is required.
04-02-2011 03:39 AM
thanks for the information , this one is also helpful , but i would rquire cisco experts to comment on the same as i am interested in the inspect snmp details from their perspective.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide