08-11-2003 10:45 PM - edited 03-02-2019 09:31 AM
I've recently applied an access list to the SNMP read & write strings To increase security on the LAN. This works fine on all IOS equipment except 2900 switches. Once the Access-list is applied to the 2900 switches they no longer talk to either ciscoworks200 or HP openview. The IP address listed in the access list is that of the NMS. Is there a known problem or is this just a characteristic of the 2900 series switch.
The configuration is listed below
access-list 99 permit X.X.X.X
snmp-server community YYYYY RO 99
snmp-server community ZZZZZ RW 99
08-12-2003 12:11 AM
We have the same config on a 2912 running 12.0(5.2)XU without a problem.
If you are sure the problem is not caused by another modification that happened at the same time (e.g. change in an interface accesslist, accidentaly changed the snmp engine-id, etc.), try turning on logging on the acl to see if it gets hit.
access-list 99 permit X.X.X.X log
access-list 99 deny any log
then watch your logs as the NMS polls the switch.
hth
Herbert
08-12-2003 07:12 PM
Thanks for your time. I've resolve dthe issue, it's a little thing called a firewall and NATing thats causing the problem.
thanks again for responding.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide