cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
655
Views
0
Helpful
2
Replies

SNMP Security risks

bjenner
Community Member

Hi,

What is the potential security risks with SNMP on a PIX firewall? To what extent could somebody access, monitor or reconfigure a PIX firewall assuming they knew the community string?

Thanks,

Bill

2 Replies 2

jsivulka
Level 10
Level 10

See "Using SNMP with the Cisco Secure PIX Firewall". This document will give you the information you are looking for.

http://www.cisco.com/warp/public/110/pixsnmp.html

mostiguy
Level 11
Level 11

Cisco PIX's SNMP support is completely read only.

There is not a ton of information available thru snmp on a pix - interface MIBs, cpu temperature and utilization (IIRC), connection count. Allowing someone to snmpwalk a pix would allow them to learn the ip addresses of each interface, so that is undesirable, but on the whole, the pix exposes not a ton of stuff, and that which is does is RO. Still, you would like to restrict access by ip address and robust community string on ideally from a secured subnet.