06-13-2004 12:14 AM - edited 03-09-2019 07:43 AM
Hi,
What is the potential security risks with SNMP on a PIX firewall? To what extent could somebody access, monitor or reconfigure a PIX firewall assuming they knew the community string?
Thanks,
Bill
06-17-2004 12:47 PM
See "Using SNMP with the Cisco Secure PIX Firewall". This document will give you the information you are looking for.
06-21-2004 05:09 AM
Cisco PIX's SNMP support is completely read only.
There is not a ton of information available thru snmp on a pix - interface MIBs, cpu temperature and utilization (IIRC), connection count. Allowing someone to snmpwalk a pix would allow them to learn the ip addresses of each interface, so that is undesirable, but on the whole, the pix exposes not a ton of stuff, and that which is does is RO. Still, you would like to restrict access by ip address and robust community string on ideally from a secured subnet.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide