06-06-2022 07:25 PM
Hi,
I would like to ask about for ntp and snmp traffic.
We are running hub spoke VPN . Should we carry ntp and snmp traffic over ipsec tunnel?
Should we carry ntp and snmp trffic as normal traffic ( without encrypt ,not using ipsec tunnel) ?
What is the best practice ?
Solved! Go to Solution.
06-07-2022 05:18 AM
Best practice is to use encrypted traffic as much as possible over public networks.
And sending traffic over VPN or using encrypted services (such as snmpv3 over snmp v1) is depends on your design and company policy.
06-06-2022 07:35 PM
There's no straight forward answer to this, because this isn't about best practice, rather your organisation's policies and compliance.
If you feel this traffic shouldn't be inspected by MITM (if the network is compromised), sure you can encrypt them via VPN.
06-06-2022 08:19 PM
This requirement is mostly depends on how you configured things. if you want to send ntp and snmp out of tunnel, you can use SNMPv3. for NTP use authentication. but if you have required processing power, try to use these traffic inside tunnel.
06-06-2022 11:39 PM
06-07-2022 03:52 AM
Hi All,
Thank.
I just want to know for security compliance.When i read for doc , i only can find how to secure ntp /snmp (eg, using ACL,V3 snmp..etc) but never mentoon about encrypted traffic or normal traffic.
So i just want to know what is the best practice for security.
06-07-2022 05:18 AM
Best practice is to use encrypted traffic as much as possible over public networks.
And sending traffic over VPN or using encrypted services (such as snmpv3 over snmp v1) is depends on your design and company policy.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide