cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3256
Views
0
Helpful
3
Replies

best practice for snmp-server views?

david.fernandes
Level 1
Level 1

As a best practice when creating an snmp-server view, should these views be excluded?

snmp-server view cutdown snmpUsmMIB excluded

snmp-server view cutdown snmpVacmMIB excluded

snmp-server view cutdown snmpCommunityMIB excluded

1 Accepted Solution

Accepted Solutions

No, it's not included automatically. You would need to include these branches in your custom view.

View solution in original post

3 Replies 3

Joe Clarke
Cisco Employee
Cisco Employee

Absolutely. With these branches included, one could learn the SNMP credentials of the device. The default v1default view is defined as:

v1default iso - included permanent active

v1default internet.6.3.15 - excluded permanent active

v1default internet.6.3.16 - excluded permanent active

v1default internet.6.3.18 - excluded permanent active

v1default ciscoMgmt.394 - excluded permanent active

v1default ciscoMgmt.395 - excluded permanent active

v1default ciscoMgmt.399 - excluded permanent active

v1default ciscoMgmt.400 - excluded permanent active

Which essentially excludes all of the branches which could result in security compromise.

Thanks. Is the v1default view included automatically when I create a new view, or do I need to add these in?

No, it's not included automatically. You would need to include these branches in your custom view.