cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3251
Views
0
Helpful
3
Replies

best practice for snmp-server views?

david.fernandes
Level 1
Level 1

As a best practice when creating an snmp-server view, should these views be excluded?

snmp-server view cutdown snmpUsmMIB excluded

snmp-server view cutdown snmpVacmMIB excluded

snmp-server view cutdown snmpCommunityMIB excluded

1 Accepted Solution

Accepted Solutions

No, it's not included automatically. You would need to include these branches in your custom view.

View solution in original post

3 Replies 3

Joe Clarke
Cisco Employee
Cisco Employee

Absolutely. With these branches included, one could learn the SNMP credentials of the device. The default v1default view is defined as:

v1default iso - included permanent active

v1default internet.6.3.15 - excluded permanent active

v1default internet.6.3.16 - excluded permanent active

v1default internet.6.3.18 - excluded permanent active

v1default ciscoMgmt.394 - excluded permanent active

v1default ciscoMgmt.395 - excluded permanent active

v1default ciscoMgmt.399 - excluded permanent active

v1default ciscoMgmt.400 - excluded permanent active

Which essentially excludes all of the branches which could result in security compromise.

Thanks. Is the v1default view included automatically when I create a new view, or do I need to add these in?

No, it's not included automatically. You would need to include these branches in your custom view.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: