cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
234
Views
5
Helpful
2
Replies

applying global access-list to SNMP strings

n.titchener
Level 1
Level 1

I've recently applied an access list to the SNMP read & write strings To increase security on the LAN. This works fine on all IOS equipment except 2900 switches. Once the Access-list is applied to the 2900 switches they no longer talk to either ciscoworks200 or HP openview. The IP address listed in the access list is that of the NMS. Is there a known problem or is this just a characteristic of the 2900 series switch.

The configuration is listed below

access-list 99 permit X.X.X.X

snmp-server community YYYYY RO 99

snmp-server community ZZZZZ RW 99

2 Replies 2

hbaerten
Level 4
Level 4

We have the same config on a 2912 running 12.0(5.2)XU without a problem.

If you are sure the problem is not caused by another modification that happened at the same time (e.g. change in an interface accesslist, accidentaly changed the snmp engine-id, etc.), try turning on logging on the acl to see if it gets hit.

access-list 99 permit X.X.X.X log

access-list 99 deny any log

then watch your logs as the NMS polls the switch.

hth

Herbert

Thanks for your time. I've resolve dthe issue, it's a little thing called a firewall and NATing thats causing the problem.

thanks again for responding.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: