Re: Limiting ip addresses which have access to SNMP agent
Dave Shield <[email protected]>
| Newsgroups | gmane.network.net-snmp.user |
|---|---|
| Message-ID | <[email protected]> |
On 12 April 2011 16:57, Lewis Adam-VNQM87 <[email protected]> wrote: > does anyone know if there is a standard MIB which allows you to configure > the list of IP addresses which have access to an agent? No. That's probably the major difference between the Net-SNMP "com2sec" token, and the official COMMUNITY-MIB framework, for SNMPv1/v2c SNMPv3 has no mechanism for limiting queries by address. This is normally handled by /etc/hosts.{allow,deny} You could look at crafting a MIB to manage these files, I suppose. That would allow you to control/configure access to *all* network services, not just SNMP. > I'm guessing there isn't because we should probably be relying on either the > community string or the auth/priv combination to control access That's the SNMP model - yes. It's probably one of the most asked-for omissions! Dave ------------------------------------------------------------------------------ Forrester Wave Report - Recovery time is now measured in hours and minutes not days. Key insights are discussed in the 2010 Forrester Wave Report as part of an in-depth evaluation of disaster recovery service providers. Forrester found the best-in-class provider in terms of services and vision. Read this report now! http://p.sf.net/sfu/ibm-webcastpromo _______________________________________________ Net-snmp-users mailing list [email protected] Please see the following page to unsubscribe or change other options: https://lists.sourceforge.net/lists/listinfo/net-snmp-users