networking-forum.com
Community BlogCommunity Wiki * Register  * Search  * Login
View unanswered postsView active topics

All times are UTC - 6 hours [ DST ]



Post new topic Reply to topic  [ 6 posts ] 
Author Message
PostPosted: Thu May 17, 2012 12:13 pm 
Offline
Site Admin
Site Admin
User avatar

Joined: Mon Dec 06, 2004 6:46 pm
Posts: 10314
Location: McKinney, TX
Certs: CCNA
Is there a way to provide RO SNMP access for a customer to a single interface on a device, an ASA in this case?

_________________
Find networking-forum.com on Facebook, LinkedIn, Twitter, Google+,or subscribe to the site's RSS feeds.


Top
 Profile  
 
PostPosted: Thu May 17, 2012 12:21 pm 
Offline
Senior Member
Senior Member
User avatar

Joined: Thu Nov 17, 2011 6:09 pm
Posts: 487
Location: Portland, OR
I've never heard of such an ACL. It's more typical to give the customer a single view to that interface on your NMS.


Top
 Profile  
 
PostPosted: Thu May 17, 2012 12:25 pm 
Offline
Post Whore
Post Whore
User avatar

Joined: Mon Jan 17, 2005 11:01 pm
Posts: 5148
Location: Canada eh
Certs: 350-001, CCNP, CXFF, ITILv3F
Maybe using views...

http://www.cisco.com/en/US/docs/ios/net ... #wp1014124

You'd have to sort out all the OIDs you want to allow though. It's not as simple as allowing an interface. Once you've defined the OIDs in the view then you can restrict it with 'snmp-server community COMMUNITY view VIEW ro' command like you would with just a straight up community.

Oh, and it likely goes without saying, but you'd for sure want ifindex persistence if you're doing this. :)

_________________
blog.brokennetwork.ca


Top
 Profile  
 
PostPosted: Thu May 17, 2012 12:27 pm 
Offline
Member
Member

Joined: Thu Feb 12, 2009 5:23 pm
Posts: 129
Location: Phoenix, AZ
You may be able to setup an SNMP view that's restricted to the OIDs for that interface and tie it to a community string for the customer. Can't say I've ever tried to go that granular with SNMP views though.

edit: Doh! Too slow.


Top
 Profile  
 
PostPosted: Thu May 17, 2012 1:57 pm 
Offline
Site Admin
Site Admin
User avatar

Joined: Mon Dec 06, 2004 6:46 pm
Posts: 10314
Location: McKinney, TX
Certs: CCNA
From http://www.cisco.com/en/US/docs/securit ... _snmp.html :

Quote:
Implementation Differences Between the ASA, ASA Services Module, and the Cisco IOS Software

The SNMP Version 3 implementation in the ASA and ASASM differs from the SNMP Version 3 implementation in the Cisco IOS software in the following ways:
[content removed]
-No support exists for view-based access control, which results in unrestricted MIB browsing.


:wall:

_________________
Find networking-forum.com on Facebook, LinkedIn, Twitter, Google+,or subscribe to the site's RSS feeds.


Top
 Profile  
 
PostPosted: Thu May 17, 2012 4:10 pm 
Offline
Senior Member
Senior Member
User avatar

Joined: Thu Nov 17, 2011 6:09 pm
Posts: 487
Location: Portland, OR
I did not know about the view-based ACL's, which sound pretty neat. Also, didn't know about the ASA limitations either! Thanks, good stuff.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 6 posts ] 

All times are UTC - 6 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 6 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
cron
Powered by phpBB® Forum Software © phpBB Group