2.2.2 Ensure SNMP version is set to v3-Only

Information

Sets the SNMP v3.

Rationale:

SNMP Version 3 provides security enhancements that are not available in SNMP Version 1 or SNMP Version 2c. SNMP Versions 1 and 2c transmit data between the SNMP server and SNMP agent in clear text. SNMP Version 3 adds authentication and privacy options to secure protocol operations. For configuration purposes, the authentication and privacy options are grouped together into security models. Security models apply to users and groups, and are divided into the following three types: -NoAuthPriv-No Authentication and No Privacy, which means that no security is applied to messages. -AuthNoPriv-Authentication but No Privacy, which means that messages are authenticated. -AuthPriv-Authentication and Privacy, which means that messages are authenticated and encrypted. It is recommended that packets should be authenticated and encrypted

Solution

Run the following command to configure the SNMP agent-version v3-only
CLI:

Hostname> set snmp agent-version v3-Only



GUI:

Navigate to System Management > SNMP > Select V3-Only in Version

Default Value:

Not Configured

See Also

https://workbench.cisecurity.org/files/2828

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: CheckPoint

Control ID: 49b86190d059917623c3361ac9ccf70129589cc2a4100f521bdbaba1dd1841e8