1.5.6 Create an 'access-list' for use with SNMP - 'SNMP deny secured by ACL'

Information

You can use access lists to control the transmission of packets on an interface, control Simple Network Management Protocol (SNMP) access, and restrict the contents of routing updates. The Cisco IOS software stops checking the extended access list after a match occurs.

Solution

Configure SNMP ACL for restricting access to the device from authorized management stations segmented in a trusted management zone.
hostname(config)#access-list <snmp_acl_number> permit <snmp_access-list>
hostname(config)#access-list deny any log

See Also

https://workbench.cisecurity.org/files/508

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(5), 800-53|SC-7(15)

Plugin: Cisco

Control ID: 0098b718a6edaa7e85ef6907ec6b792ebd863aeaf1dc4dffb2c62931fac67ede