1.5.7 Set 'snmp-server host' when using SNMP

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

SNMP notifications can be sent as traps to authorized management systems.

Rationale:

If SNMP is enabled for device management and device alerts are required, then ensure the device is configured to submit traps only to authorize management systems.

Solution

Configure authorized SNMP trap community string and restrict sending messages to authorized management systems.


hostname(config)#snmp-server host {ip_address} {trap_community_string} {notification-type}

Impact:

Organizations using SNMP should restrict sending SNMP messages only to explicitly named systems to reduce unauthorized access.

Default Value:

A recipient is not specified to receive notifications.

References:

http://www.cisco.com/en/US/docs/ios-xml/ios/snmp/command/nm-snmp-cr-s5.html#GUID-D84B2AB5-6485-4A23-8C26-73E50F73EE61

See Also

https://workbench.cisecurity.org/files/2585

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-9, CSCv6|11.7

Plugin: Cisco

Control ID: 5f09cb5bd85d508cdad050a599a1eb689eb5378db2777dbfe2b6d40f427acd98