Management Services Security - Configure read-only access; use read-write only when required - community

Information

Only permit read-only mode to eliminate any possibility of changes to the few writable MIBs.

Solution

If SNMP version 1 or 2 is required, do not configure any communities with read-write permissions.

user@host# edit snmp community <COMMUNITY>
user@host# set authorization read-only

See Also

http://www.juniper.net/us/en/training/jnbooks/day-one/fundamentals-series/hardening-junos-devices-checklist/

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6

Plugin: Juniper

Control ID: b16d26c856671e74a2183713ad5c16e38f6b3f8ac3087ef9722b9554b82fec79