SNMP: Use SNMPv3 only

Information

The exclusive use of SNMPv3 will ensure that only valid nodes can communicate with TiMOS/SR-OS devices. Used in conjunction with user access controls covered previously will eliminate possible configuration changes from unauthorized sources. Further, it ensures the communication between a SAM and a TiMOS/SR-OS device will be secured from snooping. This feature will contribute to the integrity of the operating environment.

NOTE: This check fails because SNMP is not configured.

Solution

Run the following command on the device to configure SNMPv3 for access groups: configure system security snmp access group <name> security-model usm

See Also

https://infoproducts.alcatel-lucent.com/aces/cgi-bin/dbaccessfilename.cgi/9305050101_V1_SR-OS Security Best Practices v2.0.pdf

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-2(1)

Plugin: Alcatel

Control ID: 16b32097a2814085af10e9f5e8ee3ef8cf120dc93885846d244c0f065f118986