Connecting to 2K3 via ipsec

Post support questions that relate to the Windows 2003/2000/XP operating systems.

Moderators: Developers, Moderators

Post Reply
rweales
Posts: 20
Joined: Wed May 03, 2006 12:50 pm

Connecting to 2K3 via ipsec

Post by rweales »

I've configured Network Security for the SNMP Service in Windows Server 2003 as per http://support.microsoft.com/?kbid=324261.

However I can no longer query the machine from my Linux Cacti console.

My concern stems from this part of the MS how-to:

"Click the Authentication Methods tab. Kerberos is the default authentication method. If you require alternate authentication methods, click Add. In the New Authentication Method Properties dialog box, select the authentication method that you want from the following list, and then click OK:
rweales
Posts: 20
Joined: Wed May 03, 2006 12:50 pm

Post by rweales »

For some reason, I can't post the part of the MS article, but it uses AD/Kerberos for auth. How can Cacti communicate to AD this way?
User avatar
BSOD2600
Cacti Moderator
Posts: 12171
Joined: Sat May 08, 2004 12:44 pm
Location: USA

Post by BSOD2600 »

This isn't a Cacti problem.

You've enabled kerberos authentication for snmp requests. Your linux box must authenticate itself via kerberos with the computer/domain before snmp communication will work; this does not need happen in Cacti.
rweales
Posts: 20
Joined: Wed May 03, 2006 12:50 pm

Is it neccessary

Post by rweales »

So my real question is, for those who monitor MS servers, is it necessary to follow MS guidelines in regard to securing SNMP traffic? I have denied 161 and 162 from leaving the LAN, and I understand that SNMP is clear text, but besides the community string, what is the real threat?
User avatar
BSOD2600
Cacti Moderator
Posts: 12171
Joined: Sat May 08, 2004 12:44 pm
Location: USA

Post by BSOD2600 »

I'd just set up a non-standard community name and restrict the IPs which can talk to SNMP. The risk of leaving it open, is that a person can find out a LOT about the computer via snmp.... what processes, user logged in, hardware, etc.
Post Reply

Who is online

Users browsing this forum: No registered users and 6 guests