I've configured Network Security for the SNMP Service in Windows Server 2003 as per http://support.microsoft.com/?kbid=324261.
However I can no longer query the machine from my Linux Cacti console.
My concern stems from this part of the MS how-to:
"Click the Authentication Methods tab. Kerberos is the default authentication method. If you require alternate authentication methods, click Add. In the New Authentication Method Properties dialog box, select the authentication method that you want from the following list, and then click OK:
Connecting to 2K3 via ipsec
Moderators: Developers, Moderators
This isn't a Cacti problem.
You've enabled kerberos authentication for snmp requests. Your linux box must authenticate itself via kerberos with the computer/domain before snmp communication will work; this does not need happen in Cacti.
You've enabled kerberos authentication for snmp requests. Your linux box must authenticate itself via kerberos with the computer/domain before snmp communication will work; this does not need happen in Cacti.
| Scripts: Monitor processes | RFC1213 MIB | DOCSIS Stats | Dell PowerEdge | Speedfan | APC UPS | DOCSIS CMTS | 3ware | Motorola Canopy |
| Guides: Windows Install | [HOWTO] Debug Windows NTFS permission problems |
| Tools: Windows All-in-one Installer |
Is it neccessary
So my real question is, for those who monitor MS servers, is it necessary to follow MS guidelines in regard to securing SNMP traffic? I have denied 161 and 162 from leaving the LAN, and I understand that SNMP is clear text, but besides the community string, what is the real threat?
I'd just set up a non-standard community name and restrict the IPs which can talk to SNMP. The risk of leaving it open, is that a person can find out a LOT about the computer via snmp.... what processes, user logged in, hardware, etc.
| Scripts: Monitor processes | RFC1213 MIB | DOCSIS Stats | Dell PowerEdge | Speedfan | APC UPS | DOCSIS CMTS | 3ware | Motorola Canopy |
| Guides: Windows Install | [HOWTO] Debug Windows NTFS permission problems |
| Tools: Windows All-in-one Installer |
Who is online
Users browsing this forum: No registered users and 8 guests