1.11.3 Ensure 'snmp-server host' is set to 'version 3'

Information

Sets the SNMP notification recipient or the NMS or SNMP manager that can connect to the ASA.

Rationale:

An SNMP host is an IP address to which SNMP notifications and traps are sent or which can send requests (polling) to the security appliance. To configure SNMP Version 3 hosts, along with the target IP address, the SNMP username must be provided, because traps are only sent to a configured user. It is an additional access control.

Solution

Run the following to configure the SNMP v3 host

hostname(config)# snmp-server host <interface_name> <host_ip_address> version 3 <snmp_user>

See Also

https://workbench.cisecurity.org/benchmarks/7194

Item Details

Category: CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING, PLANNING, PROGRAM MANAGEMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CM-7, 800-53|CP-6, 800-53|CP-7, 800-53|PL-8, 800-53|PM-7, 800-53|SA-8, 800-53|SC-7, CSCv7|11.1

Plugin: Cisco

Control ID: 9481e59c7b4870c7b3329b4d30aab913cb6d568cdfb9cfc44294eb7a07627e0f