2.6 Ensure proper SNMP configuration- 'community name public does not exist'

Information

Verify that SNMP (Simple Network Management Protocol) is configured and that all the
settings are correct. If SNMP is not being used, it should be disabled.Note- ESXi 5.1 supports SNMPv3 which provides stronger security than SNMPv1 or
SNMPv2, including key authentication and encryption.

*Rationale*

If SNMP is not being used, it should remain disabled. If it is being used, the proper trap
destination should be configured. If SNMP is not properly configured, monitoring
information can be sent to a malicious host.

Solution

To implement the recommended configuration state, run the following PowerCLI
command-# Update the host SNMP Configuration (single host connection required)
Get-VmHostSNMP | Set-VMHostSNMP -Enabled-$true -ReadOnlyCommunity '<secret>'

Notes-. SNMP must be configured on each ESXi host. SNMP settings can be configured using Host Profiles

See Also

https://workbench.cisecurity.org/files/902

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5c.

Plugin: VMware

Control ID: 793cd98df28a14575390822a8db6ce1e50f00bfe296b8da77424973b0236b91d