1.11.5 Ensure 'SNMP community string' is not the default string

Information

Sets a SNMP community string different from the default one

Rationale:

The SNMP community string is a key used both by the security appliance and the NMS server. The security appliance accepts or rejects the requests from the NMS is a valid key is submitted.

From version 8.2(1) and above, for each community string, there are two SNMP server groups created, one for version 1 and another for version 2C. The default SNMP community string is public and can be used by an attacker to collect unauthorized information from the ASA and hence should be changed.

Solution

Run the following command to configure the SNMP community string

HOSTNAME(CONFIG)#SNMP-SERVER COMMUNITY _<snmp_community_string>_

In a multi-context environment, run the same command in the context.

See Also

https://workbench.cisecurity.org/files/1903

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5, CSCv6|5.3

Plugin: Cisco

Control ID: e9822fb80e63f31522d0146bf9ac1c5925b0ed6f2ec4244520cc61f9f1685801