Management Services Security - Configure read-only access; use read-write only when required - usm

Information

Only permit read-only mode to eliminate any possibility of changes to the few writable MIBs.

Solution

Do not configure SNMP v3 with write permissions.

user@host# edit snmp v3 vacm access group .+
user@host# set read-view <SNMP_VIEW>

See Also

http://www.juniper.net/us/en/training/jnbooks/day-one/fundamentals-series/hardening-junos-devices-checklist/

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6(10)

Plugin: Juniper

Control ID: d331af399339fb96d91b638daf5001cc8f13c66ba3e107e2b0577ffdf8569896