Management Services Security - Allow SNMP queries and/or send traps to more than one trusted server - clients restrict

Information

SNMP traps are unsolicited messages sent by network devices to notify management stations of important events.

Solution

If SNMP version 1 or 2 is required, configure the communitys to restrict all non-specified clients by default.

user@host# edit snmp community <COMMUNITY>
user@host# set clients <IP_ADDRESS>
user@host# set clients 0.0.0.0/0 restrict

See Also

http://www.juniper.net/us/en/training/jnbooks/day-one/fundamentals-series/hardening-junos-devices-checklist/

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(5)

Plugin: Juniper

Control ID: 06d7dff8092ccd9e0c5eaf1b0f411ef1a0829af562e8b98d7ac700b73eaf0933