Configuring Remote Access for SNMP

To enable SNMP and configure remote access using SNMP, perform the following steps.
Note: For additional information on controlling management access, refer to Restricting Remote Access Using IP Addresses or MAC Addresses.
  1. Enter global configuration mode.
    device# configure terminal
    device(config)#
  2. If necessary, enable SNMP access.
    device(config)# snmp-server
  3. Enter the management access command with appropriate parameters to configure SNMP remote access. On the same line, define the IPv4, IPv6, or MAC source address or a set of source addresses, an allow or deny action, and the protocol or protocols to which the allow or deny action applies when traffic is received from the specified address or set of addresses.
  4. (Optional) Configure additional management access command lines if needed.

The following example enables SNMP and configures a MAC address as an allowed source address for SNMP traffic.

device# configure terminal
device(config)# snmp-server 
device(config)# management access mac CC:4E:24:D0:8B:81 allow snmp

The following example enables SNMP server community/group/user configurations.

device# configure terminal
device(config)# management access src-ip 10.198.137.167 255.255.255.0 allow snmp-server community test1
device(config)# management access src-ip 10.198.137.167 255.255.255.0 allow snmp-server group test1
device(config)# management access src-ip 10.198.137.167 255.255.255.0 allow snmp-server user test1

The following example drops SNMP traffic received from the specified set of IPv4 addresses.

device(config)# management access src-ip 10.10.10.0 255.255.255.0 deny snmp

The following example drops SNMP server traffic received from the community/group/user configurations.

device(config)# management access src-ip 10.198.137.167 255.255.255.0 deny snmp-server community test1
device(config)# management access src-ip 10.198.137.167 255.255.255.0 deny snmp-server group test1
device(config)# management access src-ip 10.198.137.167 255.255.255.0 deny snmp-server user test1

Note: The management access snmp-server configuration only supports source ipv4 and ipv6. It does not support MAC-based filtering.

The snmp-server with management access must not be combined with other protocols such as ssh, telnet, webui, and snmp. As group/user/community names are required for snmp-server but not for other protocols.