SNMP Overview

Simple Network Management Protocol (SNMP) is a set of protocols for managing complex networks. SNMP sends messages, called protocol data units (PDUs), to different parts of a network. SNMP-compliant devices, called agents, store data about themselves in Management Information Bases (MIBs) and return this data to the SNMP requesters.

There are several methods you can use to secure SNMP access:

  • Using ACLs to restrict SNMP access
  • Restricting SNMP access to a specific IP address
  • Restricting SNMP access to a specific VLAN
  • Disabling SNMP access

Restricting SNMP access using ACLs, VLANs, or a specific IP address constitutes the first level of defense when the packet arrives at a RUCKUS device. The next level uses one of the following methods:

  • Community string match In SNMP versions 1 and 2
  • User-based model in SNMP version 3

SNMP views are incorporated in community strings and the user-based model.

Note: For more information on using ACLs to restrict SNMP access, refer to the RUCKUS FastIron Security Configuration Guide. The protection offered by software-based ACLs are effective only after the SNMP requests reach the host; however, this doesn't prevent potential SNMP attacks such as Denial of Service (DoS) attack.