Configuring Remote Access for SNMP
- Enter global configuration mode.
- If necessary, enable SNMP access.
- Enter the
management accesscommand with appropriate parameters to configure SNMP remote access. On the same line, define the IPv4, IPv6, or MAC source address or a set of source addresses, anallowordenyaction, and the protocol or protocols to which theallowordenyaction applies when traffic is received from the specified address or set of addresses. - (Optional) Configure additional
management accesscommand lines if needed.
The following example enables SNMP and configures a MAC address as an allowed source address for SNMP traffic.
device# configure terminal device(config)# snmp-server device(config)# management access mac CC:4E:24:D0:8B:81 allow snmp
The following example enables SNMP server community/group/user configurations.
device# configure terminal device(config)# management access src-ip 10.198.137.167 255.255.255.0 allow snmp-server community test1 device(config)# management access src-ip 10.198.137.167 255.255.255.0 allow snmp-server group test1 device(config)# management access src-ip 10.198.137.167 255.255.255.0 allow snmp-server user test1
The following example drops SNMP traffic received from the specified set of IPv4 addresses.
device(config)# management access src-ip 10.10.10.0 255.255.255.0 deny snmp
The following example drops SNMP server traffic received from the community/group/user configurations.
device(config)# management access src-ip 10.198.137.167 255.255.255.0 deny snmp-server community test1 device(config)# management access src-ip 10.198.137.167 255.255.255.0 deny snmp-server group test1 device(config)# management access src-ip 10.198.137.167 255.255.255.0 deny snmp-server user test1
Note: The management access snmp-server configuration only supports
source ipv4 and ipv6. It does not support MAC-based filtering.
The snmp-server with management access must not be combined
with other protocols such as ssh, telnet, webui, and snmp. As
group/user/community names are required for snmp-server but not for other
protocols.