[nsp-sec] [TLP:Yellow] Possible IOS(-XR) SNMP security issue
Chris Morrow
morrowc at ops-netman.net
Mon Oct 30 09:30:43 EDT 2017
At Mon, 30 Oct 2017 10:22:45 +0100,
Dominik Bay <db at rrbone.net> wrote:
>
> ----------- nsp-security Confidential --------
> - SNMP RW access and bypassing SNMP ACLs via IP-Spoofing
it's worth remembering, I think, that the access-list applied to a
community is not really a packet filter, you would also want to make
sure your iACL setup is complete, and drops your net-management
station address(es) at your customer/peering edge.
(also, turn off snmp writes)
-chris
More information about the nsp-security
mailing list