<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Prevent Read-only users from viewing Read-Write/Admin SNMP Credentials in FAQs</title>
    <link>https://community.extremenetworks.com/t5/faqs/prevent-read-only-users-from-viewing-read-write-admin-snmp/m-p/46361#M390</link>
    <description>Article ID: 5898 &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Protocols/Features&lt;/B&gt;&lt;BR /&gt;
SNMP &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Goal&lt;/B&gt;&lt;BR /&gt;
Prevent Read-only users from viewing Read-Write or Admin SNMP credentials &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Symptoms&lt;/B&gt;&lt;BR /&gt;
RO users can see rw / admin snmp credentials in the MIBs &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Cause&lt;/B&gt;&lt;BR /&gt;
When setting up SNMPv1/2/3 configurations, it is not unusual to allow each user an unrestricted view of the entire MIB Tree. &lt;BR /&gt;
&lt;BR /&gt;
Doing this for read-only groups (and thus, read-only users) unfortunately allows them the possibility of viewing the branch containing the SNMP configuration parameters, which could then be used to provide sufficient credentials to obtain read-write or admin level SNMP access. &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Solution&lt;/B&gt;&lt;BR /&gt;
FAD (Functions as Designed) &lt;BR /&gt;
&lt;BR /&gt;
The following command sequence creates an SNMP view (&lt;A href="http://bit.ly/1c2ANeF" target="_blank" rel="nofollow noreferrer noopener"&gt;5610&lt;/A&gt;) permitting full MIB access &lt;I&gt;except&lt;/I&gt; for the 'snmpV2=1.3.6.1.6' branch:&lt;BR /&gt;
   set snmp view viewname RO subtree 1&lt;BR /&gt;
   set snmp view viewname RO subtree 0.0&lt;BR /&gt;
   set snmp view viewname RO subtree 1.3.6.1.6 excluded&lt;BR /&gt;
 &lt;BR /&gt;
 For any SNMP version this (case-sensitive) 'RO' view may then be referenced instead of the default 'All' view, in the 'set snmp access' commands for read-only groups (&lt;A href="http://bit.ly/1914OY1" target="_blank" rel="nofollow noreferrer noopener"&gt;5245&lt;/A&gt;).</description>
    <pubDate>Sun, 24 Nov 2013 22:42:00 GMT</pubDate>
    <dc:creator>FAQ_User</dc:creator>
    <dc:date>2013-11-24T22:42:00Z</dc:date>
    <item>
      <title>Prevent Read-only users from viewing Read-Write/Admin SNMP Credentials</title>
      <link>https://community.extremenetworks.com/t5/faqs/prevent-read-only-users-from-viewing-read-write-admin-snmp/m-p/46361#M390</link>
      <description>Article ID: 5898 &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Protocols/Features&lt;/B&gt;&lt;BR /&gt;
SNMP &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Goal&lt;/B&gt;&lt;BR /&gt;
Prevent Read-only users from viewing Read-Write or Admin SNMP credentials &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Symptoms&lt;/B&gt;&lt;BR /&gt;
RO users can see rw / admin snmp credentials in the MIBs &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Cause&lt;/B&gt;&lt;BR /&gt;
When setting up SNMPv1/2/3 configurations, it is not unusual to allow each user an unrestricted view of the entire MIB Tree. &lt;BR /&gt;
&lt;BR /&gt;
Doing this for read-only groups (and thus, read-only users) unfortunately allows them the possibility of viewing the branch containing the SNMP configuration parameters, which could then be used to provide sufficient credentials to obtain read-write or admin level SNMP access. &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Solution&lt;/B&gt;&lt;BR /&gt;
FAD (Functions as Designed) &lt;BR /&gt;
&lt;BR /&gt;
The following command sequence creates an SNMP view (&lt;A href="http://bit.ly/1c2ANeF" target="_blank" rel="nofollow noreferrer noopener"&gt;5610&lt;/A&gt;) permitting full MIB access &lt;I&gt;except&lt;/I&gt; for the 'snmpV2=1.3.6.1.6' branch:&lt;BR /&gt;
   set snmp view viewname RO subtree 1&lt;BR /&gt;
   set snmp view viewname RO subtree 0.0&lt;BR /&gt;
   set snmp view viewname RO subtree 1.3.6.1.6 excluded&lt;BR /&gt;
 &lt;BR /&gt;
 For any SNMP version this (case-sensitive) 'RO' view may then be referenced instead of the default 'All' view, in the 'set snmp access' commands for read-only groups (&lt;A href="http://bit.ly/1914OY1" target="_blank" rel="nofollow noreferrer noopener"&gt;5245&lt;/A&gt;).</description>
      <pubDate>Sun, 24 Nov 2013 22:42:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/faqs/prevent-read-only-users-from-viewing-read-write-admin-snmp/m-p/46361#M390</guid>
      <dc:creator>FAQ_User</dc:creator>
      <dc:date>2013-11-24T22:42:00Z</dc:date>
    </item>
  </channel>
</rss>

