Chapter 10
SpeedTouch™ Monitoring
E-DOC-CTC-20051017-0155 v1.0
157
10.2.11 How to Restrict SNMP Access
SNMP Access
Restriction
You can restrict SNMP Access so that it is accepted from specific IP addresses only.
To do this, add the IP address or an IP Address range to the access list for the
service SNMPV3_Agent. Note that this also covers SNMPv1.
You can also restrict access to specific interface groups such as WAN, LAN, DMZ,...
How to Add an IP
Address to the Access
List
Use the following command:
with
<ip-range>
either the IP address or the range of IP addresses from which
SNMP access should be allowed.
How to Add an
Interface Group to the
Access List
Use the following command:
The
<group>
parameter determines which interface group has access to the
SNMP service.
How to View the
Configuration
Use the following command to view the configuration:
This results in the following output:
:service system ipadd name=SNMPV3_AGENT ip=<ip-range>
:service system ifadd name=SNMPV3_AGENT group =
<{wan|local|lan|tunnel|dmz|guest} or number>
:service system list name SNMPV3_AGENT expand enabled
Idx Name
Protocol
SrcPort
DstPort
Group
-----------------------------------------------------------------------
1 SNMPV3_AGENT
udp
161
Description................ Rx snmp GET, SET and GETNEXT PDUs
Properties................. server
Attributes................. state port aclip aclif aclifgroup map log
User Managed Attributes.... state aclip aclif aclifgroup map log
Attribute Values :
State...................... (administratively) disabled
Port....................... 161
Ip Access List............. any
Interface Access List...... any
Interface Group Access List any
Map List................... 161
Logging.................... disabled
Содержание SpeedTouch 620
Страница 2: ......
Страница 3: ...SpeedTouch 620 Operator s Guide...
Страница 10: ...Contents E DOC CTC 20051017 0155 v1 0 vi...
Страница 12: ...About this Operator s Guide E DOC CTC 20051017 0155 v1 0 2...
Страница 14: ...Chapter 1 Introduction E DOC CTC 20051017 0155 v1 0 4...
Страница 24: ...Chapter 2 SpeedTouch Command Line Interface E DOC CTC 20051017 0155 v1 0 14...
Страница 54: ...Chapter 4 SpeedTouch Configuration Management E DOC CTC 20051017 0155 v1 0 44...
Страница 84: ...Chapter 6 SpeedTouch System Services E DOC CTC 20051017 0155 v1 0 74...
Страница 122: ...Chapter 8 SpeedTouch Remote Access E DOC CTC 20051017 0155 v1 0 112...
Страница 202: ...Chapter 11 SpeedTouch Advanced Diagnostics E DOC CTC 20051017 0155 v1 0 192...
Страница 212: ...Chapter 12 SLA Monitoring E DOC CTC 20051017 0155 v1 0 202...
Страница 215: ......