Tripp Lite B097048 Owners Manual for B093- B097- and B098-Series Console Serve - Page 248

Check Firewall Rules, 5.3 Enable SNMP Service

Page 248 highlights

15. Advanced Configuration 15.5.2 Check Firewall Rules Select System: Services. Ensure the SNMP daemon box has been checked for the interface required. This will allow SNMP requests through the firewall for the specified interface. 15.5.3 Enable SNMP Service The console server supports different versions of SNMP, including SNMPv1, SNMPv2c and SNMPv3. SNMP, although an industry standard, brings with it a variety of security concerns. For example, SNMPv1 and SNMPv2c offer no inherent privacy, while SNMPv3 is susceptible to man-in-the-middle attacks. Recent IETF developments suggests tunnelling SNMP over widely accepted technologies such as SSH (Secure Shell) or TLS (Transport Layer Security), rather than relying on a less mature security systems such as SNMPv3's USM (User-based Security Model). Additional information regarding SNMP security issues and SNMPv3 can be found at: http://net-snmp.sourceforge.net/wiki/index.php/TUT:Security http://www.ietf.org/html.charters/snmpv3-charter.html. • Select Alerts & Logging: SNMP. • The SNMP Service Details tab is shown by default. The SNMP Service Details tab controls aspects of the SNMP Service, including Security Level. It manages requests from external agents for Tripp Lite status information. • Check the Enable the SNMP Service box to start the SNMP Service. The service is disabled by default. • Select either UDP or TCP for the TCP/IP Protocol. UDP is the recommended protocol and selected by default. TCP should only be used in special cases, such as when Port Forwarding SNMP requests/responses to or from the Tripp Lite device is required. • Complete the Location and Contact fields. The Location field should describe the physical location of the Tripp Lite device and will be used in response to requests for the SNMPv2-MIB::sysLocation.0 of the device. The Contact field refers to the person responsible for the Tripp Lite device (i.e. System Administrator). This will be used in response to request SNMPv2MIB::sysContact.0. 248

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288

248
15. Advanced Configuration
15.5.2 Check Firewall Rules
Select
System: Services
. Ensure the
SNMP daemon
box has been checked for the interface required. This will allow SNMP
requests through the firewall for the specified interface.
15.5.3 Enable SNMP Service
The console server supports different versions of SNMP, including SNMPv1, SNMPv2c and SNMPv3.
SNMP, although an industry standard, brings with it a variety of security concerns. For example, SNMPv1 and SNMPv2c offer
no inherent privacy, while SNMPv3 is susceptible to man-in-the-middle attacks. Recent IETF developments suggests tunnelling
SNMP over widely accepted technologies such as SSH (Secure Shell) or TLS (Transport Layer Security), rather than relying on
a less mature security systems such as SNMPv3’s USM (User-based Security Model).
Additional information regarding SNMP security issues and SNMPv3 can be found at:
http://net-snmp.sourceforge.net/wiki/index.php/TUT:Security
• Select
Alerts & Logging: SNMP
.
• The
SNMP Service Details
tab is shown by default. The SNMP Service Details tab controls aspects of the SNMP Service,
including Security Level. It manages requests from external agents for Tripp Lite status information.
• Check the
Enable the SNMP Service
box to start the SNMP Service. The service is disabled by default.
• Select either
UDP
or
TCP
for the TCP/IP Protocol. UDP is the recommended protocol and selected by default. TCP should
only be used in special cases, such as when Port Forwarding SNMP requests/responses to or from the Tripp Lite device is
required.
• Complete the
Location
and
Contact
fields. The Location field should describe the physical location of the Tripp Lite device
and will be used in response to requests for the SNMPv2-MIB::sysLocation.0 of the device. The Contact field refers to the
person responsible for the Tripp Lite device (i.e. System Administrator). This will be used in response to request SNMPv2-
MIB::sysContact.0.