How to implement SNMP communication security on Win2K

  
SNMPService
Also known as Simple Network
ManagementProtocol
, it is proposed to solve the problem of router management on the Internet. Acting as an agent in the Windows operating system, it collects information that can be reported to an SNMP management station or console. Rely on the use of SNMPservices
to allow the system to collect data and manage computers based on Windows 2000/XP
/2003 operating system within the entire network
Br>.

Generally, SNMP messages are sent in clear text, but these messages can be easily intercepted "the Microsoft
Network Monitor" such Network analyzer and
decoding. Unauthorized people can capture community names to get important information about network
resources. Therefore, the service
such as SNMP must pay attention to its security
to be widely used effectively.

To protect our SNMP from unauthorized actions, we need to perform a series of security
measures on the system, such as the "IPSecurity
protocol
" is used to protect SNMP communication. The IP Sec policy that protects the communication on TCP and UDP ports 161 and 162 is created on the system to protect the security
of the SNMP service
.

Step 1: Select “Start→Control Panel→Manage Tools
→LocalSecurity
Strategy”, right click on the left column “IPSecurity
Strategy In the Local Computer
", select "Manage IP Filter List and Filter Actions".

Step 2: Select "Manage IP Filter List" and click the "Add" button. Enter "161/162 Port" in the Name field in the "IP Filter List" and "161/162 Port Filter" in the "Description" box. Click to remove the "Add Wizard" checkbox, then click the "Add" button. In the Source Address box (on the Addressing tab of the displayed IP Filter Properties dialog box), select Any IP Address. In the "Destination Address" area, select "My IP Address" and select "Mirror. You need to select the match for packets with the opposite source and destination addresses" checkbox.

Step 3: Click the " Protocol
" tab and select "UDP" in "Select Protocol
Type". In the "Set IP Protocol
Ports" area, select "From this port" and enter 161. Click "To this port", then enter 161, click the "OK" button, in the "IP Filter List" dialog box, select the "Add" button. Add the port of 162 again in the same way.
Copyright © Windows knowledge All Rights Reserved