I have a situation where i need to do snmp monitoring from a central location to a number of remote site servers, switches, routers etc. I originally set this up via ipsec vpn's between the central site c1841 and the remote site pix 501 and 506's, and c1800's. The ipsec vpn's will renegotiate their sa's and when doing this will drop the vpn and then false positives will be generated. Have tried to resolve this with keepalives and other methods but it still happens. I've also done this through assigning a static nat translation on the remote site and opening up the router/firewall for snmp(udp 161)from our central location and this works with no issues. I'm wondering if i need to be concerned about security with this method. The data being transferred is device statistical information and status and i'm assigning the snmp level as read only on a different community name than the default. wondering if this is an accepted method and how most people do this
- posted
13 years ago