Snmp Anti-Violence Attack; Snmp Anti-Brute Force Attack Overview - Zte ZXR10 ZSR V2 Configuration Manual (System Management

Intelligent integrated multi-service router
Hide thumbs Also See for ZXR10 ZSR V2:
Table of Contents

Advertisement

ZXR10 ZSR V2 Configuration Guide (System Management)
snmp-server host 61.139.48.18 Trap version 2c public udp-port 162 snmp bgp mac
ospf stp ppp arp rmon udld cfm efm lacp mc-elam tcp sctp stalarm cps interface
acl fib pim isis rip msdp aps config am um system ldp pwe3 vpn mpls-oam ptp
tunnel-te radius dhcp bfd ippool ntp ssm sqa ipsec cgn vrrp ftp_tftp ping-trace gm
snmp-server host 61.139.48.18 inform version 2c public udp-port 162 snmp
snmp-server packetsize is 1400
snmp-server security dynamic-trust-user idle-timeout 1800
snmp-server view AllView internet included
snmp-server view DefaultView system included
snmp-server version v2c enable

6.2 SNMP Anti-Violence Attack

6.2.1 SNMP Anti–Brute Force Attack Overview
SNMP Anti–Brute Force Attack Description
A brute force attack means generating huge numbers of passwords with code generation
software, and trying each one. As long as there are enough chances and the password
has no protection, the most complicated key can be broken.
The security policy defined in SNMP v1 and SNMP v2 is simple, which uses clear text to
transfer community strings, which are passwords between SNMP management processes
and agent processes. These passwords can be cracked by attackers using brute force
attacks. The SNMP anti–brute force attack function is used to prevent DoS attacks and
brute force attacks.
SNMP Anti–Brute Force Attack Features
The SNMP anti–brute force attack function has introduced two concepts: block and quiet
mode. If the detection policy is enabled, the router can reject all SNMP requests in block
mode when finding repeated SNMP community string attempt failures. The block state
can last for a period known as "quiet period".
l
To ensure that trusted user can access the ZXR10 ZSR V2 normally, the SNMP
security function supports dynamically learning and manually configuring trusted
users. In quiet mode, the ZXR10 ZSR V2 only allows to handle requests from trusted
user (if an ACL is configured in advance, the requests still need to be filtered through
the ACL first).
l
Dynamically-learned trusted users refer to users who have accessed the ZXR10 ZSR
V2 and are automatically recorded by it. If these users have not accessed the ZXR10
ZSR V2 again until the set period (ageing time) expires, they will be aged by the
device. Dynamically-learned trusted users can also be manually cleared. Users can
configure the ageing time, which is 1800 s by default.
SJ-20140504150128-007|2014-05-10 (R1.0)
6-10
ZTE Proprietary and Confidential

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents