Cisco CCNA (200-301)IP ServicesHard

A network administrator is setting up SNMP on a Cisco router. They need to configure a read-only community string 'public_view' for a specific host 192.168.10.50 and a read-write community string 'private_control' for another host 192.168.10.51. Which command sequence correctly configures these SNMP community strings with proper security?

  1. ARouter(config)# snmp-server host 192.168.10.50 public_view Router(config)# snmp-server host 192.168.10.51 private_control
  2. BRouter(config)# snmp-server community public_view ro 10 Router(config)# access-list 10 permit host 192.168.10.50 Router(config)# snmp-server community private_control rw 20 Router(config)# access-list 20 permit host 192.168.10.51
  3. CRouter(config)# snmp-server community public_view ro Router(config)# snmp-server community private_control rw
  4. DRouter(config)# snmp-server community public_view ro 192.168.10.50 Router(config)# snmp-server community private_control rw 192.168.10.51
Show answer & explanation

Correct answer: B. Router(config)# snmp-server community public_view ro 10 Router(config)# access-list 10 permit host 192.168.10.50 Router(config)# snmp-server community private_control rw 20 Router(config)# access-list 20 permit host 192.168.10.51

To restrict SNMP access to specific hosts, an access list must be associated with the community string. The 'snmp-server community [string] [ro/rw] [acl_number]' command links the community string to an access list. The access list then permits or denies the specified hosts. Option C correctly uses access lists to restrict access for each community string to its respective host.

Why the other options are wrong

  • A. The 'snmp-server host' command is used to specify a destination for SNMP traps/informs, not to define community strings or restrict access to the SNMP agent on the router.
  • C. These commands define community strings but do not restrict access to specific hosts, making them insecure for the given requirement.
  • D. This command syntax is incorrect for specifying a single host directly after 'ro' or 'rw'. It would treat '192.168.10.50' as an access-list number, which is not what's intended here.

Cisco IOS SNMP Community String with ACL

Configuring an SNMP community string on a Cisco device and associating it with an access control list (ACL) to restrict which management stations can use that string.

  • Enhances security by limiting access to SNMP data.
  • Uses 'snmp-server community [string] [ro/rw] [acl_number]'.
  • The ACL specifies permitted source IP addresses.

Memory trick: For SNMP security, the 'community string' is the 'key', but the 'ACL' is the 'bouncer' at the door.

More IP Services questions