[c-nsp] Blocking SNMPv3 engine-id discovery [was: Re: How to disable ILMI/SNMP CSCvs33325]

2022-09-21 Thread Simon Leinen via cisco-nsp
Gert Doering writes: > On Wed, Sep 21, 2022 at 08:14:30AM +0300, Hank Nussbacher wrote: >> Indeed the SNMP leaks appear to be exactly CSCtw74132 which we did >> not know about nor did Cisco TAC :-( > The more I dive into this, the more I want to return to my bed and > pull the blanket over my head

Re: [c-nsp] How to disable ILMI/SNMP CSCvs33325

2022-09-21 Thread Gert Doering via cisco-nsp
Hi, so, more on this... - on ASR9k, SNMPv3 is subject to regular control plane ACLs, so unless a SNMPv3 sender shows up in control-plane management-plane inband interface all allow all peer address ipv4 1.2.3.4/32 ! allow SNMP peer

Re: [c-nsp] How to disable ILMI/SNMP CSCvs33325

2022-09-21 Thread Gert Doering via cisco-nsp
Hi, On Wed, Sep 21, 2022 at 08:14:30AM +0300, Hank Nussbacher wrote: > Indeed the SNMP leaks appear to be exactly CSCtw74132 which we did not > know about nor did Cisco TAC :-( The more I dive into this, the more I want to return to my bed and pull the blanket over my head... So, the Cisco bug