<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic System Insight Manager (SIM) SNMP Security Document in BladeSystem - General</title>
    <link>https://community.hpe.com/t5/bladesystem-general/system-insight-manager-sim-snmp-security-document/m-p/5336847#M25989</link>
    <description>&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;Sami had a customer requirement:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;****************&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SNMP is not allowed in the customer’s network. Does SIM work without SNMP properly? What is the effect for having SIM working with WBEM only?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;****************&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;Dave replied:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;****************&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SIM will first use WBEM for most OS’s that can use it. It will use SNMP as a backup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Most network switches amongst other devices can only use SNMP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Consider the following.&amp;nbsp; Other protocols may be available for certain things, but basic communications about hardware status and faults are&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ProLiant Windows&lt;/P&gt;&lt;P&gt;ProLiant WBEM (WMI) Providers available&lt;/P&gt;&lt;P&gt;ProLiant Linux&lt;/P&gt;&lt;P&gt;ProLiant SNMP Agents only&lt;/P&gt;&lt;P&gt;ProLiant ESX 4.x&lt;/P&gt;&lt;P&gt;ProLiant SNMP Agents only&lt;/P&gt;&lt;P&gt;ProLiant ESXi 4.x&lt;/P&gt;&lt;P&gt;ProLiant WBEM Providers only&lt;/P&gt;&lt;P&gt;ProLiant ESXi 5 (vSphere 5)&lt;/P&gt;&lt;P&gt;ProLiant WBEM Providers only&lt;/P&gt;&lt;P&gt;Onboard Administrator&lt;/P&gt;&lt;P&gt;SNMP only&lt;/P&gt;&lt;P&gt;iLO, iLO 2, iLO3&lt;/P&gt;&lt;P&gt;SNMP only&lt;/P&gt;&lt;P&gt;BladeSystem interconnects&lt;/P&gt;&lt;P&gt;SNMP only&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone who claims that they don’t have SNMP on their network is misinformed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The hysteria around SNMP security is much ado about nothing, and usually is due to a security “expert” and a recent consulting engagement.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When used responsibly as we do in ProLiant and BladeSystem products, SNMP is fast, effective, and does not pose any undue security threat.&amp;nbsp; No management protocol, including encrypted “secure” ones, should be exposed unprotected to the open Internet.&amp;nbsp; So, following that guideline, if your fear around SNMP is someone sniffing your network, then honestly if someone is sniffing your corporate network, you have a bigger problem than SNMP (with one big exception:&amp;nbsp; any kind of educational institution).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;*****************&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;Comments? Do you have a security issue using SNMP?&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 19 Sep 2011 20:22:02 GMT</pubDate>
    <dc:creator>chuckk281</dc:creator>
    <dc:date>2011-09-19T20:22:02Z</dc:date>
    <item>
      <title>System Insight Manager (SIM) SNMP Security Document</title>
      <link>https://community.hpe.com/t5/bladesystem-general/system-insight-manager-sim-snmp-security-document/m-p/5336847#M25989</link>
      <description>&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;Sami had a customer requirement:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;****************&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SNMP is not allowed in the customer’s network. Does SIM work without SNMP properly? What is the effect for having SIM working with WBEM only?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;****************&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;Dave replied:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;****************&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SIM will first use WBEM for most OS’s that can use it. It will use SNMP as a backup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Most network switches amongst other devices can only use SNMP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Consider the following.&amp;nbsp; Other protocols may be available for certain things, but basic communications about hardware status and faults are&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ProLiant Windows&lt;/P&gt;&lt;P&gt;ProLiant WBEM (WMI) Providers available&lt;/P&gt;&lt;P&gt;ProLiant Linux&lt;/P&gt;&lt;P&gt;ProLiant SNMP Agents only&lt;/P&gt;&lt;P&gt;ProLiant ESX 4.x&lt;/P&gt;&lt;P&gt;ProLiant SNMP Agents only&lt;/P&gt;&lt;P&gt;ProLiant ESXi 4.x&lt;/P&gt;&lt;P&gt;ProLiant WBEM Providers only&lt;/P&gt;&lt;P&gt;ProLiant ESXi 5 (vSphere 5)&lt;/P&gt;&lt;P&gt;ProLiant WBEM Providers only&lt;/P&gt;&lt;P&gt;Onboard Administrator&lt;/P&gt;&lt;P&gt;SNMP only&lt;/P&gt;&lt;P&gt;iLO, iLO 2, iLO3&lt;/P&gt;&lt;P&gt;SNMP only&lt;/P&gt;&lt;P&gt;BladeSystem interconnects&lt;/P&gt;&lt;P&gt;SNMP only&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone who claims that they don’t have SNMP on their network is misinformed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The hysteria around SNMP security is much ado about nothing, and usually is due to a security “expert” and a recent consulting engagement.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When used responsibly as we do in ProLiant and BladeSystem products, SNMP is fast, effective, and does not pose any undue security threat.&amp;nbsp; No management protocol, including encrypted “secure” ones, should be exposed unprotected to the open Internet.&amp;nbsp; So, following that guideline, if your fear around SNMP is someone sniffing your network, then honestly if someone is sniffing your corporate network, you have a bigger problem than SNMP (with one big exception:&amp;nbsp; any kind of educational institution).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;*****************&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;Comments? Do you have a security issue using SNMP?&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2011 20:22:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/bladesystem-general/system-insight-manager-sim-snmp-security-document/m-p/5336847#M25989</guid>
      <dc:creator>chuckk281</dc:creator>
      <dc:date>2011-09-19T20:22:02Z</dc:date>
    </item>
  </channel>
</rss>

