Hacker News new | ask | show | jobs
by tptacek 3595 days ago
That's true if you're speaking SNMP over the Internet. But how many ASAs actually do that?
2 comments

ASAs are often used at the perimeter of small satellite networks using a local ISP's internet access, and then connecting back to HQ with IPSEC tunnels. I would guess that it is not uncommon, though bad practice, to centrally monitor SNMP on the external interface instead of over the IPSEC tunnel (which can be a little tricky to do).
Yeah, it's true I guess, and if you're using a random community string and this is NSA, I think we can all safely assume NSA knows every community string spoken anywhere on the public Internet.
I can count over a dozen easily, off the top of my head, without even looking into our customer database. I'm certain I'm not alone.