300-620 · Question #303
An engineer configures SNMP for an ACI fabric and created an SNMP Monitoring Destination Group called snmp_dgroup1. Snmp_dgroup1 is configured with the server hostname and community password. An SNMP
The correct answer is C. Configure an SNMP management contract to permit UDP 162.. To complete the SNMP configuration for an ACI fabric, a management contract must be configured to permit UDP port 162, which is the standard port for SNMP traps, allowing the ACI fabric to send traps to the configured destination group.
Question
An engineer configures SNMP for an ACI fabric and created an SNMP Monitoring Destination Group called snmp_dgroup1. Snmp_dgroup1 is configured with the server hostname and community password. An SNMP policy called snmp_podpolicy1 is configured to enable SNMP and add an SNMP Client Group Profile called snmp_clgroup1. Snmp_podpolicy1 is associated the default pod profile via a pod policy group named pod1. Which configuration set must the engineer enable to complete the SNMP configuration?
Options
- AConfigure the OOB management contract to permit UDP 162.
- BConfigure an SNMP management contract to permit all traffic.
- CConfigure an SNMP management contract to permit UDP 162.
- DConfigure the OOB management contract to permit all traffic.
How the community answered
(53 responses)- A6% (3)
- B11% (6)
- C81% (43)
- D2% (1)
Why each option
To complete the SNMP configuration for an ACI fabric, a management contract must be configured to permit UDP port 162, which is the standard port for SNMP traps, allowing the ACI fabric to send traps to the configured destination group.
OOB (Out-of-Band) management contracts are typically used for accessing the APICs or switches from an out-of-band network, not for the fabric itself to send traps to an external destination.
Permitting 'all traffic' in an SNMP management contract is overly permissive and introduces unnecessary security risks, deviating from best security practices.
SNMP traps are sent using UDP port 162. For the ACI fabric to successfully send SNMP traps to the monitoring destination group, an explicit management contract is required to permit this specific UDP port. This contract ensures the necessary communication path is open for SNMP traffic to leave the fabric.
Permitting 'all traffic' on an OOB management contract is both incorrect for the specific purpose of sending traps from the fabric and a significant security vulnerability.
Concept tested: ACI SNMP configuration and management contracts
Source: https://www.cisco.com/c/en/us/td/docs/dcn/aci/apic/6x/config/monitoring/cisco-aci-monitoring-config-guide-60x/m_snmp.html
Topics
Community Discussion
No community discussion yet for this question.