SNMPv2c/v1 used-paloaltonetworks-panos

SNMPv2c/v1 used-paloaltonetworks-panos

Vendor: paloaltonetworks

OS: panos

Description:
As SNMPv2 is not very secure, Indeni will alert if it is used.

Remediation Steps:
Configure SNMPv3 instead.

How does this work?
This script pulls the Palo Alto Networks firewall’s active configuration and extracts the configured services from there.

Why is this important?
SNMPv2c is an unsecure protocol and should not be used. Users should prefer the more secure SNMPv3.

Without Indeni how would you find this?
An administrator may write a script to pull this data from devices and compare against a gold configuration.

panos-show-config-merged-monitoring-xml

Failed to fetch the data: https://bitbucket.org/indeni/indeni-knowledge/src/master/parsers/src/panw/panos/show-config-merged-m/show-config-merged-m.ind.yaml

cross_vendor_snmp_v2

Failed to fetch the data: https://bitbucket.org/indeni/indeni-knowledge/src/master/rules/templatebased/crossvendor/cross_vendor_snmp_v2.scala