Loading...
Loading...
"no ip routing" shows up in the config, while all routing protocol configurations are removed. No Syslogs are logged indicating configuration change.
A read-write community string is present, such as: snmp-server community RW
See http://www.cisco.com/c/en/us/support/docs/ip/access-lists/13608-21.html#anc50 for guidance on hardening SNMP Considerations include: 1) Apply an ACL to the snmp-server community, or change to RO permissions if SNMP RW access is not needed. 2) Avoid easy to guess community strings. 3) Apply an ACL to the snmp-server community to only allow trusted hosts. 4) Change permissions to RO, instead of RW: snmp-server community hard-to-guess-string RO accesslistnumber All of the above are general best practices for SNMP configs 4) If SNMP RW access is needed, apply a view to prevent access to ipForwarding MIB, in addition to the measures above snmp-server view WORKAROUND iso included snmp-server view WORKAROUND ip.1 excluded snmp-server community hard-to-guess-string view WORKAROUND RW accesslistnumber
This bug only eases diagnosis. Only the configuration changes suggested above will prevent snmp from modifying the configuration. When "ip routing" is disabled, "ip cef" is automatically disabled too. The best way to recover from the snmpset is to enable "ip routing" and then perform a "copy start run", assuming startup config is up to date. If it is not, manual reapplication of routing configuration may be required.
Cisco Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.