- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-16-2024 06:58 AM
An IT Auditor stated that SNMP is listening through the firewall for a specific Public IP Address.
I have been filtering the network traffic on the PaloAlto 3020 for that specific IP address and also filtering with port 161. BUt Id not see any results except that the 'Deny-Deny' catch all group was being used. That is suggesting to me that the auditr's readings are false.
Question: How can I verify if port udp-161 is being allowed/used to a pass traffc thorugh the firewall? Thus far I click on the
Monitor' tab and I only see any traffic from the fiter tab and then traffic is specifically being sent to port 161 and it is being denied (catch all rule).
Question: If SNMP is being transfered from the indide world; how may I verify this?
02-16-2024 02:51 PM
Hi @PetrosKafkas ,
From the top of my mind, it comes down to SNMP that is allowed via your security policies or an SNMP trap server profile configured for your actual Palo (Device -> Server Profile -> SNMP).
To verify policies, I would double-check and verify that any internal traffic is not getting out to the questionable public IP. You can filter with any as a source with the destination being the public IP. You can also search with the public address as being the source and destination being any. Other than that, if you don't see SNMP being allowed via policy, don't see it configured as a manager, and see it being blocked then you can be confident that SNMP is not flowing through your Palo.
The only other thing that comes into question is if there is a segment of your network that bypasses the Palo and has their own internet gateway. I would reach out to the auditor and see how the testing is being done.
Good luck!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!