The HP FlexFabric switch must be configured to send SNMP traps and notifications to the SNMP manager for the purpose of sending alarms and notifying appropriate personnel as required by specific events.
An XCCDF Rule
Description
<VulnDiscussion>If appropriate actions are not taken when a network device failure occurs, a denial of service condition may occur which could result in mission failure since the network would be operating without a critical security monitoring and prevention function. Upon detecting a failure of network device security components, the HP FlexFabric Switch must activate a system alert message, send an alarm, or shut down. By immediately displaying an alarm message, potential security violations can be identified more quickly even when administrators are not logged on to the device. This can be facilitated by the switch sending SNMP traps to the SNMP manager that can then have the necessary action taken by automatic or operator intervention.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>
- ID
- SV-80791r1_rule
- Severity
- Medium
- References
- Updated
Remediation - Manual Procedure
Configure the HP FlexFabric Switch to send system alert messages and alarms to a SNMP agent:
[HP]snmp-agent
[HP]snmp-agent sys-info version v3
[HP]snmp-agent group v3 group1 privacy
[HP]snmp-agent target-host trap address udp-domain 192.168.16.103 params securityname snmp1 v3 privacy