× NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Orbi WiFi 7 RBE973
Reply

NMS300 config backup with telnet disabled?

cp42
Tutor

NMS300 config backup with telnet disabled?

Hello everybody,

 

we would like to use NMS300 to save the config of our 40 Netgear Switches automatically every night, but it seems that this requires telnet to be enabled on all switches. Is this by design or did I miss something? Transmitting a password for administrative access in cleartext over the network isn't best practice - to say the least...

Any thoughts? Thanks in advance!

 

Kind Regards

Christoph

Model: M4100-50G-PoE+ (GSM7248P)|ProSAFE 50-port Gigabit Fully Managed L2 Switch with PoE+
Message 1 of 6

Accepted Solutions
Retired_Member
Not applicable

Re: NMS300 config backup with telnet disabled?

Hi cp42,

 

Your testing result is right, telnet is required when do M4100 backup/restore (M4100 is a special case). However your idea (using encrypted protocol to do backup) is a very good. What you can do is to post suggestions and ideas at the Idea Exchange board. Adding kudos to the ideas will help as development team will be reviewing the post that has the most kudos for considering it to add to the product's future release.

 

Thank you again.

View solution in original post

Message 6 of 6

All Replies
Retired_Member
Not applicable

Re: NMS300 config backup with telnet disabled?

Hi cp42

 

Welcome to Netgear Community!

 

NMS300 support device credential via SNMPv1, SNMPv2c, SNMPv3, Telnet, SSH, HTTP and HTTPS, for Netgear Switches, we recommend to use SNMP and HTTP, then telnet has no need to enable because of security concern. That means, if you alreay select Telnet for device credential, it has to be enable when run a schedule backup task.

 

On NMS300, you can add one time or schedule task to backup devices configuration, get User Manual (page120) for more detail.

 

The new NMS300 build v1.5.0.18, which support to manage M4300 series switch:

Download Link:
Win32 bit: http://www.downloads.netgear.com/files/GDC/NMS300/NMS300_V1.5.0.18(Win32).zip
Win64 bit: http://www.downloads.netgear.com/files/GDC/NMS300/NMS300_V1.5.0.18(Win64).zip

Message 2 of 6
cp42
Tutor

Re: NMS300 config backup with telnet disabled?

Bruce, thanks for your feedback, but it doesn't solve the problem for me.

I know that NMS300 offers the configuration of device credentials for several protocols including ssh and that I can associate an ssh credential with my switches, but when I run a config backup profile for these switches I get the error message "No valid Telnet credential". I guess this means that I have to configure a Telnet credential for these switches because the config backup does work only via Telnet, right?

If it's possible to configure a config backup profile to use an encrypted connection (http and snmp are also unencrypted an therefore offer no advantage regarding security when compared to telnet) please let me know how this is possible...

Thank you!

 

Regards

Christoph

Message 3 of 6
Retired_Member
Not applicable

Re: NMS300 config backup with telnet disabled?

Hi cp42,

 

Thanks for your follow-up feedback.

 

I guess you associate telnet credential to device, however disable it on switch device side, that might be the reason to see the error message "No valid Telnet credential" (please login NMS300, go to Resources->Devices, click device to see "Device Detail View", select "credential" at the bottom, to view which credential are associated). Back to your question, Telnet is not required to backup/restore configuration file most time.

 

Which protocols to implement backup and restore? it depends on the type of devices, most Managed Switch use SNMP, most smart switch use HTTP or HTTPS, some Prosafe Firewall use HTTPS.

 

In out testing lab, we tried M6100 (Managed Switch, only associate SNMPv3) and S3300-52X (Smart Switch, associate SNMPv2 and HTTPS), schedule backup/restore on both devices working well.

 

If you have concern the unencrypted connection when do backup/restore, you can select SNMPv3 or HTTPS (please note that not all devices support backup/restore via HTTPS).

 

The latest NMS300 build fixed a schedule backup bug, please upgrade and try with my suggestion. If still can't resolve your issue, let me know the model of your Netgear switch.

Message 4 of 6
cp42
Tutor

Re: NMS300 config backup with telnet disabled?

Hi Bruce,

 

now I've found time to do some more testing:

 

- upgraded our NMS300 installation to version 1.5.0.18

- enabled SNMPv3, HTTPS and ssh and disabled telnet on one test switch of type M4100-50G-PoE+, Firmware 10.0.2.20

- created credentials for SNMPv3, HTTPS and ssh

- cretated a config backup profile with the above test switch included

- deleted telnet from the associated credentials of this switch

- associated the SNMPv3 credential to the test switch, executed the backup profile -> "No valid Telnet credential"

- associated the HTTPS credential to the test switch, executed the backup profile -> "No valid Telnet credential"

- associated the ssh credential to the test switch, executed the backup profile -> "No valid Telnet credential"

- enabled telnet on that switch

- associated the telnet credential to the test switch, executed the backup profile -> OK

 

So, if telnet is not required for a configuration backup profile, please let me know how to use an encrypted connection. I have no idea what could be wrong in my configuartion. Thanks!

 

Kind Regards

Christoph

 

 

Model: M4100-50G-PoE+ (GSM7248P)|ProSAFE 50-port Gigabit Fully Managed L2 Switch with PoE+
Message 5 of 6
Retired_Member
Not applicable

Re: NMS300 config backup with telnet disabled?

Hi cp42,

 

Your testing result is right, telnet is required when do M4100 backup/restore (M4100 is a special case). However your idea (using encrypted protocol to do backup) is a very good. What you can do is to post suggestions and ideas at the Idea Exchange board. Adding kudos to the ideas will help as development team will be reviewing the post that has the most kudos for considering it to add to the product's future release.

 

Thank you again.

Message 6 of 6
Top Contributors
Discussion stats
  • 5 replies
  • 4548 views
  • 1 kudo
  • 2 in conversation
Announcements