Implementation
The three steps to implement are:
- Create SNMPv3 group
- Create SNMPv3 user
- Validate authPriv
snmp-server group testGroup v3 priv snmp-server user testUser testGroup v3 auth sha test1234 priv aes 128 test1234 access 1
The first part of the command creates the testGroup using SNMPv3 authPriv security model. The second creates the user testUser, makes this user a member of the previously created testGroup and implements SHA based authentication with AES128 used as the privacy protocol. Note the use of test1234 for both passwords however these should be different and secure. I've also included the optional access list to the command allowing a specific IP or range to access the user. You may use named access lists instead of standard.
The following is an snmpwalk command to verify the implementation when using SNMPv3. My advice is to always test your authentication using snmpwalk or snmpget before moving on to using other platforms to implement monitoring.
snmpwalk -v3 -u testUser -A test1234 -l authPriv -a SHA -x AES -X test1234 10.254.254.253 .1.3.6.1.4.1.9.3.6.5.0
The following is a decent post detailing the other user security models. Not entirely sure why anyone would implement anything other than authPriv though if you are using SNMP version 3.
http://networking-notes.blogspot.co.uk/2012/09/snmpv3-configuration-basics-on-ios-i.html
Leave a comment
Your email address will not be published. Comments are moderated before appearing. We retain your IP address for up to 90 days for moderation, then remove it.