Cli And Snmp User Synchronization; Aaa Exclusive Behavior In Snmpv3 Servers - Cisco Nexus 7000 Series Configuration Manual

Hide thumbs Also See for Nexus 7000 Series:
Table of Contents

Advertisement

SNMPv3
The priv option offers a choice of DES or 128-bit AES encryption for SNMP security encryption. The priv
option and the aes-128 token indicate that this privacy password is for generating a 128-bit AES key. The
AES priv password can have a minimum of eight characters. If the passphrases are specified in clear text, you
can specify a maximum of 64 case-sensitive, alphanumeric characters. If you use the localized key, you can
specify a maximum of 130 characters.
For an SNMPv3 operation using the external AAA server, you must use AES for the privacy protocol in
Note
the user configuration on the external AAA server.

CLI and SNMP User Synchronization

SNMPv3 user management can be centralized at the Access Authentication and Accounting (AAA) server
level. This centralized user management allows the SNMP agent in Cisco NX-OS to leverage the user
authentication service of the AAA server. Once user authentication is verified, the SNMP PDUs are processed
further. Additionally, the AAA server is also used to store user group names. SNMP uses the group names to
apply the access/role policy that is locally available in the switch.
Any configuration changes made to the user group, role, or password results in database synchronization for
both SNMP and AAA.
Cisco NX-OS synchronizes the user configuration in the following ways:
• The authentication passphrase specified in the snmp-server user command becomes the password for
the CLI user.
• The password specified in the username command becomes the authentication and privacy passphrases
for the SNMP user.
• If you create or delete a user using either SNMP or the CLI, the user is created or deleted for both SNMP
and the CLI.
• User-role mapping changes are synchronized in SNMP and the CLI.
• Role changes (deletions or modifications) from the CLI are synchronized to SNMP.
Note
When you configure a passphrase/password in localized key/encrypted format, Cisco NX-OS does not
synchronize the user information (passwords, roles, and so on).
Cisco NX-OS holds the synchronized user configuration for 60 minutes by default.

AAA Exclusive Behavior in SNMPv3 Servers

The AAA exclusive behavior feature enables you to authenticate users based on location.
If a unique SNMPv3 user exists and the user is not a local user or a remote AAA user, the user is not verified.
If the user exists in both the local and remote database, the user will be authenticated or rejected based on
whether AAA exclusive behavior is enabled.
Cisco Nexus 7000 Series NX-OS System Management Configuration Guide
178
Configuring SNMP

Advertisement

Table of Contents
loading

Table of Contents