Cli And Snmp User Synchronization - Cisco AP775A - Nexus Converged Network Switch 5010 Configuration Manual

Cli software configuration guide
Hide thumbs Also See for AP775A - Nexus Converged Network Switch 5010:
Table of Contents

Advertisement

CLI and SNMP User Synchronization

• Message origin authentication—Ensures that the claimed identity of the user on whose behalf received
• Message confidentiality—Ensures that information is not made available or disclosed to unauthorized
SNMPv3 authorizes management operations only by configured users and encrypts SNMP messages.
Cisco NX-OS uses two authentication protocols for SNMPv3:
• HMAC-MD5-96 authentication protocol
• HMAC-SHA-96 authentication protocol
Cisco NX-OS uses Advanced Encryption Standard (AES) as one of the privacy protocols for SNMPv3 message
encryption and conforms with RFC 3826.
The priv option offers a choice of DES or 128-bit AES encryption for SNMP security encryption. The priv
option along with the aes-128 token indicates that this privacy password is for generating a 128-bit AES
key.The AES priv password can have a minimum of eight characters. If the passphrases are specified in clear
text, you can specify a maximum of 64 characters. If you use the localized key, you can specify a maximum
of 130 characters.
For an SNMPv3 operation using the external AAA server, you must use AES for the privacy protocol in
Note
user configuration on the external AAA server.
CLI and SNMP User Synchronization
SNMPv3 user management can be centralized at the Access Authentication and Accounting (AAA) server
level. This centralized user management allows the SNMP agent in Cisco NX-OS to leverage the user
authentication service of the AAA server. Once user authentication is verified, the SNMP PDUs are processed
further. Additionally, the AAA server is also used to store user group names. SNMP uses the group names to
apply the access/role policy that is locally available in the switch.
Any configuration changes made to the user group, role, or password results in database synchronization for
both SNMP and AAA.
Cisco NX-OS synchronizes user configuration in the following ways:
• The auth passphrase specified in the snmp-server user command becomes the password for the CLI
• The password specified in the username command becomes as the auth and priv passphrases for the
• Deleting a user using either SNMP or the CLI results in the user being deleted for both SNMP and the
• User-role mapping changes are synchronized in SNMP and the CLI.
When you configure passphrase/password in localized key/encrypted format, Cisco NX-OS does not
Note
synchronize the password.
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
378
data was originated is confirmed.
individuals, entities, or processes.
user.
SNMP user.
CLI.
Information About SNMP
OL-16597-01

Advertisement

Table of Contents
loading

Table of Contents