Understanding How Snmp Works; Security Models And Levels; Snmp Ifindex Persistence Feature - Cisco WS-C2948G-GE-TX Configuration Manual

Catalyst 4500 series switch
Table of Contents

Advertisement

Understanding How SNMP Works

Security Models and Levels

A security model is an authentication strategy that is set up for a user and the group in which the user
resides. A security level is the permitted level of security within a security model. A combination of a
security model and a security level will determine which security mechanism is employed when handling
an SNMP packet. Three security models are available: SNMPv1, SNMPv2c, and SNMPv3.
identifies the combinations of security models and levels.
Table 24-2 Security Model Combinations
Model Level
v1
v2c
v3
v3
v3
Note the following about SNMPv3 objects:

SNMP ifindex Persistence Feature

The SNMP ifIndex persistence feature is always enabled. With the ifIndex persistence feature, the
ifIndex value of the port and VLAN is always retained and used after the following occurrences:
For Fast EtherChannel and Gigabit EtherChannel interfaces, the ifIndex value is only retained and used
after a high-availability switchover.
Catalyst 4500 Series, Catalyst 2948G, Catalyst 2948G-GE-TX, and Catalyst 2980G Switches Software Configuration Guide—Release 8.2GLX
24-4
Authentication Encryption What Happens
noAuthNoPriv Community
String
noAuthNoPriv Community
String
noAuthNoPriv Username
authNoPriv
MD5 or SHA
authPriv
MD5 or SHA
Each user belongs to a group.
A group defines the access policy for a set of users.
SNMP objects refer to an access policy for reading, writing, and creating.
A group determines the list of notifications that its users can receive.
A group also defines the security model and security level for its users.
Switch reboot
High-availability switchover
Software upgrade
Module reset
Module removal and insertion of the same type of module
No
Uses a community string match for authentication.
No
Uses a community string match for authentication.
No
Uses a username match for authentication.
No
Provides authentication that is based on the
HMAC-MD5 or HMAC-SHA algorithms.
DES
Provides authentication that is based on the
HMAC-MD5 or HMAC-SHA algorithms.
Provides DES 56-bit encryption in addition to
authentication that is based on the CBC-DES
(DES-56) standard.
Chapter 24
Configuring SNMP
Table 24-2
78-15908-01

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents