Defining An Snmp User Account - Brocade Communications Systems FastIron Administration Manual

Ethernet switch
Table of Contents

Advertisement

The ipv6 ipv6-ACL-name option configures IPv6 ACL for SNMP group and allows incoming SNMP
packets to be filtered based on the IPv6 ACL attached to the group.
The read viewname | write viewname parameter is optional. It indicates that users who belong to this
group have either read or write access to the MIB.
The viewname variable is the name of the view to which the SNMP group members have access. If no
view is specified, then the group has no access to the MIB.
The value of viewname is defined using the snmp-server view command. The SNMP agent comes
with the "all" default view, which provides access to the entire MIB; however, it must be specified when
creating the group. The "all" view also allows SNMP version 3 to be backwards compatibility with SNMP
version 1 and version 2.
NOTE
If you will be using a view other than the "all" view, that view must be configured before creating the
user group. Refer to the section
on the include | exclude parameters.

Defining an SNMP user account

The snmp-server user command does the following:
• Creates an SNMP user.
• Defines the group to which the user will be associated.
• Defines the type of authentication to be used for SNMP access by this user.
• Specifies one of the following encryption types used to encrypt the privacy password:
Here is an example of how to create an SNMP User account.
device(config)#snmp-s user bob admin v3 access 2 auth md5 bobmd5 priv des bobdes
The CLI for creating SNMP version 3 users has been updated as follows.
Syntax: no snmp-server user name groupname v3 [ [ access standard-ACL-id ] [ [ encrypted ] [auth
md5 md5-password | sha sha-password ] [ priv [ encrypted ] des des-password-key | aes aes-
password-key ] ] ]
The name parameter defines the SNMP user name or security name used to access the management
module.
The groupname parameter identifies the SNMP group to which this user is associated or mapped. All
users must be mapped to an SNMP group. Groups are defined using the snmp-server group
command.
NOTE
The SNMP group to which the user account will be mapped should be configured before creating the
user accounts; otherwise, the group will be created without any views. Also, ACL groups must be
configured before configuring user accounts.
The v3 parameter is required.
FastIron Ethernet Switch Administration Guide
53-1003625-01
SNMP v3 configuration examples
Data Encryption Standard (DES) - A symmetric-key algorithm that uses a 56-bit key.
Advanced Encryption Standard (AES) - The 128-bit encryption standard adopted by the
U.S. government. This standard is a symmetric cipher algorithm chosen by the National
Institute of Standards and Technology (NIST) as the replacement for DES.
Defining an SNMP user account
on page 160, especially for details
153

Hide quick links:

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the FastIron and is the answer not in the manual?

Table of Contents

Save PDF