Optional) Controlling The Nm Station's Access To The Device - Huawei AR150/200 Series Configuration Manual

Enterprise routers
Table of Contents

Advertisement

Huawei AR150&200 Series Enterprise Routers
Configuration Guide - Network Management

1.2.3 (Optional) Controlling the NM Station's Access to the Device

This section describes how to specify an NM station and manageable MIB objects for SNMP-
based communication between the NM station and managed device to improve communication
security.
Context
If a device is managed by multiple NM stations that use the same community name, note the
following points:
l
l
l
l
Procedure
Step 1 Run:
system-view
The system view is displayed.
Step 2 Run:
acl acl-number
A basic ACL is created to filter the NM station users that can manage the device.
Step 3 Run:
rule [ rule-id ] { deny | permit } source { source-ip-address source-wildcard |
any }
A rule is added to the ACL.
Step 4 Run:
quit
Return to the system view.
Step 5 Run:
snmp-agent mib-view view-name { include | exclude } subtree-name [ mask mask ]
A MIB view is created, and manageable MIB objects are specified.
By default, an NM station has rights to access the objects in the Viewdefault view (1.3.6.1).
l If a few MIB objects on a device or some objects in the current MIB view do not or no longer
l If a few MIB objects on the device or some objects in the current MIB view need to be
Issue 02 (2012-03-30)
If all the NM stations that use the community name need to have rights to access the objects
in the Viewdefault view (1.3.6.1), skip the following steps.
If some of the NM stations that use the community name need to have rights to access the
objects in the Viewdefault view (1.3.6.1), skip Step5.
If all the NM stations need to manage specified objects on the device, skip Step2, Step3,
and Step4.
If some of the NM stations that use the community name need to manage specified objects
on the device, perform all the following steps.
need to be managed by the NM station, exclude needs to be specified in the related command
to exclude these MIB objects.
managed by the NM station, include needs to be specified in the related command to include
these MIB objects.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
1 SNMP Configuration
10

Advertisement

Table of Contents
loading

Table of Contents