Snmpv3; Security Models And Levels For Snmpv1, V2, V3 - Cisco Nexus 7000 Series Configuration Manual

Hide thumbs Also See for Nexus 7000 Series:
Table of Contents

Advertisement

SNMPv3

SNMPv3
SNMPv3 provides secure access to devices by a combination of authenticating and encrypting frames over
the network. The security features provided in SNMPv3 are the following:
• Message integrity—Ensures that a packet has not been tampered with in-transit.
• Authentication—Determines the message is from a valid source.
• Encryption—Scrambles the packet contents to prevent it from being seen by unauthorized sources.
SNMPv3 provides for both security models and security levels. A security model is an authentication strategy
that is set up for a user and the role in which the user resides. A security level is the permitted level of security
within a security model. A combination of a security model and a security level determines which security
mechanism is employed when handling an SNMP packet.

Security Models and Levels for SNMPv1, v2, v3

The security level determines if an SNMP message needs to be protected from disclosure and if the message
needs to be authenticated. The various security levels that exist within a security model are as follows:
• noAuthNoPriv—Security level that does not provide authentication or encryption.
• authNoPriv—Security level that provides authentication but does not provide encryption.
• authPriv—Security level that provides both authentication and encryption.
Three security models are available: SNMPv1, SNMPv2c, and SNMPv3. The security model combined with
the security level determine the security mechanism applied when the SNMP message is processed. The
following table identifies what the combinations of security models and levels mean.
noAuthnoPriv is not supported in SNMPv3.
Note
Table 20: SNMP Security Models and Levels
Model
v1
v2c
v3
Cisco Nexus 7000 Series NX-OS System Management Configuration Guide
176
Level
Authentication
noAuthNoPriv
Community string
noAuthNoPriv
Community string
noAuthNoPriv
Username
Configuring SNMP
Encryption
What Happens
No
Uses a community
string match for
authentication.
No
Uses a community
string match for
authentication.
No
Uses a username
match for
authentication.

Advertisement

Table of Contents
loading

Table of Contents