Prerequisites; Controlling Network Management Users By Source Ip Addresses; Configuration Example - H3C S5100-SI Operation Manual

Ethernet switches
Hide thumbs Also See for H3C S5100-SI:
Table of Contents

Advertisement

Defining an ACL
Applying the ACL to control users accessing the switch through SNMP
To control whether an NMS can manage the switch, you can use this function.

Prerequisites

The controlling policy against network management users is determined, including the source IP
addresses to be controlled and the controlling actions (permitting or denying).

Controlling Network Management Users by Source IP Addresses

Controlling network management users by source IP addresses is achieved by applying basic
ACLs, which are numbered from 2000 to 2999.
Follow these steps to control network management users by source IP addresses:
To do...
Enter system view
Create a basic ACL or
enter basic ACL view
Define rules for the ACL
Quit to system view
Apply the ACL while
configuring the SNMP
community name
Apply the ACL while
configuring the SNMP
group name
Apply the ACL while
configuring the SNMP
user name

Configuration Example

Network requirements
Only SNMP users sourced from the IP addresses of 10.110.100.52 are permitted to log in to the
switch.
Use the command...
system-view
acl number acl-number [ match-order
{ auto | config } ]
rule [ rule-id ] { deny | permit } [ rule-string ]
quit
snmp-agent community { read | write }
community-name [ acl acl-number |
mib-view view-name ]*
snmp-agent group { v1 | v2c }
group-name [ read-view read-view ]
[ write-view write-view ] [ notify-view
notify-view ] [ acl acl-number ]
snmp-agent group v3 group-name
[ authentication | privacy ] [ read-view
read-view ] [ write-view write-view ]
[ notify-view notify-view ] [ acl acl-number ]
snmp-agent usm-user { v1 | v2c }
user-name group-name [ acl acl-number ]
snmp-agent usm-user v3 user-name
group-name [ [ cipher ]
authentication-mode { md5 | sha }
auth-password [ privacy-mode { des56 |
aes128 } priv-password ] ] [ acl
acl-number ]
9-4
Remarks
As for the acl number
command, the config
keyword is specified by
default.
Required
Required
According to the SNMP
version and configuration
customs of NMS users,
you can reference an ACL
when configuring
community name, group
name or username. For
the detailed configuration,
refer to SNMP-RMON for
more.

Advertisement

Table of Contents
loading

This manual is also suitable for:

H3c s5100-ei

Table of Contents