C
L
I
R
OMMAND
INE
NTERFACE
EFERENCE
SNMP
CREATE USER
Use the snmp create user command to create USM (user based security model) users with authentication and
privacy options. A remote engine identity is required when an SNMPv3 inform is configured. The engine identity
is used to compute the security digest for authenticating and encrypting packets sent to a user on the remote host.
To configure a remote user, specify the IP address or port number for the remote SNMP agent of the device where
the user resides. Also, before you configure remote users for a particular agent, configure the SNMP engine ID,
using the command snmp-server engineID with the remote option. The remote agent's SNMP engine ID is
needed when computing the authentication/privacy digests from the password. If the remote engine ID is not
configured first, the configuration command will fail.
SNMP passwords are localized using the SNMP engine ID of the authoritative SNMP engine. For informs, the
authoritative SNMP agent is the remote agent. You need to configure the remote agent's SNMP engine ID in the
SNMP database before you can send proxy requests or informs to it.
NOTE: Any users created must be added VACM access control tables for them to be operative. username is used as
security-name in the snmp create sectogroup command. Privacy options are valid only when authentication is
specified.
SNMP
SNMPv3
Command form
snmp create user username [
passphrase} ] [
username
{
auth
authphrase
authphrase}
|
{
auth
none | MD5
engine-id]
local | remote
The username for the new user. The following restrictions apply to the username:
• maximum of 32 alpha-numeric characters (case sensitive)
• no spaces, punctuation or other special characters
• first character must be a letter
(Optional) Specifies the method of message encryption used by the authorizing
none | MD5
client such as the router to authorize the user. The following encryption methods are
| SHA
available (choose one):
specifies that no authorization message encryption is used by the authorizing
none
client.
authphrase specifies that message authentication support is provided by using
MD5
the message digest algorithm 5 (MD5). passphrase specifies the passphrase (8–64
characters) used to authenticate the user.
authphrase specifies that the message authentication support is provided by
SHA
Secure Hash Algorithm (SHA). passphrase specifies the passphrase (8–64 characters)
used to authenticate the user.
S
NA™ 10G N
MART
authphrase
authphrase} ] [
| SHA
DRAFT
A
(S
NA-X)
ETWORK
CCESS
MART
{
passphrase
priv
none | DES
| AES
172
Need help?
Do you have a question about the SmartNA-X and is the answer not in the manual?