22
mib-view
view-name
: Specifies the MIB view available for the community. The
view-name
argument represents a MIB view name, a case-sensitive string of 1 to 32 characters. A MIB view
represents a set of accessible MIB objects. If you do not specify a view, the specified community can
access the MIB objects in the default MIB view
ViewDefault
.
user-role
role-name
: Specifies a user role name for the community, a case-sensitive string of 1
to 63 characters.
acl
: Specifies a basic or advanced IPv4 ACL for the community.
ipv4-acl-number
: Specifies a basic or advanced IPv4 ACL by its number. The basic IPv4 ACL
number is in the range of 2000 to 2999. The advanced IPv4 ACL number is in the range of 3000 to
3999.
name
ipv4-acl-name
: Specifies a basic or advanced IPv4 ACL by its name, a case-insensitive
string of 1 to 63 characters.
acl
ipv6:
Specifies a basic or advanced IPv6 ACL for the community.
ipv6-acl-number
: Specifies a basic or advanced IPv6 ACL by its number. The basic IPv6 ACL
number is in the range of 2000 to 2999. The advanced IPv6 ACL number is in the range of 3000 to
3999.
name ipv6-acl-name
: Specifies a basic or advanced IPv6 ACL by its name, a case-insensitive
string of 1 to 63 characters.
Usage guidelines
This command is not available in FIPS mode.
Only users with the network-admin or level-15 user role can execute this command. Users with other
user roles cannot execute this command even if these roles are granted access to commands of the
SNMP feature or this command.
An SNMP community is identified by a community name. It contains a set of NMSs and SNMP
agents. Devices in an SNMP community authenticate each other by using the community name. An
NMS and an SNMP agent can communicate only when they use the same community name.
Typically,
public
is used as the read-only community name and
private
is used as the read and write
community name. To enhance security, you can assign your SNMP communities a name other than
public
and
private
.
The
snmp-agent community
command allows you to use either of the following modes to control
SNMP community access to MIB objects:
•
View-based access control model
—The VACM mode controls access to MIB objects by
assigning MIB views to SNMP communities.
•
Role based access control
—The RBAC mode controls access to MIB objects by assigning
user roles to SNMP communities.
The network-admin and level-15 user roles have the read and write access to all MIB
objects.
The network-operator user role has the read-only access to all MIB objects.
For more information about user roles, see
Fundamentals Configuration Guide
.
RBAC mode controls access on a per MIB object basis, and VACM mode controls access on a MIB
view basis. As a best practice to enhance MIB security, use RBAC mode.
You can create a maximum of 10 SNMP communities by using the
snmp-agent community
command.
If you execute the command multiple times to specify the same community name but different other
settings each time, the most recent configuration takes effect.
If you do not specify the
simple
or
cipher
keyword, the community name is created and saved in
plaintext form.
Summary of Contents for SOHO IE4300
Page 285: ...i Contents Tcl commands 1 cli 1 tclquit 1 tclsh 2...
Page 288: ...i Contents Python commands 1 exit 1 python 1 python filename 2...
Page 291: ...i Contents Automatic configuration commands 1 autodeploy udisk enable 1...
Page 323: ...25 Sysname Ten GigabitEthernet1 0 51 undo shutdown Related commands irf port...
Page 465: ...ii stp vlan enable 55 vlan mapping modulo 55...
Page 602: ...12 Related commands display mvrp statistics...
Page 609: ...i Contents VLAN mapping commands 1 display vlan mapping 1 vlan mapping 2...
Page 678: ...9 Related commands reset pppoe relay statistics...
Page 846: ...i Contents Basic IP forwarding commands 1 display fib 1 ip forwarding table save 2...
Page 1770: ...i Contents Time range commands 1 display time range 1 time range 1...
Page 2026: ...34 Related commands display mac authentication...
Page 2028: ...ii...
Page 2143: ...i Contents User profile commands 1 display user profile 1 user profile 2...
Page 2308: ...61 ipsec transform set...
Page 2531: ...i Contents SAVI commands 1 ipv6 savi down delay 1 ipv6 savi log enable 1 ipv6 savi strict 2...
Page 2534: ...3 Sysname ipv6 savi strict Related commands ipv6 verify source...
Page 2791: ...14 Sysname track 1 Related commands delay display track...
Page 2939: ...9 sntp authentication keyid sntp reliable authentication keyid...
Page 2967: ...27 Related commands apply poe profile poe enable poe max power interface view poe priority...