1.2.3 (Optional) Controlling the NM Station's Access to the Device
This section describes how to specify an NM station and manageable MIB objects for SNMP-
based communication between the NM station and managed device to improve communication
security.
Context
If a device is managed by multiple NM stations that use the same community name, note the
following points:
l
If all the NM stations that use the community name need to have rights to access the objects
in the Viewdefault view (1.3.6.1), skip the following steps.
l
If some of the NM stations that use the community name need to have rights to access the
objects in the Viewdefault view (1.3.6.1), skip
.
l
If all the NM stations need to manage specified objects on the device, skip
,
l
If some of the NM stations that use the community name need to manage specified objects
on the device, perform all the following steps.
Procedure
Step 1
Run:
system-view
The system view is displayed.
Step 2
Run:
acl
acl-number
A basic ACL is created to filter the NM station users that can manage the device.
Step 3
Run:
rule
[
rule-id
] {
deny
|
permit
}
source
{
source-ip-address
source-wildcard
|
any
}
A rule is added to the ACL.
Step 4
Run:
quit
Return to the system view.
Step 5
Run:
snmp-agent mib-view
view-name
{
include
|
exclude
}
subtree-name
[
mask
mask
]
A MIB view is created, and manageable MIB objects are specified.
By default, an NM station has rights to access the objects in the Viewdefault view (1.3.6.1).
l
If a few MIB objects on a device or some objects in the current MIB view do not or no longer
need to be managed by the NM station,
exclude
needs to be specified in the related command
to exclude these MIB objects.
l
If a few MIB objects on the device or some objects in the current MIB view need to be
managed by the NM station,
include
needs to be specified in the related command to include
these MIB objects.
Huawei AR150&200 Series Enterprise Routers
Configuration Guide - Network Management
1 SNMP Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
10