7-4
Stinger®
Administration Guide
Administering the SNMP Agent
Securing the SNMP agent
admin>
write
SNMP written
Securing the SNMP agent
TAOS provides the following means to secure the SNMP agent in the Stinger unit
against unwanted access from remote SNMP managers, to specify the type of access
granted to SNMP managers, and to configure encryption and authentication for the
communications between the agent and managers:
Ability to specify community strings when you enable read-write access.
Enforcement of SNMP manager host authentication.
Configuration of SNMPv3 messaging features such as authentication and
encryption between the SNMP agent and manager. (This capability requires the
network management software license.)
Configuration of view-based access control model (VACM) features to control
different types of access to various objects in the system. Control is applied on the
basis of the security name in the request, the security level specified for the
request, or the context name and object identifier (OID) of the object for which
access is being attempted.
Enabling read-write access and setting community strings
Caution
For security reasons, Lucent Technologies recommends that when you
enable read-write access, you change the read-write community string from the well-
known
write
value. By default, read-write access is disabled.
To set the community strings and enable read-write access, proceed as in the
following example:
admin>
set read-community = !3gtest0
admin>
set read-write-enabled = yes
admin>
set read-write-community = @456test!
admin>
write
SNMP written
Configuring host address security
You can also enforce host address authentication before the agent accepts SNMP
requests. Address security is optional but recommended. By enabling the
enforce-
address-security
parameter in the SNMP profile, you exclude SNMP access from
host SNMP manager addresses other than those you have specified. You create an
snmp-manager
profile to grant read and write access for an
unlimited
number of SNMP
managers that use either SNMPv1 or SNMPv3.
Enabling host address security
To configure the unit to enforce host address security, proceed as follows:
admin>
read snmp
SNMP read
admin>
set enforce-address-security = yes
Summary of Contents for Stinger
Page 1: ...Stinger Administration Guide Part Number 7820 0712 008 For software version 9 7 0 August 2004 ...
Page 4: ......
Page 16: ......
Page 18: ......
Page 62: ......
Page 82: ......
Page 96: ......
Page 182: ......
Page 218: ......
Page 236: ......
Page 252: ......
Page 288: ......
Page 350: ......
Page 362: ......
Page 374: ......