PVIQ™ CONNECTIVITY SYSTEM USER MANUAL V 1.0
174
set http off
o
SNMP may be disabled from the Telnet CLI.
config snmp disable rear
o
Telnet and SNMP may be disabled from the SNMP MIB.
•
Do not disable all management interfaces. Only disable the ones that won’t be
used.
•
Configure system users to only have access to secure protocols.
•
Configure firewall and/or Intrusion Detection/Prevention Systems to allow
TCP/UDP access to only expected protocols on to the PViQ Panel Manager.
Secure Deployment for SNMPv3 Access Only
This section is intended to help SmartZone DCIM Integrators and Customers configure
the product in a secure manner. It assumes the integrator will use Telnet for bulk
configuration and troubleshooting and SNMPv3 with a single SHA-1/AES-128 user for
all other operations. SNMPv3 Traps are also used.
•
Use Telnet to access the PViQ Panel Manager CLI, disable HTTP and set up a
trap receiver.
o
set http off
o
config snmp disable v1v2c
o
config snmp -trapip 1 IPv4.Address.of.NMS
o
config snmp -traver 1 v3
o
config snmp -trapon 1 all
•
Configure additional SNMP Trap Receivers as required.
•
Use Telnet to change the admin user’s password.
o
config password NEWADMINPASSWORD
•
Use a SNMPv3 USM management tool to configure a SNMPv3 user that has
authPriv access.
o
The “v3bulkupdate.bat” script demonstrates how to use net-snmp’s
snmpusm command to manage the users on the PViQ Panel Manager.
o
Delete all of the users except for
v3ShaAesUser
.