290
C
HAPTER
19: SNMP C
OMMANDS
User Guidelines
To use SNMPv3, you have to specify an engine ID for the device. You can
specify your own ID or use a default string that is generated using the
MAC address of the device.
If the SNMPv3 engine ID is deleted or the configuration file is erased,
SNMPv3 cannot be used. By default, SNMPv1/v2 are enabled on the
device. SNMPv3 is enabled only by defining the Local Engine ID.
If you want to specify your own ID, you do not have to specify the entire
32-character engine ID if it contains trailing zeros. Specify only the
portion of the engine ID up to the point where just zeros remain in the
value. For example, to configure an engine ID of
123400000000000000000000, you can specify snmp-server engineID
local 1234.
Since the engine ID should be unique within an administrative domain,
the following is recommended:
For a standalone device, use the default keyword to configure the engine
ID.
Changing the value of the engine ID has the following important
side-effect. A user's password (entered on the command line) is
converted to an MD5 or SHA security digest. This digest is based on both
the password and the local engine ID. The user’s command line password
is then destroyed, as required by RFC 2274. As a result, the security
digests of SNMPv3 users become invalid if the local value of the engine ID
change, and the users will have to be reconfigured.
You cannot specify an engine ID that consists of all 0x0, all 0xF or
0x000000001.
The
show running-config
Privileged EXEC mode command does not
display the SNMP engine ID configuration. To see the SNMP engine ID
configuration, enter the
snmp-server engineID l
ocal Global
Configuration mode command.
Example
The following example enables SNMPv3 on the device and sets the local
engine ID of the device to the default value.
Console(config) #
snmp-server engineID local default
Содержание 3CRUS2475 24
Страница 18: ......
Страница 40: ...40 CHAPTER 2 AAA COMMANDS ...
Страница 54: ...54 CHAPTER 3 ACL COMMANDS ...
Страница 76: ...76 CHAPTER 4 ADDRESS TABLE COMMANDS ...
Страница 165: ...show sntp status 165 g13 0 0 0 0 00 00 00 0 Feb 19 2005 vlan 1 16 1 1 2 00 15 15 16 0 LLBG Feb 19 2006 ...
Страница 166: ...166 CHAPTER 10 CLOCK COMMANDS ...
Страница 200: ...200 CHAPTER 13 LACP COMMANDS ...
Страница 208: ...208 CHAPTER 14 POWER OVER ETHERNET COMMANDS ...
Страница 262: ...262 CHAPTER 15 SPANNING TREE COMMANDS ...
Страница 278: ...278 CHAPTER 17 RADIUS COMMAND ...
Страница 281: ...show ports monitor 281 g1 8 RX TX Active g2 8 RX TX Active g18 8 RX Active ...
Страница 282: ...282 CHAPTER 18 PORT MONITOR COMMANDS ...
Страница 306: ...306 CHAPTER 19 SNMP COMMANDS ...
Страница 316: ...316 CHAPTER 20 IP ADDRESS COMMANDS ...
Страница 330: ...330 CHAPTER 22 WIRELESS ROGUE AP COMMANDS ...
Страница 350: ...350 CHAPTER 23 WIRELESS ESS COMMANDS ...
Страница 382: ...382 CHAPTER 25 SSH COMMANDS ...
Страница 400: ...400 CHAPTER 27 TACACS COMMANDS Global values TimeOut 3 ...
Страница 444: ...444 CHAPTER 31 USER INTERFACE COMMANDS ...
Страница 454: ...454 CHAPTER 32 GVRP COMMANDS ...
Страница 492: ...492 CHAPTER 34 802 1X COMMANDS ...
Страница 521: ...Troubleshooting Solutions 521 ...
Страница 522: ...522 CHAPTER 37 TROUBLESHOOTING ...