18-17
Cisco MDS 9000 Fabric Manager Switch Configuration Guide
OL-7753-01
Chapter 18 Configuring Switch Security
About SNMP Security
Figure 18-3
Common Roles
Each role in SNMP is the same as a role created or modified through the CLI. Common Roles allow you
to use a set of rules to set the scope of VSAN security. Each role can be restricted to one or more VSANs
as required.
You can create new roles or modify existing roles using SNMP or the CLI.
To configure Common Roles from the Device Manager, choose
Common Roles
from the Security menu.
You can then access the Rules dialog box to configure the set of rules. To configure Common Roles from
Fabric Manager, choose
Security > SNMP
and click the
Roles
tab in the Information pane. Fabric
Manager uses a default rules set for roles; therefore, no Rules dialog box is displayed.
See the
“Creating Common Roles” section on page 18-18
for additional information.
Creating and Modifying Users
You can create users or modify existing users using SNMP or the CLI.
•
SNMP—Create a user as a clone of an existing user in the vsmUserTable on the switch. Once you
have created the user, change the cloned secret key before activating the user. Refer to RFC2574.
You must explicitly configure password(s) for SNMP users. The SNMP user passwords are not
generated as the part of the configuration file as they are not portable across devices. The password
is limited to a minimum of 8 characters and a maximum of 64 characters.
An SNMP user must be created on each switch to which the user requires access. If the user is
managing 10 switches, each of the 10 switches must have the SNMP user defined.
•
CLI—You can create a user or modify an existing user using the
snmp-server user
command.
By default, only two roles are available in a Cisco MDS 9000 Family switch—network-operator and
network-admin. You can also use any role that is configured in the Common Roles database.
CLI
SNMP
Switch 1
Role: network admin
Description: Predefined network admin
access to all the switch commands
Role: network-operator
Description: Predefined network operation
access to
show
commands and selected E
Role: sangroup
Description: SAN management group
Rule Type Command-type Features
1.
permit
config
config
debug
exec
*
2.
deny
fspf
3.
permit
zone
4.
permit
fcping
Common Roles
99017
Содержание DS-C9216I-K9
Страница 26: ...Contents xxvi Cisco MDS 9000 Fabric Manager Switch Configuration Guide OL 7753 01 ...
Страница 42: ...xlii Cisco MDS 9000 Fabric Manager Switch Configuration Guide OL 7753 01 New and Changed Information ...
Страница 128: ...10 8 Cisco MDS 9000 Fabric Manager Switch Configuration Guide OL 7753 01 Chapter 10 Managing System Hardware ...