data:image/s3,"s3://crabby-images/6ae88/6ae885c9ebc324c7d07e7d6351f94949d0f3b618" alt="Cisco Nexus 5000 Series Скачать руководство пользователя страница 367"
S e n d f e e d b a c k t o n x 5 0 0 0 - d o c f e e d b a c k @ c i s c o . c o m
1-3
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
OL-16597-01
Chapter 1 Configuring SNMP
Information About SNMP
Security Models and Levels for SNMPv1, v2, v3
The security level determines if an SNMP message needs to be protected from disclosure and if the
message needs to be authenticated. The various security levels that exist within a security model are as
follows:
•
noAuthNoPriv—Security level that does not provide authentication or encryption.
•
authNoPriv—Security level that provides authentication but does not provide encryption.
•
authPriv—Security level that provides both authentication and encryption.
Three security models are available: SNMPv1, SNMPv2c, and SNMPv3. The security model combined
with the security level determine the security mechanism applied when the SNMP message is processed.
identifies what the combinations of security models and levels mean.
User-Based Security Model
SNMPv3 User-Based Security Model (USM) refers to SNMP message-level security and offers the
following services:
•
Message integrity—Ensures that messages have not been altered or destroyed in an unauthorized
manner and that data sequences have not been altered to an extent greater than can occur
non-maliciously.
•
Message origin authentication—Ensures that the claimed identity of the user on whose behalf
received data was originated is confirmed.
•
Message confidentiality—Ensures that information is not made available or disclosed to
unauthorized individuals, entities, or processes.
SNMPv3 authorizes management operations only by configured users and encrypts SNMP messages.
Table 1-1
SNMP Security Models and Levels
Model
Level
Authentication
Encryption
What Happens
v1
noAuthNoPriv
Community string No
Uses a community string match for
authentication.
v2c
noAuthNoPriv
Community string No
Uses a community string match for
authentication.
v3
noAuthNoPriv
Username
No
Uses a username match for
authentication.
v3
authNoPriv
HMAC-MD5 or
HMAC-SHA
No
Provides authentication based on the
Hash-Based Message Authentication
Code (HMAC) Message Digest 5
(MD5) algorithm or the HMAC
Secure Hash Algorithm (SHA).
v3
authPriv
HMAC-MD5 or
HMAC-SHA
DES
Provides authentication based on the
HMAC-MD5 or HMAC-SHA
algorithms. Provides Data Encryption
Standard (DES) 56-bit encryption in
addition to authentication based on
the Cipher Block Chaining (CBC)
DES (DES-56) standard.