![Dell S6000-ON Скачать руководство пользователя страница 839](http://html.mh-extra.com/html/dell/s6000-on/s6000-on_configuration-manual_84557839.webp)
The SNMPv3 feature also uses a FIPS-validated cryptographic module for all of its cryptographic
operations when the system is configured with the
fips mode enable
command in Global
Configuration mode. When the FIPS mode is enabled on the system, SNMPv3 operates in a FIPS-
compliant manner, and only the FIPS-approved algorithm options are available for SNMPv3 user
configuration. When the FIPS mode is disabled on the system, all options are available for SNMPv3 user
configuration.
The following table describes the authentication and privacy options that can be configured when the
FIPS mode is enabled or disabled:
Table 81. Authentication and Privacy Options
FIPS Mode
Privacy Options
Authentication Options
Disabled
des56 (DES56-CBC)
aes128 (AES128-CFB)
md5 (HMAC-MD5-96)
sha (HMAC-SHA1-96)
Enabled
aes128 (AES128-CFB)
sha (HMAC-SHA1-96)
To enable security for SNMP packets transferred between the server and the client, you can use the
snmp-server user
username
group
groupname
3 auth
authentication-type auth-
password
priv aes128
priv-password
command to specify that AES-CFB 128 encryption
algorithm needs to be used.
Dell(conf)#snmp-server user snmpguy snmpmon 3 auth sha AArt61wq priv aes128
jntRR59a
In this example, for a specified user and a group, the AES128-CFB algorithm, the authentication password
to enable the server to receive packets from the host, and the privacy password to encode the message
contents are configured.
SHA authentication needs to be used with the AES-CFB128 privacy algorithm only when FIPS is enabled
because SHA is then the only available authentication level. If FIPS is disabled, you can use MD5
authentication in addition to SHA authentication with the AES-CFB128 privacy algorithm
You cannot modify the FIPS mode if SNMPv3 users are already configured and present in the system. An
error message is displayed if you attempt to change the FIPS mode by using the
fips mode enable
command in Global Configuration mode. You can enable or disable FIPS mode only if SNMPv3 users are
not previously set up. If previously configured users exist on the system, you must delete the existing
users before you change the FIPS mode.
Keep the following points in mind when you configure the AES128-CFB algorithm for SNMPv3:
1.
SNMPv3 authentication provides only the
sha
option when the FIPS mode is enabled.
2.
SNMPv3 privacy provides only the
aes128 privacy
option when the FIPS mode is enabled.
3.
If you attempt to enable or disable FIPS mode and if any SNMPv3 users are previously configured, an
error message is displayed stating you must delete all of the SNMP users before changing the FIPS
mode.
4.
A message is logged indicating whether FIPS mode is enabled for SNMPv3. This message is
generated only when the first SNMPv3 user is configured because you can modify the FIPS mode
Simple Network Management Protocol (SNMP)
839
Содержание S6000-ON
Страница 1: ...Dell Configuration Guide for the S6000 ON System 9 9 0 0 ...
Страница 505: ...Figure 60 Inspecting Configuration of LAG 10 on ALPHA Link Aggregation Control Protocol LACP 505 ...
Страница 508: ...Figure 62 Inspecting a LAG Port on BRAVO Using the show interface Command 508 Link Aggregation Control Protocol LACP ...
Страница 509: ...Figure 63 Inspecting LAG 10 Using the show interfaces port channel Command Link Aggregation Control Protocol LACP 509 ...
Страница 552: ...mac address table static multicast mac address vlan vlan id output range interface 552 Microsoft Network Load Balancing ...
Страница 557: ...Figure 80 Configuring OSPF and BGP for MSDP Multicast Source Discovery Protocol MSDP 557 ...
Страница 558: ...Figure 81 Configuring PIM in Multiple Routing Domains 558 Multicast Source Discovery Protocol MSDP ...
Страница 562: ...Figure 83 MSDP Default Peer Scenario 1 562 Multicast Source Discovery Protocol MSDP ...
Страница 563: ...Figure 84 MSDP Default Peer Scenario 2 Multicast Source Discovery Protocol MSDP 563 ...
Страница 564: ...Figure 85 MSDP Default Peer Scenario 3 564 Multicast Source Discovery Protocol MSDP ...
Страница 665: ...Policy based Routing PBR 665 ...
Страница 672: ...ip pim bsr border Remove candidate RP advertisements clear ip pim rp mapping 672 PIM Sparse Mode PIM SM ...
Страница 818: ...Figure 110 Single and Double Tag TPID Match 818 Service Provider Bridging ...
Страница 819: ...Figure 111 Single and Double Tag First byte TPID Match Service Provider Bridging 819 ...
Страница 995: ...Figure 140 Setup OSPF and Static Routes Virtual Routing and Forwarding VRF 995 ...