6-30
RADIUS Authentication, Authorization, and Accounting
Using SNMP To View and Configure Switch Authentication Features
Using SNMP To View and Configure
Switch Authentication Features
SNMP MIB object access is available for switch authentication configuration
(hpSwitchAuth) features. This means that the switches covered by this Guide
allow, by default, manager-only SNMP read/write access to a subset of the
authentication MIB objects for the following features:
■
number of primary and secondary login and enable attempts
■
server configuration and status
■
RADIUS server configuration
■
selected 802.1X settings
■
key management subsystem chain configuration
■
key management subsystem key configuration
■
OSPF interface authentication configuration
■
local switch operator and manager usernames and passwords
With SNMP access to the hpSwitchAuth MIB enabled, a device with manage-
ment access to the switch can view the configuration for the authentication
features listed above (excluding usernames, passwords, and keys). Using
SNMP sets, a management device can change the authentication configuration
(
including
changes to usernames, passwords, and keys). Operator read/write
access to the authentication MIB is always denied.
S e c u r i t y N o t e s
All usernames, passwords, and keys configured in the hpSwitchAuth MIB are
not returned via SNMP, and the response to SNMP queries for such informa-
tion is a null string. However, SNMP sets can be used to configure username,
password, and key MIB objects.
To help prevent unauthorized access to the switch’s authentication MIB, HP
recommends following the “SNMP Security Guidelines” on page 1-14.
If you do not want to use SNMP access to the switch’s authentication config-
uration MIB, then use the
snmp-server mib hpswitchauthmib excluded
command
to disable this access, as described in the next section.
If you choose to leave SNMP access to the security MIB open (the default
setting), HP recommends that you configure the switch with the SNMP version
3 management and access security feature, and disable SNMP version 2c
access. (Refer to “Access Security Features” on page 1-3.)
Содержание E3800 Series
Страница 1: ...HP Switch Software E3800 switches Software version KA 15 03 September 2011 Access Security Guide ...
Страница 2: ......
Страница 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Страница 30: ...xxviii ...
Страница 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Страница 186: ...4 72 Web and MAC Authentication Client Status ...
Страница 290: ...6 74 RADIUS Authentication Authorization and Accounting Dynamic Removal of Authentication Limits ...
Страница 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Страница 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Страница 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Страница 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Страница 659: ...14 11 Configuring and Monitoring Port Security Port Security Figure 14 5 Examples of Show Mac Address Outputs ...
Страница 730: ...20 Index ...
Страница 731: ......