Read-write
:
For the authorized management workstation provides read and write access to all MIB
variables.
Currently available security model there are two categories:SNMPv1
、
SNMPv2C
。
The table below for the currently available security model and security level
10.2.
Configure SNMP
Configuration of SNMP is completed in the global configuration mode of network equipment, in the
SNMP configuration, please enter global configuration mode.
10.2.1. Set authentication name and access permissions
The security scheme of Community-based SNMPv1/SNMPv2C.The SNMP agent only accept from the
same authentication name (Community-String) management operations,SNMP packets and network
equipment certification name does not match will not be response, discarded directly.Certification
name equivalent to between NMS and Agent password.
Can set the access list, only the specified IP address NMS can manage;
Can set permissions of operation of the community, it is ReadOnly or ReadWrite.
Specify the name for the view, view based management.The default does not specify a view, which
allows access to all MIB objects;
You can specify to use the certification of management IP. If not specified, were not limiting the use of
the certification of management of IP address.The default is not to limit the use of the certification of
management of IP address;
To configure SNMP authentication, execute the following command in the global configuration mode:
can configure one or more specified, to specify a number of different community name,Allows network
devices to NMS for different permissions management,To delete the community name and
permissions, in global configuration mode,execute no snmp-server community Community name
command.
Command
Function
Switch#configure terminal
Enter the global model
Switch(config)#snmp-server start
Enable SNMP
Switch(config)#
snmp-server community
Community name
[ro | r w|]
IP access list number [1-1000]
Set authentication and authority.
Security
model
Security level
Identify
Encryption
Instructions
SNMPv1
noAuthNoPriv
Certificat
e name
none
Through the certification confirmed data
validity
SNMPv2c
noAuthNoPriv
Certificat
e name
none
Through the certification confirmed data
validity