
Using Traps to Monitor Performance
Establishing SNMP access security
MAX Administration Guide
9-3
Information held in the Ascend Events Group is erased and its values are initialized when the
MAX is reset by software or by toggling the power off and on. The SNMP object
sysAbsoluteStartupTime
is the time in seconds since January 1, 1990, and is not
modified. To determine whether the MAX has actually reset, retrieve
sysAbsoluteStartupTime
and compare its value against the previous poll’s value for
Ascend Events Group variables.
Specifying User-based security
If the MAX unit has the Network Management option installed, specify whether the unit
supports SNMPv1 (hereafter referred to as SNMP), SNMPv3, or both by using the Message
Type parameter. In addition, the Security Level specifies whether or not the MAX unit verifies
user’s the Security Level settings. The unit compares the Security Level field in the incoming
message to the one specified on the unit. If the Security Levels do not match, the unit sends a
report message.
For more details regarding SNMPv3, see “Using the SNMPv3 User-based Security Model” on
page 9-4.
Example of SNMP security configuration
The following procedure sets the community strings, enforces address security, and prevents
write access:
1
Open Ethernet > Mod Config > SNMP Options.
2
Set R/W Comm Enable to
Yes
.
3
Specify the Read Comm and R/W Comm parameter strings.
4
Set Security to
Yes
.
5
Specify up to five host addresses in the RD MgrN parameters. Leave the WR MgrN
parameters set to zero to prevent write access.
6
Close the Ethernet profile.
Following is an example of a profile configured with the preceding procedure.
Ethernet
Mod Config
SNMP options...
Read Comm=Secret-1
R/W Comm Enable=Yes
R/W Comm=Secret-2
Security=Yes
RD Mgr1=10.0.0.1
RD Mgr2=10.0.0.2
RD Mgr3=10.0.0.3
RD Mgr4=10.0.0.4
RD Mgr5=10.0.0.5
WR Mgr1=0.0.0.0
WR Mgr2=0.0.0.0
WR Mgr3=0.0.0.0
WR Mgr4=0.0.0.0
WR Mgr5=0.0.0.0