
Managing Authentication Servers
LDAP Servers
OmniSwitch AOS Release 7 Network Configuration Guide
June 2013
page 29-21
Setting the SNMP Security Level
Use the table below to set the appropriate
bop-asa-snmp-level-security
attribute.
Configuring Functional Privileges on the Server
Configuring the functional privileges attributes (
bop-asa-func-priv-read-1
,
bop-asa-func-priv-read-2
,
bop-asa-func-priv-write-1
,
bop-asa-func-priv-write-2
) requires using read and write bitmasks for
command families on the switch.
1
To display the functional bitmasks of the desired command families, use the
command.
2
On the LDAP server, configure the functional privilege attributes with the bitmask values.
For more information about configuring users on the switch, see the Switch Security chapter of the
OmniSwitch AOS Release 7 Switch Management Guide
.
Configuring Authentication Key Attributes
The alp2key tool is provided on the Alcatel-Lucent software CD for computing SNMP authentication
keys.The alp2key application is supplied in two versions, one for Unix (Solaris 2.5.1 or higher) and one
for Windows (NT 4.0 and higher).
To configure the bop-shakey or bop-md5key attributes on the server:
1
Use the alp2key application to calculate the authentication key from the password of the user. The
switch automatically computes the authentication key, but for security reasons the key is never displayed
in the CLI.
2
Cut and paste the key to the relevant attribute on the server.
An example using the alp2key tool to compute the SHA and MD5 keys for
mypassword
:
ors40595{}128: alp2key mypassword
bop-shakey: 0xb1112e3472ae836ec2b4d3f453023b9853d9d07c
bop-md5key: 0xeb3ad6ba929441a0ff64083d021c07f1
ors40595{}129:
Level
LDAP snmp-
level-security
Definition
no
1
No SNMP access allowed
no auth
2
SNMP access allowed without any SNMP authentication and
encryption
sha
3
SHA authentication algorithm needed for authenticating SNMP
md5
4
MD5 authentication algorithm needed for authenticating SNMP
sha+des
5
SHA authentication algorithm and DES encryption needed for
authentication SNMP
md5+des
6
MD5 authentication algorithm and DES encryption needed for
authentication SNMP
Содержание os6900
Страница 28: ...Contents xxviii OmniSwitch AOS Release 7 Network Configuration Guide June 2013...
Страница 374: ...VRF Route Leak Configuring IP page 15 40 OmniSwitch AOS Release 7 Network Configuration Guide June 2013...
Страница 692: ...Policy Applications Configuring QoS page 25 84 OmniSwitch AOS Release 7 Network Configuration Guide June 2013...