Cisco Systems WSC2960X24TDL, WSC2960X48TSL manual Model, Level, Authentication, Encryption, Result

Models: WSC2960X24TSL C2960XSTACK WSC2960X24PDL WSC2960X24TSLL WSC2960X24PSL WSC2960X48TSL WSC2960X24TDL

1 112
Download 112 pages 36.97 Kb
Page 56
Image 56
Model

Configuring Simple Network Management Protocol

Prerequisites for SNMP

SNMPv2C replaces the Party-based Administrative and Security Framework of SNMPv2Classic with the community-string-based Administrative Framework of SNMPv2C while retaining the bulk retrieval and improved error handling of SNMPv2Classic. It has these features:

SNMPv2Version 2 of the Simple Network Management Protocol, a Draft Internet Standard, defined in RFCs 1902 through 1907.

SNMPv2CThe community-string-based Administrative Framework for SNMPv2, an Experimental Internet Protocol defined in RFC 1901.

SNMPv3Version 3 of the SNMP is an interoperable standards-based protocol defined in RFCs 2273 to 2275. SNMPv3 provides secure access to devices by authenticating and encrypting packets over the network and includes these security features:

Message integrityEnsures that a packet was not tampered with in transit.

AuthenticationDetermines that the message is from a valid source.

EncryptionMixes the contents of a package to prevent it from being read by an unauthorized source.

Note To select encryption, enter the priv keyword.

Both SNMPv1 and SNMPv2C use a community-based form of security. The community of managers able to access the agents MIB is defined by an IP address access control list and password.

SNMPv2C includes a bulk retrieval function and more detailed error message reporting to management stations. The bulk retrieval function retrieves tables and large quantities of information, minimizing the number of round-trips required. The SNMPv2C improved error-handling includes expanded error codes that distinguish different kinds of error conditions; these conditions are reported through a single error code in SNMPv1. Error return codes in SNMPv2C report the error type.

SNMPv3 provides for both security models and security levels. A security model is an authentication strategy set up for a user and the group within which the user resides. A security level is the permitted level of security within a security model. A combination of the security level and the security model determine which security method is used when handling an SNMP packet. Available security models are SNMPv1, SNMPv2C, and SNMPv3.

The following table identifies characteristics and compares different combinations of security models and levels:

Table 7: SNMP Security Models and Levels

 

 

 

Model

Level

Authentication

Encryption

Result

SNMPv1

noAuthNoPriv

Community string

No

Uses a community

 

 

 

 

string match for

 

 

 

 

authentication.

SNMPv2C

noAuthNoPriv

Community string

No

Uses a community

 

 

 

 

string match for

 

 

 

 

authentication.

 

Catalyst 2960-X Switch Network Management Configuration Guide, Cisco IOS Release 15.0(2)EX

44

OL-29044-01

Page 56
Image 56
Cisco Systems WSC2960X24TDL, WSC2960X48TSL, WSC2960X24PSL, WSC2960X24TSLL Model, Level, Authentication, Encryption, Result