Enhancements

Release M.08.89 Enhancements

Security Notes

Passwords and keys configured in the hpSwitchAuth MIB are not returned via SNMP, and the response to SNMP queries for such information is a null string. However, SNMP sets can be used to configure password and key MIB objects.

To help prevent unauthorized access to the switch’s authentication MIB, ProCurve recommends enhancing security according to the guidelines under “Enforcing Switch Security” on page 10.

If you do not want to use SNMP access to the switch’s authentication configuration MIB, then you should use the snmp-server mib hpswitchauthmib excluded command to disable this access, as described in the next section.

If you choose to leave SNMP access to the security MIB open (the default setting), ProCurve recommends that you configure the switch with the SNMP version 3 management and access security feature, and disable SNMP version 2c access. (Refer to “Enforcing Switch Security” on page 10.)

Changing and Viewing the SNMP Access Configuration

Syntax: snmp-server mib hpswitchauthmib < excluded included >

included: Enables manager-level SNMP read/write access to the switch’s authentication configuration (hpSwitchAuth) MIB.

excluded: Disables manager-level SNMP read/write access to the switch’s authentication configuration (hpSwitchAuth) MIB.

(Default: included )

Syntax: show snmp-server

The output for this command has been enhanced to display the current access status of the switch’s authentication configuration MIB in the Excluded MIBs field.

36