Technical Configuration Guide for SNMP | v2.0 | December 2006 |
Table of Contents
1. | SNMPV3 OVERVIEW | 5 | |
2. | SNMP UPGRADE CONSIDERATIONS | 6 | |
| 2.1 | HIDDEN FILE DETAILS | 6 |
3. | BLOCKING SNMP | 7 | |
| 3.1 | BLOCKING SNMPV1/2 ONLY | 7 |
| 3.2 | BLOCKING SNMP VIA AN ACCESS POLICY – PRIOR TO SOFTWARE RELEASE 3.7.9 OR 4.1 | 7 |
| 3.3 | SNMP GROUP ACCESS POLICY – RELEASE 3.7.9, 4.1 OR HIGHER | 9 |
| 3.4 | NEW DEFAULT COMMUNITY STRINGS IN HIGH SECURE (HSECURE) MODE | 19 |
4. | SNMP SETTINGS | 20 | |
5. | SNMP WITH RADIUS AUTHENTICATION AND ACCOUNTING | 22 | |
6. | CONFIGURING SNMPV3 | 23 | |
| 6.1 | LOADING THE DES OR AES ENCRYPTION MODULE | 23 |
| 6.2 | ADDING A NEW SNMPV3 USER TO USM TABLE | 23 |
| 6.3 | ASSIGN USM USER TO USM GROUP | 24 |
| 6.4 | ASSIGNING THE USM GROUP ACCESS LEVEL | 25 |
| 6.5 | ASSIGNING THE MIB VIEW TO THE USM GROUP | 26 |
| 6.6 | CREATING A MIB VIEW | 27 |
7. | CONFIGURATION EXAMPLE: CHANGING SNMP COMMUNITIES | 28 | |
| 7.1 | CONFIGURATION EXAMPLE: SNMP COMMUNITIES WITH RELEASE 3.5 | 28 |
7.2CONFIGURATION EXAMPLE: CHANGING THE DEFAULT SNMP COMMUNITY NAME WITH
RELEASE 3.7 OR 4.1 | 29 |
7.3CONFIGURATION EXAMPLE: ADDING A NEW SNMP COMMUNITY TO AN EXISTING SNMP
GROUP MEMBER | 29 | |
7.4 | TESTING SNMP USING DEVICE MANAGER | 32 |
7.5 | CONFIGURATION EXAMPLE: CHANGING THE MIB VIEW FOR AN SNMPV1/2 COMMUNITY | 32 |
8. CONFIGURATION EXAMPLE USING SNMPV3 | 34 | |
8.1 | TESTING SNMPV3 USING DEVICE MANAGER | 35 |
9. SOFTWARE BASELINE: | 36 | |
10. | REFERENCE DOCUMENTATION: | 37 |
11. APPENDIX A: CONFIGURATION FILES | 38 | |
11.1 | FROM CONFIGURATION EXAMPLE 7.5 | 38 |
11.2 | FROM CONFIGURATION EXAMPLE 8 | 38 |
______________________________________________________________________________________________________
NORTEL | External Distribution | 3 |