Cisco SRW2048 User Guide - Page 59

Security Level

Page 59 highlights

Chapter 5 Advanced Configuration SNMP > Group Profile The Group Profile screen provides information for creating SNMP groups and assigning SNMP access control privileges to SNMP groups. Groups allow network managers to assign access rights to specific device features, or features aspects. SNMP > Group Membership The Group Membership screen provides information for assigning SNMP access control privileges to SNMP groups. SNMP > Group Profile Group Name Displays the user-defined group name (up to 30 characters) to which access control rules are applied. Security Model Defines the SNMP version attached to the group. The possible field values are: •• SNMPv1 SNMPv1 is defined for the group. •• SNMPv2 SNMPv2 is defined for the group. •• SNMPv3 SNMPv3 is defined for the group. Security Level Defines the security level attached to the group. Security levels apply to SNMPv3 only. The possible field values are: •• No Authentication Indicates that neither the Authentication nor the Privacy security levels are assigned to the group. •• Authentication Authenticates SNMP messages, and ensures the SNMP messages origin is authenticated. •• Privacy Encrypts SNMP messages. Operation Defines the group access rights. The possible field values are: •• Read The management access is restricted to readonly, and changes cannot be made to the assigned SNMP view. •• Write The management access is read-write and changes can be made to the assigned SNMP view. •• Notify Sends traps for the assigned SNMP view. WebView Switches SNMP > Group Membership User name Provides a user-defined local user list. Engine ID Indicates either the local or remote SNMP entity to which the user is connected. Changing or removing the local SNMP Engine ID deletes the SNMPv3 User Database. •• Local Indicates that the user is connected to a local SNMP entity. •• Remote Indicates that the user is connected to a remote SNMP entity. If the Engine ID is defined, remote devices receive inform messages. Group Name Contains a list of user-defined SNMP groups. SNMP groups are defined in the SNMP Group Profile page. Authentication Method Indicates the Authentication method used. The possible field values are: •• None Indicates that no authentication method is used to authenticate the port. •• MD5 Password Indicates that port authentication is performed via HMAC-MD5-96 password authentication. •• SHA Password Indicates that port authentication is performed via HMAC-SHA-96 password authentication. •• MD5 Key Indicates that port authentication is performed via the HMAC-MD5 algorithm. •• SHA Key Indicates that port authentication is performed via HMAC-SHA-96 authentication. Password Define the local user password. Local user passwords can contain up to 159 characters. 52

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96

Chapter 5
Advanced Configuration
52
WebView Switches
SNMP > Group Profile
The
Group Profile
screen provides information for creating
SNMP groups and assigning SNMP access control privileges
to SNMP groups. Groups allow network managers to
assign access rights to specific device features, or features
aspects.
SNMP > Group Profile
Group Name
Displays the user-defined group name
(up to 30 characters) to which access control rules are
applied.
Security Model
Defines the SNMP version attached to
the group. The possible field values are:
SNMPv1
SNMPv1 is defined for the group.
SNMPv2
SNMPv2 is defined for the group.
SNMPv3
SNMPv3 is defined for the group.
Security Level
Defines the security level attached to the
group. Security levels apply to SNMPv3 only. The possible
field values are:
No
Authentication
Indicates
that
neither
the
Authentication nor the Privacy security levels are
assigned to the group.
Authentication
Authenticates SNMP messages, and
ensures the SNMP messages origin is authenticated.
Privacy
Encrypts SNMP messages.
Operation
Defines the group access rights. The possible
field values are:
Read
The management access is restricted to read-
only, and changes cannot be made to the assigned
SNMP view.
Write
The management access is read-write and
changes can be made to the assigned SNMP view.
Notify
Sends traps for the assigned SNMP view.
SNMP > Group Membership
The
Group Membership
screen provides information
for assigning SNMP access control privileges to SNMP
groups.
SNMP > Group Membership
User name
Provides a user-defined local user list.
Engine ID
Indicates either the local or remote SNMP entity
to which the user is connected. Changing or removing the
local SNMP Engine ID deletes the SNMPv3 User Database.
Local
Indicates that the user is connected to a local
SNMP entity.
Remote
Indicates that the user is connected to a
remote SNMP entity. If the Engine ID is defined, remote
devices receive inform messages.
Group Name
Contains a list of user-defined SNMP
groups. SNMP groups are defined in the SNMP Group
Profile page.
Authentication Method
Indicates the Authentication
method used. The possible field values are:
None
Indicates that no authentication method is
used to authenticate the port.
MD5 Password
Indicates that port authentication
is
performed
via
HMAC-MD5-96
password
authentication.
SHA Password
Indicates that port authentication
is
performed
via
HMAC-SHA-96
password
authentication.
MD5
Key
Indicates
that
port
authentication
is
performed via the HMAC-MD5 algorithm.
SHA
Key
Indicates
that
port
authentication
is
performed via HMAC-SHA-96 authentication.
Password
Define the local user password. Local user
passwords can contain up to 159 characters.