HP 6125XLG R2306-HP 6125XLG Blade Switch Network Management and Monitoring Com - Page 114

Specifies the AES Advanced Encryption Standard algorithm., Security Configuration Guide

Page 114 highlights

snmp-agent usm-user v3 user-name group-name [ remote { ip-address | ipv6 ipv6-address } [ vpn-instance vpn-instance-name ] ] { cipher | simple } authentication-mode sha auth-password [ privacy-mode aes128 priv-password ] [ acl acl-number | acl ipv6 ipv6-acl-number ] * undo snmp-agent usm-user v3 user-name group-name { local | engineid engineid-string | remote { ip-address | ipv6 ipv6-address } [ vpn-instance vpn-instance-name ] } Default No SNMPv3 users have been configured. Views System view Predefined user roles network-admin Parameters user-name: Specifies an SNMPv3 username, a case-sensitive string of 1 to 32 characters. group-name: Specifies an SNMPv3 group name, a case-sensitive string of 1 to 32 characters. remote { ip-address | ipv6 ipv6-address }: Specifies the IPv4 or IPv6 address of the remote SNMP entity. To send SNMPv3 informs to an NMS, you must specify the IPv4 or IPv6 address of the NMS in the snmp-agent usm-user v3 command and map the IPv4 or IPv6 address to the SNMP engine ID of the NMS by using the snmp-agent remote command. vpn-instance vpn-instance-name: Specifies the VPN for the target host receiving SNMP notifications. The vpn-instance-name argument specifies the name of the MPLS L3VPN, a case-sensitive string of 1 to 31 characters. If this parameter is not specified, the target host is in public network. cipher: Specifies that auth-password and priv-password are encrypted keys, which can be calculated to a hexadecimal string by using the snmp-agent calculate-password command. simple: Specifies that auth-password and priv-password are plaintext keys. authentication-mode: Specifies an authentication algorithm. MD5 is faster but less secure than SHA. For more information about these algorithms, see Security Configuration Guide. • md5: Specifies the MD5 authentication algorithm. • sha: Specifies the SHA-1 authentication algorithm. auth-password: Specifies a case-sensitive plaintext or encrypted authentication key. In non-FIPS mode, a plaintext key is a string of 1 to 64 visible characters. In FIPS mode, a plaintext key is a string of 15 to 64 visible characters, which must contain numbers, upper-case letters, lower-case letters, and special characters. If the cipher keyword is specified, the encrypted authentication key length requirements differ by authentication algorithm and key string format, as shown in Table 28. Table 28 Encrypted authentication key length requirements Authentication algorithm MD5 SHA Hexadecimal string 32 characters 40 characters Non-hexadecimal string 53 characters 57 characters privacy-mode: Specifies an encryption algorithm for privacy. AES is slower but more secure than DES. • aes128: Specifies the AES (Advanced Encryption Standard) algorithm. 112

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207

112
snmp-agent
usm-user
v3
user-name
group-name
[
remote
{
ip-address
|
ipv6
ipv6-address
}
[
vpn-instance
vpn-instance-name
] ] {
cipher
|
simple
}
authentication-mode
sha
auth-password
[
privacy-mode
aes128
priv-password
] [
acl
acl-number
|
acl
ipv6
ipv6-acl-number
] *
undo
snmp-agent
usm-user
v3
user-name
group-name
{
local
|
engineid
engineid-string
|
remote
{
ip-address
|
ipv6
ipv6-address
} [
vpn-instance
vpn-instance-name
] }
Default
No SNMPv3 users have been configured.
Views
System view
Predefined user roles
network-admin
Parameters
user-name
: Specifies an SNMPv3 username, a case-sensitive string of 1 to 32 characters.
group-name
: Specifies an SNMPv3 group name, a case-sensitive string of 1 to 32 characters.
remote
{
ip-address
|
ipv6
ipv6-address
}: Specifies the IPv4 or IPv6 address of the remote SNMP entity.
To send SNMPv3 informs to an NMS, you must specify the IPv4 or IPv6 address of the NMS in the
snmp-agent
usm-user
v3
command and map the IPv4 or IPv6 address to the SNMP engine ID of the
NMS by using the
snmp-agent remote
command.
vpn-instance
vpn-instance-name
: Specifies the VPN for the target host receiving SNMP notifications. The
vpn-instance-name
argument specifies the name of the MPLS L3VPN, a case-sensitive string of 1 to 31
characters. If this parameter is not specified, the target host is in public network.
cipher
: Specifies that
auth-password
and
priv-password
are encrypted keys, which can be calculated to
a hexadecimal string by using the
snmp-agent calculate-password
command.
simple
: Specifies that
auth-password
and
priv-password
are plaintext keys.
authentication-mode
: Specifies an authentication algorithm. MD5 is faster but less secure than SHA. For
more information about these algorithms, see
Security Configuration Guide
.
md5
: Specifies the MD5 authentication algorithm.
sha
: Specifies the SHA-1 authentication algorithm.
auth-password
: Specifies a case-sensitive plaintext or encrypted authentication key. In non-FIPS mode, a
plaintext key is a string of 1 to 64 visible characters. In FIPS mode, a plaintext key is a string of 15 to 64
visible characters, which must contain numbers, upper-case letters, lower-case letters, and special
characters. If the
cipher
keyword is specified, the encrypted authentication key length requirements differ
by authentication algorithm and key string format, as shown in
Table 28
.
Table 28
Encrypted authentication key length requirements
Authentication
algorithm
Hexadecimal string
Non-hexadecimal string
MD5
32 characters
53 characters
SHA
40 characters
57 characters
privacy-mode
: Specifies an encryption algorithm for privacy. AES is slower but more secure than DES.
aes128
: Specifies the AES (Advanced Encryption Standard) algorithm.