HP GbE2c HP GbE2c Ethernet Blade Switch for c-Class BladeSystem Command Refere - Page 98

User Security Model configuration

Page 98 highlights

SNMP version 3 (SNMPv3) is an extensible SNMP Framework that supplements the SNMPv2 Framework by supporting the following: • a new SNMP message format • security for messages • access control • remote configuration of SNMP parameters For more details on the SNMPv3 architecture please see RFC2271 to RFC2275. The following table describes the SNMPv3 Configuration Menu options. Table 85 SNMPv3 Configuration Menu options Command Description usm view access group comm taddr tparam notify v1v2 disable|enable cur Configures a user security model (USM) entry for an authorized user. You can also configure this entry through SNMP. The range is 1-16. Configures different MIB views. The range is 1-128. Configures access rights. The View-based Access Control Model defines a set of services that an application can use for checking access rights of the user. You need access control when you have to process retrieval or modification request from an SNMP entity. The range is 1-32. Configures an SNMP group. A group maps the user name to the access group names and their access rights needed to access SNMP management objects. A group defines the access rights assigned to all names that belong to a particular group. The range is 116. Configures a community table entry. The community table contains objects for mapping community strings and version-independent SNMP message parameters. The range is 1-16. Configures the destination address and user security levels for outgoing notifications. This is also called the transport endpoint. The range is 1-16. Configures SNMP parameters, consisting of message processing model, security model, security level, and security name information. There may be multiple transport endpoints associated with a particular set of SNMP parameters, or a particular transport endpoint may be associated with several sets of SNMP parameters. Configures a notification index. A notification application typically monitors a system for particular events or conditions, and generates Notification-Class messages based on these events or conditions. The range is 1-16. Enables or disables the access to SNMP version 1 and version 2. This command is enabled by default. Displays the current SNMPv3 configuration. User Security Model configuration Command: /cfg/sys/ssnmp/snmpv3/usm [SNMPv3 usmUser 1 Menu] name - Set USM user name auth - Set authentication protocol authpw - Set authentication password priv - Set privacy protocol privpw - Set privacy password del - Delete usmUser entry cur - Display current usmUser configuration You can make use of a defined set of user identities using this Security Model. An SNMP engine must have the knowledge of applicable attributes of a user. This menu helps you create a user security model entry for an authorized user. You need to provide a security name to create the USM entry. The following table describes the User Security Model Configuration Menu options. Configuration Menu 98

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175

Configuration Menu 98
SNMP version 3 (SNMPv3) is an extensible SNMP Framework that supplements the SNMPv2 Framework by
supporting the following:
a new SNMP message format
security for messages
access control
remote configuration of SNMP parameters
For more details on the SNMPv3 architecture please see RFC2271 to RFC2275.
The following table describes the SNMPv3 Configuration Menu options.
Table 85
SNMPv3 Configuration Menu options
Command
Description
usm <
1-16
>
Configures a user security model (USM) entry for an authorized user. You can also
configure this entry through SNMP. The range is 1-16.
view <
1-128>
Configures different MIB views. The range is 1-128.
access <
1-32
>
Configures access rights. The View-based Access Control Model defines a set of services
that an application can use for checking access rights of the user. You need access
control when you have to process retrieval or modification request from an SNMP entity.
The range is 1-32.
group <
1-16
>
Configures an SNMP group. A group maps the user name to the access group names
and their access rights needed to access SNMP management objects. A group defines
the access rights assigned to all names that belong to a particular group. The range is 1-
16.
comm <
1-16
>
Configures a community table entry. The community table contains objects for mapping
community strings and version-independent SNMP message parameters.
The range is 1-16.
taddr <
1-16
>
Configures the destination address and user security levels for outgoing notifications. This
is also called the transport endpoint. The range is 1-16.
tparam <
1-16
>
Configures SNMP parameters, consisting of message processing model, security model,
security level, and security name information. There may be multiple transport endpoints
associated with a particular set of SNMP parameters, or a particular transport endpoint
may be associated with several sets of SNMP parameters.
notify <
1-16
>
Configures a notification index. A notification application typically monitors a system for
particular events or conditions, and generates Notification-Class messages based on
these events or conditions. The range is 1-16.
v1v2 disable|enable
Enables or disables the access to SNMP version 1 and version 2. This command is
enabled by default.
cur
Displays the current SNMPv3 configuration.
User Security Model configuration
Command:
/cfg/sys/ssnmp/snmpv3/usm
[SNMPv3 usmUser 1
Menu]
name
- Set USM user name
auth
- Set authentication protocol
authpw
- Set authentication password
priv
- Set privacy protocol
privpw
- Set privacy password
del
- Delete usmUser entry
cur
- Display current usmUser configuration
You can make use of a defined set of user identities using this Security Model. An SNMP engine must have the
knowledge of applicable attributes of a user.
This menu helps you create a user security model entry for an authorized user. You need to provide a security name
to create the USM entry.
The following table describes the User Security Model Configuration Menu options.