Concept Guide

3 is the most secure of the security modes.
2c allows transmission of informs and counter 64, which allows for integers twice the
width of what is normally allowed.
The default is 1.
encrypted (OPTIONAL) Enter the keyword encrypted to specify the password appear in
encrypted format (a series of digits, masking the true characters of the string).
auth (OPTIONAL) Enter the keyword auth to specify authentication of a packet without
encryption.
md5 | sha (OPTIONAL) Enter the keyword md5 or sha to designate the authentication level.
md5 — Message Digest Algorithm
sha — Secure Hash Algorithm
auth-password (OPTIONAL) Enter a text string (up to 20 characters long) password that enables the
agent to receive packets from the host and to send packets to the host. Minimum: eight
characters long.
priv des56 (OPTIONAL) Enter the keywords priv des56 to initiate a privacy authentication level
setting using the CBC-DES privacy authentication algorithm (des56).
aes128 (OPTIONAL) Enter the keyword aes128 to initiate the AES128-CFB encryption
algorithm for transmission of SNMP packets.
priv password (OPTIONAL) Enter a text string (up to 20 characters long) password that enables the
host to encrypt the contents of the message it sends to the agent and decrypt the
contents of the message it receives from the agent. Minimum: eight characters long.
access-list-name (Optional) Enter the standard IPv4 access list name (a string up to 16 characters long).
Defaults If no authentication or privacy option is congured, then the messages are exchanged (attempted anyway) without
any authentication or encryption.
Command Modes CONFIGURATION
Supported Modes Full–Switch Mode
Command History
Version Description
9.9(0.0) Introduced on the FN IOM.
9.3(0.0) Added support for the AES128-CFB encryption algorithm on the MXL 10/40GbE Switch
IO Module platform.
8.3.16.1 Introduced on the MXL 10/40GbE Switch IO Module.
Usage Information
No default values exist for authentication or privacy algorithms and no default password exists. If you forget a
password, you cannot recover it; the user must be recongured. You can specify either a plain-text password or an
encrypted cypher-text password. In either case, the password is stored in the conguration in an encrypted form
and displayed as encrypted in the show running-config command.
If you have an encrypted password, you can specify the encrypted string instead of the plain-text password. The
following command is an Example of how to specify the command with an encrypted string.
NOTE: The number of congurable users is limited to 16.
1248 Simple Network Management Protocol (SNMP) and Syslog