Specifications
SNMP Configuration Summary
5-2 SNMP Configuration
SNMPv1 and SNMPv2c
ThecomponentsofSNMPv1andSNMPv2cnetworkmanagementfallintothreecategories:
•Manageddevices(suchasaswitch)
•SNMPagentsandMIBs,includingSNMPtraps,communitystrings,andRemoteMonitoring
(RMON)MIBs,whichrunonmanageddevices
•SNMPnetworkmanagementapplications,suchasEnterasysNetSight,whichcommunicate
withagentstoget
statisticsandalertsfromthemanageddevices.
SNMPv3
SNMPv3isaninteroperablestandards‐basedprotocolthatprovidessecureaccesstodevicesby
authenticatingandencryptingframesoverthenetwork.Theadvancedsecurityfeaturesprovided
inSNMPv3areasfollows:
• Message integrity — Collects data securely without being tampered with or corrupted.
• Authentication — Determines the message is from a valid source.
• Encryption — Scrambles the contents of a frame to prevent it from being seen by an
unauthorized source.
UnlikeSNMPv1andSNMPv2c,inSNMPv3,theconceptofSNMPagentsandSNMPmanagersno
longerapply.TheseconceptshavebeencombinedintoanSNMPentity.AnSNMPentityconsists
ofanSNMPengineandSNMPapplications.AnSNMPengineconsistsofthefollowingfour
components:
•Dispatcher—Thiscomponentsends
andreceivesmessages.
•Messageprocessingsubsystem—ThiscomponentacceptsoutgoingPDUsfromthe
dispatcherandpreparesthemfortransmissionbywrappingtheminamessageheaderand
returningthemtothedispatcher.Themessageprocessingsubsystemalsoacceptsincoming
messagesfromthedispatcher,processeseachmessageheader,andreturns
theenclosedPDU
tothedispatcher.
•Securitysubsystem—Thiscomponentauthenticatesandencryptsmessages.
• Accesscontrolsubsystem—Thiscomponentdetermineswhichusersandwhichoperations
areallowedaccesstomanagedobjects.
About SNMP Security Models and Levels
AnSNMPsecuritymodelisanauthenticationstrategythatissetupforauserandthegroupin
whichtheuserresides.Asecuritylevelisthepermittedlevelofsecuritywithinasecuritymodel.
ThethreelevelsofSNMPsecurityare:Noauthenticationrequired(NoAuthNoPriv);
authenticationrequired(AuthNoPriv);and
privacy(authPriv).Acombinationofasecuritymodel
andasecurityleveldetermineswhichsecuritymechanismisemployedwhenhandlinganSNMP
frame.Table 5‐1identifiesthelevelsofSNMPsecurityavailableonMatrixSeriesdevicesand
authenticationrequiredwithineachmodel.