Specifications

SNMP Support on Enterasys Devices
March 28, 2011 Page 5 of 27
control,SNMPv3alsoprovidesahigherdegreeofreliabilityfornotifyingmanagement
stationswhencriticaleventsoccur.
SNMPv3isfullydescribedinRFC2571,RFC 2572,RFC2573,RFC2574,and RFC2575.
SNMPv1 andv2c Network Management Components
TheEnterasysimplementationofSNMPv1andv2cnetworkmanagementcomponentsfallintothe
followingthreecategories:
•Manageddevices(suchasaswitch).
•SNMPagentsandMIBs,includingSN MPtraps,communitystrings,andRemoteMonitoring
(RMON)MIBs,whichrunonmanageddevices.
•SNMPnetworkmanagementapplications,suchastheEnterasysNetSightapplication,
which
communicatewithagentstogetstatisticsandalertsfromthemanageddevices.
SNMPv3 User-Based Security Model (USM) Enhancements
SNMPv3addstov1andv2ccomponentsbyprovidingsecureaccesstodevicesbyauthenticating
andencryptingframesoverthenetwork.TheEnterasyssupportedadvancedsecurityfeatures
providedinSNMPv3’sUserBasedSecurityModelareasfollows:
•MessageintegrityCollectsdatasecurelywithoutbeingtamperedwithorcorrupted.
Authentication
Determinesthemessageisfromavalidsource.
•EncryptionScramblesthecontentsofaframetopreventitfrombeingseenbyan
unauthorizedsource.
UnlikeSNMPv1andSNMPv2c,inSNMPv3,theconceptofSNMPagentsandSNMPmanagersno
longerapply.Theseconceptshavebeencombinedintoan
SNMPentity.AnSNMPentityconsists
ofanSNMPengineandSNMPapplications.AnSNMPengineconsistsofthefollowingfour
components:
–DispatcherSendsandreceivesmessages.
MessageprocessingsubsystemAcceptsoutgoingPDUsfromthedispatcherand
preparesthemfortransmissionbywrappingtheminamessageheaderand
returning
themtothedispatcher.Alsoacceptsincomingmessagesfromthedispatcher,processes
eachmessageheader,andreturnstheenclosedPDUtothedispatcher.
–SecuritysubsystemAuthenticatesandencryp tsmessages.
AccesscontrolsubsystemThiscomponentdetermineswhichusersandwhich
operationsareallowedaccesstomanagedobjects.
Terms and Definitions
Table 2listscommonSNMPtermsanddefinestheiruseonEnterasysdevices.
Table 2 SNMP Terms and Definitions
Term Definition
community A name string used to authenticate SNMPv1 and v2c users.
context A subset of MIB information to which associated users have access rights.