Specifications
SNMP Support on Enterasys Devices
March 28, 2011 Page 5 of 27
control,SNMPv3alsoprovidesahigherdegreeofreliabilityfornotifyingmanagement
stationswhencriticaleventsoccur.
SNMPv3isfullydescribedinRFC2571,RFC 2572,RFC2573,RFC2574,and RFC2575.
SNMPv1 andv2c Network Management Components
TheEnterasysimplementationofSNMPv1andv2cnetworkmanagementcomponentsfallintothe
followingthreecategories:
•Manageddevices(suchasaswitch).
•SNMPagentsandMIBs,includingSN MPtraps,communitystrings,andRemoteMonitoring
(RMON)MIBs,whichrunonmanageddevices.
•SNMPnetworkmanagementapplications,suchastheEnterasysNetSightapplication,
which
communicatewithagentstogetstatisticsandalertsfromthemanageddevices.
SNMPv3 User-Based Security Model (USM) Enhancements
SNMPv3addstov1andv2ccomponentsbyprovidingsecureaccesstodevicesbyauthenticating
andencryptingframesoverthenetwork.TheEnterasyssupportedadvancedsecurityfeatures
providedinSNMPv3’sUser‐BasedSecurityModelareasfollows:
•Messageintegrity—Collectsdatasecurelywithoutbeingtamperedwithorcorrupted.
• Authentication—
Determinesthemessageisfromavalidsource.
•Encryption—Scramblesthecontentsofaframetopreventitfrombeingseenbyan
unauthorizedsource.
UnlikeSNMPv1andSNMPv2c,inSNMPv3,theconceptofSNMPagentsandSNMPmanagersno
longerapply.Theseconceptshavebeencombinedintoan
SNMPentity.AnSNMPentityconsists
ofanSNMPengineandSNMPapplications.AnSNMPengineconsistsofthefollowingfour
components:
–Dispatcher—Sendsandreceivesmessages.
– Messageprocessingsubsystem—AcceptsoutgoingPDUsfromthedispatcherand
preparesthemfortransmissionbywrappingtheminamessageheaderand
returning
themtothedispatcher.Alsoacceptsincomingmessagesfromthedispatcher,processes
eachmessageheader,andreturnstheenclosedPDUtothedispatcher.
–Securitysubsystem—Authenticatesandencryp tsmessages.
– Accesscontrolsubsystem—Thiscomponentdetermineswhichusersandwhich
operationsareallowedaccesstomanagedobjects.
Terms and Definitions
Table 2listscommonSNMPtermsanddefinestheiruseonEnterasysdevices.
Table 2 SNMP Terms and Definitions
Term Definition
community A name string used to authenticate SNMPv1 and v2c users.
context A subset of MIB information to which associated users have access rights.