User guide

78 Sun Storage Fibre Channel Switch 5802 QuickTools User Guide September 2008
SNMP v3 Security
Simple Network Management Protocol Version 3 (SNMPv3) is an interoperable
standards-based protocol for network management. SNMPv3 provides secure access
to devices by a combination of authenticating and encrypting packets over the
network. SNMP v3 security is an additional layer of security offered with the
firmware. The SNMP v3 security is available to a switch that has a secure
connection, and can only be configured on the entry switch. The security features
provided in SNMPv3 are:
Message integrity — ensuring that a packet has not been tampered with during
transit.
Authentication — determining the message is from a valid source.
Encryption — scrambling the contents of a packet to prevent it from being seen by
an unauthorized source.
The SNMP v3 Manager dialog allows you to add, remove, and edit an SNMP v3
user. To display the SNMP v3 Manager dialog (
FIGURE 3-12) open the Switch menu,
select SNMP, and select SNMP v3 Manager. The SNMP v3 Security option allows
you to turn SNMP v3 security on or off.
Click the Add button to open the SNMP v3 User Editor dialog (
FIGURE 3-13), and add
an SNMP v3 user. After SNMP v3 users are configured and saved, they are
displayed in the SNMPv3 Users list window in the SNMP v3 Manager dialog. Select
a user from the list, and that user’s settings are displayed on the right in the Selected
SNMPv3 User area. The Remove and Edit buttons become active when you select a
Trap Community Trap community password (up to 32 characters) that authorizes an
SNMP agent to receive traps. This is a write-only field. The value on the
switch and the SNMP management server must be the same. The default
is “public”.
Trap Severity Specifies a severity level to assign to the trap. Open the drop-down list
and choose a level. The Trap 1 Enabled option on the SNMP Properties
dialog must be enabled to access this drop-down list. Trap severity levels
include Unknown, Emergency, Alert, Critical, Error, Warning, Notify,
Info, Debug, and Mark
Trap Port* Specifies the port number (between 1-65535) on which a trap is set. The
default is 162.
* Trap address (other than 0.0.0.0) and trap port combinations must be unique. For example, if trap 1 and trap 2
have the same address, then they must have different port values. Similarly, if trap 1 and 2 have the same port
value, they must have different addresses.
TABLE 3-8
SNMP Trap Configuration Parameters (Continued)
Parameter Description