Securing snmp access, Snmp overview, Chapter 8 – Brocade TurboIron 24X Series Configuration Guide User Manual
Page 197

Brocade TurboIron 24X Series Configuration Guide
163
53-100305301
Chapter
8
Securing SNMP Access
In this chapter
•
•
Establishing SNMP community strings . . . . . . . . . . . . . . . . . . . . . . . . . . . . 164
•
•
•
•
SNMP v3 Configuration examples . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 175
SNMP overview
SNMP is a set of protocols for managing complex networks. SNMP sends messages, called protocol
data units (PDUs), to different parts of a network. SNMP-compliant devices, called agents, store
data about themselves in Management Information Bases (MIBs) and return this data to the SNMP
requesters.
Chapter 5, “Securing Access to Management Functions”
introduced a few methods used to secure
SNMP access. They included the following:
•
“Using ACLs to restrict SNMP access”
•
“Restricting SNMP access to a specific IP address”
•
“Restricting SNMP access to a specific VLAN”
•
This chapter presents additional methods for securing SNMP access to devices. It contains the
following sections:
•
“Establishing SNMP community strings”
•
•
“SNMP v3 Configuration examples”
•
•
•
“SNMP v3 Configuration examples”
Restricting SNMP access using ACL, VLAN, or a specific IP address constitute the first level of
defense when the packet arrives at a device. The next level uses one of the following methods:
•
Community string match In SNMP versions 1 and 2
•
User-based model in SNMP version 3
SNMP views are incorporated in community strings and the user-based model.