SNMPv3 authPriv Configuration: Cisco and Juniper Examples - 夜莺博客

SNMPv3 authPriv Configuration: Cisco and Juniper Examples

SNMPv2c still works and is still everywhere, but it sends a cleartext community string on every poll and trap, which makes it unsuitable for anything crossing an untrusted link. SNMPv3 replaces that with per-user authentication and optional encryption. This article configures authPriv — authentication plus privacy — on both Cisco IOS and Junos, and shows how to verify it.

Security levels, in one table

Level Authentication Encryption Use
noAuthNoPriv No No Lab only
authNoPriv Yes (MD5/SHA) No Integrity but readable payloads
authPriv Yes Yes (DES/AES) Standard for production

Prefer SHA-1 or better over MD5 for authentication and AES over DES for privacy; MD5 and DES remain supported largely for interoperability with legacy collectors.

Cisco IOS / IOS-XE

ip access-list standard SNMP-SOURCES
 permit 10.10.10.50
 permit 10.10.10.51
!
snmp-server view MONITORED iso included
snmp-server group NETOPS v3 priv read MONITORED access SNMP-SOURCES
snmp-server user netops NETOPS v3 auth sha AuthPassw0rd! priv aes 128 PrivPassw0rd!
!
snmp-server enable traps
snmp-server host 10.10.10.50 version 3 priv netops

The view restricts which MIB subtrees the group may read — without it the group defaults to broad access. The access-list limits which management stations may use the credentials at all, which is the cheapest meaningful hardening step available. Note that snmp-server user entries are hidden from the running configuration by default; check with show snmp user.

Junos

set snmp v3 usm local-engine user netops authentication-sha authentication-password AuthPassw0rd!
set snmp v3 usm local-engine user netops privacy-aes128 privacy-password PrivPassw0rd!
set snmp v3 vacm security-to-group security-model usm security-name netops group NETOPS
set snmp v3 vacm access group NETOPS default-context-prefix security-model usm security-level privacy read-view MONITORED
set snmp view MONITORED oid 1 include
set snmp community public authorization read-only   # remove if unused
set snmp trap-group NETOPS targets 10.10.10.50

Junos splits the work across three hierarchies that must agree: usm defines the user and its authentication/privacy algorithms, vacm maps that user to a group and a read view, and the trap group defines destinations. A user configured in usm with no vacm mapping authenticates and then returns nothing — the classic "SNMPv3 works but the walk is empty" symptom.

Verification

# from the management station
snmpwalk -v3 -l authPriv -u netops -a SHA -A 'AuthPassw0rd!'          -x AES -X 'PrivPassw0rd!' 10.10.10.1 1.3.6.1.2.1.1

# on the device
show snmp user
show snmp group
show snmp stats oid

If the walk returns Authentication failure, the auth protocol or password differs between device and collector. If it returns Unknown user name, the user or the engine ID is wrong. If it succeeds but returns nothing, the VACM view is empty. Those three symptoms cover almost every SNMPv3 deployment problem.

Related reading: Huawei NQA test instances and SLA monitoring, Junos RPM probes and SLA monitoring, Dynamic ARP inspection failure scenarios.

原文链接:https://www.juniper.net/documentation/us/en/software/junos/network-mgmt/topics/topic-map/configure-the-snmpv3-authentication-type-and-encryption-type.html