How To
Summary
This document will cover the steps to take in order to successfully configure SNMPv3 encrypted on a AIX system.
Objective
Compared to its predecessors which have downsides like only 32 bit counters and plaintext community strings transmitted over the network, SNMPv3 is unique due to it's focus on security.
Steps
b) For a complete step by step guide on downloading media from ESS please refer tot he following tech note:
# snmpv3_ssw -e
#VACM_VIEW defaultView 1.3.6.1.4.1.2.2.1.1.1.0 - included -
#VACM_VIEW defaultView 1.3.6.1.4.1.2.6.191.1.6 - included -
#VACM_VIEW defaultView snmpModules - excluded -
#VACM_VIEW defaultView 1.3.6.1.6.3.1.1.4 - included -
#VACM_VIEW defaultView 1.3.6.1.6.3.1.1.5 - included -
#VACM_VIEW defaultView 1.3.6.1.4.1.2.6.191 - included -
logging size=1000000 level=3
END OF FILE
VACM_VIEW - specifies view name and view mask
VACM_ACCESS - associates a group with security and views
NOTIFY, TARGET_ADDRESS, TARGET_PARAMETERS - where to send SNMP traps
COMMUNITY - specifies community name and access
DEFAULT_SECURITY - defines the default security posture to be configured for the SNMP agent
NOTIFY notify2 traptag2 trap -
NOTIFY notify3 traptag3 trap -
TARGET_ADDRESS Target2 UDP 9.3.58.66 traptag2 trapparms2 - - -
TARGET_ADDRESS Target3 UDP 127.0.0.1 traptag3 trapparms3 - - -
TARGET_PARAMETERS trapparms2 SNMPv1 SNMPv1 public noAuthNoPriv -
TARGET_PARAMETERS trapparms3 SNMPv1 SNMPv1 public noAuthNoPriv -
# cat /etc/snmpd.boots
000000020000000009033A79 0000000046
# pwtokey -u all u1password 9.3.58.12
Replace with your IP address in the example above. Note: This password is not related to the community name, it's only used to generate keys for user based security.
One authentication (authKey) key pair and one privacy (privKey) key pair are generated.
“localized” key used by AIX SNMP agent in /etc/snmpdv3.conf file
“non-localized” key to be used by SNMP management station
USM_USER u1 - HMAC-MD5
6b5bddcf9702102641a9ab8b1d5f791f DES
6b5bddcf9702102641a9ab8b1d5f791f L -
The second string is the localized privKey generated in step 6.
Note that it is ONE line only, ending with a dash as seen bellow
VACM_ACCESS groupu1 - - AuthPriv USM defaultView - defaultView -
# stopsrc -s aixmibd
# stopsrc -s hostmibd
# stopsrc -s snmpmibd
# stopsrc -s snmpd
# startsrc -s snmpd
# startsrc -s aixmibd
# startsrc -s hostmibd
# startsrc -s snmpmibd
7a3e34265e0e029f27d8b4235ecfa987 DES
7a3e34265e0e029f27d8b4235ecfa987
# clsnmp -h user1 -v walk system
Additional Information
| SUPPORT | ||
|---|---|---|
|
If additional assistance is required after completing all of the instructions provided in this document, please follow the step-by-step instructions below to contact IBM to open a case for software under warranty or with an active and valid support contract. The technical support specialist assigned to your case will confirm that you have completed these steps. 1. Document and/or take screen shots of all symptoms, errors, and/or messages that might have occurred. 2. Capture any logs or data relevant to the situation. 3. Contact IBM to open a case: -For electronic support, please visit the IBM Support Community: 4. Provide a good description of your issue, and reference this Technote, and any issues you had with the instructions. 5. Collect the system snap and upload all of the details and data for your case.
|
Related Information
Was this topic helpful?
Document Information
Modified date:
31 May 2019
UID
ibm10886219