Security planning Chapter 2 Planning considerations
phn-1115_006v000
2-38
Sep 2010
Web-based management of SNMPv3 security
Identify the format used for SNMP Engine ID. Three formats are available:
• MAC address (default)
• IP address
• Text string
If SNMP Engine ID will be based on a text string, identify the text string required by
the network management system. This is often based on some identifier that survives
replacement of the PTP hardware.
Identify the user names and security roles of initial SNMPv3 users. Two security roles
are available:
• Read Only
• System Administrator
Identify the security level for each of the security roles. Three security levels are
available:
• No authentication, no privacy
• Authentication, no privacy
• Authentication, privacy
If authentication is required, identify the protocol. Two authentication protocols are
available:
• MD5
• SHA
If privacy will be used, identify the protocol. Two privacy protocols are available:
• DES
• AES
AES link encryption is only available to users who have purchased an appropriate
license key.
If authentication or authentication and privacy protocols are required, identify
passphrases for each protocol for each SNMP user. It is considered good practice to
use different passphrases for authentication and privacy. Passphrases must have
length between 8 and 32 characters, and may contain any of the characters listed in
Table 2-5.
Comments to this Manuals