<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SNMP and AAA in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/snmp-and-aaa/m-p/778418#M409036</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SNMPv3 provides for both security models and security levels. A security model is an authentication strategy that is set up for a user and the role in which the user resides. A security level is the permitted level of security within a security model. A combination of a security model and a security level determines which security mechanism is employed when handling an SNMP packet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Access Control occurs (either implicitly or explicitly) in an SNMP entity when processing SNMP retrieval or modification request  messages from an SNMP entity.  For example a Command Responder application applies Access Control when processing requests that it  received from a Command Generator application.  These requests contain Read Class and Write Class PDUs as defined in [RFC3411].&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   Access Control also occurs in an SNMP entity when an SNMP notification message is generated (by a Notification Originator  application).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To implement the model described above, an SNMP entity needs to retain information about access rights and policies.  This information is part of the SNMP engine's Local configuration Datastore (LCD).  See [RFC3411] for the definition of LCD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As of Cisco MDS SAN-OS, SNMP v3 user management can be centralized at the AAA server level. This centralized user management allows the SNMP agent running on the Cisco MDS switch to leverage the user authentication service of AAA server. Once user authentication is verified, the SNMP PDUs are processed further. Additionally, the AAA server is also used to store user group names. SNMP uses the group names to apply the access/role policy that is locally available in the switch.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 05 Sep 2007 21:52:08 GMT</pubDate>
    <dc:creator>Dev Vishwakarma</dc:creator>
    <dc:date>2007-09-05T21:52:08Z</dc:date>
    <item>
      <title>SNMP and AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/snmp-and-aaa/m-p/778417#M409035</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone get working the SNMP v3 authentication thru AAA servers?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any feedback is greatly appreciated&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:22:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/snmp-and-aaa/m-p/778417#M409035</guid>
      <dc:creator>eastcoast5</dc:creator>
      <dc:date>2019-03-10T22:22:02Z</dc:date>
    </item>
    <item>
      <title>Re: SNMP and AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/snmp-and-aaa/m-p/778418#M409036</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SNMPv3 provides for both security models and security levels. A security model is an authentication strategy that is set up for a user and the role in which the user resides. A security level is the permitted level of security within a security model. A combination of a security model and a security level determines which security mechanism is employed when handling an SNMP packet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Access Control occurs (either implicitly or explicitly) in an SNMP entity when processing SNMP retrieval or modification request  messages from an SNMP entity.  For example a Command Responder application applies Access Control when processing requests that it  received from a Command Generator application.  These requests contain Read Class and Write Class PDUs as defined in [RFC3411].&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   Access Control also occurs in an SNMP entity when an SNMP notification message is generated (by a Notification Originator  application).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To implement the model described above, an SNMP entity needs to retain information about access rights and policies.  This information is part of the SNMP engine's Local configuration Datastore (LCD).  See [RFC3411] for the definition of LCD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As of Cisco MDS SAN-OS, SNMP v3 user management can be centralized at the AAA server level. This centralized user management allows the SNMP agent running on the Cisco MDS switch to leverage the user authentication service of AAA server. Once user authentication is verified, the SNMP PDUs are processed further. Additionally, the AAA server is also used to store user group names. SNMP uses the group names to apply the access/role policy that is locally available in the switch.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Sep 2007 21:52:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/snmp-and-aaa/m-p/778418#M409036</guid>
      <dc:creator>Dev Vishwakarma</dc:creator>
      <dc:date>2007-09-05T21:52:08Z</dc:date>
    </item>
    <item>
      <title>Re: SNMP and AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/snmp-and-aaa/m-p/778419#M409037</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please mark it resolved so other can benefit from it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;-dev&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Sep 2007 12:44:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/snmp-and-aaa/m-p/778419#M409037</guid>
      <dc:creator>Dev Vishwakarma</dc:creator>
      <dc:date>2007-09-19T12:44:41Z</dc:date>
    </item>
  </channel>
</rss>

