<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What SHA ciphers are used for network device SNMP? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/what-sha-ciphers-are-used-for-network-device-snmp/m-p/4735240#M578737</link>
    <description>&lt;P&gt;Great answer!&lt;/P&gt;&lt;P&gt;Have been looking at updating our priv &amp;amp; auth options.&lt;/P&gt;</description>
    <pubDate>Fri, 09 Dec 2022 01:23:06 GMT</pubDate>
    <dc:creator>Mark Potter</dc:creator>
    <dc:date>2022-12-09T01:23:06Z</dc:date>
    <item>
      <title>What SHA ciphers are used for network device SNMP?</title>
      <link>https://community.cisco.com/t5/network-access-control/what-sha-ciphers-are-used-for-network-device-snmp/m-p/4504557#M571116</link>
      <description>&lt;P&gt;I want to disabled SHA1 Ciphers on ISE, but I have configured SNMP for multiple switches for SNMP CoA, the SNMP authentication protocol is set to SHA, will SNMP CoA fail then? I am worried about the impact for this, I am not sure if SHA1 will be used or not,&lt;/P&gt;</description>
      <pubDate>Wed, 17 Nov 2021 23:48:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/what-sha-ciphers-are-used-for-network-device-snmp/m-p/4504557#M571116</guid>
      <dc:creator>SMD28316</dc:creator>
      <dc:date>2021-11-17T23:48:31Z</dc:date>
    </item>
    <item>
      <title>Re: What SHA ciphers are used for network device SNMP?</title>
      <link>https://community.cisco.com/t5/network-access-control/what-sha-ciphers-are-used-for-network-device-snmp/m-p/4507459#M571204</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1171789"&gt;@SMD28316&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Using ISE 3.0 and snmpwalk, I tested and the SNMPv3 agent in ISE still responds even if you disabled SHA1 in the GUI. It seems that this SHA1 disabling has nothing to do with the SNMP agent in ISE.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Net-SNMP command below allows you to test with SHA1 (which is what I am using) and also SHA-256 etc - I tested them all - only SHA1 works with ISE.&lt;/P&gt;
&lt;PRE&gt;snmpwalk -v 3 -x AES -u arne -X cisco123123 -a SHA -A cisco123123 172.16.0.10 -l authPriv&lt;/PRE&gt;
&lt;PRE&gt;CiscoISE/admin# &lt;STRONG&gt;show snmp-server user&lt;/STRONG&gt;
User: arne
  EngineID: 9HMXXXXXXE7M
  Auth Protocol: sha
  Priv Protocol: aes-128
&lt;/PRE&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISE-SNMPv3.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/137846i0FD485EEA15C09FB/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISE-SNMPv3.png" alt="ISE-SNMPv3.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Nov 2021 23:59:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/what-sha-ciphers-are-used-for-network-device-snmp/m-p/4507459#M571204</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2021-11-23T23:59:36Z</dc:date>
    </item>
    <item>
      <title>Re: What SHA ciphers are used for network device SNMP?</title>
      <link>https://community.cisco.com/t5/network-access-control/what-sha-ciphers-are-used-for-network-device-snmp/m-p/4735240#M578737</link>
      <description>&lt;P&gt;Great answer!&lt;/P&gt;&lt;P&gt;Have been looking at updating our priv &amp;amp; auth options.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2022 01:23:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/what-sha-ciphers-are-used-for-network-device-snmp/m-p/4735240#M578737</guid>
      <dc:creator>Mark Potter</dc:creator>
      <dc:date>2022-12-09T01:23:06Z</dc:date>
    </item>
  </channel>
</rss>

