<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SNMP v3 encryption and authentication in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/snmp-v3-encryption-and-authentication/m-p/4732534#M1095633</link>
    <description>&lt;P&gt;You can always choose both the hash and encryption algorithms with snmpv3.&lt;/P&gt;
&lt;P&gt;The "encrypted" keyword means you are providing the snmp password already encrypted (an uncommon use case). As &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1342399"&gt;@tvotna&lt;/a&gt; noted, the snmpv3 password will be saved in secure form automatically (no matter how you provide it initially).&lt;/P&gt;</description>
    <pubDate>Mon, 05 Dec 2022 12:41:22 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2022-12-05T12:41:22Z</dc:date>
    <item>
      <title>SNMP v3 encryption and authentication</title>
      <link>https://community.cisco.com/t5/network-security/snmp-v3-encryption-and-authentication/m-p/4732446#M1095627</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I'm trying to understand the configurations of SNMP v3. From Cisco's "Software Configuration Guide" &amp;gt; Configuring Simple Network Management Protocol &amp;gt; Configuring SNMP Groups and Users, Step 5, in Purpose column:&lt;/P&gt;&lt;P class=""&gt;"&lt;EM&gt;Enter the SNMP version number (&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;v1&lt;/SPAN&gt; &lt;/SPAN&gt;, &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;v2c&lt;/SPAN&gt; &lt;/SPAN&gt;, or &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;v3&lt;/SPAN&gt; &lt;/SPAN&gt;). If you enter &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;v3&lt;/SPAN&gt; &lt;/SPAN&gt;, you have these additional options:&lt;/EM&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P class=""&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;encrypted&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/STRONG&gt;specifies that the password appears in encrypted format. This keyword is available only when the &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;v3&lt;/SPAN&gt; &lt;/SPAN&gt;keyword is specified.&lt;/EM&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;auth&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/STRONG&gt;is an authentication level setting session that can be either the HMAC-MD5-96 (&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;md5&lt;/SPAN&gt; &lt;/SPAN&gt;) or the HMAC-SHA-96 (&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;sha&lt;/SPAN&gt; &lt;/SPAN&gt;) authentication level and requires a password string &lt;SPAN class=""&gt;auth-password &lt;/SPAN&gt;(not to exceed 64 characters).&lt;/EM&gt;"&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;First observation is that the &lt;STRONG&gt;encrypted&lt;/STRONG&gt; parameter will encrypt the password, while the &lt;STRONG&gt;auth&lt;/STRONG&gt; parameter will hash the password.&lt;/P&gt;&lt;P&gt;If i write &lt;STRONG&gt;encrypted&lt;/STRONG&gt; i cannot choose which encryption algorithm is used. The only two choices i have is &lt;STRONG&gt;access&lt;/STRONG&gt; to specify an access list and &lt;STRONG&gt;auth&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tranem_1-1670236476533.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/169889i75706CD8D6CD56A3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="tranem_1-1670236476533.png" alt="tranem_1-1670236476533.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the other hand, if i write &lt;STRONG&gt;auth &lt;/STRONG&gt;as my first parameter, i can choose the authentication (hashing) algorithm as &lt;STRONG&gt;md5&lt;/STRONG&gt; or &lt;STRONG&gt;sha&lt;/STRONG&gt;. My next two parameters are &lt;STRONG&gt;access&lt;/STRONG&gt; again, and &lt;STRONG&gt;priv&lt;/STRONG&gt; which lets me choose my encryption algorithm.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tranem_0-1670236446486.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/169888iCF525689FD5F4F76/image-size/medium?v=v2&amp;amp;px=400" role="button" title="tranem_0-1670236446486.png" alt="tranem_0-1670236446486.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Am i totally misunderstanding something or does this mean that you can only specify which encryption algorithm you want to use, if you also choose to hash it? And if you choose to hash it, you can always choose the authentication algorithm?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2022 10:36:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-v3-encryption-and-authentication/m-p/4732446#M1095627</guid>
      <dc:creator>trane.m</dc:creator>
      <dc:date>2022-12-05T10:36:55Z</dc:date>
    </item>
    <item>
      <title>Re: SNMP v3 encryption and authentication</title>
      <link>https://community.cisco.com/t5/network-security/snmp-v3-encryption-and-authentication/m-p/4732457#M1095628</link>
      <description>&lt;P&gt;Don't put "encrypted" into the command line. The system will add it automatically into the running-config to hash auth and priv passwords you entered. So, just do snmp-server user &amp;lt;user&amp;gt; &amp;lt;group&amp;gt; v3 auth sha &amp;lt;auth-password&amp;gt; priv aes 128 &amp;lt;encr-password&amp;gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2022 11:00:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-v3-encryption-and-authentication/m-p/4732457#M1095628</guid>
      <dc:creator>tvotna</dc:creator>
      <dc:date>2022-12-05T11:00:02Z</dc:date>
    </item>
    <item>
      <title>Re: SNMP v3 encryption and authentication</title>
      <link>https://community.cisco.com/t5/network-security/snmp-v3-encryption-and-authentication/m-p/4732534#M1095633</link>
      <description>&lt;P&gt;You can always choose both the hash and encryption algorithms with snmpv3.&lt;/P&gt;
&lt;P&gt;The "encrypted" keyword means you are providing the snmp password already encrypted (an uncommon use case). As &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1342399"&gt;@tvotna&lt;/a&gt; noted, the snmpv3 password will be saved in secure form automatically (no matter how you provide it initially).&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2022 12:41:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-v3-encryption-and-authentication/m-p/4732534#M1095633</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-12-05T12:41:22Z</dc:date>
    </item>
  </channel>
</rss>

