cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
17969
Views
15
Helpful
6
Replies

configuring for SNMP V3 on cisco switches C3560

WIN PHYO AUNG
Level 1
Level 1

Hi,

We are currently using SNMP as below config.

What is the current SNMP version enable. I understand that if no "version" command, default is version1. Is it?

And we are planning to migrate to V3.

What need to be configured on our switches to work with version?

What information should i check with our monitoring server team?

Can we configure to add in without affecting existing monitoring ?

#####################################

Existing

snmp-server community STRING RO

snmp-server trap-source Vlan150

snmp-server source-interface informs Vlan150

snmp-server enable traps snmp authentication linkdown linkup coldstart warmstart

snmp-server enable traps tty

snmp-server enable traps cluster

snmp-server enable traps entity

snmp-server enable traps cpu threshold

snmp-server enable traps power-ethernet group 1

snmp-server enable traps vtp

snmp-server enable traps vlancreate

snmp-server enable traps vlandelete

snmp-server enable traps flash insertion removal

snmp-server enable traps port-security

snmp-server enable traps envmon fan shutdown supply temperature status

snmp-server enable traps config-copy

snmp-server enable traps config

snmp-server enable traps hsrp

snmp-server enable traps bridge newroot topologychange

snmp-server enable traps stpx inconsistency root-inconsistency loop-inconsistenc                                                                                        y

snmp-server enable traps syslog

snmp-server enable traps rtr

snmp-server enable traps mac-notification change move threshold

snmp-server enable traps vlan-membership

snmp-server host x.x.x.x STRING

snmp-server host x.x.x.x STRING

snmp-server host x.x.x.x STRING

##########################################

1 Accepted Solution

Accepted Solutions

AFROJ AHMAD
Cisco Employee
Cisco Employee

Hi ,

What is the current SNMP version enable. I understand that if no "version" command, default is version1. Is it?

Ans: currently , you are using SNMPv2c .

snmp-server host x.x.x.x STRING  >> If you don't specify anything in this command then only SNMP v1 traps will be sent. In this same command you can specify the type of traps you want to recive.

for e.g:

WL-6500(config)#snmp-server host 11.1.1.1 version ?

  1   Use SNMPv1

  2c  Use SNMPv2c

  3   Use SNMPv3

What need to be configured on our switches to work with version? 

Attached is the SAMPLE SNMPV3 configuration :

What information should i check with our monitoring server team?

you need to add the device or eidt the device with SNMPV3 credentials on the monitoring tool.

Can we configure to add in without affecting existing monitoring ?

Yes.

Thanks-

Afroz

[Do rate the useful post]

Thanks- Afroz [Do rate the useful post] ****Ratings Encourages Contributors ****

View solution in original post

6 Replies 6

AFROJ AHMAD
Cisco Employee
Cisco Employee

Hi ,

What is the current SNMP version enable. I understand that if no "version" command, default is version1. Is it?

Ans: currently , you are using SNMPv2c .

snmp-server host x.x.x.x STRING  >> If you don't specify anything in this command then only SNMP v1 traps will be sent. In this same command you can specify the type of traps you want to recive.

for e.g:

WL-6500(config)#snmp-server host 11.1.1.1 version ?

  1   Use SNMPv1

  2c  Use SNMPv2c

  3   Use SNMPv3

What need to be configured on our switches to work with version? 

Attached is the SAMPLE SNMPV3 configuration :

What information should i check with our monitoring server team?

you need to add the device or eidt the device with SNMPV3 credentials on the monitoring tool.

Can we configure to add in without affecting existing monitoring ?

Yes.

Thanks-

Afroz

[Do rate the useful post]

Thanks- Afroz [Do rate the useful post] ****Ratings Encourages Contributors ****

Hi Afroz,

Thanks for the sharing.

I think in the attach steps, you are using local user account, is it? For remote users, we need to define remote Engine ID?

I am confused with view, is "iso" the standard MIB view?

Thanks

Win

Hi ,

I think in the attach steps, you are using local user account, is it?  Yes

For remote users, we need to define remote Engine ID? Yes , you are correct.

I am confused with view, is "iso" the standard MIB view?  yes ISO is the TOP in the hierarchy of the MIBS

Thanks-

Afroz

[Do rate the useful post]

Thanks- Afroz [Do rate the useful post] ****Ratings Encourages Contributors ****

Hi

Afroz,

Thank you for the replay. It really helped.

Thanks

Win

that's  great..

Kindly resolved the thread \ rate the post

Thanks-

Thanks- Afroz [Do rate the useful post] ****Ratings Encourages Contributors ****

CiscOptimist
Level 1
Level 1

You can find a step-by-step guide on how to configure SNMP v3 on any Cisco device, including IOS based ones like C3560:

https://bestmonitoringtools.com/configure-snmpv3-on-cisco-router-switch-asa-nexus-a-step-by-step-guide/

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: