09-17-2014 11:59 AM - edited 02-21-2020 05:17 AM
Under LMS 4.0.1 when I look at devices under credential settings for devices SHA1 is only available. Is there an add-on that needs to be installed to support SHA 256?
09-17-2014 08:31 PM
Where exactly do you see the SHA settings in LMS?
I can only recall using that setting on the IOS devices themselves when specifying the integrity type for IPsec VPNs or the enable secret password encryption (type 4 - implementation flawed and thus not recommended).
You can of course create cli templates and compliance checks in LMS that use those options.
09-18-2014 08:11 AM
Under the "Inventory" tab Add/Import/Manage devices. When I select a switch to edit under credential settings the drop down box for SNMPV3 settings only has MD5 and SHA1 options available.
09-18-2014 08:46 AM
That's because the only SNMP v3 authentication algorithms supported (on either IOS or NX-OS or ASA software) are MD5 and SHA1.
The SNMP v3 encryption algorithms support up to AES-256 (on NX-OS and IOS) and that is selectable in the SNMPv3 credentials settings on LMS.
That applies even on the latest updated Prime LMS Version 4.2(5).
09-18-2014 10:07 AM
Marvin,
Thank you for the insightful information. Initially searching the web and LMS documentation didn't seem to provide any direct answers to this question.
Doug
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide