Configure SNMPv3 Users

Use this procedure to add, modify, or delete SNMPv3 users.
  1. Choose from the following actions:
    • Go to Sites and select a site to configure SNMPv3 users for the switches associated with the site. Then, select the Advanced tab.
    • Go to Administration > System > Settings > SNMP to configure SNMPv3 users for the full ExtremeCloud IQ Controller environment.
  2. From the SNMP field drop-down list, select SNMPv3.
    If any SNMPv3 users have been configured, they appear in the SNMPv3 Users table. The parameters related to SNMPv3 configuration differ if you are configuring settings from the Sites workbench versus the Administration workbench. If you are configuring from the Sites workbench, proceed to the next step. If you are configuring from the Administration workbench, set or modify the parameters described in SNMPv3 Parameters – Administration Workbench, then proceed to the next step.
    Table 1. SNMPv3 Parameters – Administration Workbench
    ParameterDescription
    Context StringA description of the SNMP context. An SNMP context is information that you can access through the SNMP agent. A device can support multiple contexts.
    Engine IDThe SNMPv3 engine ID for the appliance running the SNMP agent. The Engine ID must be from 5 to 32 characters long.
  3. Choose from the following actions:
    • To delete an existing SNMPv3 user, select the user in the list, then select Delete.
    • To configure a new SNMPv3 user, select Add. The Create User window opens. Proceed to the next step.
    • To modify the settings for an existing SNMPv3 user, select the user in the list, then select Edit. The Edit User window opens. Modify settings in accordance with the instructions in this procedure.
  4. Configure or edit SNMPv3 Users parameters as described in SNMPv3 Users Parameters.
    Table 2. SNMPv3 Users Parameters
    ParameterDescription
    SecuritySelect a security type from the drop-down list. Options are:
    • No Authentication / No Privacy

    • Authentication / No Privacy

    • Authentication / Privacy

    Note: The other parameters described in this table appear only if you selected Authentication/No Privacy or Authentication/Privacy.
    Authentication/No Privacy or Authentication/Privacy
    Auth TypeSelect an authentication type from drop-down list. Options are:
    • MD5 — generates a 128-bit (16-byte) hash value from any given input

    • SHA — generates a 160-bit (20-byte) hash value from any given input

    • SHA224 — generates a 224-bit (112-byte) hash value from any given input

    • SHA256 — generates a 256-bit (32-byte) hash value from any given input

    • SHA384 — generates a 384-bit (48-byte) hash value from any given input

    • SHA512 — generates a 224-bit (64-byte) hash value from any given input

    Auth PasswordEnter a password to be used to enable authentication. The password consists of 8 to 32 alphanumeric and special characters. Valid special characters include: ~!@#$%^&*()-=_+[]{}|:";'<>?,./~
    Confirm PasswordConfirm the password to be used to enable authentication.
    MaskBy default, the password is masked. Clear the check box to unmask the password.
    Authentication/Privacy
    Privacy TypeSelect a privacy type from drop-down list. Options are:
    • AES — encrypts data in fixed-size blocks, typically 128 bits. Uses the same key for both encryption and decryption (sender and receiver must use the same secret key). Supports cryptographic keys of 128, 192, and 256 bits, with 256-bit being the most secure.

    • DES — encrypts data in fixed-size, 64-bit blocks. Uses the same key for both encryption and decryption (sender and receiver must use the same secret key). Supports cryptographic keys of 56 bits.

    • AES192 — encrypts data in fixed-size, 128-bit blocks. Uses the same key for both encryption and decryption (sender and receiver must use the same secret key). Supports cryptographic keys of 192 bits.

    • AES256 — encrypts data in fixed-size, 128-bit blocks. Uses the same key for both encryption and decryption (sender and receiver must use the same secret key). Supports cryptographic keys of 256 bits.

    Privacy PasswordEnter a password to be used to enable privacy authentication. For DES encryption, the password consists of 8 to 24 alphanumeric and special characters. For all other encryption options, the password consists of 16 to 32 alphanumeric and special characters. Valid special characters include: ~!@#$%^&*()-=_+[]{}|:";'<>?,./~
    Confirm PasswordConfirm the password to be used to enable privacy authentication.
    MaskBy default, the password is masked. Clear the check box to unmask the password.
  5. Configure SNMP Notifications and Forward Traps as described in Configure SNMP Notifications and Traps.
  6. Select Save to save settings.