snmp-server user

Creates or changes the attributes of SNMPv3 users, and allows an SNMPv3 user to be associated with the user-defined group name.
Syntax
snmp-server user user-name group-name v3 [ access acl-num ] [ auth { md5 | sha } auth-password [ priv { aes | des } password-string ] ]
no snmp-server user user-name group-name v3 [ access acl-num ] [ auth { md5 | sha } auth-password [ priv { aes | des } password-string ] ]
Command Default

SNMP users are not configured.

Parameters
user-name
Specifies the SNMP username or security name used to access the management module.
group-name
Identifies the SNMP group to which this user is associated or mapped.
v3
Configures the group using the User Security Model (SNMPv3).
access
Specifies the access list associated with the user.
acl-num
Standard IP access list number allowing access. The valid values are from 1 through 99.
auth
Specifies the type of encryption the user must have to be authenticated.
md5
Configures the HMAC MD5 algorithm for authentication.
sha
Configures the HMAC SHA algorithm for authentication.
auth-password
Specifies the authorization password for the user (8 through 16 characters for MD5; 8 through 20 characters for SHA).
priv
Configures the encryption type (DES or AES) used to encrypt the privacy password.
aes
Configures CFB128-AES-128 encryption for privacy.
des
Configures CBC56-DES encryption for privacy.
password-string
Specifies the DES or AES password string for SNMPv3 encryption for the user. The password must have a minimum of 8 characters.
Modes

Global configuration mode

Usage Guidelines

The snmp-server user command creates an SNMP user, defines the group to which the user will be associated, defines the type of authentication to be used for SNMP access by this user, specifies either the AES or DES encryption types used to encrypt the privacy password.

All users must be mapped to an SNMP group. Groups are defined using the snmp-server group command.

Note: The SNMP group to which the user account will be mapped should be configured before creating the user accounts; otherwise, the group will be created without any views. Also, ACL groups must be configured before configuring user accounts.
Note: The ACL specified in a user account overrides the ACL assigned to the group to which the user is mapped. If no ACL is entered for the user account, then the ACL configured for the group will be used to filter packets.

The priv parameter specifies the encryption type (DES or AES) used to encrypt the privacy password. If the encrypted keyword is used, do the following:

  • If DES is the privacy protocol to be used, enter des followed by a 16-octet DES key in hexadecimal format for the DES-password-key . If you include the encrypted keyword, enter a password string of at least 8 characters.
  • If AES is the privacy protocol to be used, enter aes followed by the AES password key. For a small password key, enter 12 characters. For a big password key, enter 16 characters.

The no form of the command removes the SNMP access.

Examples

The following example configures an SNMP user account.

device(config)# snmp-server user user1 admin v3 access 2 auth md5 abc123 priv des xyz123