SNMP

In the FIPS mode of operation, the device uses the existing SNMP configuration. However, MIB objects related to keys and passwords output NULL or a 0 value.

SNMP allows peer-to-peer authentication or client-to-server authentication. To authorize an authentication, use commands such as the following to configure shared secret keys for SNMP:

device(config)# snmp-server group admingrp v3 priv read all write all notify all

Syntax: [no] snmp-server group groupname { v3 auth | noauth | priv [access standard-ACL-id ] [ read viewstring | write viewstring | notify viewstring ] }

device(config)# snmp-server user adminuser admingrp v3 encrypted auth md5
c1c510d4f3c6bec15ff14f9c0f3ec120 priv encrypted aes
b0c4c6c05cded8cfe3a335299347c71b

Syntax: [no] snmp-server user name groupname v3 [ [access standard-ACL-id[ [ encrypted ] [ auth | sha sha-password] [priv [encrypted ] aes aes-password-key ] ] ] ]

SNMP CSP objects

The following SNMP MIB objects represent the critical security parameter (CSP) entities that are restricted in FIPS mode.

Enterprise MIB objects:

  • snRadiusKey
  • snRadiusServerRowKey
  • snVrrpIfAuthPassword
  • snAgGblPassword
  • snAgGblReadOnlyCommunity
  • snAgGblReadWriteCommunity
  • snAgGblTelnetPassword
  • snAgentUserAccntPassword
  • fdryRadiusServerRowKey
  • snOspfIfAuthKey
  • snOspfIfMd5AuthKey
  • snOspfIf2AuthKey
  • snOspfIf2Md5authKey
  • snOspfVirtIfAuthKey
  • snOspfVirtIfMd5AuthKey
  • snOspfIfStatusAuthKey
  • snOspfIfStatusMd5AuthKey
  • snOspfVirtIfStatusAuthKey
  • snOspfVirtIfStatusMd5AuthKey
  • snBgp4NeighGenCfgPass
  • snVrrpIf2AuthPassword
  • snVsrpIfAuthPassword

Standard MIB objects:

  • rip2IfConfAuthKey
  • vrrpOperAuthKey
  • dvmrpInterfaceKey