Adding an SNMP Community String

A community string is encrypted by default. You can assign an SNMP community string and indicate whether the string is encrypted.
When encryption is enabled, the community string is encrypted in the CLI regardless of the access level you are using. In the Web Management Interface, the community string is encrypted at the read-only access level. but is visible at the read-write access level.
  1. Enter global configuration mode.
    device# configure terminal
  2. Add an encrypted community string and save the configuration.
    device(config)# snmp-server community private
    device(config)# write memory
    In the example, you must enter the community string "private" to gain SNMP access.
  3. Configure the access privileges for the community string from one of the following options:
    • Read-only (ro) access
    • Read-write (rw) access
    device(config)# snmp-server community private ro
    device(config)# snmp-server community private rw
  4. Set the encryption option for the community string from one of following options:
    • 0: Disables encryption for the community string you specify with the command. The community string is shown as clear text in the running-config and the startup-config files. Use this option if you do not want the display of the community string to be encrypted.
    • 1: Assumes that the community string you enter is encrypted, and decrypts the value before using it.
    device(config)# snmp-server community 0 private rw
    device(config)# write memory
    In the example, the community string "private" is added in the clear, which means that the string is displayed in the clear.
  5. (Optional) Associate a view to the members of the community string.
    device(config)# snmp-server community private ro view sysview
    The view that you want must exist before you can associate it to a community string. In the example, the "sysview" view is associated to the community string "private" and the community string has read-only access to "sysview". If no view is specified, access to the full MIB is granted.
  6. (Optional) Specify the ACL group to filter incoming SNMP packets.
    device(config)# snmp-server community myread ro view sysview 2
    device(config)# snmp-server community myread ro view sysview myACL
    You can enter either the ACL name or its ID. In the first example, ACL group "2" filters incoming SNMP packets. In the second example, ACL group "myACL" filters incoming packets.
    Note: To make configuration changes, including changes involving SNMP community strings, you must first configure a read-write community string using the CLI. Alternatively, you must configure another authentication method and log in to the CLI using a valid password for that method.

The following example shows how to configure an SNMP community string.

device# configure terminal
device(config)# snmp-server community private
device(config)# snmp-server community private ro
device(config)# snmp-server community 0 private ro
device(config)# write memory
device(config)# snmp-s community myread ro view sysview myACL