Configuring SNMPv3 on RUCKUS Devices
- Enter global configuration mode.
- Change the default engine ID
using the
snmp-server engineid localcommand. - Define an SNMP group using the
snmp-server groupcommand.SNMP groups map SNMP users to SNMP views. For each SNMP group, you can configure a read view, a write view, or both. Users who are mapped to a group will use its views for access control. The default view is "all", providing access to the entire MIB; however, it must be specified when creating the SNMP group. For more information, refer to "SNMPv3 Configuration Examples".
In the example, an SNMPv3 group named "admin" is created with read and write access.
- Define an SNMP user using the
snmp-server usercommand.In the example, an SNMPv3 user named "bob" is configured to be associated with the SNMPv3 group "admin". Here "2" specifies the access list associated with the user with MD5 type of authentication to access SNMP and DES encryption to encrypt the privacy password.Note: The SNMP group to which the user account will be mapped should be configured before creating the user accounts; otherwise, the group will be created without any views. Also, the ACL groups must be configured before configuring user accounts.
The following example shows how to configure SNMPv3 on RUCKUS devices. The SNMP group and SNMP user are configured.
device# configure terminal device(config)# snmp-server engineid local 800007c70300e05290ab60 device(config)# snmp-server group admin v3 auth read all write all device(config)# snmp-server user bob admin v3 access 2 auth md5 bobmd5 priv des bobdes