User-based Security Model

SNMP version 3 (SNMPv3) (RFC 2570 through 2575) introduces a User-based Security model (USM) (RFC 2574) for authentication and privacy services.

SNMP version 1 and version 2 use community strings to authenticate SNMP access to management modules. This method can still be used for authentication. In SNMPv3, the User-based Security Model can be used to secure against the following threats:

  • Modification of information
  • Masquerading the identity of an authorized entity
  • Message stream modification
  • Disclosure of information

SNMPv3 also supports the View-based Access Control Mechanism (VACM) (RFC 2575) to control access at the PDU level. It defines mechanisms for determining whether access to a managed object in a local MIB by a remote principal should be allowed. For more information, refer to SNMPv3 Configuration Examples.