snmp-server user

Creates or changes the attributes of SNMPv3 users, and allows an SNMPv3 user to be associated with the user-defined group name.
Syntax
snmp-server user user-name group-name v3 [ auth { md5 | sha | sha512 | sha384 | sha256 | sha224 } auth-password [ priv { aes | des } password-string ] ]
no snmp-server user user-name group-name v3 [ auth { md5 | sha | sha512 | sha384 | sha256 | sha224 } auth-password [ priv { aes | des } password-string ] ]
Command Default

SNMP users are not configured.

Parameters
user-name
Specifies the SNMP username or security name used to access the management module.
group-name
Identifies the SNMP group to which this user is associated or mapped.
v3
Configures the group using the User Security Model (SNMPv3).
encrypted
Specifies the encrypted string that hides the password.
auth
Specifies the type of encryption the user must have to be authenticated.
md5
Configures the HMAC MD5 algorithm for authentication.
sha
Configures the HMAC SHA algorithm for authentication.
sha512
Configures the HMAC SHA512 algorithm for authentication.
sha384
Configures the HMAC SHA384 algorithm for authentication.
sha256
Configures the HMAC SHA256 algorithm for authentication.
sha224
Configures the HMAC SHA224 algorithm for authentication.
auth-password
Specifies the authorization password for the user (8 through 16 characters for MD5; 8 through 20 characters for SHA).
priv
Configures the encryption type (DES or AES) used to encrypt the privacy password.
aes
Configures CFB128-AES-128 encryption for privacy.
des
Configures CBC56-DES encryption for privacy.
password-string
Specifies the DES or AES password string for SNMPv3 encryption for the user. The password must have a minimum of 8 characters.
Modes

Global configuration mode

Usage Guidelines

The snmp-server user command creates an SNMP user, defines the group to which the user will be associated, defines the type of authentication to be used for SNMP access by this user, specifies either the AES or DES encryption types used to encrypt the privacy password.

All users must be mapped to an SNMP group. Groups are defined using the snmp-server group command.

Note: The SNMP group to which the user account will be mapped should be configured before creating the user accounts; otherwise, the group will be created without any views.

The priv parameter specifies the encryption type (DES or AES) used to encrypt the privacy password. If the encrypted keyword is used, do the following:

  • If DES is the privacy protocol to be used, enter des followed by a 16-octet DES key in hexadecimal format for the DES-password-key . If you include the encrypted keyword, enter a password string of at least 8 characters.
  • If AES is the privacy protocol to be used, enter aes followed by the AES password key. For a small password key, enter 12 characters. For a big password key, enter 16 characters.

Examples

The following examples configures an SNMP user account.

device(config)# snmp-server user user1 admin v3 auth md5 abc123 priv des xyz123
device(config)# snmp-server user admin grpadmin v3 auth sha224 test123 priv aes test12345
Usage Guidelines

The no form of the command removes the SNMP access. To use the no form of the command, you must know and enter the password as part of the command syntax. If you have forgotten or lost the password, you can copy all the encrypted string that hides the password from the output of the show running-config command using the encrypted keyword into the no snmp-server command instead.

The following examples removes the SNMP user access.

device(config)# show running-config | include snmp-server
aaa authentication snmp-server default local
snmp-server user user1 admin v3 encrypted auth md5 7c545376563546dhg67236732463 priv encrypted des 2736237hgfhe365635bvdf

device(config)# no snmp-server user user1 admin v3 auth md5
Incomplete command.

device(config)# no snmp-server user user1 admin v3 encrypted auth md5 7c545376563546dhg67236732463 priv encrypted des 2736237hgfhe365635bvdf
device(config)# show running-config | include snmp-server
aaa authentication snmp-server default local
History
Release version Command history
09.0.10e The command was modified to remove the ACL options.
10.0.10c The command was modified to include the new keywords.