Configuring SNMPv3 on RUCKUS Devices

You can create SNMPv3 groups and configure the SNMPv3 users.
  1. Enter global configuration mode.
    device# configure terminal
  2. Change the default engine ID using the snmp-server engineid local command.
    device(config)# snmp-server engineid local 800007c70300e05290ab60
    A default engine ID is generated during system startup. Use the show snmp engineid command to view the default engine ID.
  3. Define an SNMP group using the snmp-server group command.
    device(config)# snmp-server group admin v3 auth read all write all

    SNMP groups map SNMP users to SNMP views. For each SNMP group, you can configure a read view, a write view, or both. Users who are mapped to a group will use its views for access control. The default view is "all", providing access to the entire MIB; however, it must be specified when creating the SNMP group. For more information, refer to "SNMPv3 Configuration Examples".

    In the example, an SNMPv3 group named "admin" is created with read and write access.

  4. Define an SNMP user using the snmp-server user command.
    device(config)# snmp-server user bob admin v3 auth md5 bobmd5 priv des bobdes
    In the example, an SNMPv3 user named "bob" is configured to be associated with the SNMPv3 group "admin". Here we use the MD5 type of authentication to access SNMP and DES encryption to encrypt the privacy password.
    device(config)# snmp-server user admin grpadmin v3 auth sha224 test123 priv aes test12345

    In the example, an SNMPv3 user named "user" is configured to be associated with the SNMPv3 group "grpadmin". Here we use the sha224 type of authentication to configure the HMAC SHA224 algorithm for authentication.

    Refer to RUCKUS FastIron Command Reference for more authentication methods.

    Note: The SNMP group to which the user account will be mapped should be configured before creating the user accounts; otherwise, the group will be created without any views.

The following example shows how to configure SNMPv3 on RUCKUS devices. The SNMP group and SNMP user are configured.

device# configure terminal
device(config)# snmp-server engineid local 800007c70300e05290ab60
device(config)# snmp-server group admin v3 auth read all write all
device(config)# snmp-server user bob admin v3 auth md5 bobmd5 priv des bobdes

To use the no form of the command, you must know and enter the password as part of the command syntax. If you have forgotten or lost the password, you can copy all the encrypted string that hides the password from the output of the show running-config command using the encrypted keyword into the no snmp-server command instead.

device(config)# show running-config | include snmp-server
aaa authentication snmp-server default local
snmp-server user user1 admin v3 encrypted auth md5 7c545376563546dhg67236732463 priv encrypted des 2736237hgfhe365635bvdf

device(config)# no snmp-server user user1 admin v3 auth md5
Incomplete command.

device(config)# no snmp-server user user1 admin v3 encrypted auth md5 7c545376563546dhg67236732463 priv encrypted des 2736237hgfhe365635bvdf
device(config)# show running-config | include snmp-server
aaa authentication snmp-server default local