Configuration notes

When using the snAgGblPassword object in a Set operation, the following must be considered:

The device always insist on a password to be part of snAgGblPassword object. You can override this requirement by entering the no snmp-server pw-check command.

By default, the object uses the value of the enable super-user password configured on the device as the default password. To allow a device to use other authentication schemes, use the aaa authen snmp-server default enable | local | none command.

The enable option instructs the device to use the configured enable super-user password. If the enable super-user password is missing, then the device checks for the if implicit TACACS+ enable password. The device stores a previous (unrelated to SNMP) implicit enable operation result and remembers the enable password that was approved by TACACS+. You can enter the following command to use this method.

SnmpSet(snAgGblPassword.0="<enable-password>", snAgEraseNVRAM.0=3) 

The local option instructs the device to use a configured local username and password value. You can enter the following SNMP command to use this method.

SnmpSet(snAgGblPassword.0="<username> <password>", snAgEraseNVRAM.0=3) 

The none option instructs the device to ignore the value of snAgGblPassword and the authentication check will always pass. You can enter the following SNMP command to use this method.

SnmpSet(snAgGblPassword.0="<anything here>", snAgEraseNVRAM.0=3)
aaa authentication login default TACACS+ 
aaa authentication enable default TACACS+ 
aaa authentication enable implicit-user 

The snAgGblPassword object must be set for the following objects:

  • snAgCfgLoad
  • snAgImgLoad
  • snAgConfigFromNVRAM
  • snAgEraseNVRAM
  • snAgWriteNVRAM
  • snAgGblTelnetPassword
  • snAgReload
  • snAgSystemLog