H3C Technologies H3C WX3000 Series Unified Switches User Manual

Page 412

Advertising
background image

41-8

# Set the access right of the NMS to the MIB of the SNMP agent.

[device] snmp-agent mib-view include internet 1.3.6.1

# For SNMPv3, set:

z

SNMPv3 group and user

z

security to the level of needing authentication and encryption

z

authentication protocol to HMAC-MD5

z

authentication password to passmd5

z

encryption protocol to AES

z

encryption password to cfb128cfb128

[device] snmp-agent group v3 managev3group privacy write-view internet

[device] snmp-agent usm-user v3 managev3user managev3group authentication-mode md5 passmd5

privacy-mode aes128 cfb128cfb128

# Set the VLAN-interface 2 as the interface used by NMS. Add port GigabitEthernet 1/0/2, which is to be
used for network management, to VLAN 2. Set the IP address of VLAN-interface 2 as 10.10.10.2.

[device] vlan 2

[device-vlan2] port Ethernet 1/0/2

[device-vlan2] quit

[device] interface Vlan-interface 2

[device-Vlan-interface2] ip address 10.10.10.2 255.255.255.0

[device-Vlan-interface2] quit

# Enable the SNMP agent to send Trap messages to the NMS whose IP address is 10.10.10.1. The
SNMP community name to be used is “public”.

[device] snmp-agent trap enable standard authentication

[device] snmp-agent trap enable standard coldstart

[device] snmp-agent trap enable standard linkup

[device] snmp-agent trap enable standard linkdown

[device] snmp-agent target-host trap address udp-domain 10.10.10.1 udp-port 5000 params

securityname public

Configuring the NMS

The device supports iMC NMS. SNMPv3 adopts user name and password authentication. When you
use the iMC, you need to set user names and choose the security level in. For each security level, you
need to set authorization mode, authorization password, encryption mode, encryption password, and
so on. In addition, you need to set timeout time and maximum retry times.

You can query and configure the device through the NMS. For more information, refer to the
corresponding manuals of network management products.

Authentication-related configuration on the NMS must be consistent with that of the devices for the
NMS to manage the devices successfully.

Advertising