RE: access control

"Mike Ayers" <[email protected]>
Newsgroups gmane.network.net-snmp.user
Message-ID <83E753BE7B6A324ABB336245BAF1DAAC07FDA171@mailserver.metatv-ds.metatv.com>
> From: [email protected] 
> [mailto:[email protected]] On 
> Behalf Of Masoud Fatollahy
> Sent: Thursday, February 21, 2008 8:24 AM

> com2sec cust1_sec 192.168.55.0/24  public
> com2sec cust2_sec 192.168.56.0/24  public

	Note that the community "public" will now have acces to both cust1_sec rights and cust2_sec rights, so customers 1 and 2 can see each other's data.  Probably not what you want if you went to the trouble to specify them individually.

> view all    included  .1

	If myuser is not the system administrator, then you should at least remove the VACM, USM, and coexistence MIBs from the view.

> view cust1_v included  .1.3.6.1.2.1.2.2.1.1.1 ff.a0

	I'd suggest not writing no-effect masks.  That's just a maintenance hazard.  The line:

view cust1_v included  .1.3.6.1.2.1.2.2.1.1.1

...would have the same effect.

> Do i missing something?

	Looks good.  Note, however, that the only things viewable in non-default contexts are those MIBs you explicitly register to present data in those contexts.  MIB-II, IF-MIB, etc. are only available in the default context.


	HTH,

Mike

-------------------------------------------------------------------------
This SF.net email is sponsored by: Microsoft
Defy all challenges. Microsoft(R) Visual Studio 2008.
http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/
_______________________________________________
Net-snmp-users mailing list
[email protected]
Please see the following page to unsubscribe or change other options:
https://lists.sourceforge.net/lists/listinfo/net-snmp-users
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.