The problem of allowing a cooomunity or usmUser to belong to multiple group

Fatima Peter <[email protected]>
Newsgroups gmane.network.net-snmp.user
Message-ID <[email protected]>
Hello All,
   I have a question on vacm group and whether the same communitystring or
usmUser can belong to multiple groups.

For example let us say we have a community string "public" which is
configured to belong to 2 groups "v1Group1" and "v1Group2".

com2sec  test      10.10.0.0/16    public

group   v1Group1          v2c         test
group   v1Group2          v2c         test

We have 2 views all and none:
view     all                included   .1
view     none              excluded  .1

The vacm access is configured like below:
#                context sec.model sec.level    match  read          write
notif
access      v1Group1          ""      any       noauth       exact
all      none   none
access      v1Group2          ""      any       noauth       exact     none
none   none

Now, we have the community "public" have 2 opposing views because of the
fact that "public" belongs to multiple groups with opposing access control.

Is this configuration acceptable and allowed? If not, is this specified in
the snmp specifications? Should we allow it and use some rule of thumb to
determine vacm access?

Thanks in advance for your input.

Regards,
Fatima

------------------------------------------------------------------------------
Download Intel&#174; Parallel Studio Eval
Try the new software tools for yourself. Speed compiling, find bugs
proactively, and fine-tune applications for parallel performance.
See why Intel Parallel Studio got high marks during beta.
http://p.sf.net/sfu/intel-sw-dev

_______________________________________________
Net-snmp-users mailing list
[email protected]
Please see the following page to unsubscribe or change other options:
https://lists.sourceforge.net/lists/listinfo/net-snmp-users
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.