Snmpv3: Dependency between user and group's security level
"Marcelo ." <[email protected]>
| Newsgroups | gmane.network.net-snmp.user |
|---|---|
| Message-ID | <[email protected]> |
I did some tests in GNS3 configuring different snmpv3 groups within a router (i.e. a no-auth group, an auth group and a priv group); creating different users with different security levels and making all the possible combinations between users and groups. After capturing with Wireshark those results (i'll put them at the end of the question) I write my own "rule", the "general conclusion" of that dependency between the security level of groups and users, as follows: " Within the agent, the group's security level has precedence over the user's security level member of that group, if the group's security level is greater than the user's security level. This is explained with the following two scenarios. First scenario, If inside the agent, the group which the user belongs, does not have any securities (a noauth group) and the user inside of it has a security level greater, for example, authPriv; an external incoming request to the user of this agent, with authNoPriv security level, will be able to gather the information that was looking for, despite the user inside router's agent has configured both authentication and privacy protocols and keys. Second scenario, the opposite situation. When the group's security level is higher, for example authPriv and the user within the group has a lower security level (for example, a noAuthNoPriv user or a authNoPriv user) an external incoming request to the user of this agent, with noAuthNoPriv or authNoPriv security level, will get a NULL response to the request. That's why concordance must exist between the security level of both the group and the users members of that group. Another important consideration is consider the interaction between user's security levels (admin and agents). The security level of the user has precedence over the request's security level of the admin console, because if the security level of the incoming request is higher than the configured for the user who it is asking to, the request won't be successfull and an error message "unsupported security level" will be sent to the admin console." Please I want to know if the conclusion I reached after the analisis of the results of tests is correct, or if it's imprecise, you can help me to improve it. I read a very meager description of this in a cisco forum (that said that the group has precedence over the user, but this is not always true demonstrated with the first scenario example). Thanks in advance Results of the tests: ------------------------------------------------------------------------------ How ServiceNow helps IT people transform IT departments: 1. Consolidate legacy IT systems to a single system of record for IT 2. Standardize and globalize service processes across IT 3. Implement zero-touch automation to replace manual, redundant tasks http://pubads.g.doubleclick.net/gampad/clk?id=51271111&iu=/4140/ostg.clktrk _______________________________________________ Net-snmp-users mailing list [email protected] Please see the following page to unsubscribe or change other options: https://lists.sourceforge.net/lists/listinfo/net-snmp-users
grop-user-seclev.jpg
(image/jpeg, 82 KB) - not displayed