Describes how SNMP secure-v3 CLI features enforce the secure network management by restricting configuration to strong authentication and encryption algorithms.
A SNMP secure-v3 feature is a network management configuration option that
-
enables the secure-v3 keyword for SNMP CLI commands to require only SHA-2 authentication algorithms and AES-based privacy encryption,
-
removes support for legacy SNMP versions (v1, v2c) and insecure cryptographic options such as MD5, SHA-1, DES, and 3DES, and
-
requires explicit authentication and privacy settings for all SNMP users, with all passwords entered using
clearorencryptedoptions and stored using AES encryption.
|
Feature Name |
Release Information |
Feature Description |
|---|---|---|
|
Configure SNMP secure-v3 |
Release 26.3.1 |
Introduced in this release on: Fixed Systems-Cisco 8010 Series Routers (ASIC: A100), Cisco 8200 Series Routers (ASICs: Q100, Q200, and P100), and Cisco 8700 Series Routers (ASICs: P100 and K100). This feature enhances the SNMP security by configuring only SNMPv3 with SHA-2 authentication and AES-based privacy using the secure-v3 CLI. The router continues to support SNMPv1, SNMPv2c, and legacy SNMPv3 configurations, but these configurations are deprecated. If a legacy SNMP configuration remains active, the router logs a deprecation warning every 30 days. The router rejects the commit if the same group, user, or notification host user is configured through both legacy SNMP and SNMP secure-v3. |