This section lists the key security features that SNMPv3 adds and the types of security threats it addresses.
Starting with Cisco IOS XR Release 26.3.1,
-
SNMP secure-v3 enforces authentication and encryption for every configured user. For more information, see Configure SNMP secure-v3.
-
Legacy SNMPv1, SNMPv2c, and SNMPv3 configurations are deprecated but remain supported. If a deprecated SNMP configuration remains active, the router logs a deprecation warning every 30 days.
SNMPv3 provides secure access to devices through:
-
authentication,
-
encryption, and
-
access control.
These enhancements protect against the following threats:
-
Masquerade: An SNMP user assumes another's identity to perform unauthorized operations.
-
Message stream modification: Messages are maliciously reordered, delayed, or replayed to cause unauthorized management operations.
-
Disclosure: Packet exchanges are eavesdropped.
SNMPv3 also enforces access control over SNMP managed objects, further reducing the risk of unauthorized access.