...
- After attache SNMPV3 feature template to cedge ISR4331/K9 there is no output to the "show snmp user" JM-MNH-SDW01#show snmp user JM-MNH-SDW01# - We receive next errors: M-MNH-SDW01#debug snmp detail SNMP Detail Debugs debugging is on JM-MNH-SDW01#terminal monitor JM-MNH-SDW01#SrParseV3SnmpMessage:Wrong User Name. SrParseV3SnmpMessage: Failed. SrParseV3SnmpMessage:Wrong User Name. SrParseV3SnmpMessage: Failed. SrDoSnmp: authentication failure, Unknown User Name SrDoSnmp: authentication failure, Unknown User Name SrParseV3SnmpMessage:Wrong User Name. SrParseV3SnmpMessage: Failed. SrDoSnmp: authentication failure, Unknown User Name - SNMPV3 feature template change
- vManage/vBond/vSmart - 19.2.1 https://vmanage-1459444.viptela.net SDWAN - 331983 - The cEdge we are testing is a ISR4331/K9 running 16.12.02r.0.23 - SNMPv3 feature template
- We need to change the cedge from vmanage mode to CLI mode and add manually the snmp-server user command. "snmp-server user v3userAuthPriv groupauthPriv v3 auth md5 priv aes 128 " ( the auth password in cisco SHOULD contain alphabet and number and should be minimum 8 characters) JM-MNH-SDW01(config)# snmp-server user CiscoV3User CiscoV3Group v3 auth sha jKBQHm1WZKEpr4ApM5J0 priv aes 128 UKBQHm1RZKEpr4ApM5J5 JM-MNH-SDW01(config)# end Uncommitted changes found, commit them? [yes/no/CANCEL] yes Commit complete. JM-MNH-SDW01#sh snmp user User name: CiscoV3User Engine ID: 766D616E6167652D0AC832FE storage-type: nonvolatile active Authentication Protocol: SHA Privacy Protocol: AES128 Group-name: CiscoV3Group
- SNMPV3 feature template change CU passwords from "snmp-server user CiscoV3User CiscoV3Group v3 auth sha jKBQHm1WZKEpr4ApM5J0 priv aes 128 UKBQHm1RZKEpr4ApM5J5" to user CiscoV3User CiscoV3Group v3 encrypted auth sha 56:2D:88:A5:21:73:81:76:A3:15:54:0F:BB:F9:FB:63:12:86:AF:00 priv aes 128 CE:42:1C:D7:0B:DC:DB:D5:14:A7:68:C8:A5:E0:9C:A0:FE:35:CE:AB adding the "encrypted" world on the command. - I tested with CU if we add manually the "encrypted" world on the command. JM-MNH-SDW01(config)# snmp-server user CiscoV3User CiscoV3Group v3 encrypted auth sha jKBQHm1WZKEpr4ApM5J0 priv aes 128 UKBQHm1RZKEpr4ApM5J5 there is no output to the "show snmp user" JM-MNH-SDW01#show snmp user JM-MNH-SDW01# -if we put the command without "encrypted" word. JM-MNH-SDW01(config)# snmp-server user CiscoV3User CiscoV3Group v3 encrypted auth sha jKBQHm1WZKEpr4ApM5J0 priv aes 128 UKBQHm1RZKEpr4ApM5J5 there is an output to the "show snmp user" JM-MNH-SDW01#sh snmp user User name: CiscoV3User Engine ID: 766D616E6167652D0AC832FE storage-type: nonvolatile active Authentication Protocol: SHA Privacy Protocol: AES128 Group-name: CiscoV3Group - I tested again form working config to template config: Config difference: Template drop 844 snmp-server user CiscoV3User CiscoV3Group v3 auth sha jKBQHm1WZKEpr4ApM5J0 priv aes 128 UKBQHm1RZKEpr4ApM5J5 and add snmp-server user CiscoV3User CiscoV3Group v3 encrypted auth sha 56:2D:88:A5:21:73:81:76:A3:15:54:0F:BB:F9:FB:63:12:86:AF:00 priv aes 128 CE:42:1C:D7:0B:DC:DB:D5:14:A7:68:C8:A5:E0:9C:A0:FE:35:CE:AB onfig comparative just template drop 844 snmp-server user CiscoV3User CiscoV3Group v3 auth sha jKBQHm1WZKEpr4ApM5J0 priv aes 128 UKBQHm1RZKEpr4ApM5J5 CLI config: 834 no crypto ikev2 diagnose error 835 no crypto isakmp diagnose error 836 snmp-server contact isns@jminsure.com 837 snmp-server enable traps 838 snmp-server engineID local 766D616E6167652D0ac832fe 839 snmp-server group CiscoV3Group v3 priv read InternetView 840 snmp-server host 10.3.1.98 vrf 20050 version 3 priv CiscoV3User udp-port 161 841 snmp-server location Manhattan 842 snmp-server trap timeout 30 843 snmp-server trap-source Loopback0 844 snmp-server user CiscoV3User CiscoV3Group v3 auth sha jKBQHm1WZKEpr4ApM5J0 priv aes 128 UKBQHm1RZKEpr4ApM5J5 845 snmp-server user CiscoV3User CiscoV3Group v3 encrypted auth sha 56:2D:88:A5:21:73:81:76:A3:15:54:0F:BB:F9:FB:63:12:86:AF:00 priv aes 128 CE:42:1C:D7:0B:DC:DB:D5:14:A7:68:C8:A5:E0:9C:A0:FE:35:CE:AB 846 snmp-server view InternetView 1.3.6.1 included template config: 827 no crypto ikev2 diagnose error 828 no crypto isakmp diagnose error 829 snmp-server contact isns@jminsure.com 830 snmp-server enable traps 831 snmp-server engineID local 766D616E6167652D0ac832fe 832 snmp-server group CiscoV3Group v3 priv read InternetView 833 snmp-server host 10.3.1.98 vrf 20050 version 3 priv CiscoV3User udp-port 161 834 snmp-server location Manhattan 835 snmp-server trap timeout 30 836 snmp-server trap-source Loopback0 837 snmp-server user CiscoV3User CiscoV3Group v3 encrypted auth sha 56:2D:88:A5:21:73:81:76:A3:15:54:0F:BB:F9:FB:63:12:86:AF:00 priv aes 128 CE:42:1C:D7:0B:DC:DB:D5:14:A7:68:C8:A5:E0:9C:A0:FE:35:CE:AB 838 snmp-server view InternetView 1.3.6.1 included