Restricting Switch Access
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m .
Restricting Switch Access
You can restrict access to a Cisco MDS 9000 Family switch using IP Access Control Lists (IP-ACLs).
See
Group-Based SNMP Access
Because group is a standard SNMP term used industry-wide, we refer to role(s) as group(s) in this SNMP
Note
section.
SNMP access rights are organized by groups. Each group in SNMP is similar to a role through the CLI.
Each group is defined with three accesses: read access, write access, and notification access. Each access
can be enabled or disabled within each group.
You can begin communicating with the agent once your user name is created, your roles are set up by
your administrator, and you are added to the roles.
Creating and Modifying Users
You can create users or modify existing users using SNMP or the CLI.
•
•
By default only two roles are available in a Cisco MDS 9000 Family switch—network-operator and
network-admin. You can also use any role that is configured in the Common Roles database (see the
"Configuring Common Roles" section on page
Tip
All updates to the CLI security database and the SNMP user database are synchronized. You can use the
SNMP password to log into either Fabric Manager or Device Manager. However, after you use the CLI
password to log into Fabric Manager or Device Manager, you must use the CLI password for all future
logins. If a user exists in both the SNMP database and the CLI database before upgrading to Cisco MDS
SAN-OS Release 2.0(1b), then the set of roles assigned to the user becomes the union of both sets of
roles after the upgrade.
Configuring SNMP Users from the CLI
The passphrase specified in snmp-server user command and the username command are synchronized
(see the
Cisco MDS 9000 Family Configuration Guide
27-4
Chapter 29, "Configuring IP Access Control Lists."
SNMP—Create a user as a clone of an existing user in the usmUserTable on the switch. Once you
have created the user, change the cloned secret key before activating the user. Refer to RFC 2574.
CLI—Create a user or modify an existing user using the snmp-server user command.
"SNMPv3 CLI User Management and AAA Integration" section on page
26-9).
OL-6973-03, Cisco MDS SAN-OS Release 2.x
Chapter 27
Configuring SNMP
27-3).