Management and Configuration Guide K/KA/KB.15.15

SNMPv3 users
NOTE: To create new users, most SNMPv3 management software requires an initial user record
to clone. The initial user record can be downgraded and provided with fewer features, but not
upgraded by adding new features. For this reason, HP recommends that when you enable SNMPv3,
you also create a second user with SHA authentication and DES privacy.
To use SNMPv3 on the switch, you must configure the users that will be assigned to different groups:
1. Configure users in the User Table with the snmpv3 user command.
To view the list of configured users, enter the show snmpv3 user command.
2. Assign users to Security Groups based on their security model with the snmpv3 group
command.
CAUTION: If you add an SNMPv3 user without authentication, privacy, or both, to a group that
requires either feature, the user will not be able to access the switch. Ensure that you add a user
with the appropriate security level to an existing security group.
About adding users
To configure an SNMPv3 user, you must first add the user name to the list of known users with the
snmpv3 user command, as shown in Figure 114 (page 243).
Figure 114 Adding SNMPv3 users and displaying SNMPv3 configuration
Group access levels
The switch supports eight predefined group access levels, shown in Table 6-3 (page 243). There
are four levels for use by version 3 users and four are used for access by version 2c or version 1
management applications.
Table 18 Predefined group access levels
Group write viewGroup read viewGroup access typeGroup name
ManagerWriteViewManagerReadViewVer3 Must have
Authentication and Privacy
managerpriv
ManagerWriteViewManagerReadViewVer3 Must have
Authentication
managerauth
DiscoveryViewOperatorReadViewVer3 Must have
Authentication
operatorauth
DiscoveryViewOperatorReadViewVer3 No Authenticationoperatornoauth
SNMPv3 users 243