LINUXOR.SK ... open source notes ...

NetApp - ONTAP: SNMPv3 user for Sensu

category: solutionz · date: 2019-12-31 · updated: 2026-10-02 · author: LALA

NetApp Solution · Config document · referenced from Logging, monitoring and AutoSupport

noteThe passwords are placeholders. SHA-1 with DES is what ONTAP 9.1 offered, not something to copy.

The SNMP configuration of a cluster: one read-only SNMPv3 user for the monitoring system, and the SNMPv1 community the cluster itself uses to poll its FC switches.

ItemValue
Runs onThe cluster shell, as admin
Shown here forDC1-A-XNAS001
Also applied toDC1-B-XNAS001
Queried bySensu, dc1-a-vcsns001.adm.example.net
Security levelauthPriv: authentication SHA, privacy DES
ONTAP version at the time9.1

The command set

bash
# --- 1. SNMPv3 user "sensu", read-only ----------------------------------------
# The command is interactive. Answers as given:
#   authoritative entity's EngineID [local EngineID] : <Enter>
#   authentication protocol (none, md5, sha)         : sha
#   authentication protocol password                 : <SNMP_AUTH_PASSWORD>
#   privacy protocol (none, des)                     : des
#   privacy protocol password                        : <SNMP_PRIV_PASSWORD>
security login create -username sensu -application snmp -authentication-method usm -role readonly

# --- 2. Community for the cluster's health monitoring of the FC switches -----
# After the default SNMPv1 communities were replaced on the Brocade switches,
# the cluster is told the new read-only community, once per switch.
# (The notes write these lines as "switch modify", without "storage".)
storage switch modify -switch-name Brocade_10.11.15.45 -snmp-community <SNMP_COMMUNITY>
storage switch modify -switch-name Brocade_10.11.15.46 -snmp-community <SNMP_COMMUNITY>
storage switch modify -switch-name Brocade_10.11.23.45 -snmp-community <SNMP_COMMUNITY>
storage switch modify -switch-name Brocade_10.11.23.46 -snmp-community <SNMP_COMMUNITY>

# --- 3. Check ------------------------------------------------------------------
# Expected: snmp-version SNMPv1 and the new community for each switch.
storage switch show -switch-name Brocade_10.11.15.45 -fields snmp-version,snmp-community
storage switch show -switch-name Brocade_10.11.15.46 -fields snmp-version,snmp-community
storage switch show -switch-name Brocade_10.11.23.45 -fields snmp-version,snmp-community
storage switch show -switch-name Brocade_10.11.23.46 -fields snmp-version,snmp-community

No community, trap host or trap is configured on the cluster for queries from outside: the as-built report shows that table empty and traps disabled.

DifferenceDC1-A-XNAS001DC1-B-XNAS001
Section 1As shownThe same command and answers
Sections 2 and 3As shownThe same eight commands; both clusters monitor all four switches of the site

The notes hold no SNMP commands for site 2.

Checked against ONTAP 9.19.1

As builtToday
security login create -username sensuThe parameter is -user-or-group-name; -username is not in the 9.19.1 parameter list
Prompts offer authentication none, md5, sha and privacy none, desThe prompts offer none, md5, sha, sha2-256 and none, des, aes128; in FIPS mode only sha, sha2-256 and aes128
storage switch modify, storage switch showFrom ONTAP 9.8 storage switch is replaced by system switch fibre-channel; adding a switch takes -snmp-version (SNMPv1, SNMPv2c or SNMPv3, default SNMPv2c) and -snmp-community-or-username
SNMPv1 with a community towards the FC switchesFor Fabric OS 9.0.1 and later SNMPv3 is mandatory; ONTAP supports SHA-256 with AES-128 towards switches. Switches on Fabric OS 10.x, which offers only SHA-512, cannot be monitored
storage bridge show, bridges polled over SNMPstorage bridge became system bridge in 9.8. In-band management of the bridges is the default from 9.8, and out-of-band management over SNMP is deprecated

A user created today would be SHA-256 with AES-128. The as-built SHA-1 with DES user should not be copied.

← solutionz