NetApp - ONTAP: SNMPv3 user for Sensu
NetApp Solution · Config document · referenced from Logging, monitoring and AutoSupport
noteThe passwords are placeholders. SHA-1 with DES is what ONTAP 9.1 offered, not something to copy.
The SNMP configuration of a cluster: one read-only SNMPv3 user for the monitoring system, and the SNMPv1 community the cluster itself uses to poll its FC switches.
| Item | Value |
|---|---|
| Runs on | The cluster shell, as admin |
| Shown here for | DC1-A-XNAS001 |
| Also applied to | DC1-B-XNAS001 |
| Queried by | Sensu, dc1-a-vcsns001.adm.example.net |
| Security level | authPriv: authentication SHA, privacy DES |
| ONTAP version at the time | 9.1 |
The command set
# --- 1. SNMPv3 user "sensu", read-only ---------------------------------------- # The command is interactive. Answers as given: # authoritative entity's EngineID [local EngineID] : <Enter> # authentication protocol (none, md5, sha) : sha # authentication protocol password : <SNMP_AUTH_PASSWORD> # privacy protocol (none, des) : des # privacy protocol password : <SNMP_PRIV_PASSWORD> security login create -username sensu -application snmp -authentication-method usm -role readonly # --- 2. Community for the cluster's health monitoring of the FC switches ----- # After the default SNMPv1 communities were replaced on the Brocade switches, # the cluster is told the new read-only community, once per switch. # (The notes write these lines as "switch modify", without "storage".) storage switch modify -switch-name Brocade_10.11.15.45 -snmp-community <SNMP_COMMUNITY> storage switch modify -switch-name Brocade_10.11.15.46 -snmp-community <SNMP_COMMUNITY> storage switch modify -switch-name Brocade_10.11.23.45 -snmp-community <SNMP_COMMUNITY> storage switch modify -switch-name Brocade_10.11.23.46 -snmp-community <SNMP_COMMUNITY> # --- 3. Check ------------------------------------------------------------------ # Expected: snmp-version SNMPv1 and the new community for each switch. storage switch show -switch-name Brocade_10.11.15.45 -fields snmp-version,snmp-community storage switch show -switch-name Brocade_10.11.15.46 -fields snmp-version,snmp-community storage switch show -switch-name Brocade_10.11.23.45 -fields snmp-version,snmp-community storage switch show -switch-name Brocade_10.11.23.46 -fields snmp-version,snmp-community
No community, trap host or trap is configured on the cluster for queries from outside: the as-built report shows that table empty and traps disabled.
| Difference | DC1-A-XNAS001 | DC1-B-XNAS001 |
|---|---|---|
| Section 1 | As shown | The same command and answers |
| Sections 2 and 3 | As shown | The same eight commands; both clusters monitor all four switches of the site |
The notes hold no SNMP commands for site 2.
Checked against ONTAP 9.19.1
| As built | Today |
|---|---|
security login create -username sensu | The parameter is -user-or-group-name; -username is not in the 9.19.1 parameter list |
Prompts offer authentication none, md5, sha and privacy none, des | The prompts offer none, md5, sha, sha2-256 and none, des, aes128; in FIPS mode only sha, sha2-256 and aes128 |
storage switch modify, storage switch show | From ONTAP 9.8 storage switch is replaced by system switch fibre-channel; adding a switch takes -snmp-version (SNMPv1, SNMPv2c or SNMPv3, default SNMPv2c) and -snmp-community-or-username |
| SNMPv1 with a community towards the FC switches | For Fabric OS 9.0.1 and later SNMPv3 is mandatory; ONTAP supports SHA-256 with AES-128 towards switches. Switches on Fabric OS 10.x, which offers only SHA-512, cannot be monitored |
storage bridge show, bridges polled over SNMP | storage bridge became system bridge in 9.8. In-band management of the bridges is the default from 9.8, and out-of-band management over SNMP is deprecated |
A user created today would be SHA-256 with AES-128. The as-built SHA-1 with DES user should not be copied.