AdvancedPublished 2026-07-04
SNMPv3 AuthPriv Monitoring
Bundle lab
Lab 8 of 10 in Network Discovery & Monitoring · ← Previous · Next →
CCNA exam domain: IP Services
Harden the monitoring plane by replacing cleartext SNMPv2c with authenticated and encrypted SNMPv3 (authPriv) on R1. You will create a v3 group that requires privacy and a user with SHA authentication and AES-128 encryption, then verify the configuration. The flat management LAN avoids routing complexity so you can focus on the security mechanics of SNMPv3.
Learning objectives
- Explain SNMPv3 security levels: noAuthNoPriv, authNoPriv, and authPriv
- Configure an SNMPv3 group that enforces authentication and privacy (authPriv)
- Create an SNMPv3 user with SHA authentication and AES-128 privacy bound to the group
- Verify group and user binding with show snmp group and show snmp user
- Appreciate why SNMPv2c (cleartext community) must be retired in favor of SNMPv3
Troubleshooting focus
- SNMPv3 user exists but is not in a group set to priv (authPriv) → polling fails at higher security level
- Security level mismatch between NMS request and device user (e.g., authNoPriv vs authPriv)
- Auth/privacy algorithm mismatch (SHA vs MD5, AES-128 vs AES-192/256) or bad passwords
- Attempting v2c against a device that no longer supports a community string
- Missing engine/user on the NMS side or wrong credentials
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the
running-config— a change that only exists in a terminal session never reaches the grader. - You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.