AdvancedPublished 2026-07-04
SNMPv3 AuthPriv Monitoring
Bundle lab · $29.99
Harden the monitoring plane by replacing cleartext SNMPv2c with authenticated and encrypted SNMPv3 (authPriv) on R1. You will create a v3 group that requires privacy and a user with SHA authentication and AES-128 encryption, then verify the configuration. The flat management LAN avoids routing complexity so you can focus on the security mechanics of SNMPv3.
Learning objectives
- Explain SNMPv3 security levels: noAuthNoPriv, authNoPriv, and authPriv
- Configure an SNMPv3 group that enforces authentication and privacy (authPriv)
- Create an SNMPv3 user with SHA authentication and AES-128 privacy bound to the group
- Verify group and user binding with show snmp group and show snmp user
- Appreciate why SNMPv2c (cleartext community) must be retired in favor of SNMPv3
Troubleshooting focus
- SNMPv3 user exists but is not in a group set to priv (authPriv) → polling fails at higher security level
- Security level mismatch between NMS request and device user (e.g., authNoPriv vs authPriv)
- Auth/privacy algorithm mismatch (SHA vs MD5, AES-128 vs AES-192/256) or bad passwords
- Attempting v2c against a device that no longer supports a community string
- Missing engine/user on the NMS side or wrong credentials
Topology
Own this lab's topology — and every lab — in Network Discovery & Monitoring.
Unlock with Network Discovery & MonitoringFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.
Grade your work
Create a free account to submit your completed lab for grading.
Create a free account