Nonprivileged Mode Read Only

Use the RO keyword of the snmp-server community command to provide nonprivileged access to your routers via SNMP. The following configuration command sets the agent in the router to allow only SNMP GETREQUEST and GETNEXTREQUEST messages that are sent with the community string "public":

snmp-server community public RO 1

You can also specify a list of IP addresses that are allowed to send messages to the router using the access-list option with the snmp-server community command. In the following configuration example, only hosts 1.1.1.1 and 2.2.2.2 are allowed nonprivileged-mode SNMP access to the router:

access-list 1 permit 1.1.1.1 access-list 1 permit 2.2.2.2 snmp-server community public RO 1

Was this article helpful?

0 0

Post a comment