Controllerless Networks

last person joined: 2 days ago 

Instant Mode - the controllerless Wi-Fi solution that's easy to set up, is loaded with security and smarts, and won't break your budget
Expand all | Collapse all

Aruba Instant and SNMPv2 support

This thread has been viewed 0 times
  • 1.  Aruba Instant and SNMPv2 support

    Posted May 17, 2019 11:00 AM

    Hi community.

    I would like to demystify a topic about SNMPv2 and SNMPv2c.

    Some Aruba products claim that they support SNMPv2 and others claim they support SNMPv2c.

    What is the difference between both protocols?, which one is a better option?, which one has more capabilities?.

    In the case of Aruba Instant, the iuser guide refers it supports SNMPv2 ... does it refers to SNMPv2c? ... many people use terms SNMPv2 and SNMPv2c as equivalence, they assume they mean exactly the same, but I do not think it is correct.

    Any help with this?

    Regards



  • 2.  RE: Aruba Instant and SNMPv2 support

    EMPLOYEE
    Posted May 20, 2019 03:50 AM

    According to this message, v2c is the variant that uses community strings, the other variant v2u has user based security. It's the first time I researched this question as before I have seen snmp-v2 and snmp-v2c being used interchangeably and never experienced any issues. 

     

    To answer your question, you probably should not use any SNMPv2 as the community is transmitted in plain text and someone who can capture a single SNMP request packet has access to the community string. Use SNMPv3 instead with the highest encryption (AES) whenever possible. See also this advisory by US-CERT.



  • 3.  RE: Aruba Instant and SNMPv2 support

    Posted May 27, 2019 10:31 AM

    Thanks for your input Herman.

     

    This question is about only compliance. Of course that during deployment, the most suitable and secure option is SNMPv3 encrypted.

     

    My question is still not answered.

    You introduced a third version of SNMP: SNMPv2u ... like you, it is the first time I hear about it.

     

    My questions are:

    • If the RFI I have got sets SNMPv2 as a compliance, and my user guide says my solution complies SNMPv2c, does the solution comply the requirement?
    • If the RFI I have got sets SNMPv2c as a compliance, and my user guide says my solution complies SNMPv2, does the solution comply the requirement?

    What is the difference between SNMPv2 and SNMPv2c?, which protocol does have an advantage over the other?, which protocol technically is better than the other?

    Many people uses both terms interchangeably, but both protocols are different.

    RFCs are not so simple and clear to define the difference between SNMPv2 and SNMPv2c

     

    Regards



  • 4.  RE: Aruba Instant and SNMPv2 support

    EMPLOYEE
    Posted May 27, 2019 12:03 PM

    I can't officially answer that question, but from that link in my first message, I would say that SNMPv2 and SNMPv2c are used interchangeably, and where SNMPv2 is written that SNMPv2c should be read as I haven't seen any SNMPv2u implementation.

     

    Checking the RFCs, points in the same direction: https://tools.ietf.org/html/rfc3416:

    Message protocols for transferring management information.  The
             first version of the SNMP message protocol is called SNMPv1 and
             described in STD 15, RFC 1157 [RFC1157].  A second version of
             the SNMP message protocol, which is not an Internet standards
             track protocol, is called SNMPv2c and described in RFC 1901
             [RFC1901] and STD 62, RFC 3417 [RFC3417].  The third version of
             the message protocol is called SNMPv3 and described in STD 62,
             RFC 3417 [RFC3417], RFC 3412 [RFC3412] and RFC 3414 [RFC3414].
    

    If you need an authoritative answer, please check with your local Aruba Sales team.

     



  • 5.  RE: Aruba Instant and SNMPv2 support

    EMPLOYEE
    Posted May 27, 2019 12:25 PM

    Both snmpv2 and snmpv2c are mostly same but in snmpv2 have additional different types of PDU which are suitable to manage large networks like GETBulk, Informs, where as snmpv2c is lighter verion of snmpv2 which is mostly used to manage smaller network.

     

    Currently snmpv2 /snmpv2c replaced by snmpv3 and we always recommand to use snmpv3 for security reasons.