ZXR10ZSRV2ConīægurationGuide(SystemManagement)
Steps
1.ActivatetheSNMPsecurityfunction.
CommandFunction
ZXR10(config)#snmp-serversecurityblock<
block-seconds><detect-tries><detect-seconds>[when
<tries><startup-seconds>]
TheSNMPsecurityprotectionfunction
isdisabledbydefault.Thiscommand
isusedtoactivatethisfunction.
block<block-seconds>:blocktime(lengthofthequietperiod),unit:second,range:
1ā65535.
<detect-tries>:maximumnumberoftimesoffailedattemptsinmonitoringmode,range:
1ā65535.
<detect-seconds>:maximumdetectiontimeinmonitoringmode,unit:second,range:
1ā65535.
<tries>:maximumnumberoftimesoffailedattemptsinnormalmode,range:1ā65535,
default:50.
<startup-seconds>:maximumdetectiontimeinnormalmode,unit:second,range:
1ā65535,default:60.
2.ConīæguretheACLforcontrollinghoststhataccessthesystemthroughSNMP .
CommandFunction
ZXR10(config)#snmp-serveraccess-list{ipv4|
ipv6}<acl-name>
UsesaconīæguredACLtocontrol
hoststhataccessthesystemthrough
SNMP .
3.Conīæguretheageingtimeofdynamictrustedusersandconīægurestatictrustedusers.
StepCommandFunction
1ZXR10(config)#snmp-serversecurity
dynamic-trust-useridle-timeout<timeout-seconds>
Conīægurestheageingtimeof
dynamictrustedusers.Range:
1ā65535,default:1800s.
2ZXR10(config)#snmp-serversecurity
static-trust-user<static-ip-addr>
Conīæguresstatictrustedusersthat
areconīæguredmanually.
4.ConīægurethegenerationoflogsandTrapmessageswhencommunitystringattempts
failorastateisswitched.
CommandFunction
ZXR10(config)#snmp-serversecurityon-failurelog[and
Trap]
Conīæguresthegenerationoflogs
andTrapmessageswhencommunity
stringattemptsfailorastateis
switched.
6-12
SJ-20140504150128-007|2014-05-10(R1.0)ZTEProprietaryandConīædential