About SNMP Community Strings

SNMP is a protocol that offers network management services within the Internet suite of protocols.

SNMP uses a lightweight security mechanism whereby each protocol data unit (PDU) contains a community string. The SET community string is used in an SNMP Control operation and the GET community string is used in an SNMP Monitor operation.

SNMP community strings provide only a rudimentary form of security because they are transmitted in clear text in each SNMP request. Therefore, the community strings are exposed to any stations capable of monitoring an IP or Internetwork Packet ExchangeTM (IPXTM) network

Because Management Agent for Novell NetWare and Management Agent for Windows are based on SNMP, all actions that are directed from network Novell ConsoleOne to a server involve SNMP SET and GET requests from the manager to the agent. Novell ConsoleOne® requests data from a managed server by issuing an SNMP GET request. An SNMP SET command is required to set server alarm thresholds or configuration parameters. In most cases, you are unaware of the underlying SNMP commands required to carry out requests you make in Novell ConsoleOne, unless you are issuing requests on an SNMP-enabled device through the MIB Browser.


SNMP Security

Conducting management operations from Novell ConsoleOne raises the issue of ensuring security. In particular, if unauthorized users configuration parameters on a server, performance problems or even sabotage network operations are encountered.

For these reasons, you should establish a scheme for changing the default community string PUBLIC to a proprietary community string used for communication between the management system and your SNMP agents.

Use the community keyword to define the community string to be used in the generated traps. The length of the community string is restricted to 32 bytes and cannot contain a space (except between quotes), tab, square bracket, equals sign, colon, semicolon, or number sign (#) characters. You can use Unicode* or International characters for the community string.

The default community string for Monitor operations is PUBLIC and for Control operations is null.