Data Domain: Managing SNMP
Summary: The Simple Network Management Protocol (SNMP) is a standard protocol for exchanging network management information, and is a part of the Transmission Control Protocol/Internet Protocol (TCP/IP) protocol suite. SNMP provides a tool for network administrators to manage and monitor network-attached devices, such as Data Domain systems, for conditions that warrant administrator attention. ...
Instructions
How to Manage SNMP on Dell Data Domain
Duration: 00:04:06 (hh:mm:ss)
When available, closed caption (subtitles) language settings can be chosen using the CC icon on this video player.
You can also view this video on YouTube.
Viewing SNMP Status and Configuration:
The SNMP tab displays the current SNMP status and configuration. The SNMP view shows the SNMP status, SNMP properties, SNMP V3 configuration, and SNMP V2C configuration.
Steps for enabling or disabling SNMP
- Select Administration > Settings > SNMP.
- In the Status area, click Enable or Disable.
Downloading the SNMP MIB
Use the SNMP tab to download the SNMP MIB.
- Select Administration > Settings > SNMP.
- Click Download the MIB file.
- In the Opening .mib dialog box, select Open.
- Click Browse and select a browser to view the MIB in a browser window.
- Save the MIB or exit the browser.

Configuring SNMP Properties
Use the SNMP tab to configure the text entries for system location and system contact.
Steps to configure entries:
- Select Administration > Settings > SNMP.
- In the SNMP Properties area, click Configure. The SNMP Configuration dialog box appears.
- In the text fields, specify the following information; and or an
- SNMP System Location is a description of where the protection system is located.
- SNMP System Contact: The email address of the system administrator
- SNMP System Notes: (Optional) More SNMP configuration information
- SNMP Engine ID: A unique identifier for the SNMP entity where the following requirements and guidelines apply:
- The engine ID must be 34 hexadecimal characters (SNMP V3 only)
- Use a value meaningful to the installation
- For HA pairs, the engine ID can only be changed from the active node, and is the same for all nodes
- Click OK.
SNMP V3 User Management
Use the SNMP tab to create, modify, and delete SNMP V3 users and trap hosts. When you create SNMP V3 users, you define a username, specify either read-only or read/write access, and select an authentication protocol.
Creating SNMP V3 Users:
- Select Administration > Settings > SNMP.
- In the SNMP Users area, click Create. The Create SNMP User dialog box appears.
- In the Name text field, enter the name of the user for whom you want to grant access to the system agent. The name must be a minimum of eight characters.
- Select either read-only or read/write access for this user.
- To authenticate the user, select Authentication.
- Select the MD5, SHA1, or SHA256 protocol.
- Enter the authentication key in the Key text field. (Do not start key with the leading "#" character)
- To provide encryption to the authentication session, select Privacy.
- Select either the AES or DES protocol.
- Enter the encryption key in the Key text field. (Do not start key with the leading "#" character)
- Click OK. The newly added user account appears in the SNMP Users table.
Modifying SNMP V3 Users
Review Data Domain: SNMP v3 Trap does not immediately reflect a user authentication or privacy change for limitations on user credential changes.
Use the SNMP tab to modify the access level (read-only or read/write) and the authentication protocol for existing SNMP V3 users is available.
- Select Administration > Settings > SNMP.
- In the SNMP Users area, select a checkbox for the user and click Modify. The Modify SNMP User dialog box appears. Add or change any of the following settings.
- Select either read-only or read/write access for this user.
- To authenticate the user, select Authentication.
- Select the MD5, SHA1, or SHA256 protocol.
- Enter the authentication key in the Key text field. (Do not start key with the leading "#" character)
- To provide encryption to the authentication session, select Privacy.
- Select either the AES or DES protocol.
- Enter the encryption key in the Key text field. (Do not start key with the leading "#" character)
- Click OK. The new settings for this user account appear in the SNMP Users table.
Removing SNMP V3 Users
Use the SNMP tab to delete existing SNMP V3 users.
- Select Administration > Settings > SNMP.
- In the SNMP Users area, select a checkbox for the user and click Delete. The Delete SNMP User dialog box appears.
- Verify the username to be deleted and click OK.
- In the Delete SNMP User Status dialog box, click Close. The user account is removed from the SNMP Users table.
SNMP V2C Community Management
Define SNMP V2C communities (which serve as passwords) to control management system access to the protection system. To restrict access to specific hosts that use the specified community, assign the hosts to the community.
Note: SNMP community definitions do not enable the transmission of SNMP traps to a management station. You must define trap hosts to enable trap submission to management stations.
Creating SNMP V2C Communities
Create communities to restrict access to the DDR system or for use in sending traps to a trap host. You must create a community and assign it to a host before you can select that community for use with the trap host.
- Select Administration > Settings > SNMP.
- In the Communities area, click Create. The Create SNMP V2C Community dialog box appears.
- In the Community box, enter the name of a community for whom you want to grant access to the system agent.
- Select either read-only or read/write access for this community.
- If you want to associate the community to one or more hosts, add the hosts as follows:
- Click (+) to add a host. The host dialog box appears.
- In the Host text field, enter the IP address or domain name of the host.
- Click OK. The host is added to the host list.
- Click OK. The new community entry appears in the Communities table and lists the selected hosts
Modifying SNMP V2C Communities
- Select Administration > Settings > SNMP.
- In the Communities area, select the checkbox for the community and click Modify. The Modify SNMP V2C Community dialog box appears.
- To change the access mode for this community, select either read-only or read/write access.
- To add one or more hosts to this community, do the following:
- Click (+) to add a host. The Host dialog box appears.
- In the Host text field, enter the IP address or domain name of the host.
- Click OK. The Host is added to the host list.
- To delete one or more hosts from the host list, do the following but review the information first.
- Select the checkbox for each host or click the Host check box in the table head to select all listed hosts.
- Click the delete button (X)
- To edit a hostname, do the following:
- Select the checkbox for the host.
- Click the edit button (pencil).
- Edit the hostname.
- Click OK.
- Click OK. The modified community entry appears in the Communities table.
Deleting SNMP V2C Communities
Use the SNMP tab to delete existing SNMP V2 communities.
- Select Administration > Settings > SNMP.
- In the Communities area, select a checkbox for the community and click Delete. The Delete SNMP V2C Communities dialog box appears.
- Verify the community name to be deleted and click OK.
- In the Delete SNMP V2C Communities Status dialog box, click Close. The community entry is removed from the Communities table.
SNMP Trap Host Management
Trap host definitions enable protection systems to send alert messages in SNMP trap messages to an SNMP management station. Creating SNMP V3 and V2C trap hosts definitions identify remote hosts that receive SNMP trap messages from the system.
Prerequisites:
If you plan to assign an existing SNMP V2C community to a trap host, you must first use the Communities area to assign the trap host to the community.
Creating SNMP V3 and V2C Trap Hosts
- Select Administration > Settings > SNMP.
- In the SNMP V3 Trap Hosts or SNMP V2C Trap Hosts area, click Create. The Create SNMP Trap Hosts dialog appears.
- In the Host box, enter the IP address or domain name of the SNMP Host to receive traps.
- In the Port box, enter the port number for sending traps (port 162 is a common port).
- Select the user (SNMP V3) or the community (SNMP V2C) from the drop-down menu.
- To create a new community:
- Select Create New Community in the Community drop-down menu.
- Enter the name for the new community in the Community box.
- Select the Access type.
- Click the add (+) button.
- Enter the trap hostname.
- Click OK.
- Click OK.
- Click OK.
Modifying SNMP V3 and V2C Trap Hosts
You can modify the port number and community selection for existing trap host configurations.
- Select Administration > Settings > SNMP.
- In the SNMP V3 Trap Hosts or SNMP V2C Trap Hosts area, select a Trap Host entry, and click Modify. The Modify SNMP Trap Hosts dialog box appears.
- To modify the port number, enter a new port number in the Port box (port 162 is a common port).
- Select the user (SNMP V3) or the community (SNMP V2C) from the drop-down menu.
- To create a new community:
- Select Create New Community in the Community drop-down menu.
- Enter the name for the new community in the Community box.
- Select the Access type.
- Click the add (+) button.
- Enter the trap hostname.
- Click OK.
- Click OK.
- Click OK.
Removing SNMP V3 and V2C Trap Hosts
Use the SNMP tab to delete existing trap host configurations.
- Select Administration > Settings > SNMP.
- In the Trap Hosts area (either for V3 or V2C), select a checkbox for the trap host and click Delete. The Delete SNMP Trap Hosts dialog box appears.
- Verify the hostname to be deleted and click OK.
- In the Delete SNMP Trap Hosts status dialog box, click Close. The trap host entry is removed from the Trap Hosts table.
Additional Information
The SNMP is a standard protocol for exchanging network management information, and is a part of the TCP/IP protocol suite. SNMP provides a tool for network administrators to manage and monitor network-attached devices, such as Data Domain systems, for conditions that warrant administrator attention.
To monitor systems using SNMP, install the DDOS MIB in your SNMP Management system. DDOS also supports the standard MIB-II so you can query MIB-II statistics for general data such as network statistics. For full coverage of available data, use both the DDOS MIB and the standard MIB-II.
The DDOS system SNMP agent accepts queries for system-specific information from management systems using SNMP V1, V2C, and V3. SNMP V3 provides a greater degree of security than V2C and V1 by replacing cleartext community strings (used for authentication) with user-based authentication using either MD5, SHA1, or SHA256. SNMP V3 use
See the Dell DDOS 7.9 MIB Quick Reference for complete details. (log in to Dell Support is required to view this document)
NetWorker:
- SNMP V3 is not supported in the latest networker version 19.7 as stated in the Dell NetWorker 19.7 Security Configuration Guide.
Related articles:
- Port requirements for allowing access to a Data Domain through a Firewall
- Data Domain: Common SNMP configuration and Issues causing Monitoring Services disabled in Integrated Backup Software or DPA
- Data Domain: Importance of keeping SNMP trap disabled
- Data domain: SNMP Frequently Asked Questions (FAQ) and How to download MIB files
- Data Domain: SNMP server fail to return queries to client
- Data Domain SNMP status request consistently fails with timeout errors
- NetWorker: SNMP V3 for Data Domain SNMP Monitoring
- Data Domain: SNMP V3 Trap does not immediately reflect a user authentication or privacy change
- Data Domain: Default SNMP community names are identified by security scanners (CVE-1999-0517)
- Data Domain - System hardening and best practices guide