SNMP

Prev Next

The SNMP page can only be used to configure the settings of the SNMP service installed with the Net-SNMP package included with OneSpan Authentication Server. If you did not installed the included Net-SNMP package, the options in this page are disabled.

To use SNMP notifications you must first install an SNMP manager. Net-SNMP is installed and is currently the only SNMP manager that can be used. A number of MIBs are provided for use with SNMP.

SNMP traps can only be sent when Net-SNMP is configured via this page. Specify the information that is to be written into the snmpd.conf and snmp.conf configuration files of the Net-SNMP service. The snmpd.conf configuration file contains information about the OneSpan Authentication Server SNMP sub-agent, as is located in %PROGRAMFILES%\VASCO\Net-SNMP\etc\snmp\snmpd.conf.

The SNMP service configuration cannot be read, but only be overwritten. Applying changes via this tab will replace any existing SNMP configuration.

Table: SNMP page
Field nameDescription
Overwrite SNMP configurationSelect this checkbox to overwrite the SNMP configuration for the Net-SNMP service included with OneSpan Authentication Server.
IP AddressThe IP address of the server that handles SNMP requests, i.e., the IP address of OneSpan Authentication Server.
Port

The port of the server that handles SNMP requests.

By default, the SNMP agent will run on the local host and listen on port 161.

Security NameThe user name for SNMPv3, or the community name for SNMPv2c.
Authentication Type

The authentication protocol. If not set to None, messages sent will be signed using the selected protocol.

Possible values:

  • None. Messages are not authenticated.
  • MD5
  • SHA
  • SHA-224
  • SHA-256
  • SHA-384
  • SHA-512
SecretThe passphrase used by the authentication protocol to authenticate messages. Must contain at least eight characters.
Privacy Type

The privacy protocol. If not set to None, messages sent will be encrypted using the selected protocol.

Possible values:

  • None. Messages are not encrpyted.
  • AES
  • DES
  • AES-192
  • AES-256
SecretThe passphrase used by the privacy protocol to encrypt and decrypt messages. Must contain at least eight characters.

SNMP security considerations

We strongly recommend to configure and use SNMPv3 with both authentication and privacy enabled. Use SHA-2 with a minimum key length of 256 bit (or more) for authentication, together with the AES-256 privacy protocol.

Additionally, while SNMP passphrases must be at least eight characters long, we recommend to use longer passphrases – ideally at least 16 characters – to improve security.

The audit message information is included in the SNMP trap sent.

When an SNMP trap is sent, the information is added to the Security Alert Table. This is an SNMP table defined in OneSpan Authentication Server and contains a list of recent security alerts. This list is defined in the VASCO-IDENTIKEY-MIB.txt file and can be accessed using an SNMP viewer. It is non-persistent, i.e. the list is cleared when the OneSpan Authentication Server service is stopped.