If you installed OneSpan Authentication Server in basic mode, Net-SNMP is installed, but must be configured manually after the installation if required.
To configure Net-SNMP
Launch the OneSpan Authentication Server Configuration Utility.
Switch to the SNMP tab.
Select Override SNMP configuration.
Configure SNMP:
Type the IP address and the port to use for SNMPv3 requests.
By default, the SNMP agent will run on the local host and listen on port 161.
Type a security name.
Configure the authentication and privacy settings. Those settings specify which authentication and privacy protocols to use for SNMPv3 requests. When enabling and configuring the authentication and privacy type, you need to include a passphrase (authentication/privacy secret) for it.
Authentication type. Specifies whether messages sent will be signed and the protocol to use for signing: None, MD5, SHA, SHA-224, SHA-256, SHA-384, or SHA-512.
Privacy type. Specifies whether messages sent will be encrypted and the protocol to use for encryption: None, AES, DES, AES-192, or AES-256.
When you configure SNMP targets, make sure to set either the authentication type only or both authentication and privacy type for a complete trap configuration. You cannot set a privacy type without setting an authentication type.
SNMP security considerations
We strongly recommend to configure SNMP with both authentication and privacy enabled. Use SHA-2 with a minimum key length of 256 bit (or more) for authentication, together with the AES-256 privacy protocol.
Additionally, while SNMP passphrases must be at least eight characters long, we recommend to use longer passphrases – ideally at least 16 characters – to improve security.
Click OK to save the SNMP configuration and restart the SNMP service.