Dave,
    Thanks for the clarification. However, I am not sure I understand why this 
will not work for v3. Will the following directive:

    group             doomedGrp           usm                              
 not2allow<1>

    not ensure that for v3 we include the not2allow<1> security name in the 
doomedgroup - which, in turn is denied access for read/write/trap?

    Yup - I understand that this will be Net-SNMP specific solution and nothing 
to do with VACM mib interface! But, that will suit my requirement just fine!


-Arijit

----- Original Message ----
From: Dave Shield <[EMAIL PROTECTED]>
To: arijit <[EMAIL PROTECTED]>
Cc: net-snmp net-snmp <[email protected]>
Sent: Saturday, January 12, 2008 1:57:20 PM
Subject: Re: How to deny access from only some hosts usinf vacm


On 11/01/2008, arijit <[EMAIL PROTECTED]> wrote:
>    I think using the standard snmpd.conf configuration directives, I
 might still be
> able to deny access to a particular community from a particular host
 or subnet.

For particular *community* - yes, of course this is possible.

But that only works for SNMPv1/2c.
I stand by what I said earlier - you cannot do this for SNMPv3.

And even for SNMPv1/2c, it isn't possible to do this through
the VACM MIB interface alone.   What you propose relies on
the "com2sec" directive, which is a private Net-SNMP-specific
config, outside the scope of the VACM MIBs.

Dave





      
____________________________________________________________________________________
Looking for last minute shopping deals?  
Find them fast with Yahoo! Search.  
http://tools.search.yahoo.com/newsearch/category.php?category=shopping

-------------------------------------------------------------------------
Check out the new SourceForge.net Marketplace.
It's the best place to buy or sell services for
just about anything Open Source.
http://ad.doubleclick.net/clk;164216239;13503038;w?http://sf.net/marketplace
_______________________________________________
Net-snmp-users mailing list
[email protected]
Please see the following page to unsubscribe or change other options:
https://lists.sourceforge.net/lists/listinfo/net-snmp-users

Reply via email to