Enable SNMPv3 on Fedora (net-snmp)

Install

sudo dnf install -y net-snmp net-snmp-utils

Create the SNMPv3 user

sudo systemctl stop snmpd
sudo net-snmp-create-v3-user -ro -A "AuthPassword" -X "PrivPassword" -a SHA -x AES snmp_user

Configure the agent

In /etc/snmp/snmpd.conf make sure you have:

agentAddress udp:AGENT_IP:161
rouser snmp_user authPriv

Start the service

sudo systemctl enable --now snmpd
sudo systemctl status snmpd

Open UDP 161 only for the monitoring server

sudo firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="MONITORING_SERVER_IP" port port="161" protocol="udp" accept'
sudo firewall-cmd --reload

Test

snmpwalk -v3 -u snmp_user -l authPriv -a SHA -A "AuthPassword" -x AES -X "PrivPassword" localhost sysDescr

Authentication errors?

Check that the user exists:

sudo grep -i snmp_user /var/lib/net-snmp/snmpd.conf

If it doesn't, or the password doesn't match, delete the stored users and create it again:

sudo systemctl stop snmpd
sudo rm -f /var/lib/net-snmp/snmpd.conf
sudo net-snmp-create-v3-user -ro -A "AuthPassword" -X "PrivPassword" -a SHA -x AES snmp_user
sudo systemctl start snmpd

Related: SNMPv3 on Ubuntu/Debian with PRTG.

Written by Daniel Ruiz Peláez, Systems & Infrastructure Engineer (Linux, VMware, Proxmox, Active Directory, networking and security). These are notes from real problems I have solved.

← Back to all posts