247-IT Guide
Setting up SNMPv3 securely on a UPS network card
Many UPS network cards still run SNMP v1 or v2c with the community "public". That lets anyone on the network read the UPS, and with a write community even control it. SNMPv3 replaces the community with users and passwords and encrypts the traffic. How to set it up and test it.
The problem with v1 and v2c
With SNMP v1 and v2c the community is the only password, and it travels in
plain text. Out of the box it is often public for reading and
private for writing. Anyone who knows the write community can, on many cards,
change settings, switch outlets or shut the UPS down.
SNMPv3 (RFC 3414) introduces users. Every request is signed with the user's password, and the content can be encrypted. Eavesdropping or forging requests on the network is then no longer straightforward.
Security levels and algorithms
| Level | Authentication | Encryption | Recommendation |
|---|---|---|---|
noAuthNoPriv | user name only | no | do not use |
authNoPriv | password, signed | no | only if the card can't do more |
authPriv | password, signed | yes | default |
For authentication, older cards offer MD5 and SHA-1, newer ones also SHA-2 (SHA-256 to SHA-512, RFC 7860). For privacy (encryption) there are DES and AES-128, and some cards also offer AES-192 or AES-256. Pick the strongest that both sides support. In practice SHA-1 or SHA-256 with AES-128 is available almost everywhere. Use MD5 and DES only if the card offers nothing else.
Per RFC 3414, the authentication and privacy passwords must be at least eight characters long. Use two different, long passwords.
Setting up SNMPv3 on the network card
APC (Network Management Card 2 and 3), Eaton (Network-M2/M3), Vertiv, Socomec and others offer SNMPv3 in the card's web interface. Menu names differ by firmware; the steps are the same:
- Update the firmware — older firmware often knows only MD5 and DES; newer firmware adds SHA-2 and AES and fixes security flaws in the card.
- Create an SNMPv3 user — user name, authentication protocol with password, privacy protocol with password. Read access is enough for monitoring.
- Restrict access — in the access control, allow only the IP address of the monitoring machine (network management station).
- Enable SNMPv3, disable v1/v2c — or at least restrict v1 to read-only and the monitoring machine's address and change the default communities.
- Test — before switching v1 off for good, check the v3 query (section 04).
Checking the connection
With the net-snmp command-line tools (usually present on Linux, installable on Windows) you query the battery charge from the RFC 1628 standard, which almost every UPS card provides:
snmpget -v3 -l authPriv -u monitor -a SHA -A "AuthPassword" \
-x AES -X "PrivPassword" 192.168.10.20 1.3.6.1.2.1.33.1.2.4.0
If a number comes back, everything is fine. The most common errors:
| Message | Cause |
|---|---|
| Unknown user name | User not created, misspelled, or SNMPv3 not enabled on the card. |
| Authentication failure | Authentication password or protocol (MD5, SHA-1, SHA-256 …) does not match. |
| Decryption error | Privacy password or protocol (DES, AES …) does not match. |
| Timeout | Card unreachable, UDP port 161 blocked, or access control does not allow the IP address. |
SNMPv3 in the UPS Hyper-V Shutdown Monitor
In the UPS Hyper-V Shutdown Monitor you choose SNMP v3 in the UPS settings and enter the user, authentication and privacy protocol and the two passwords. The test button checks the connection right away.
- Authentication — SHA-1, SHA-256, SHA-384, SHA-512 and, for legacy devices, MD5.
- Encryption — AES-128, AES-192, AES-256 and, for legacy devices, DES and 3DES.
- Vendor values and the standard — APC, Eaton, Socomec, Vertiv, Huawei and CyberPower are read via their own values, everything else via the RFC 1628 standard.
- Passwords stored protected — encrypted with Windows DPAPI, bound to the machine.
SNMPv3 is included in every edition. If you run several vendors, see Monitoring UPS units from multiple vendors.
Securing the UPS card
- Current firmware — also because of known vulnerabilities in older card generations.
- authPriv with SHA and AES — as strong as both sides support.
- Two long, different passwords — at least eight characters, preferably much more.
- v1/v2c disabled — or restricted to read-only and the monitoring machine's address, with the default communities changed.
- The card's web interface — default password changed, HTTP off, HTTPS only.
- Management network — the card in its own network, not in the office or guest network.
Frequently asked questions
What is the difference between SNMP v2c and v3?
SNMP v2c protects access only with a community that is sent in plain text. SNMPv3 uses users with passwords, signs every request and can encrypt the content. For UPS network cards, v3 with the authPriv level is the secure choice.
Which algorithms should I choose for SNMPv3?
The strongest that both the card and the monitoring software support: SHA-256, or at least SHA-1, for authentication and AES for encryption. Use MD5 and DES only for devices that offer nothing else.
Why does snmpget report "Authentication failure"?
The authentication password or protocol does not match the card's setting, for example SHA-1 instead of SHA-256. Both must be identical on card and client.
Can I switch off SNMP v1 after the change?
Yes, once every system that queries the UPS works via SNMPv3. Check monitoring systems and other clients first. Where v1 has to stay, restrict it to read-only and the address of the querying machine.
More guides
Replacing UPS batteries
Ageing, warning signs and swapping without a protection gap.
Restarting after a power outage
Starting servers, storage and VMs automatically when power returns.
Eaton IPM alternative for Hyper-V
Node licensing, editions and Hyper-V integration compared.
Hyper-V on Server Core
Protect hosts without a desktop via WinRM or a web interface.
Shutting down Hyper-V VMs in a power outage
Stop action, shutdown order and time budget for an orderly shutdown.
NUT on Windows
Query a UPS via Network UPS Tools from a NAS or Linux server.
Hyper-V failover cluster power outage
Coordinating quorum, CSV and live migration.
Active Directory & power outages
The USN rollback myth and the real risks for domain controllers.
SQL Server & Exchange on Hyper-V
Protecting databases during a power outage.
Calculating UPS runtime
Why the datasheet runtime rarely holds.
PowerChute alternative for Hyper-V
UPS shutdown without vendor lock-in.
Monitoring UPS units from multiple vendors
One tool instead of several silos.
Set up an ordered shutdown yourself
30 days free, every feature included. With test mode and dry run, so the first real power outage is not the first test.