Skip to content
UPSmonitor 247-IT

247-IT Guide

Setting up SNMPv3 securely on a UPS network card

Many UPS network cards still run SNMP v1 or v2c with the community "public". That lets anyone on the network read the UPS, and with a write community even control it. SNMPv3 replaces the community with users and passwords and encrypts the traffic. How to set it up and test it.

01 Why v3 What v1 and v2c leave open.

The problem with v1 and v2c

With SNMP v1 and v2c the community is the only password, and it travels in plain text. Out of the box it is often public for reading and private for writing. Anyone who knows the write community can, on many cards, change settings, switch outlets or shut the UPS down.

SNMPv3 (RFC 3414) introduces users. Every request is signed with the user's password, and the content can be encrypted. Eavesdropping or forging requests on the network is then no longer straightforward.

02 Security levels Three levels, two passwords.

Security levels and algorithms

SNMPv3 security levels
Level Authentication Encryption Recommendation
noAuthNoPrivuser name onlynodo not use
authNoPrivpassword, signednoonly if the card can't do more
authPrivpassword, signedyesdefault

For authentication, older cards offer MD5 and SHA-1, newer ones also SHA-2 (SHA-256 to SHA-512, RFC 7860). For privacy (encryption) there are DES and AES-128, and some cards also offer AES-192 or AES-256. Pick the strongest that both sides support. In practice SHA-1 or SHA-256 with AES-128 is available almost everywhere. Use MD5 and DES only if the card offers nothing else.

Per RFC 3414, the authentication and privacy passwords must be at least eight characters long. Use two different, long passwords.

03 Setup The steps are the same for every vendor, only the menus differ.

Setting up SNMPv3 on the network card

APC (Network Management Card 2 and 3), Eaton (Network-M2/M3), Vertiv, Socomec and others offer SNMPv3 in the card's web interface. Menu names differ by firmware; the steps are the same:

  1. Update the firmware — older firmware often knows only MD5 and DES; newer firmware adds SHA-2 and AES and fixes security flaws in the card.
  2. Create an SNMPv3 user — user name, authentication protocol with password, privacy protocol with password. Read access is enough for monitoring.
  3. Restrict access — in the access control, allow only the IP address of the monitoring machine (network management station).
  4. Enable SNMPv3, disable v1/v2c — or at least restrict v1 to read-only and the monitoring machine's address and change the default communities.
  5. Test — before switching v1 off for good, check the v3 query (section 04).
04 Testing With net-snmp on the command line.

Checking the connection

With the net-snmp command-line tools (usually present on Linux, installable on Windows) you query the battery charge from the RFC 1628 standard, which almost every UPS card provides:

snmpget -v3 -l authPriv -u monitor -a SHA -A "AuthPassword" \
        -x AES -X "PrivPassword" 192.168.10.20 1.3.6.1.2.1.33.1.2.4.0

If a number comes back, everything is fine. The most common errors:

Typical SNMPv3 errors
MessageCause
Unknown user nameUser not created, misspelled, or SNMPv3 not enabled on the card.
Authentication failureAuthentication password or protocol (MD5, SHA-1, SHA-256 …) does not match.
Decryption errorPrivacy password or protocol (DES, AES …) does not match.
TimeoutCard unreachable, UDP port 161 blocked, or access control does not allow the IP address.
05 Implementation SNMPv3 in the UPS Hyper-V Shutdown Monitor.

SNMPv3 in the UPS Hyper-V Shutdown Monitor

In the UPS Hyper-V Shutdown Monitor you choose SNMP v3 in the UPS settings and enter the user, authentication and privacy protocol and the two passwords. The test button checks the connection right away.

  1. Authentication — SHA-1, SHA-256, SHA-384, SHA-512 and, for legacy devices, MD5.
  2. Encryption — AES-128, AES-192, AES-256 and, for legacy devices, DES and 3DES.
  3. Vendor values and the standard — APC, Eaton, Socomec, Vertiv, Huawei and CyberPower are read via their own values, everything else via the RFC 1628 standard.
  4. Passwords stored protected — encrypted with Windows DPAPI, bound to the machine.

SNMPv3 is included in every edition. If you run several vendors, see Monitoring UPS units from multiple vendors.

06 Checklist Tool-independent.

Securing the UPS card

  1. Current firmware — also because of known vulnerabilities in older card generations.
  2. authPriv with SHA and AES — as strong as both sides support.
  3. Two long, different passwords — at least eight characters, preferably much more.
  4. v1/v2c disabled — or restricted to read-only and the monitoring machine's address, with the default communities changed.
  5. The card's web interface — default password changed, HTTP off, HTTPS only.
  6. Management network — the card in its own network, not in the office or guest network.
07 Questions Short answers to common questions.

Frequently asked questions

What is the difference between SNMP v2c and v3?

SNMP v2c protects access only with a community that is sent in plain text. SNMPv3 uses users with passwords, signs every request and can encrypt the content. For UPS network cards, v3 with the authPriv level is the secure choice.

Which algorithms should I choose for SNMPv3?

The strongest that both the card and the monitoring software support: SHA-256, or at least SHA-1, for authentication and AES for encryption. Use MD5 and DES only for devices that offer nothing else.

Why does snmpget report "Authentication failure"?

The authentication password or protocol does not match the card's setting, for example SHA-1 instead of SHA-256. Both must be identical on card and client.

Can I switch off SNMP v1 after the change?

Yes, once every system that queries the UPS works via SNMPv3. Check monitoring systems and other clients first. Where v1 has to stay, restrict it to read-only and the address of the querying machine.

Set up an ordered shutdown yourself

30 days free, every feature included. With test mode and dry run, so the first real power outage is not the first test.