× NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Orbi WiFi 7 RBE973
Reply

Re: CAUTION: GS7xxT v6.3.1.43 update destroys SNMPv3 credentials!

mvduin
Guide

CAUTION: GS7xxT v6.3.1.43 update destroys SNMPv3 credentials!

Without any mention in the release notes, the latest GS7xxT firmware v6.3.1.43 has a few important changes (compared to the previous release, v6.3.1.39) that affect management via SNMPv3:

  1. SHA512 is the only hash algorithm supported by the latest firmware, while the previous firmware only supported MD5 and SHA1.
  2. AES is the only encryption algorithm supported by the latest firmware, while the previous firmware only supported DES.
  3. The SNMP Engine ID is different when running the latest firmware, specifically the enterprise number changed from 4413 (Broadcom) to 4526 (Netgear).

While the new choices are mostly sensible (except SHA512 being serious overkill), these changes are all backwards-incompatible and changing the hash algorithm and/or SNMP Engine ID will invalidate any configured SNMPv3 credentials, leaving you unable to manage the switch via SNMPv3 until you've reset the credentials via the web interface and reconfigured your manager (assuming it supports these algorithms!).

 

This obviously deserves a prominent warning in the release notes.

Message 1 of 2
mvduin
Guide

Re: CAUTION: GS7xxT v6.3.1.43 update destroys SNMPv3 credentials!

Note that the nodejs net-snmp library does not support any of the SHA2 family algorithms, hence if you're (directly or indirectly) relying on this library you will not be able to securely manage your switch after upgrading to v6.3.1.43. You'd need to use SNMPv2c instead, which has no security whatsoever, or downgrade back to v6.3.1.39.

 

Another caution: if you downgrade back to v6.3.1.39, the password of the web interface will get reset to factory default ("password").

Message 2 of 2
Top Contributors
Discussion stats
  • 1 reply
  • 632 views
  • 1 kudo
  • 1 in conversation
Announcements