SNMP-USER-BASED-SM-MIB

MIB Reference — IPNetwork Monitor · Updated September 09, 2026

All MIBsSNMP-USER-BASED-SM-MIB

Organization: SNMPv3 Working Group

Last Updated: 2002-10-16

Category: SNMP Framework

Description: Provides managed objects for administering the SNMPv3 User-Based Security Model (USM), covering user credentials and the configuration of authentication and privacy protocols.

IPNetwork Monitor uses several OIDs from this MIB in network discovery and polling the applicable devices. Start monitoring SNMP-USER-BASED-SM-MIB with a free 30-day trial of IPNetwork Monitor.

What Is SNMP-USER-BASED-SM-MIB?

SNMP-USER-BASED-SM-MIB is the vendor-neutral IETF standards MIB (RFC 3414) defining the User-based Security Model (USM) that underlies SNMPv3 authentication and privacy. It exposes objects for configuring and monitoring SNMPv3 user credentials, authentication protocol (MD5/SHA) and privacy protocol (DES/AES) settings per user/engine, along with a set of security-violation statistics counters. Rather than hardware sensors, this MIB's status role is software/security-oriented: usmStatsUnsupportedSecLevels, usmStatsNotInTimeWindows, usmStatsUnknownUserNames, usmStatsUnknownEngineIDs, usmStatsWrongDigests, and usmStatsDecryptionErrors let an operator detect SNMPv3 authentication failures, replay/time-window issues, or misconfigured credentials on the managed agent. It is tightly coupled to SNMP-FRAMEWORK-MIB and SNMPv3's core architecture, since usmUserTable entries are indexed by the SNMP engine ID defined there. It is present on essentially any device or NMS implementing SNMPv3 with the USM security model, from routers and switches to servers running an SNMP agent, and consulting the SNMP-USER-BASED-SM-MIB OID list shows usmUserTable alongside the six usmStats counters as the module's primary manageable objects.

IPNetwork Monitor allows you to monitor SNMP objects defined in SNMP-USER-BASED-SM-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • vendor-neutral, standards-based MIB, not tied to a specific manufacturer
  • any device or host running an SNMPv3 agent

Monitoring Examples

An administrator monitors usmStatsUnknownUserNames and usmStatsWrongDigests to catch repeated SNMPv3 authentication failures, which could indicate a misconfigured monitoring credential or an attempted unauthorized access probe against the agent. usmUserTable/usmUserEntry rows (keyed by usmUserEngineID and usmUserName) show which SNMPv3 users are provisioned on the device and their configured usmUserSecurityName. A climbing usmStatsNotInTimeWindows counter would flag clock-skew or replay-protection issues between the manager and agent.

What Can Be Monitored

  • SNMPv3 user accounts and security names
  • authentication failure counts (unknown user names, wrong digests)
  • unsupported security level attempts
  • time window/replay failures
  • unknown engine ID errors
  • decryption error counts
Imported Objects

From SNMP-FRAMEWORK-MIB

SnmpAdminString
SnmpEngineID
snmpAuthProtocols
snmpPrivProtocols

From SNMPv2-CONF

MODULE-COMPLIANCE
OBJECT-GROUP

From SNMPv2-SMI

Counter32
MODULE-IDENTITY
OBJECT-IDENTITY
OBJECT-TYPE
snmpModules

From SNMPv2-TC

AutonomousType
RowPointer
RowStatus
StorageType
TEXTUAL-CONVENTION
TestAndIncr
OIDs

RFC description

Defines managed objects for managing the User-Based Security Model (USM) for SNMPv3, including user credentials, authentication, and privacy protocol configuration.

Start monitoring vendor-neutral, standards-based MIB, any device or host running an SNMPv3 agent (USM user credentials/security-violation counters) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download SNMP-USER-BASED-SM-MIB