SNMP-VIEW-BASED-ACM-MIB

MIB Reference — IPNetwork Monitor · Updated September 09, 2026

All MIBsSNMP-VIEW-BASED-ACM-MIB

Organization: SNMPv3 Working Group

Last Updated: 2002-10-16

Category: SNMP Framework

Description: Defines managed objects for managing the View-Based Access Control Model (VACM) for SNMP, controlling which users can access which MIB objects and operations.

IPNetwork Monitor uses several OIDs from this MIB in network discovery and polling the applicable devices. Start monitoring SNMP-VIEW-BASED-ACM-MIB with a free 30-day trial of IPNetwork Monitor.

What Is SNMP-VIEW-BASED-ACM-MIB?

SNMP-VIEW-BASED-ACM-MIB (RFC 3415) is a vendor-neutral IETF standards-track module defining the View-Based Access Control Model (VACM) used by SNMPv3 agents to control which users or groups can access which MIB views and operations. It exposes configuration tables mapping security principals to groups, groups to access permissions per context/security-model/security-level, and named MIB view families, along with storage type and row status for each entry. Rather than hardware or performance telemetry, its monitoring value is administrative/security status — confirming which access control mappings are actually active on an agent, verifying that a group's permissions match policy, and detecting unauthorized or stale access entries. Many MIB browsers list snmp-view-based-acm-mib objects alongside those of SNMP-TARGET-MIB when auditing SNMPv3 access policy. It is a core piece of the SNMPv3 security architecture and depends on the companion SNMP-FRAMEWORK-MIB and USM (User-based Security Model) modules for the security identities it references. It is present on essentially any SNMPv3-capable network device or agent where access control auditing is required.

IPNetwork Monitor allows you to monitor SNMP objects defined in SNMP-VIEW-BASED-ACM-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • vendor-neutral, standards-based MIB, not tied to a specific manufacturer
  • any SNMPv3-capable network device or agent

Monitoring Examples

An administrator would poll vacmSecurityToGroupTable (vacmSecurityModel, vacmSecurityName, vacmGroupName) alongside vacmAccessTable to audit which security names map to which groups and what access those groups have; an unexpected entry in vacmSecurityToGroupTable or a vacmAccessTable permission broader than expected would reveal a misconfigured or unauthorized SNMPv3 access grant.

What Can Be Monitored

  • security-to-group mappings
  • access control permissions per context/security level
  • MIB view family definitions
  • storage type and row status of access control entries
Imported Objects

From SNMP-FRAMEWORK-MIB

SnmpAdminString
SnmpSecurityLevel
SnmpSecurityModel

From SNMPv2-CONF

MODULE-COMPLIANCE
OBJECT-GROUP

From SNMPv2-SMI

MODULE-IDENTITY
OBJECT-TYPE
snmpModules

From SNMPv2-TC

RowStatus
StorageType
TestAndIncr
OIDs

RFC description

Defines managed objects for SNMPv3 View-Based Access Control Model (VACM) including security level, user, group, and access control views as standardized in RFC 3415.

Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device or agent (VACM access-control mapping) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download SNMP-VIEW-BASED-ACM-MIB