20.01.2014 Views

Lectures notes for 2010 - KTH

Lectures notes for 2010 - KTH

Lectures notes for 2010 - KTH

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

SNMPv3<br />

March 1997, the SNMPv3 Working group was chartered to define a standard <strong>for</strong> SNMP<br />

security and administration. Target: April 1998 - all SNMPv3 specifications<br />

submitted to IESG <strong>for</strong> consideration as Proposed Standards.<br />

Based on “An Architecture <strong>for</strong> Describing SNMP Management Frameworks” (RFC<br />

2271)<br />

Composed of multiple subsystems:<br />

1.a message processing and control subsystem - Message Processing and Dispatching <strong>for</strong> SNMP (RFC 2272)<br />

2.a security subsystem - based on a User-based Security Model (USM) (RFC 2274), provides SNMP message level<br />

security (Keyed-MD5 as the authentication protocol and the use of CBC-DES as the privacy protocol - but with support<br />

<strong>for</strong> others) defines a MIB <strong>for</strong> remotely monitoring/managing the configuration parameters <strong>for</strong> this Security model<br />

3.a local processing subsystem - responsibile <strong>for</strong> processing the SNMP PDUs that operate on local instrumentation,<br />

applies access control [View-based Access Control Model (VACM) (RFC 2275)] and invokes method routines to<br />

access management in<strong>for</strong>mation, and prepares a response to the received SNMP request.<br />

4.SNMPv3 Applications (RFC 2273) - includes Proxy Forwarder Applications, which can <strong>for</strong>ward SNMP requests to<br />

other SNMP entities, to translate SNMP requests of one version into SNMP requests of another version or into<br />

operations of some non-SNMP management protocol; and support aggregated managed objects where the value of one<br />

managed object depends upon the values of multiple (remote) items.<br />

Maguire SNMPv3 9: 7 of 71<br />

maguire@kth.se <strong>2010</strong>.03.21 Internetworking/Internetteknik

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!