chapter 8

23
1 Chapter 8 Network Management Security

Upload: teagan-stephens

Post on 01-Jan-2016

27 views

Category:

Documents


0 download

DESCRIPTION

Chapter 8. Network Management Security. Outline. Basic Concepts of SNMP SNMPv1 Community Facility SNMPv3 Recommended Reading and WEB Sites. Basic Concepts of SNMP. An integrated collection of tools for network monitoring and control. Single operator interface - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: Chapter 8

1

Chapter 8

Network Management

Security

Page 2: Chapter 8

2

Outline

Basic Concepts of SNMP SNMPv1 Community Facility SNMPv3 Recommended Reading and WEB

Sites

Page 3: Chapter 8

3

Basic Concepts of SNMP An integrated collection of tools for network

monitoring and control. Single operator interface Minimal amount of separate equipment. Software and

network communications capability built into the existing equipment

SNMP key elements: Management station Managament agent Management information base Network Management protocol

Get, Set and Notify

Page 4: Chapter 8

4

Protocol context of SNMP

Page 5: Chapter 8

5

Proxy Configuration

Page 6: Chapter 8

6

Page 7: Chapter 8

7

SNMP v1 and v2 Trap – an unsolicited message

(reporting an alarm condition) SNMPv1 is ”connectionless” since it

utilizes UDP (rather than TCP) as the transport layer protocol.

SNMPv2 allows the use of TCP for ”reliable, connection-oriented” service.

Page 8: Chapter 8

8

Comparison of SNMPv1 and SNMPv2

SNMPv1 PDU SNMPv2 PDU Direction DescriptionGetRequest GetRequest Manager to agent Request value for

each listed object

GetRequest GetRequest Manager to agent Request next value for each listed object

------ GetBulkRequest Manager to agent Request multiple values

SetRequest SetRequest Manager to agent Set value for each listed object

------ InformRequest Manager to manager

Transmit unsolicited information

GetResponse Response Agent to manager or Manage to manager(SNMPv2)

Respond to manager request

Trap SNMPv2-Trap Agent to manager Transmit unsolicited information

Page 9: Chapter 8

9

SNMPv1 Community Facility

SNMP Community – Relationship between an SNMP agent and SNMP managers.

Three aspect of agent control: Authentication service Access policy Proxy service

Page 10: Chapter 8

10

SNMPv1 Administrative Concepts

Page 11: Chapter 8

11

Traditional SNMP Manager

Page 12: Chapter 8

12

Traditional SNMP Agent

Page 13: Chapter 8

13

SNMPv3 Flow

Page 14: Chapter 8

14

SNMPv3

Page 15: Chapter 8

15

SNMP3 Message Format with USM

Page 16: Chapter 8

16

User Security Model (USM) Designed to secure against:

Modification of information Masquerade Message stream modification Disclosure

Not intended to secure against: Denial of Service (DoS attack) Traffic analysis

Page 17: Chapter 8

17

Key Localization Process

Page 18: Chapter 8

18

View-Based Access Control Model (VACM)

VACM has two characteristics: Determines wheter access to a managed

object should be allowed. Make use of an MIB that:

Defines the access control policy for this agent.

Makes it possible for remote configuration to be used.

Page 19: Chapter 8

19

VACM VACM enables and SNMP engine to be

configured to enforce a particular set pf access rights, which constitutes access policy that depends on : Principal Security level and model MIB context object instance Type of access

Page 20: Chapter 8

20

VACM logic

Page 21: Chapter 8

21

Access control processing

An SNMP application invokes VACM via the isAcessAllowedprimitive, with the input parameters.

Page 22: Chapter 8

22

Considerations for making the access control decision. Who Where How Why What which

Page 23: Chapter 8

23

Summary

We have discussed Basic concepts of SNMP Versions of SNMP