Network Management Security NS8

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

0 comments

Post a comment

    Post a comment
    Embed Video
    Edit your comment Cancel

    Favorites, Groups & Events

    Network Management Security NS8 - Presentation Transcript

    1. Chapter 8 Network Management Security Henric Johnson Blekinge Institute of Technology, Sweden http://www.its.bth.se/staff/hjo/ [email_address]
    2. Outline
      • Basic Concepts of SNMP
      • SNMPv1 Community Facility
      • SNMPv3
      • Recommended Reading and WEB Sites
    3. Basic Concepts of SNMP
      • An integrated collection of tools for network monitoring and control.
        • Single operator interface
        • Minimal amount of separate equipment. Software and network communications capability built into the existing equipment
      • SNMP key elements:
        • Management station
        • Managament agent
        • Management information base
        • Network Management protocol
          • Get, Set and Notify
    4. Protocol context of SNMP
    5. Proxy Configuration
    6.  
    7. SNMP v1 and v2
      • Trap – an unsolicited message (reporting an alarm condition)
      • SNMPv1 is ”connectionless” since it utilizes UDP (rather than TCP) as the transport layer protocol.
      • SNMPv2 allows the use of TCP for ”reliable, connection-oriented” service.
    8. Comparison of SNMPv1 and SNMPv2 Transmit unsolicited information Agent to manager SNMPv2-Trap Trap Respond to manager request Agent to manager or Manage to manager(SNMPv2) Response GetResponse Transmit unsolicited information Manager to manager InformRequest ------ Set value for each listed object Manager to agent SetRequest SetRequest Request multiple values Manager to agent GetBulkRequest ------ Request next value for each listed object Manager to agent GetRequest GetRequest Request value for each listed object Manager to agent GetRequest GetRequest Description Direction SNMPv2 PDU SNMPv1 PDU
    9. SNMPv1 Community Facility
      • SNMP Community – Relationship between an SNMP agent and SNMP managers.
      • Three aspect of agent control:
        • Authentication service
        • Access policy
        • Proxy service
    10. SNMPv1 Administrative Concepts
    11. SNMPv3
      • SNMPv3 defines a security capability to be used in conjunction with SNMPv1 or v2
    12. SNMPv3 Flow
    13. Traditional SNMP Manager
    14. Traditional SNMP Agent
    15. SNMP3 Message Format with USM
    16. User Security Model (USM)
      • Designed to secure against:
        • Modification of information
        • Masquerade
        • Message stream modification
        • Disclosure
      • Not intended to secure against:
        • Denial of Service (DoS attack)
        • Traffic analysis
    17. Key Localization Process
    18. View-Based Access Control Model (VACM)
      • VACM has two characteristics:
        • Determines wheter access to a managed object should be allowed.
        • Make use of an MIB that:
          • Defines the access control policy for this agent.
          • Makes it possible for remote configuration to be used.
    19. Access control decision
    20. Recommended Reading and WEB Sites
      • Subramanian, Mani. Network Management . Addison-Wesley, 2000
      • Stallings, W. SNMP, SNMPv1, SNMPv3 and RMON 1 and 2 . Addison-Wesley, 1999
      • IETF SNMPv3 working group (Web sites)
      • SNMPv3 Web sites

    + koolkampuskoolkampus, 3 years ago

    custom

    590 views, 0 favs, 1 embeds more stats

    More info about this document

    © All Rights Reserved

    Go to text version

    • Total Views 590
      • 589 on SlideShare
      • 1 from embeds
    • Comments 0
    • Favorites 0
    • Downloads 65
    Most viewed embeds
    • 1 views on http://koolkampus.com

    more

    All embeds
    • 1 views on http://koolkampus.com

    less

    Flagged as inappropriate Flag as inappropriate
    Flag as inappropriate

    Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

    Cancel
    File a copyright complaint
    Having problems? Go to our helpdesk?

    Categories