FW: RSTP-MIB coments
"David B Harrington" <[email protected]> Thu, 31 Mar 2005 12:28:21 -0500
| Newsgroups | gmane.ietf.bridge |
|---|---|
| Message-ID | <[email protected]> |
Hi, The security considerations section of the RSTP-MIB needs details. Please review this proposed text to make sure these statements look to be true. > The text in dot1dStpVersion will need to change since there > are two 802.1D specs. > <suggested text> > "The version of Spanning Tree Protocol the bridge is > currently running. The value 'stpCompatible(0)' > indicates the Spanning Tree Protocol specified in > IEEE 802.1D-1998 and 'rstp(2)' indicates the Rapid Spanning > Tree Protocol specified in IEEE 802.1w and clause 17 of > 802.1D-2004. New values may be defined as future versions > of the protocol become available." > </suggested text> > > Security Considerations: > <suggested text> > A number of writable objects could be misused to cause > network delays and spanning tree instabilities, including > dot1dStpVersion, dot1dStpTxHoldCount, > dot1dStpPortProtocolMigration, dot1dStpPortAdminEdgePort, and > dot1dStpPortAdminPathCost. > > dot1dStpVersion could be read by an attacker to identify > environments containing applications or protocols which are > potentially sensitive to RSTP mode. > > dot1dStpPortAdminPointToPoint could be used to mislead an > access control protocol, such as 802.1X, to believe that only > one other system is attached to the LAN segment and to enable > network access based on that assumption. This situation could > permit potential man-in-the-middle attacks. > > </suggested text> David Harrington [email protected]