RE: MIDCOM Protocol Semantics <-> SNMPv3

"Harrington, David" <[email protected]>
Newsgroups gmane.ietf.midcom
Message-ID <6D745637A7E0F94DA070743C55CDA9BA013B1248@NHROCMBX1.ets.enterasys.com>
Hi Albrecht,

The terminology you use in your question means different things to
different people. 
Let me try to answer what I think you're asking.

The MIDCOM MIB work is designed to enable the dynamic changes to
firewalls and NATs for discrete uses as described in the semantics
document. The design team is utilizing existing mib modules where
possible, and supplementing those mib modules with a midcom-specific mib
module. 

The MIDCOM MIB will help coordinate the dynamic changes to the
configuration in the leveraged mib modules for midcom-specific purposes.
For example, the MIDCOM MIB will be used to coordinate the length and
owner of a midcom session, concepts not naturally part of a firewall or
a NAT or SNMPv3 permissions.

For firewall management, the design team will leverage the capabilities
of the IPSP MIB, including rule specification and rule groupings. For
NAT management, the design team will leverage the NAT MIB, including
public and private addresses and binds. For security, the design team
will leverage the security features of SNMPv3, including which midcom
agents are authorized to modify which mib modules.

These "leveraged" mibs will allow you to provision firewalls and NATS
and permissions, beyond that for midcom purposes (depending of course on
what you're trying to provision). 

So for provisioning of firewalls, look at the IPSP MIB. This has expired
in the I-D respository, and is in the process of being rewritten into
three smaller mib modules, which hopefully will be published soon, and
announced to the midcom WG.

For NAT provisioning, look for draft-ietf-nat-natmib-07.txt.

I hope this helps,
dbh

> -----Original Message-----
> From: [email protected] 
> [mailto:[email protected]] 
> Sent: Monday, November 24, 2003 8:56 AM
> To: [email protected]
> Cc: [email protected]
> Subject: [midcom] MIDCOM Protocol Semantics <-> SNMPv3
> 
> 
> 
> 
> 
> 
> 
> Dear MIDCOM experts
> 
> The "semantics draft" is now going for informational RFC in my
> understanding. SNMPv3 was recommended as MIDCOM protocol end of last
> year to my knowledge.
> I'm wondering whether
> (1) SNMPv3 is used as "MIDCOM protocol syntax" for the 
> "MIDCOM Protocol
> Semantics"?
> and
> (2) if yes, will there be an additional "MIB plane" for provisioning
> midcom boxes (besides the dynamic configuration actions according
> "MIDCOM Protocol Semantics")?
> 
> Thanks,
> Albrecht Schwarz
> ALCATEL
> 
> 
> 
> 
> 
> 
> 
> 
> _______________________________________________
> midcom mailing list
> [email protected]
> https://www1.ietf.org/mailman/listinfo/midcom
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.