RE: SNMPv3 security

David Spakes <[email protected]> Thu, 7 Aug 2003 17:21:56 -0400 (EDT)
Newsgroups gmane.ietf.snmpv3
Message-ID <[email protected]>
On Thu, 7 Aug 2003, Fleischman, Eric wrote:

> No user or security administrator can bear the overhead of
> redistributing tens of thousands of SNMPv3 passwords. They certainly
> can't regularly do this within an adequately short key lifetime
> quantum in order to make the current SNMPv3 approach begin to be
> viable. Egads!!!


Hi Eric,

SNMP Research has a policy-based configuration tool for SNMPv3 called
Simple PolicyPro.  It is part of a suite of applications called EnterPol
(http://www.snmp.com/products/enterpol.html).

Redistributing tens of thousands of SNMPv3 passwords on a regular basis is
one of the design goals of Simple PolicyPro.  Changing one user's password
in the policy definition takes just a few mouse clicks and keystrokes in
the GUI.  A background process performs the necessary Set requests to the 
usmUserTable on all of the remote agents to which that policy is assigned.

When a company has so many hosts, there's bound to be at least a few that
are down or unreachable at any given point in time.  Simple PolicyPro
stores policy changes in a database so retries can be made over several
days or longer if necessary--the behavior is configurable.

Let me know if you would like a free evaluation copy.

Regards,

David Spakes


-------------------------------------------------------------  
 David Spakes                       email:   [email protected]  
 SNMP Research                      voice:   +1 865 573 1434  
 3001 Kimberlin Heights Road          fax:   +1 865 573 9197  
 Knoxville, TN  37920-9716  USA      http://www.snmp.com  
-------------------------------------------------------------  

                      SNMPv3 is now... 
           the Full Internet Management Framework 
                      (RFC 3410-3418)
  Are your management tools secure, open, flexible, and scalable?
     Rely on the proven experts when taking your next step