RE: [Isms] Why SNMPv3? [WG Review: Integrated Security Model for SNMP (isms)]

"David T. Perkins" <[email protected]> Thu, 23 Sep 2004 09:58:02 -0700 (PDT)
Newsgroups gmane.ietf.snmpv3
Message-ID <[email protected]>
HI,

Do you use syslog? Are you dissatisfied with it? Do you know it's
limitations?

If you answsered "yes" to any of the above, then I believe that
SNMPv3/SBSM will provide you great benefit.

In SNMPv3/USM, the mechanisms for administering notifications
was, I believe pretty horrible. However, I believe that using
SNMPv3/SBSM with a little work on the MIB modules for notification
targets and loggings, then we will have a real winner.

And, all of the below I believe, but I also believe that with
SNMPv3/SBSM it will be even easier to deploy a new system than 
what is required for SNMPv1 and SNMPv2c.

On Thu, 23 Sep 2004, Pekka Savola wrote:

> Thanks for the explicit note.
> 
> On Wed, 22 Sep 2004, David B Harrington wrote:
> > As Wes point sout, SNMPv3 provides security enhancements, but I think
> > we need to be more specific. 
> > 
> > 1) SNMPv3 provides an application-level authentication of the security
> > principal. 
> [...]
> > 2) SNMPv3 USM provides robust authentication of a security principal.
> [...]
> > 3) SNMPv3 provides access control over the principal's data-level
> > authorization
> [...]
> 
> So, in short, the security features (different kinds) set SNMPv3 apart 
> from SNMPv1/2.
> 
> Then I'll have to say that SNMPv3 does not seem all that interesting
> to many operators, but I'll totally agree that some indeed absolutely
> want these features.
> 
> Let's consider our particular case (a national research network).  I
> guess it should be quite common.
> 
>  1) we only use SNMP for read-only access.
>  2) we only use SNMP to the routers from (about) two network 
> management hosts within our own network.
>  2.b) there is one external host from a network monitoring 
> organization, using separate [direct] connectivity, which has the same 
> RO privileges
>  3) we restrict the access to the SNMP port [in all the routers] to 
> the IP addresses of the network management.
>  4) we eliminate IP spoofing of the network management host addresses
> (actually all the addresses, but that's beside the point) at the edge.
> 
> To sum it up, as we use SNMP only for RO, the hosts are well-defined,
> and the borders are secure, we don't need any encryption or strong
> authentication.  Community 'public' is good enough.  Further, we also
> don't require providing different views to the different users (two
> our own, 1 external) -- that would be more trouble than its worth.
> 
> It should seem obvious to me why a lot of folks still stick to
> SNMPv1/2, and will continue to do so.
> 
> On the other hand, if we wanted to do something like:
>  - SNMP writes (e.g., config updates, etc.)
>  - provide the customers access to certain parts of the MIB tree of 
> their (C)PE router [though some of this is already part of SNMPv2 I 
> recall]
>  - [etc.]
> 
> .. then the justification for SNMPv3's increased security features
> would indeed be higher.  But few folks do SNMP writes, and many don't
> bother providing SNMP access to untrusted parties, so the features may
> not be all that interesting.
> 
> -- 
> Pekka Savola                 "You each name yourselves king, yet the

Regards,
/david t. perkins