RE: [Isms] Why SNMPv3? [WG Review: Integrated Security Model for SNMP (isms)]
"David T. Perkins" <[email protected]> Thu, 23 Sep 2004 09:58:02 -0700 (PDT)
| Newsgroups | gmane.ietf.snmpv3 |
|---|---|
| Message-ID | <[email protected]> |
HI, Do you use syslog? Are you dissatisfied with it? Do you know it's limitations? If you answsered "yes" to any of the above, then I believe that SNMPv3/SBSM will provide you great benefit. In SNMPv3/USM, the mechanisms for administering notifications was, I believe pretty horrible. However, I believe that using SNMPv3/SBSM with a little work on the MIB modules for notification targets and loggings, then we will have a real winner. And, all of the below I believe, but I also believe that with SNMPv3/SBSM it will be even easier to deploy a new system than what is required for SNMPv1 and SNMPv2c. On Thu, 23 Sep 2004, Pekka Savola wrote: > Thanks for the explicit note. > > On Wed, 22 Sep 2004, David B Harrington wrote: > > As Wes point sout, SNMPv3 provides security enhancements, but I think > > we need to be more specific. > > > > 1) SNMPv3 provides an application-level authentication of the security > > principal. > [...] > > 2) SNMPv3 USM provides robust authentication of a security principal. > [...] > > 3) SNMPv3 provides access control over the principal's data-level > > authorization > [...] > > So, in short, the security features (different kinds) set SNMPv3 apart > from SNMPv1/2. > > Then I'll have to say that SNMPv3 does not seem all that interesting > to many operators, but I'll totally agree that some indeed absolutely > want these features. > > Let's consider our particular case (a national research network). I > guess it should be quite common. > > 1) we only use SNMP for read-only access. > 2) we only use SNMP to the routers from (about) two network > management hosts within our own network. > 2.b) there is one external host from a network monitoring > organization, using separate [direct] connectivity, which has the same > RO privileges > 3) we restrict the access to the SNMP port [in all the routers] to > the IP addresses of the network management. > 4) we eliminate IP spoofing of the network management host addresses > (actually all the addresses, but that's beside the point) at the edge. > > To sum it up, as we use SNMP only for RO, the hosts are well-defined, > and the borders are secure, we don't need any encryption or strong > authentication. Community 'public' is good enough. Further, we also > don't require providing different views to the different users (two > our own, 1 external) -- that would be more trouble than its worth. > > It should seem obvious to me why a lot of folks still stick to > SNMPv1/2, and will continue to do so. > > On the other hand, if we wanted to do something like: > - SNMP writes (e.g., config updates, etc.) > - provide the customers access to certain parts of the MIB tree of > their (C)PE router [though some of this is already part of SNMPv2 I > recall] > - [etc.] > > .. then the justification for SNMPv3's increased security features > would indeed be higher. But few folks do SNMP writes, and many don't > bother providing SNMP access to untrusted parties, so the features may > not be all that interesting. > > -- > Pekka Savola "You each name yourselves king, yet the Regards, /david t. perkins