RE: [Isms] Why SNMPv3? [WG Review: Integrated Security Model for SNMP (isms)]
"McDonald, Ira" <[email protected]> Thu, 23 Sep 2004 08:18:51 -0700
| Newsgroups | gmane.ietf.snmpv3 |
|---|---|
| Message-ID | <CFEE79A465B35C4385389BA5866BEDF00C78DA@mailsrvnt02.enet.sharplabs.com> |
Hi Pekka, SNMPv1 read-only still allows anyone INSIDE your network to monitor and read interesting configuration and event info from your routers by packet-sniffing. And your "direct" connection to your outside network manager had better be entirely non-Internet (or completely encrypted) if you want reasonable security and also availability for their network management functionality. I'd say secure SNMPv3 has a lot to offer in your network. Cheers, - Ira Ira McDonald (Musician / Software Architect) Blue Roof Music / High North Inc PO Box 221 Grand Marais, MI 49839 phone: +1-906-494-2434 email: [email protected] -----Original Message----- From: [email protected] [mailto:[email protected]]On Behalf Of Pekka Savola Sent: Thursday, September 23, 2004 12:51 AM To: David B Harrington Cc: [email protected]; [email protected] Subject: RE: [Isms] Why SNMPv3? [WG Review: Integrated Security Model for SNMP (isms)] <...snip...> Let's consider our particular case (a national research network). I guess it should be quite common. 1) we only use SNMP for read-only access. 2) we only use SNMP to the routers from (about) two network management hosts within our own network. 2.b) there is one external host from a network monitoring organization, using separate [direct] connectivity, which has the same RO privileges 3) we restrict the access to the SNMP port [in all the routers] to the IP addresses of the network management. 4) we eliminate IP spoofing of the network management host addresses (actually all the addresses, but that's beside the point) at the edge. -- Pekka Savola "You each name yourselves king, yet the Netcore Oy kingdom bleeds." Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings