RE: [Isms] Why SNMPv3? [WG Review: Integrated Security Model for SNMP (isms)]

"McDonald, Ira" <[email protected]> Thu, 23 Sep 2004 08:18:51 -0700
Newsgroups gmane.ietf.snmpv3
Message-ID <CFEE79A465B35C4385389BA5866BEDF00C78DA@mailsrvnt02.enet.sharplabs.com>
Hi Pekka,

SNMPv1 read-only still allows anyone INSIDE your network to
monitor and read interesting configuration and event info
from your routers by packet-sniffing.

And your "direct" connection to your outside network manager
had better be entirely non-Internet (or completely encrypted)
if you want reasonable security and also availability for
their network management functionality.

I'd say secure SNMPv3 has a lot to offer in your network.

Cheers,
- Ira

Ira McDonald (Musician / Software Architect)
Blue Roof Music / High North Inc
PO Box 221  Grand Marais, MI  49839
phone: +1-906-494-2434
email: [email protected]

-----Original Message-----
From: [email protected] [mailto:[email protected]]On
Behalf Of Pekka Savola
Sent: Thursday, September 23, 2004 12:51 AM
To: David B Harrington
Cc: [email protected]; [email protected]
Subject: RE: [Isms] Why SNMPv3? [WG Review: Integrated Security Model
for SNMP (isms)]

<...snip...>

Let's consider our particular case (a national research network).  I
guess it should be quite common.

 1) we only use SNMP for read-only access.
 2) we only use SNMP to the routers from (about) two network 
management hosts within our own network.
 2.b) there is one external host from a network monitoring 
organization, using separate [direct] connectivity, which has the same 
RO privileges
 3) we restrict the access to the SNMP port [in all the routers] to 
the IP addresses of the network management.
 4) we eliminate IP spoofing of the network management host addresses
(actually all the addresses, but that's beside the point) at the edge.

-- 
Pekka Savola                 "You each name yourselves king, yet the
Netcore Oy                    kingdom bleeds."
Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings