Re: [OPSAWG] Syslog message to Remote Rerver

"ietfdbh" <[email protected]> Mon, 25 Feb 2013 01:54:14 -0500
Newsgroups gmane.ietf.syslog,gmane.ietf.opsawg
Message-ID <[email protected]>
This is a multipart message in MIME format.

--===============6548515804875041247==
Content-Type: multipart/alternative;
	boundary="----=_NextPart_000_0044_01CE12FB.03DF4C20"
Content-Language: en-us

This is a multipart message in MIME format.

------=_NextPart_000_0044_01CE12FB.03DF4C20
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit

 

 

From: [email protected] [mailto:[email protected]] On Behalf Of
Aditya Dogra (addogra)
Sent: Thursday, February 21, 2013 11:25 AM
To: [email protected]; [email protected]
Subject: [OPSAWG] Syslog message to Remote Rerver

 

Hi All ,

 

Currently syslog messages collected locally on the network device are
transmitted to the remote syslog servers as per RFC 5424 (UDP protocol used
for transmission) and RFC 3195 (TCP protocol used for transmission) 

 

[dbh>] RFC5424 defines the IETF version of the syslog protocol message
format (not the UDP transport).

RFC5424 RECOMMENDS using a TLS-based transport (RFC5425) rather than a
UDP-based or plain-TCP-based transport for syslog.

 

If you use a UDP-based transport for interoperability, it should probably
follow RFC5426.

The IETF standard for syslog over UDP (RFC5426) states:

"   Network administrators and architects should be aware of the

   significant reliability and security issues of this transport, which

   stem from the use of UDP."

 

Note that RFC6587 (plain TCP transport for syslog) is Historic, and contains
an IESG Note:

 

   The IESG does not recommend implementing or deploying syslog over

   plain tcp, which is described in this document, because it lacks the

   ability to enable strong security [RFC3365].

 

   Implementation of the TLS transport [RFC5425] is recommended so that

   appropriate security features are available to operators who want to

   deploy secure syslog.  Similarly, those security features can be

   turned off for those who do not want them.

 

 

However, we have observed that increasingly, customers are using syslog
messages archived in the remote server for business logic .

 

[dbh>] If customers are using archived messages, they might want to consider
using signing syslog messages.

       RFC5848, Signed syslog,  describes a mechanism to add origin
authentication,

   message integrity, replay resistance, message sequencing, and

   detection of missing messages to the transmitted syslog messages.

Signed syslog helps ensure integrity of messages both in-transit and in
archived storage.

I think that would be a valuable feature in support of business logic.

 

David Harrington

[email protected]

+1-603-828-1401

co-chair, syslog WG

 

In some networks, it is possible that some of the syslog messages may be
dropped due to link failure or other network conditions. 

However, the customers are expecting much higher resiliency for the syslog
messages. 

 

The questions we seek clarification are: 

 

a)         What are the expectations from the external syslog delivery? 

 

b)         Should we rely on syslog's alone ? Please note that SNMP traps
functionality for network management is also there.?

 

 

 

Your thoughts and suggestions much appreciated. 

 

 

Regards,

Aditya dogra

 

 


------=_NextPart_000_0044_01CE12FB.03DF4C20
Content-Type: text/html;
	charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" =
xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" =
xmlns=3D"http://www.w3.org/TR/REC-html40"><head><meta =
http-equiv=3DContent-Type content=3D"text/html; =
charset=3Dus-ascii"><meta name=3DGenerator content=3D"Microsoft Word 14 =
(filtered medium)"><style><!--
/* Font Definitions */
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
	{font-family:Consolas;
	panose-1:2 11 6 9 2 2 4 3 2 4;}
@font-face
	{font-family:"Book Antiqua";
	panose-1:2 4 6 2 5 3 5 3 3 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p.MsoPlainText, li.MsoPlainText, div.MsoPlainText
	{mso-style-priority:99;
	mso-style-link:"Plain Text Char";
	margin:0in;
	margin-bottom:.0001pt;
	font-size:10.5pt;
	font-family:Consolas;}
span.PlainTextChar
	{mso-style-name:"Plain Text Char";
	mso-style-priority:99;
	mso-style-link:"Plain Text";
	font-family:Consolas;}
span.EmailStyle19
	{mso-style-type:personal;
	font-family:"Book Antiqua","serif";
	color:windowtext;}
span.EmailStyle20
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]--></head><body lang=3DEN-US link=3Dblue =
vlink=3Dpurple><div class=3DWordSection1><p class=3DMsoNormal><a =
name=3D"_MailEndCompose"><span =
style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></a></p><p =
class=3DMsoNormal><span =
style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p><div><div =
style=3D'border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in =
0in 0in'><p class=3DMsoNormal><b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'>From:</span>=
</b><span style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'> =
[email protected] [mailto:[email protected]] <b>On Behalf Of =
</b>Aditya Dogra (addogra)<br><b>Sent:</b> Thursday, February 21, 2013 =
11:25 AM<br><b>To:</b> [email protected]; =
[email protected]<br><b>Subject:</b> [OPSAWG] Syslog message to Remote =
Rerver<o:p></o:p></span></p></div></div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt;font-family:"Book Antiqua","serif"'>Hi All =
,<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt;font-family:"Book =
Antiqua","serif"'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt;font-family:"Book Antiqua","serif"'>Currently =
syslog messages collected locally on the network device are transmitted =
to the remote syslog servers as per RFC 5424 (UDP protocol used for =
transmission) and RFC 3195 (TCP protocol used for transmission) =
<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt;font-family:"Book =
Antiqua","serif";color:#1F497D'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal =
style=3D'line-height:14.4pt;background:white'><b><i><span =
style=3D'color:#1F497D'>[dbh&gt;] </span></i></b><span =
style=3D'font-size:10.0pt;font-family:"Courier New"'>RFC5424 defines the =
IETF version of the syslog protocol message format (not the UDP =
transport).<o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'line-height:14.4pt;background:white'><span =
style=3D'font-size:10.0pt;font-family:"Courier New"'>RFC5424 RECOMMENDS =
using a TLS-based transport (RFC5425) rather than a UDP-based or =
plain-TCP-based transport for syslog.<o:p></o:p></span></p><p =
class=3DMsoNormal style=3D'line-height:14.4pt;background:white'><span =
style=3D'font-size:10.0pt;font-family:"Courier =
New"'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal =
style=3D'line-height:14.4pt;background:white'><span =
style=3D'font-size:10.0pt;font-family:"Courier New"'>If you use a =
UDP-based transport for interoperability, it should probably follow =
RFC5426.<o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'line-height:14.4pt;background:white'><span =
style=3D'font-size:10.0pt;font-family:"Courier New"'>The IETF standard =
for syslog over UDP (RFC5426) states:<o:p></o:p></span></p><p =
class=3DMsoNormal style=3D'line-height:14.4pt'><span =
style=3D'font-size:10.0pt;font-family:"Courier New"'>&#8220;&nbsp;&nbsp; =
Network administrators and architects should be aware of =
the<o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'line-height:14.4pt'><span =
style=3D'font-size:10.0pt;font-family:"Courier New"'>&nbsp;&nbsp; =
significant reliability and security issues of this transport, =
which<o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'line-height:14.4pt;background:white'><span =
style=3D'font-size:10.0pt;font-family:"Courier New"'>&nbsp;&nbsp; stem =
from the use of UDP.&#8221;<o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'line-height:14.4pt;background:white'><span =
style=3D'font-size:10.0pt;font-family:"Courier =
New"'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal =
style=3D'line-height:14.4pt;background:white'><span =
style=3D'font-size:10.0pt;font-family:"Courier New"'>Note that RFC6587 =
(plain TCP transport for syslog) is Historic, and contains an IESG =
Note:<o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'line-height:14.4pt;background:white'><span =
style=3D'font-size:10.0pt;font-family:"Courier =
New"'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal =
style=3D'line-height:14.4pt;background:white'><span =
style=3D'font-size:10.0pt;font-family:"Courier New"'>&nbsp;&nbsp; The =
IESG does not recommend implementing or deploying syslog =
over<o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'line-height:14.4pt;background:white'><span =
style=3D'font-size:10.0pt;font-family:"Courier New"'>&nbsp;&nbsp; plain =
tcp, which is described in this document, because it lacks =
the<o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'line-height:14.4pt;background:white'><span =
style=3D'font-size:10.0pt;font-family:"Courier New"'>&nbsp;&nbsp; =
ability to enable strong security [RFC3365].<o:p></o:p></span></p><p =
class=3DMsoNormal style=3D'line-height:14.4pt;background:white'><span =
style=3D'font-size:10.0pt;font-family:"Courier =
New"'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal =
style=3D'line-height:14.4pt;background:white'><span =
style=3D'font-size:10.0pt;font-family:"Courier New"'>&nbsp;&nbsp; =
Implementation of the TLS transport [RFC5425] is recommended so =
that<o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'line-height:14.4pt;background:white'><span =
style=3D'font-size:10.0pt;font-family:"Courier New"'>&nbsp;&nbsp; =
appropriate security features are available to operators who want =
to<o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'line-height:14.4pt;background:white'><span =
style=3D'font-size:10.0pt;font-family:"Courier New"'>&nbsp;&nbsp; deploy =
secure syslog.&nbsp; Similarly, those security features can =
be<o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'line-height:14.4pt;background:white'><span =
style=3D'font-size:10.0pt;font-family:"Courier New"'>&nbsp;&nbsp; turned =
off for those who do not want them.<o:p></o:p></span></p><p =
class=3DMsoNormal style=3D'line-height:14.4pt;background:white'><span =
style=3D'font-size:10.0pt;font-family:"Courier =
New"'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Book =
Antiqua","serif"'>However, we have observed that increasingly, customers =
are using syslog messages archived in the remote server for business =
logic .<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal =
style=3D'line-height:14.4pt;background:white'><b><i><span =
style=3D'color:#1F497D'>[dbh&gt;] </span></i></b><span =
style=3D'font-size:10.0pt;font-family:"Courier New"'>If customers are =
using archived messages, they might want to consider using signing =
syslog messages.<o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'line-height:14.4pt;background:white'><b><i><span =
style=3D'color:#1F497D'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
</span></i></b><span style=3D'color:#1F497D'>&nbsp;</span>RFC5848, =
Signed syslog<b><i>, &nbsp;</i></b><span =
style=3D'font-size:10.0pt;font-family:"Courier New"'>describes a =
mechanism to add origin authentication,<o:p></o:p></span></p><p =
class=3DMsoNormal style=3D'line-height:14.4pt;background:white'><span =
style=3D'font-size:10.0pt;font-family:"Courier New"'>&nbsp;&nbsp; =
message integrity, replay resistance, message sequencing, =
and<o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'line-height:14.4pt;background:white'><span =
style=3D'font-size:10.0pt;font-family:"Courier New"'>&nbsp;&nbsp; =
detection of missing messages to the transmitted syslog =
messages.<o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'line-height:14.4pt;background:white'><span =
style=3D'font-size:10.0pt;font-family:"Courier New"'>Signed syslog helps =
ensure integrity of messages both in-transit and in archived =
storage.<o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'line-height:14.4pt;background:white'><span =
style=3D'font-size:10.0pt;font-family:"Courier New"'>I think that would =
be a valuable feature in support of business =
logic.<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'=
>David Harrington</span><span =
style=3D'font-size:12.0pt;font-family:"Times New =
Roman","serif";color:#1F497D'><o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'=
><a =
href=3D"mailto:[email protected]">[email protected]</a></span><span =
style=3D'font-size:12.0pt;font-family:"Times New =
Roman","serif";color:#1F497D'><o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'=
>+1-603-828-1401</span><span =
style=3D'color:#1F497D'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt;font-family:"Book =
Antiqua","serif";color:#1F497D'>co-chair, syslog =
WG<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Book =
Antiqua","serif"'>In some networks, it is possible that some of the =
syslog messages may be dropped due to link failure or other network =
conditions. <o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt;font-family:"Book Antiqua","serif"'>However, =
the customers are expecting much higher resiliency for the syslog =
messages. <span style=3D'color:#1F497D'><o:p></o:p></span></span></p><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Book =
Antiqua","serif"'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt;font-family:"Book Antiqua","serif"'>The =
questions we seek clarification are: <o:p></o:p></span></p><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Book =
Antiqua","serif"'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt;font-family:"Book =
Antiqua","serif"'>a)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
What are the expectations from the external syslog delivery? =
<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt;font-family:"Book =
Antiqua","serif"'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt;font-family:"Book =
Antiqua","serif"'>b)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
Should we rely on syslog's alone ? Please note that SNMP traps =
functionality for network management is also =
there.?<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt;font-family:"Book =
Antiqua","serif"'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt;font-family:"Book =
Antiqua","serif"'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt;font-family:"Book =
Antiqua","serif"'>&nbsp;<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt;font-family:"Book Antiqua","serif"'>Your =
thoughts and suggestions much appreciated. <o:p></o:p></span></p><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Book =
Antiqua","serif"'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt;font-family:"Book =
Antiqua","serif"'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal>Regards,<o:p></o:p></p><p class=3DMsoNormal>Aditya =
dogra<o:p></o:p></p><p class=3DMsoNormal><o:p>&nbsp;</o:p></p><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p></div></body></html>
------=_NextPart_000_0044_01CE12FB.03DF4C20--


--===============6548515804875041247==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Syslog mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/syslog

--===============6548515804875041247==--