Re: linux core net-snmp management

Iacopo Masi <[email protected]>
Newsgroups gmane.network.net-snmp.user
Message-ID <[email protected]>
lunedì 5 marzo 2007 11:10:14 hai scritto:

>
> That's probably the most interesting one.
> We did have a firewall module, but due to licensing restrictions,
> it can't be distributed with the rest of the source.  AFAIK, it's
> still available (see agent/mibgroup/ipfwchains/README), but
> it probably hasn't been maintained or updated for quite a while.
>

I downloaded the ipfwchain MIB Module. It's a good point to start, but the 
problem is that quite old. And moreover It can only list table of firewall 
and flush chains. It is not able to add some specifies rules.

For the other parts like LAN,WLAN e Routing, If they are covered by net-snmp 
agent,
How do I query them?
Is there some special file.conf or MIBS to configure?

> > For example, let's take the Firewall example, that is covered in linux by
> > iptables and netfilter. I would create a snmp agent that could get the
> > list of iptables entries for all chains and all tables. And by the way
> > the agent could receive a snmpset command to add some new rules.
> >
> > How do I create this?
>
> Well the first thing to do would be to analyse the requirements of
> both monitoring and managing iptables and netfilter, and come up
> with a design for the MIB.
ok, So do you think is better to design a MIB file to deal with?
Please,  Could you  send me some other wiki or howto, (if U have it of course) 
that is not the just read [1].

Many thanks.
>
> There's no point in even thinking about implementing this in
> code, until you've got a suitable MIB design to work with.
>
> > In other way, Should I deal with "/proc/net/dev" or with "ifconfig" for
> > the example of the LAN interfaces?
>
> If possible, it's always best to work with API calls and/or status
> files (or pseudo-files).  Invoking a sub-command such as "ifconfig"
> should always be kept as a last resort.
>    This sometimes seems the easiest way to proceed, but it's
> a lazy form of development, and tends to store up problems for
> the future.
>   If there's a clean interface, then use it!
Yes, these are best practices! you're right,man.



[1]http://www.net-snmp.org/tutorial/tutorial-5/toolkit/mfd/index.html

--
best regards,
iacopo

-------------------------------------------------------------------------
Take Surveys. Earn Cash. Influence the Future of IT
Join SourceForge.net's Techsay panel and you'll get the chance to share your
opinions on IT & business topics through brief surveys-and earn cash
http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV

_______________________________________________
Net-snmp-users mailing list
[email protected]
Please see the following page to unsubscribe or change other options:
https://lists.sourceforge.net/lists/listinfo/net-snmp-users
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.3 (GNU/Linux)

iD8DBQBF7DAZxxDdR8gVUnIRArsGAKDEXUDI6odgnRwGNTXQP//oSNDUxwCeJ7FW
NW2LI4GySxrutKKkHl/bakg=
=7wNg
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.