【正文】
a NMS in response to a GetRequest, a GetNextRequest or a SetRequest used to return requested values or to indicate success or failure of set request includes an error status and an error index 42 SNMP: Trap Message ? trap message: message from an agent to a NMS in response to a status change or event in the agent ? trap conditions: coldStart warmStart linkDown linkUp authenticationFailure egpNeighborLoss enterpriseSpecific 43 SNMP: InformRequest ? like a “reliable trap” ? designed to be used between work management stations ? expanding to other uses ? resent until acknowledged 44 SNMP: Communities ? provides trivial security ? like a password ? munity name sent in clear over with each message ? some agents have more than one munity for different access modes these are know as views ? some agents can link access to munity name and IP address of NMS 45 Summary ? Simple Network Management Protocol ? mostly a query response system ? little work traffic initiated by agent ? currently only a primitive security system SNMPv2 was to have real security but working group fragmented, SNMPv3 now ready ? uses database defined in MIB ? can have enterprise extensions to MIB ? SMI defines structure of MIB ? SMI defines data structure using Use CMU packge: snmpwalk 作業(yè) 任選 1題: SNMPv SNMPv RMON,分組完成,下堂課每組 25分鐘介紹并回答提問(wèn)。 48 分組 ? SNMPv2; 黎燦兵、李晗、王亞磊、耿文驥 ? SNMPv3: 葉紹志、李賀武、陳旭春、練鍇、許靜芳 ? RMON: 劉亮、馮偉、楊超、楊繼章 Brief on SNMP RFC1098 Simple Network Management Protocol (SNMP). . Case, M. Fedor, . Schoffstall, C. Davin. Apr011989. (Format: TXT=71563 bytes) (Obsoletes RFC1067) (Obsoleted by RFC1157) (Status: UNKNOWN) SNMPv1 SNMPv2c,SNMPv2*,SNMPv2u, … SNMPv3 50 SNMPv3 ? add security to SNMPv2 secure SET support protect against modification of information masquerade message stream modification disclosure does not deal with denial of service traffic analysis 51 SNMPv3, contd. ? three levels of security no authentication, no privacy authentication, no privacy authentication amp。 privacy ? can support more than one security model userbased security model defined security based on “name” of a user ? new message format to add security information ? overview in RFC 2261 RMON ? Remote Network Monitoring ? Defines remote monitoring MIB that supplements MIBII and is a step towards interwork management ? It extends SNMP functionality though it is simply a specification of a MIB ? Problem w/ MIBII Can obtain info that is purely local to individual devices Cannot easily learn about LAN traffic as a whole (eg like LANanalyzers or “remote monitors”) RMON1 / RMON2 structure 54