U2.5 SNMPv1

Description

Nework Security Mind Map on U2.5 SNMPv1, created by jjanesko on 09/04/2014.
jjanesko
Mind Map by jjanesko, updated more than 1 year ago
jjanesko
Created by jjanesko about 10 years ago
50
0

Resource summary

U2.5 SNMPv1
  1. general
    1. ISO 7498-2
      1. network mgt protocols provide
        1. configuration management
          1. accounting
            1. event logging
            2. defines network mgt security in general
            3. SNMP RFCs
              1. RFC 1155-1157
                1. RFC 1441-1448
                  1. RFC 2570-2576
                2. architectural model
                  1. SNMP protocol entities

                    Attachments:

                    1. at least one management station
                      1. acts as management role
                      2. a number of network elements
                        1. acts as agent role
                      3. all entities have a management information base (MIB)
                        1. SNMP access MIB on top of UDP and IP

                          Attachments:

                          1. connectionless!!
                            1. ports
                              1. 161
                                1. for requests (GET, SET)
                                2. 162
                                  1. for traps
                          2. 3 operations
                            1. GET
                              1. enables mgt station to retrieve object values from managed entity
                              2. SET
                                1. enables the management station to set object values in managed entity
                                2. TRAP
                                  1. enables a managed entity to notify the management station of significant events
                                  2. implemented with "protocol data units" (PDUs)
                                    1. 3 parts to a PDU message
                                      1. version
                                        1. community
                                          1. SNMP operation
                                      2. security services provided
                                        1. authentication service
                                          1. Assure the destination device that the SNMP PDU does come from the source from which it claims to be
                                          2. access control service
                                            1. Limit the SNMP operations that a device can request according to device's identity
                                          3. security mechanisms
                                            1. authentication mechanism
                                              1. community name
                                                1. All PDUs from mgt station must contain the community name
                                              2. access mode mechanism
                                                1. community profile
                                                  1. Each device stores a community profile that specifies which MIB values and how those values can be access by an entity bearing the associated community name.
                                              3. threats
                                                1. primary
                                                  1. data modification
                                                    1. masquerade
                                                    2. secondary
                                                      1. message stream modification
                                                        1. eavesdropping
                                                      2. vulnerabilities
                                                        1. no integrity protection
                                                          1. no timeliness guarantee
                                                            1. no replay protection
                                                              1. weath authentication mechanism
                                                                1. no confidentiality protection
                                                                Show full summary Hide full summary

                                                                Similar

                                                                U2.6 SNMPv3
                                                                jjanesko
                                                                U2.1 Cables, Hubs, Sniffers
                                                                jjanesko
                                                                U2.4 LANs, MANs, WANs
                                                                jjanesko
                                                                U2.1 Cables,Hubs,Sniffers- Thin Ethernet
                                                                jjanesko
                                                                U2.5 SNMPv1 - architectural model
                                                                jjanesko
                                                                U2.1 Cables, Hubs, Sniffers - Hub Diagram
                                                                jjanesko
                                                                U2.2 Switches, ARP - ARP spoofing steps
                                                                jjanesko
                                                                U2.3 TCP, Routers - Router Diagram
                                                                jjanesko
                                                                U2.5 SNMPv1 - SNMPv1 protocol stack
                                                                jjanesko
                                                                U2.2 Switches, ARP
                                                                jjanesko
                                                                U2.3 TCP, Routers, VLAN
                                                                jjanesko