MIDCOM MIB Juergen Quittek, Martin Stiemerling, Pyda Srisuresh 60th IETF meeting, MIDCOM session.

Slides:



Advertisements
Similar presentations
XML Configuration Access Protocol (XCAP) Jonathan Rosenberg dynamicsoft.
Advertisements

DISTRIBUTED MANAGEMENT THREE APPROACHES ARE BEING DEFINED MIB BASED EXPRESSION MIB EVENT MIB NOTIFICATION LOG MIB SCRIPT BASED SCRIPT MIB SCHEDULE MIB.
TCP/IP Protocol Suite 1 Chapter 21 Upon completion you will be able to: Network Management: SNMP Understand the SNMP manager and the SNMP agent Understand.
December 10, Policy Terminology - 01 Report for 49th IETF Preview for AAA Arch RG John Schnizlein.
Check Disk. Disk Defragmenter Using Disk Defragmenter Effectively Run Disk Defragmenter when the computer will receive the least usage. Educate users.
Session-based Security Model for SNMPv3 (SNMPv3/SBSM) David T. Perkins Wes Hardaker IETF November 12, 2003.
McGraw-Hill The McGraw-Hill Companies, Inc., 2000 SNMP Simple Network Management Protocol.
FIREWALL TECHNOLOGIES Tahani al jehani. Firewall benefits  A firewall functions as a choke point – all traffic in and out must pass through this single.
Framework & Requirements for an Access Node Control Mechanism in Broadband Multi-Service Networks ANCP WG IETF 70 – Vancouver draft-ietf-ancp-framework-04.txt.
PPSP Tracker Protocol draft-gu-ppsp-tracker-protocol PPSP WG IETF 82 Taipei Rui Cruz (presenter) Mário Nunes, Yingjie Gu, Jinwei Xia, David Bryan, João.
03/20/01Pyda Srisuresh - Jasmine Networks1 Framework for interfacing with NAT Pyda Srisuresh.
Firewall and Internet Access Mechanism that control (1)Internet access, (2)Handle the problem of screening a particular network or an organization from.
Dean Cheng Jouni Korhonen Mehamed Boucadair
SDP negotiation of DataChannel sub-protocols draft-ejzak-mmusic-data-channel-sdpneg-02 draft-ejzak-dispatch-msrp-usage-data-channel-01 IETF 91 Honolulu.
1 Notification Rate Control draft-ietf-sipcore-event-rate-control th IETF,
1 Event Throttle draft-niemi-sipping-event-throttle th IETF, Minneapolis.
Framework & Requirements for an Access Node Control Mechanism in Broadband Multi-Service Networks ANCP WG IETF 71 – Philadelphia draft-ietf-ancp-framework-05.txt.
0 NAT/Firewall NSLP IETF 62th – March 2005 draft-ietf-nsis-nslp-natfw-05.txt Martin Stiemerling, Hannes Tschofenig, Cedric Aoun.
1 Network Management: SNMP The roots of education are bitter, but the fruit is sweet. - Aristotle.
Web Services Management Framework by Umut Bultan & Gül Hünerkar.
Yang Shi (Richard), Yong Zhang IETF 74 th 26 March 2009, San Francisco CAPWAP WG MIB Drafts Report.
Real-time Flow Management 2 BOF: Remote Packet Capture Extensions Jürgen Quittek NEC Europe Ltd, Heidelberg, Germany Georg Carle GMD.
SNMP 1. SNMP is an Internet protocol developed by the IETF. It is designed to facilitate the exchange of management information between network elements.
© 2003, Cisco Systems, Inc. All rights reserved. CSIDS 4.0—15-1 Chapter 15 Blocking Configuration.
ESA UNCLASSIFIED – For Official Use Workshop #23 Pasadena, USA 25 rd March 2015 Sam Cooper Common services update (part 2)
IETF-81, Quebec City, July 25-29, 2011
Generic Aggregation of Resource Reservation Protocol (RSVP) for IPv4 and IPv6 Reservation over PCN domains Georgios Karagiannis, Anurag Bhargava draft-ietf-tsvwg-rsvp-pcn-01.
NSIS NAT/Firewall NSLP Martin Stiemerling, Hannes Tschofenig, Miquel Martin, Cedric Aoun NSIS WG, 59th IETF.
PSAMP MIB Status Managed Objects for Packet Sampling A Status Report Thomas Dietz Benoit Claise
Real-Time Streaming Protocol draft-ietf-mmusic-rfc2326bis-01.txt Magnus Westerlund.
1 © 2013 Cisco and/or its affiliates. All rights reserved. Tidal Enterprise Orchestrator Cisco Service Portal Adapter Training October, 2012.
ISMS IETF72 David Harrington. Status IETF72 Transport Subsystem for the Simple Network Management Protocol (SNMP) –IETF69: draft-ietf-isms-tmsm-09.txt.
A Framework for Session Initiation Protocol User Agent Profile Delivery (draft-ietf-sipping-config-framework-11) SIPPING – IETF 68 Mar 19, 2007 Sumanth.
Dean Cheng 81 st IETF Quebec City RADIUS Extensions for CGN Configurations draft-cheng-behave-cgn-cfg-radius-ext
Session Traversal Utilities for NAT (STUN) IETF-92 Dallas, March 26, 2015 draft-ietf-tram-stunbis Marc Petit-Huguenin, Gonzalo Salgueiro.
7/27/2004IETF San-Diego Plenary meeting 8/2004 EPON MIBs Lior Khermosh – Passave Technologies
Nov. 9, 2004IETF61 PANA WG PANA Specification Last Call Issues Yoshihiro Ohba, Alper Yegin, Basavaraj Patil, D. Forsberg, Hannes Tschofenig.
Slide title In CAPITALS 50 pt Slide subtitle 32 pt RTSP draft-ietf-mmusic-rfc2396bis-10 Magnus Westerlund Co-auhtors: Henning Schulzrinne, Rob Lanphier,
0 NAT/Firewall NSLP IETF 63th – August 2005 draft-ietf-nsis-nslp-natfw-07.txt Martin Stiemerling, Hannes Tschofenig, Cedric Aoun.
Slide 1 2/22/2016 Policy-Based Management With SNMP SNMPCONF Working Group - Interim Meeting May 2000 Jon Saperia.
July 28, 2009BLISS WG IETF-751 Shared Appearance of a SIP AOR draft-ietf-bliss-shared-appearances-03 Alan Johnston Mohsen Soroushnejad Venkatesh Venkataramanan.
SIP Events: Changes and Open Issues IETF 50 / SIP Working Group Adam Roach
IPFIX MIB Status Managed Object for IP Flow Export A Status Report Thomas Dietz Atsushi Kobayashi
NSIS NAT/Firewall Signaling NSIS Interim Meeting Romsey/UK, June 2004 Martin Stiemerling, Hannes Tschofenig, Cedric Aoun.
Draft-ietf-behave-nat-udp-00 NAT Behavioral Requirements for Unicast UDP draft-ietf-behave-nat-upd-00 François Audet - Cullen Jennings.
Copyright © 2007, Oracle. All rights reserved. Managing Items and Item Catalogs.
DICOMwebTM 2015 Conference & Hands-on Workshop University of Pennsylvania, Philadelphia, PA September 10-11, 2015 DICOMweb Workflow API (UPS-RS) Jonathan.
Multiple Interfaces (MIF) WG documents status MIF WG IETF 80, Prague Problem statement and current practices documents.
I2rs Requirements for NETCONF IETF 93. Requirement Documents
CCNA4-1 Chapter 7-1 NAT Chapter 11 Routing and Switching (CCNA2)
12/14/00IETF 49 - Pyda Srisuresh1 Framework for interfacing with NAT Pyda Srisuresh.
SNMP.
Managed Objects for Packet Sampling
MIDCOM Protocol Semantics 55th IETF
Connectionless OAM yang model
PANA Issues and Resolutions
Instructor Materials Chapter 9: NAT for IPv4
Topic #1 & #5 “All that has to do with header formats”
Routing and Switching Essentials v6.0
DHCP Lease Query DHC Working Group Kim Kinnear Cisco Systems
Introduction to Networking
Subscribing to YANG datastore push updates draft-netconf-yang-push-00 IETF #94 Yokohama A. Clemm A. Gonzalez Prieto
Distributed Mobility Management (DMM) WG DMM Work Item: Forwarding Path & Signaling Management (FPSM) draft-ietf-dmm-fpc-cpdp-01.txt IETF93, Prague.
* Essential Network Security Book Slides.
Layer Management and MIBs Sections Report
Instructor Materials Chapter 9: NAT for IPv4
Setting Up Firewall using Netfilter and Iptables
– Chapter 3 – Device Security (B)
Chapter 16 Host Configuration : BOOTP and DHCP
Chapter 11: Network Address Translation for IPv4
Presentation transcript:

MIDCOM MIB Juergen Quittek, Martin Stiemerling, Pyda Srisuresh 60th IETF meeting, MIDCOM session

IETF 60 MIDCOM MIB2 Changes Since Version -00 A lot of editorial changes  added a lot of clarifications  renamed signaling group to transaction group  added entity relationship diagram for MIB tables Added Section 7 on Usage examples for monitoring resources (NAT, firewall)  not yet complete (firewall part is missing) Completed Security Considerations

IETF 60 MIDCOM MIB3 Issue 1: MIB Structure Changes MIDCOM MIB Tables  Session Table  Rule Table  Group Table  Capabilities Table  IP interface configuration  Notifications  Firewall Configuration Table  Resource Mapping Table  Session and Rule Statistics implementing MIDCOM semantics add on's Proposed changes in structure  Merge firewall Configuration table and Capabilities table?  Replace session table by Target MIB and/or Notification MIB? next version needs study

IETF 60 MIDCOM MIB4 Issue 1: MIB Structure Changes Removing Session Table  The session table mainly serves for  subscribing to notifications  distinguish MIDCOM clients using the same SNMP manager  Instead of specifying a session table, the existing Target MIB and/or Notification MIB should be used.

IETF 60 MIDCOM MIB5 Issue 2: Firewall Configuration Request for more detailed assignment of firewall priority Currently, we have the same priority for all rules per interface. This is OK even for overlapping rules since we decided to have allow actions only and no deny actions. Issue solved.

IETF 60 MIDCOM MIB6 Issue 3: Notification Subscription No means for configuring which notifications to receive  Which essential transaction needs notifications? Supported Notifications  Session termination  Rule event  Group event Alternative solutions:  adding a BITS object to session table  or use Target MIB / Notifications MIB

IETF 60 MIDCOM MIB7 Issue 4: Idempotency MidcomRuleLifetime can have idempotency failures  resulting in longer lifetime than intended  depending on SNMP retransmission timeout  in general the longer lifetime will be known by the MIDCOM agent  Solution: The total lifetime needs to be stored  either at the MIDCOM server (additional managed object)  or at the MIDCOM client (additional client state)  preference: use additional managed object in rule table There are further idempotency problems with session index and rule index generated from session table  These will probably disappear, if the session table is replaced

IETF 60 MIDCOM MIB8 Issue 5: MaxIdleTime Should the default be  using the NAT's default maximum idle time?  would require an additional object that reports the default idle time  or disabling the max idle time mechanism?

IETF 60 MIDCOM MIB9 Issue 6: MaxIdleTime for PRR Is MaxIdleTime an input parameter to PRR?  MIB uses a Lifetime attribute for each policy rule  Additionally, for each policy rule, a MaxIdleTime attribute can be defined  specifies an idle time after which the policy may be removed  The Policy Reserve Rule (PRR) does not contain any action affecting packets, it just reserves resources to be used by a policy.  Solution: make it an optional parameter to PRR

IETF 60 MIDCOM MIB10 Issue 7: Naming Conflict Naming conflict between MIDCOM terminology and NAT terminology  MIDCOM semantics uses internal/inside and external/outside  NAT MIB uses privateSource/privateDestination and publicSource/publicDestination  Solution: use one of them consistently

IETF 60 MIDCOM MIB11 Recently Raised Issues midcomRuleNatService  raised by Suresh  For what kind of middleboxes is this object useful? midcomInsideInterface and midcomOutsideInterface are missing  raised by Bob Penfield  to be discussed RuleLifetime and/or RuleMaxIdletime differ for policy rules using the same resource