Convergence of Network Management Protocols

Slides:



Advertisements
Similar presentations
YANG Boot Camp The YANG Gang IETF 71. YANG Boot Camp The YANG Gang IETF 71.
Advertisements

XCON - IETF 62 (March 2005) - Minneapolis 1 XCON data modeling – NETCONF, RDF and others draft-schulzrinne-sipping-emergency-req-01 draft-sipping-sos Henning.
Distributed components
2006 IEEE International Conference on Web Services ICWS 2006 Overview.
NS-H /11041 SNMP. NS-H /11042 Outline Basic Concepts of SNMP SNMPv1 Community Facility SNMPv3 Recommended Reading and WEB Sites.
A Heterogeneous Network Access Service based on PERMIS and SAML Gabriel López Millán University of Murcia EuroPKI Workshop 2005.
Polaris Financial Technologies Welcomes the members of Hyderabad chapter for the 2nd event on 4 th July 14 held by PACE (The Testing Practice)
Network Management Complexities Dan Romascanu (Contributed in discussions by Andy Bierman, David Harrington, Juergen Schoenwealder) IESG Retreat Boston,
1 Network Management and SNMP  What is Network Management?  ISO Network Management Model (FCAPS)  Network Management Architecture  SNMPv1 and SNMPv2.
Integrated Security Model for SNMPv3 (ISMS) pronounced "is" "miss" David T. Perkins & Wes Hardaker 60 th IETF August 6, 2004.
Session-based Security Model for SNMPv3 (SNMPv3/SBSM) David T. Perkins Wes Hardaker IETF November 12, 2003.
McGraw-Hill The McGraw-Hill Companies, Inc., 2000 SNMP Simple Network Management Protocol.
1 Introduction to Internet Network Management Mi-Jung Choi Dept. of Computer Science KNU
September, 2005What IHE Delivers 1 ITI Security Profiles – ATNA, CT IHE Vendors Webinar 2006 IHE IT Infrastructure Education Robert Horn, Agfa Healthcare.
1 © 1999 BMC SOFTWARE, INC. 2/10/00 SNMP Simple Network Management Protocol.
SMI to XSD Translations IETF70 David Harrington. Agenda The Need The Approaches Comparisons.
Abierman-nanog-30may03 1 XML Router Configs BOF Operator Involvement Andy Bierman
© Hitachi, Ltd All rights reserved. NETCONF Configuration I/F Advertisement by WSDL and XSD Hideki Okita, Tomoyuki Iijima, Yoshifumi Atarashi, Ray.
(Preliminary) Gap Analysis Hannes Tschofenig. Goal of this Presentation The IETF has developed a number of security technologies that are applicable to.
Abierman-netconf-mar03 1 NETCONF BOF 56th IETF San Francisco, California March 17, 2003 Discussion: Admin:
Slide 1 SNMPv3, SSH & Cisco Matthew G. Marsh Chief Scientist of the NEbraskaCERT.
Network Management Security
68th IETF – OPS area – XML MIB Modules XML MIB Modules draft-stephan-ops-xml-mib-module-template-00 draft-stephan-ops-xml-mib-module-template-00.
Do We Need a New Network Management Framework? David Harrington IETF66 OPS Area Meeting Montreal, Quebec, Canada.
SNMP for the PAA-EP protocol PANA wg - IETF 60 San Diego -> Yacine El Mghazli (Alcatel)
SNMPv3 1.DESIGN REQUIREMENTS 2.BIRTH & FEATURES of SNMPv3 3.ARCHITECTURE 4.SECURE COMMUNICATION - USER SECURITY MODEL (USM) 5. ACCESS CONTROL - VIEW BASED.
International Telecommunication Union ITU Seminar on the Standardization and ICT development for the Information Society Uzbekistan, 6-8 October 2003 Network.
XML Schema for Accessing SMIv2 Data Models IETF69 Chicago BOF David Harrington.
Management Attributes RADEXT WG November 8, 2005 Dave Nelson Greg Weber IETF-64, Vancouver.
Network Management Security
SubmissionZuniga and others1 XML for Wireless Network Management Juan-Carlos Zuniga, Marian Rudolf, Joe Kwak, InterDigital and Paul Gray, Jason Luther,
SNMP for the PAA-2-EP protocol PANA wg - IETF 59 Seoul -> Yacine El Mghazli (Alcatel)
ISMS IETF72 David Harrington. Status IETF72 Transport Subsystem for the Simple Network Management Protocol (SNMP) –IETF69: draft-ietf-isms-tmsm-09.txt.
SSHSM Issues David Harrington IETF64 ISMS WG Vancouver, BC.
Presentation at ISMS WG Meeting1 ISMS – March 2005 IETF David T. Perkins.
Requirements and Selection Process for RADIUS Crypto-Agility December 5, 2007 David B. Nelson IETF 70 Vancouver, BC.
Netconf Event Notifications IETF 66 Sharon Chisholm Hector Trevino
Copyright 2007, Information Builders. Slide 1 iWay Web Services and WebFOCUS Consumption Michael Florkowski Information Builders.
Netconf Schema Query Mark Scott IETF 70 Vancouver December 2007
RADIUS Extended Attributes for Management Authorization David B. Nelson IETF 62, RADEXT WG March 9, 2005.
YANG Background and Discussion: Why we need a new language for NETCONF configuration modeling The YANG Gang IETF 70 Vancouver, Canada.
RADIUS Attributes for Management Authorization David B. Nelson IETF 66, RADEXT WG July 10, 2006.
Topic 11 Network Management. SNMPv1 This information is specific to SNMPv1. When using SNMPv1, the snmpd agent uses a simple authentication scheme to.
YANG Modelling and NETCONF Protocol Discussion
Implementing Cisco Secure Access Solutions
The Transport Layer Implementation Services Functions Protocols
SBSM BOF Session-Based Security Model for SNMPv3
56th IETF syslog WG Chair: Chris Lonvick
Information Security Professionals
August 2004 at IETF-60 Thoughts on RADIUS Data Model Issues and Some Possible New Approaches -- Including Diameter Compatibility.
draft-ietf-netconf-reverse-ssh
EA C451 Vishal Gupta.
PAA-EP protocol considerations PANA wg - IETF 57 Vienna
Cryptography and Network Security Chapter 16
Introduction to Internet Network Management
NETCONF Configuration I/F Advertisement by WSDL and XSD
RADEXT WG RADIUS Attribute Guidelines draft-weber-radius-attr-guidelines-01.txt Greg Weber November 8th, 2005 v1 IETF-64, Vancouver.
Cisco Real Exam Dumps IT-Dumps
draft-levin-xcon-cccp-02.txt Orit Levin
IETF68 Mini-BOF MIB-Doctor-Sponsored MIB Document Templates
SNMP Usage Recommendations
Chapter 8: Monitoring the Network
IEEE MEDIA INDEPENDENT HANDOVER DCN:
PAA-2-EP protocol PANA wg - IETF 58 Minneapolis
5G Use Case Configuration & PNF SW Upgrade using NETCONF ONAP DDF, Jan 9, 2019 Ericsson.
O&M Area Working Group WG
Network Management Security
Standards, Models and Language
Presentation transcript:

Convergence of Network Management Protocols David Harrington IETF64 O&M Area Meeting Vancouver, BC

Duplicate Efforts for Secure NM A number of efforts occurring in the IETF are related to network management and security. Many of the options being considered are similar, but decisions are often made in isolation. Working together would be better resource management. Purpose of this presentation is to describe some efforts under way so people are aware of other work in a similar problem space Having a “balanced” security approach between NM protocols would provide a more secure NM environment.

Message Security WGs are striving to integrate Network Management protocols, including UDP-based, with existing security solutions Many security protocols run over TCP-based transport; few run over UDP-based transport A survey of NANOG operators showed the most popular for Network Management authentication: 66% local accounts 49% SSH

Message Security + Transport Protocol SNMP/ISMS Netconf Syslog Content MIBs TBD Not Standard Modeling Language SMIv2 XML Schema Structured ASCII Authorization RADIUS TBD Operations Get-*/SET GET/EDIT none NM Protocols are converging on common security solutions Netconf runs over SSH (mandatory), BEEP, and SOAP ISMS WG developing SSH security model for SNMP SSH chosen as first Transport-mapped security model to be developed Architected to permit additional secure transports, such as SASL/TLS Syslog discussing secure transports possibly SSH in common with Netconf and SNMP TLS or other protocol may better fit syslog requirements Message Security USM->SSH SSH SSH or TLS? Transport UDP->TCP TCP UDP->TCP?

Operations Protocol ISMS Netconf Syslog Content MIBs TBD Not Standard Modeling Language SMIv2 XML Schema Structured ASCII Authorization RADIUS TBD Operations GET*/Set/Notify GET/EDIT/Notify Log/Notify Operations for Netconf and SNMP are similar, but snmp currently offers finer granularity. Ultimately, the operations are read and write and notifications. We should discuss how operations can be shared and correlated. Message Security USM->SSH SSH SSH or TLS Transport UDP->TCP TCP UDP->TCP

Authorization Protocol ISMS Netconf Syslog Content MIBs TBD Not Standard Modeling Language SMIv2 XML Schema Structured ASCII Authorization RADIUS/VACM All-or-nothing All-or-nothing Operations GET-*/SET GET/EDIT none SNMPv3 uses statically-defined view-based access control Groups have access to assigned views for specific operation types Currently, Users are statically assigned to VACM Groups (role-based access control) The ISMS will support AAA to authenticate the principal and tie into SNMPv3’s VACM Netconf - TBD Message Security SSH SSH SSH or TLS? Transport UDP->TCP TCP UDP->TCP

AAA Authorization A survey of NANOG operators showed these as most popular for NM authorization: 40% RADIUS 29% TACACS+ ISMS WG is asking RADEXT WG to define RADIUS attributes that name policies for management access control for SNMP, Netconf, and other NM protocols draft-nelson-radius-management-authorization-02.txt The mapping of authenticated principal to administratively-named policies to be done by AAA server Approach to policy and the mapping of policy names to policy implementations should be left to specific management protocols

Data Modeling Protocol ISMS Netconf Syslog Content MIBs TBD, incl. MIBs Not Standard Modeling Language SMIv2 XML Schema Structured ASCII Authorization RADIUS TBD Operations GET-*/SET GET/EDIT SNMP MIB modules Wide deployment of SNMP MIB modules Large number of IETF standard MIB modules Large number of enterprise MIB modules Need to preserve the knowledge-base SNMP and XML Some SNMP tools and stacks support XML; NMRG has researched translating SNMP messages to XML format NMRG found SMIv2 a serious constraint to effective data modeling, and recommends utilizing XML without the SMIv2 constraints SMIv2 based on an adapted subset of ASN.1-1998 XML is more flexible, and is taught in schools XML being used by other SDO NM data models Message Security SSH SSH SSH or TLS Transport UDP->TCP TCP UDP->TCP

Data Modeling Languages Lots of data overlap between protocols SNMP and XML Some SNMP tools and stacks support XML and NMRG has researched translating SNMP messages to XML format. NMRG and SMING WG found SMIv2 a serious constraint to effective data modeling, XML more extensible than SMIv2

Possible Convergence Work Protocol SNMP/ISMS Netconf Syslog Content MIB models-- TBD, incl. MIBs <--Standardize Modeling Language SMIv2 XML Schema Structured ASCII Authorization RADIUS/AAA AAA Operations Get-*/SET GET/EDIT Develop loose “layered” architecture for IETF NM standards, ala Netconf or these slides Netconf and SNMP Develop Netconf <snmp-* > operations and an snmp varbind in XML so Netconf can access SNMP data (starter for migration purposes) Develop extended operations for accessing SNMP data (e.g. using XPath expressions) Develop common NM authorization in AAA for SNMP, Netconf, Syslog, and others Other Converge SIMPLE XML-based “patch” proposal with Netconf IPFIX and Syslog may be able to converge to a common TLS-secured transport maybe ISMS and Netconf should move to SASL/TLS as well Message Security SSH SSH SSH or TLS? Transport UDP->TCP TCP UDP->TCP?

Netconf and SNMP Multiple Approaches to Discuss Use same secure transport (i.e. SSH) Develop common NM authorization in AAA for SNMP, Netconf, Syslog, and others, as applicable Develop Netconf <snmp-* > operations and an snmp varbind in XML so Netconf can access SNMP data (i.e. have netconf actually do snmp, and ultimately replace snmp) Develop extended operations for accessing SNMP data to supplement snmp, e.g. using XPath expressions rather than getnext/bulk Create “snmp” dataset (Cf. running, candidate)