SNMP In Depth. SNMP u Simple Network Management Protocol –The most popular network management protocol –Hosts, firewalls, routers, switches…UPS, power.

Slides:



Advertisements
Similar presentations
HP OpenView Network Node Manager
Advertisements

CCNA2 Module 4. Discovering and Connecting to Neighbors Enable and disable CDP Use the show cdp neighbors command Determine which neighboring devices.
Overview of Network Management. Outline Describe responsibilities of a network manager Define network management vocabulary Discuss network management.
Session 13 NM Tools Adapted from Network Management: Principles and Practice © Mani Subramanian 2000 and solely used for Network Management course at.
1 CCNA 2 v3.1 Module 4. 2 CCNA 2 Module 4 Learning about Devices.
Chapter 15 Chapter 15: Network Monitoring and Tuning.
CSEE W4140 Networking Laboratory Lecture 11: SNMP Jong Yul Kim
1 System support & Management Protocols Lesson 13 NETS2150/2850 School of Information Technologies.
NETWORK MANAGEMENT Semester 4, Chapter 7. The Administrative Side of Network Management.
Monitoring System Monitors Basics Monitor Types Alarms Actions RRD Charts Reports.
SNMP Simple Network Management Protocol
Guide to TCP/IP, Third Edition Chapter 11: Monitoring and Managing IP Networks.
Check Disk. Disk Defragmenter Using Disk Defragmenter Effectively Run Disk Defragmenter when the computer will receive the least usage. Educate users.
ICONICS Worldwide Customer Summit – September 2006 Jim Desrosiers SNMP Data Mining for IT Connectivity.
Remote Monitoring and Desktop Management Week-7. SNMP designed for management of a limited range of devices and a limited range of functions Monitoring.
Ch. 31 Q and A CS332 Spring Network management more than just Ethernet Q: Comer mentions that network managers need to be able to account for different.
ENS 1 SNMP M Clements. ENS 2 Simple Network Management Protocol Manages elements in networks – E.g. routers, switches, IP phones, printers etc. Uses manager.
Chapter 6 Overview Simple Network Management Protocol
McGraw-Hill The McGraw-Hill Companies, Inc., 2000 SNMP Simple Network Management Protocol.
Chapter 2  Overview of Network Management 1 Chapter 2 Overview  Why is network mgmt necessary?  Network managers job  Network management vocabulary.
1.  TCP/IP network management model: 1. Management station 2. Management agent 3. „Management information base 4. Network management protocol 2.
Network Protocols UNIT IV – NETWORK MANAGEMENT FUNDAMENTALS.
11 NETWORK PROTOCOLS AND SERVICES Chapter 10. Chapter 10: Network Protocols and Services2 NETWORK PROTOCOLS AND SERVICES  Identify how computers on TCP/IP.
Workshop 1: Introduction to TCP/IP
Module 7: Configuring TCP/IP Addressing and Name Resolution.
NMS Labs Mikko Suomi LAB1 Choose SNMP device managment software Features: –Gives Nice overview of network –Bandwith monitoring –Multible.
Hands-On Microsoft Windows Server 2003 Networking Chapter Three TCP/IP Architecture.
Network Protocols. Why Protocols?  Rules and procedures to govern communication Some for transferring data Some for transferring data Some for route.
Robert E. Meyers CCNA, CCAI Youngstown State University Manager, Cisco Regional Academy Cisco Networking Academy Program Semester 4, v Chapter 7:
9/15/2015© 2008 Raymond P. Jefferis IIILect Application Layer.
A+ Guide to Managing and Maintaining Your PC Fifth Edition Chapter 19 PCs on the Internet.
Network Management System The Concept –From a central computer, network administrator can manage entire network Collect data Give commands –Moving gradually.
SNMP (Simple Network Management Protocol)
1 SNMP Simple network management protocol Group: Techno Presented by: Karthik Gottiparthy Gautami Parulkar Neeraj Sharma Jigar Patel Hariharan Venkataraman.
1 © 1999 BMC SOFTWARE, INC. 2/10/00 SNMP Simple Network Management Protocol.
ECE Prof. John A. Copeland Office: Klaus or call.
Network Security Part I: Introduction Network Security Management.
BAI513 - PROTOCOLS SNMP BAIST – Network Management.
Objectives Configure routing in Windows Server 2008 Configure Routing and Remote Access Services in Windows Server 2008 Network Address Translation 1.
Network Management Tool Amy Auburger. 2 Product Overview Made by Ipswitch Affordable alternative to expensive & complicated Network Management Systems.
Network Management Presentation HP Openview Christopher Scott December 10, 2004.
COMP1321 Digital Infrastructure Richard Henson February 2014.
Lec 3: Infrastructure of Network Management Part2 Organized by: Nada Alhirabi NET 311.
Linux+ Guide to Linux Certification, Second Edition Chapter 14 Network Configuration.
Hour 7 The Application Layer 1. What Is the Application Layer? The Application layer is the top layer in TCP/IP's protocol suite Some of the components.
1 Chapter 8 Network Management Security. 2 Outline Basic Concepts of SNMP SNMPv1 Community Facility SNMPv3 Recommended Reading and WEB Sites.
Maintaining and Updating Windows Server Monitoring Windows Server It is important to monitor your Server system to make sure it is running smoothly.
1 Implementing Monitoring and Reporting. 2 Why Should Implement Monitoring? One of the biggest complaints we hear about firewall products from almost.
McGraw-Hill©The McGraw-Hill Companies, Inc., 2001 TCP/IP Application Layer.
70-291: MCSE Guide to Managing a Microsoft Windows Server 2003 Network, Enhanced Chapter 3: TCP/IP Architecture.
CCNA4 v3 Module 6 v3 CCNA 4 Module 6 JEOPARDY K. Martin.
1 by Behzad Akbari Fall 2008 In the Name of the Most High Network Management Applications.
1 Kyung Hee University Prof. Choong Seon HONG SNMP Network Management Concepts.
Monitoring Troubleshooting TCP/IP Chapter 3. Objectives for this Chapter Troubleshoot TCP/IP addressing Diagnose and resolve issues related to incorrect.
OpenView and Network Node Manager Fundamentals. [vpo_nnm_fund] 2 OpenView and NNM Fundamentals A Network Management Protocol – SNMP Simple Network Management.
Network management Basic Networking - what’s happening on my network ?!
1 Bus topology network. 2 Data is sent to all computers, but only the destination computer accepts 02608c
Network Management CCNA 4 Chapter 7. Monitoring the Network Connection monitoring takes place every day when users log on Ping only shows that the connection.
COMP1321 Digital Infrastructure Richard Henson March 2016.
Cisco Routers Routers collectively provide the main feature of the network layer—the capability to forward packets end-to-end through a network. routers.
Lec 3: Infrastructure of Network Management Part2 Organized by: Nada Alhirabi NET 311.
Network Management Presentation HP Openview. OpenView Network Node Manager (NNM) Overview How it works Capabilities Technical and business benefits Summary.
Network Management Security in distributed and remote network management protocols.
or call for office visit, or call Kathy Cheek,
SNMP Simple network management protocol
Karl Quinn 23rd November 2004 NDS M.Sc.
SNMP M Clements ENS.
SNMP M Clements ENS.
SNMP M Clements ENS.
Chapter 15: Network Monitoring and Tuning
Presentation transcript:

SNMP In Depth

SNMP u Simple Network Management Protocol –The most popular network management protocol –Hosts, firewalls, routers, switches…UPS, power strips, ATM cards -- ubiquitous u “One of the single biggest security nightmares on networks today”

SNMP Transport Mechanism Flaws u UDP Based –Unreliable - packets may or may not be received –Easily forged - trivial to forge source of packets

Management Information Base u MIB -- Management Information Base –MIBs describe object attributes –Some MIBs are pre-loaded –Additional MIBs are needed »Loaded manually »Downloaded from manufacture’s WEB sites u Standard MIBs –MIB-I –MIB-II –RMON –RMON 2 –Bridge –Repeater

iso (1) org (3) dod (6) internet (1) directory (1) mgmt (2) experimental private (4) mib-2 (1) enterprises (1) system (1) interfaces (2) snmp (11) cisco (9) hp(11) novell(23) sysObjectID (2) sysDescr (1) MIB Structure

SNMP Basics ManagerAgent MIB Data Trap  Trap or Notification - A message initiated by the agent without requiring the management station to send a request Set  Set request - Writes a value into a specific variable alter Get Response Retrieve  Get request - Reads a value from a specific variable  GetNext request - Traverse information from a table of specific variables  GetBulk request -  Get response - Replies to a get or a set request SNMP Router, etc.

SNMP Popular Defaults u Popular defaults –public –private –write –“all private” –monitor –manager –security –admin –lan –default –password –tivoli –openview –community –snmp –snmpd –system –and on and on...

SNMP v1 Information Disclosure u Routing tables u Network topology u Network traffic patterns u Filter rules

SNMP Options u SNMP configuration u Event Configuration –Customize event notification messages –Define the type of event notification –Define automatic actions when an event is received. –Create/modify alarm categories –Configure additional actions for the operator –Configure event correlations u SNMP data collection and threshold u SNMP MIB application builder u Load/unload MIB u Network polling configuration u License password

SNMP Tools u Remotely turn on the power of a PC u Web base access u Terminal Connect- provides the ability to establish a telnet session from a local system in order to manage a remote system u SNMP MIB Browser- provides a functional tool that can be used to explore, query, and set MIB values u DMI Browser

Agent Data Collection u Network data collected using –SNMPv1 ; SNMPv2 –IP Protocol »TCP/IP »UDP »ICMP »ARP/RARP –IPX –DMI »Desktop Management Interface for accessing information about PC and their components

Auto-discovery u Auto discovery of network objects based on –IP Protocol –Routing data on routers (ARP table) –SNMP data u Auto assignments of symbols to represent objects u Auto arrangement of symbols on the maps and submaps

SNMP Event Generation u SNMP agents continuously watch for certain incidents to occur u When an incident occurs, an event is generated u Events are categorized based on the alarm type –Alarm types are user definable u Events are displayed with color coded severity –Severity and color codes are user definable u Event trap configuration –Pre-defined –User-defined generic traps –User-defined specific traps

Event Correlation u Event correlation –Discovers events that are either the same event and/or related events –Presents these events as a single main event –Allow drill down of the main event to view the related events u Provides four pre-defined correlations: –Connector Down Correlation –Scheduled Maintenance Correlation –Repeated Event Correlation –Pair Wise Correlation u Additional correlations may be obtained –From web page –From a 3rd party for a fee –Developed by yourself -- not recommended

Performance Management u Network activities –Status of the interfaces –Error rate and percentage –Ethernet traffic –SNMP authentication failures, traffic, errors –List of TCP connections u Graph CPU load and disk space usage u Graph SNMP data collected with MIB data collector u Graph data based on Interface status polling and SNMP node polling

Configuration Management u Network Configuration (at selected remote SNMP node) –List interface properties –List IP and link addresses –List routing table –List ARP cache table –List the supported services u List the services for which the selected remote SNMP nodes are configured to support u List the management systems (by IP Address) that are configured to receive traps u Run the Microsoft Windows NT operating system Registry Editor

Performance Management u Network activities –Status of the interfaces –Error rate and percentage –Ethernet traffic –SNMP authentication failures, traffic, errors –List of TCP connections u Graph CPU load and disk space usage (HP-UX only) u Graph SNMP data collected with MIB data collector u Graph data based on Interface status polling and SNMP node polling

Fault Management u Alarms -- show all alarms of selected nodes u Network Connectivity –Poll node -- information about selected objects –Status poll -- status about selected objects –Capability poll -- check for remote DMI, web-management, and web server capabilities. –Ping –Remote ping –Locate route via SNMP u Test IP/TCP/SNMP u Interface Status -- Graphic display of number and rate of bad packets u Window NT Event Viewer u Window NT Diagnostic tool

SNMPv1 Security Flaws u Transport Mechanism –Data manipulation –Denial of Service –Replay u Authentication –Host Based –Community Based u Information Disclosure

SNMP Authentication Flaws u Host Based –Fails due to UDP transport –DNS cache poisoning u Community Based –Cleartext community –Community name prediction/brute forcing –Default communities

RMON and RMON2 Security u SNMPv1’s flaws u additional hazards by introducing “action invocation” objects u collects extensive info on subnet u packet captures

SNMP Fixes u Disable it u ACL It u Read-Only