L. NETWORK ADMINISTRATION
Given the sheer number and variety of devices on the network, it is vital that the administrator is able to view and/or manage all these disparate entities from a single point. A good management system must be capable of providing status information on the various network entities and carrying out any administrative or corrective actions deemed necessary.
1. SNMP protocol
SNMP (Simple Network Management Protocol) is the standard protocol for monitoring TCP/IP networks, developed on the initiative of the US Department of Defense. It can be divided into three main components: Architecture, System Information (MIB), and Access Control.
2. Architecture SNMP
SNMP systems consist of managers and agents. The SNMP manager can request information from the agent using a very basic command structure. When the manager requires information from the agent, it sends a ‘get-request’ command. This is effectively a request to access the MIB (Management Information Base) on the agent machine. Upon receiving the command, the agent first checks whether the management entity has provided the correct community string and, if so, responds by providing the requested information.
The basic SNMP operations are:
· Get-Request : the manager requests the value of one or more variables from the MIB.
· Get-Next-Request: allows you to traverse the MIB sequentially.
· Get-Bulk (SNMPv2+): efficient retrieval of large amounts of data.
· Set-Request: the manager changes the value of a variable in the MIB.
· Get-Response: the agent's response to GET requests.
· Trap: an event message sent by the agent to the manager in the event of an incident.
3. MIB — Management Information Base
An MIB is a definition of the type of information that must be made available by the unit running the SNMP agent software.
This information may include:
· The status of the network interfaces (up/down, speed, type).
· The number of packets sent and received, and the error rate.
· The services available on the unit and the connections established.
· The number of retransmitted packets (an indicator of congestion or link quality).
· System information (uptime, software version, etc.).
ℹ Read-only and read-write fields
Some of the fields within the MIB are read-only and are provided for information purposes only. More usefully, if an SNMP manager provides the correct community string (Control Community), it will be able to modify the values selected in the MIB. This ability to make changes must be carefully protected to prevent unauthorised modifications.
4. Community Strings SNMP
SNMP provides a basic security mechanism to control manager-agent access. A ‘community string’ is specified in the configuration and is included with all requests.
There are three types of community string:
Monitor Community: equivalent to read-only access to the agent MIB (viewing statistics).
Control Community: equivalent to Read-Write access to the agent MIB (configuration modification).
Trap Community: SNMP traps are event messages sent to a machine for logging purposes.
Community strings can be up to 32 characters long (case-sensitive). By default, devices use 'public' (read-only) and 'private' (read-write), which constitutes a security vulnerability if they are not changed.
⚠ SNMP security — use SNMPv3
SNMPv1 and SNMPv2c transmit community strings in plain text over the network, making them vulnerable to eavesdropping. SNMPv3 (RFC 3411–3418) provides authentication (HMAC-MD5, HMAC-SHA) and data encryption (DES, AES), as well as user-based access control (USM/VACM). SNMPv3 is now the recommended security standard for network monitoring.