Google Answers Logo
View Question
 
Q: internet technology ( Answered,   0 Comments )
Question  
Subject: internet technology
Category: Science
Asked by: jyw-ga
List Price: $10.00
Posted: 01 Sep 2002 15:44 PDT
Expires: 01 Oct 2002 15:44 PDT
Question ID: 60757
what are the technologies advantages of SNMP version 3 (simple network
management protocol) over SNMP version 1?
Answer  
Subject: Re: internet technology
Answered By: answerguru-ga on 01 Sep 2002 16:33 PDT
 
Hi jyw-ga,

There are numerous reasons why one would choose SNMPv3 over SNMPv1. I
will be providing descriptions of the differences and/or links for the
main categories that are relevant here:

There is essentially no security measures integrated into v1, however,
v3 offers many features which combat this problem. Some of them
include:

Authentication:

* shared manager/agent authentication key
* the USM (Used-based Security Model) defines two authentication
protocols
* inclusion of timeliness mechanisms

Privacy:

* this is optional due to regulations in many countries that disallow
its use
* manager and agent share a secret encryption key (different
passwords)

Security Levels:

* three levels that can be used in some combination consistent with
perceived protection needs - "The lowest level does not provide
authentication or privacy (noAuthNoPriv). This level's security is
thus comparable to SNMPv1. The second level provides authentication,
but no privacy (AuthNoPriv), and the highest level provides
authentication and security (AuthPriv). (The combination of no
authentication with privacy is not supported by SNMPv3). "

Access Control:

"Access control is a security function performed at the PDU level.
SNMPv3 allows for the definition of multiple access controls, but
suggests the View-based Access Control Model (VACM).([10]). Strong
access control demands strong authentication, which SNMPv3 does have."

http://www.cs.utk.edu/~race/594paper.html

Another source, ISP-Planet, verifies the points made in the paper
above, stating that:

"SNMPv3 was introduced in 1999, and gets around the security concerns
by making it possible to encrypt all SNMP related traffic. It also
accommodates authentication via a digital signature for remote
systems. "

They also point out several other features made available in v3 that
are missing from v1:

* auditing
* enhanced time synchronization protocol 
* increased set of management tools
* non-security related enhancements that were included in SNMPv2

Taking directly from the article, "SNMPv3 takes the best of version 2,
perfects these features, adds a few of its own and then makes it
secure. Another major plus for SNMPv3 is that it has been designed in
a modular manner that, some say, will make it unnecessary for a new
version (v4 per chance) to be introduced in the near future. When the
need for new functionality is realized, it can be incorporated into
SNMPv3 without the need for wholesale changes."

http://www.isp-planet.com/technology/2002/snmp_v1v2v3.html

Just to get an idea of the features in SNMPv2 that were alluded to in
the source above, I strongly suggest referring to William Stalling's
"Data and Computer Communications" 6th Edition (pg. 705-709) for a
concise and informative overview. Unfortunately this cannot be
reproduced here due to copyright restrictions. The ISBN is:
0-13-084370-9.

If you have any problems understanding the information above please
post a clarification and I will respond to it. Happy networking :)

Cheers!

answerguru-ga

Request for Answer Clarification by jyw-ga on 15 Sep 2002 18:17 PDT
Hi, answerguru:

thanks for your answer.  I'd like to know about the difference between
secure socket layer (SSL) and SNMP.  What are the different areas /
functions do they serve?

If you think I need to pay for this question, I'd like to pay 5
dollars.

jyw

Clarification of Answer by answerguru-ga on 15 Sep 2002 23:13 PDT
Hi again jyw-ga,

The purpose for clarifications is more to allow the asker to clear up
any points regarding the original question. If you'd like to ask
another question, all you need to do is post it (like you did for this
one) along with the price you are willing to pay and one of our
researchers will answer it.

Thanks for using Google Answers!

answerguru-ga
Comments  
There are no comments at this time.

Important Disclaimer: Answers and comments provided on Google Answers are general information, and are not intended to substitute for informed professional medical, psychiatric, psychological, tax, legal, investment, accounting, or other professional advice. Google does not endorse, and expressly disclaims liability for any product, manufacturer, distributor, service or service provider mentioned or any opinion expressed in answers or comments. Please read carefully the Google Answers Terms of Service.

If you feel that you have found inappropriate content, please let us know by emailing us at answers-support@google.com with the question ID listed above. Thank you.
Search Google Answers for
Google Answers  


Google Home - Answers FAQ - Terms of Service - Privacy Policy