Avaya Using Technician Interface Software Manual de usuario Pagina 182

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 344
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 181
Using Technician Interface Software
7-46
308657-14.00 Rev 00
Managing SNMP Secure Mode
Nortel Networks implements an optional security mechanism for all SNMP
set
requests. This proprietary mechanism is an interim solution to solve some SNMP
security problems until a stable, widely accepted industry-standard security
solution is available.
Our security system uses counters to synchronize management operations
between manager and agent. In secure mode, when Site Manager sends a
set
request to the router, the request includes the encrypted value of a counter plus 1
as the first variable binding in the PDU.
When the agent on the router receives the
set
request, it compares the decrypted
value with the value of its own counter plus 1. If the two values match, the agent
considers the
set
request to be authentic and increments the counter by 2. The
agent stores the new value of the counter in an encrypted form in the MIB and
sends it back to Site Manager as the first variable binding in the response.
The manager receiving the response validates that the received counter matches
the manager’s counter plus 2. If the two values match, the response is declared
authentic.
The use of counters guards against masquerade security violations because an
intruder would have to know the encryption key and the correct counter to send as
the first variable binding. The security mechanism also guards against message
stream modification; an intruder cannot reorder a sequence of
set
requests
because the requests’ counters would not match the next sequence expected by the
agent.
The following sections describe the Technician Interface commands you use to
manage the security feature.
Vista de pagina 181
1 2 ... 177 178 179 180 181 182 183 184 185 186 187 ... 343 344

Comentarios a estos manuales

Sin comentarios