SNMP
Simple Network Management
Protocol
Department of Information Technology, TIST IT7/ACN/AGK
Network Management
• Maintenance and
administration of networks at
the top level
• Configuration Management
• Fault Management
• Performance Management
• Security Management
• Bandwidth Management
Department of Information Technology, TIST IT7/ACN/AGK
Architectural Model
Department of Information Technology, TIST IT7/ACN/AGK
Terminology
• Agent
– Runs on arbitrary system (e.g., a
router)
– Responds to manager’s requests
• Management software
– Runs on manager’s workstation
– Sends requests to agents as
directed by the manager
Department of Information Technology, TIST IT7/ACN/AGK
TCP/IP Network Management Protocols
• SNMP network managed devices
are dictated by:
– Management Information Base (MIB)
– Structure of Management Information
(SMI)
– Abstract Syntax Notation One (ASN.1)
Department of Information Technology, TIST IT7/ACN/AGK
Management Information Base (MIB)
• A map of the hierarchical order of
all managed objects
• Leaves represent individual data
items
Department of Information Technology, TIST IT7/ACN/AGK
Position of MIB In The ASN.1 Hierarchy
Department of Information Technology, TIST IT7/ACN/AGK
Management Information Base (MIB)
• A MIB is a set of variables and the
semantics of fetch and store on
each variable
• All management commands are
encoded as fetch or store
operations on ‘‘variables’’
• Example: to reboot, store a zero in
a variable that corresponds to the
time until reboot.
Department of Information Technology, TIST IT7/ACN/AGK
MIB Categories
Department of Information Technology, TIST IT7/ACN/AGK
Examples of MIB Variables
Department of Information Technology, TIST IT7/ACN/AGK
Structure of Management Information (SMI)
• Set of rules for defining MIB
variable names
• Includes basic definitions such as
– Variable Name(4-octet value)
– Counter (integer from 0 to 232 - 1)
• Specifies using Abstract Syntax
Notation 1 (ASN.1)
Department of Information Technology, TIST IT7/ACN/AGK
Position of MIB In The ASN.1 Hierarchy
Example: prefix for mgmt node is
[Link]
[Link].2
Department of Information Technology, TIST IT7/ACN/AGK
Example Of SEQUENCE Definition
IpAddrEntry ::= SEQUENCE {
ipAdEntAddr IpAddress,
ipAdEntIfIndex INTEGER,
ipAdEntNetMask IpAddress,
ipAdEntBcastAddr IpAddress,
ipAdEntReasmMaxSize INTEGER
(0..65535)
}
Department of Information Technology, TIST IT7/ACN/AGK
Simple Network Management Protocol (SNMP)
• Specifies communication between
manager’s workstation and
managed entity
• Uses fetch-store paradigm
Department of Information Technology, TIST IT7/ACN/AGK
Department of Information Technology, TIST IT7/ACN/AGK
SNMP Operations
managing managing
entity entity
request trap
response
agent data agent data
Managed device Managed device
Request/Response Mode Trap Mode
Department of Information Technology, TIST IT7/ACN/AGK
Operations That SNMP Supports
Department of Information Technology, TIST IT7/ACN/AGK
SNMP Message Format
• Do not have fixed fields
• Defined using ASN.1 notation
Department of Information Technology, TIST IT7/ACN/AGK
Example ASN.1 Definition
SNMPv3Message ::=
SEQUENCE {
msgVersion INTEGER (0..2147483647),
-- note: version number 3 is used for SNMPv3
msgGlobalData HeaderData,
msgSecurityParameters OCTET STRING,
msgData ScopedPduData
}
Department of Information Technology, TIST IT7/ACN/AGK
Definition Of HeaderData Area In SNMP Message
HeaderData ::= SEQUENCE {
msgID INTEGER (0..2147483647),
-- used to match responses with requests
msgMaxSize INTEGER (484..2147483647),
-- maximum size reply the sender can accept
msgFlags OCTET STRING (SIZE(1)),
-- Individual flag bits specify message characteristics
-- bit 7 authorization used
-- bit 6 privacy used
-- bit 5 reportability (i.e., a response needed)
msgSecurityModel INTEGER (1..2147483647)
-- determine exact format of security parameters that follow
}
Department of Information Technology, TIST IT7/ACN/AGK
• RMON
• [Remote Network Monitoring]
Department of Information Technology, TIST IT7/ACN/AGK
Remote Network Monitoring
• RMON Allows network managers to
monitor the traffic on the network
• RMON allows a central network
management station to
communicate with monitors
throughout the network.
Department of Information Technology, TIST IT7/ACN/AGK
Remote Network Monitoring
• RMON -> Monitor MIB
• Allows remote control of monitors
• Allows multiple managers
Department of Information Technology, TIST IT7/ACN/AGK
A Sample RMON Configuration
Department of Information Technology, TIST IT7/ACN/AGK