SNMP Notifications
SNMP's key feature is that it enables you to generate notifications from SNMP agents.
Cisco routers can be configured to send SNMP traps or informed requests to a network management system (NMS), where a network administrator can view the data.
Figure 2-6 displays the typical communication between an SNMP manager and the SNMP agent (for example, a Cisco-enabled SNMP router).
Figure 2-6 Communication Between SNMP Manager and SNMP Agent
Trap (no acknowledge) or Inform Requests (acknowledgment sent)
Trap (no acknowledge) or Inform Requests (acknowledgment sent)
Figure 2-6 Communication Between SNMP Manager and SNMP Agent
Inform acknowledgment sent
Inform acknowledgment sent
Unsolicited notifications can be generated as traps or inform requests. Traps are messages that alert the SNMP manager about a condition on the network (sent by the SNMP agent). Inform requests (informs) are traps that include a request for confirmation of receipt from the SNMP manager. SNMP notifications can indicate improper user authentication, restarts, the closing of a connection, loss of connection to a neighbor router, or other significant events.
The major difference between a trap and an inform packet is that an SNMP agent has no way of knowing if an SNMP trap was received by the SNMP manager. An inform request will be sent continually until an acknowledgment is received by the sending SNMP agent.
|
Term |
Description |
|
Managed device |
A network node that contains an SNMP agent and resides on a managed network. Managed devices collect and store management information and make this information available to NMSs using SNMP. |
|
Agent |
A network management software module that resides in a managed device. An agent has local knowledge of management information and translates that information into a form compatible with SNMP. |
|
Network management system (NMS) |
Executes applications that monitor and control managed devices. |
|
SNMP manager |
Management station that collects SNMP information from agents such as routers or switches. |
NOTE Managed devices are monitored and controlled using three common SNMP commands:
■ read—Used by an NMS to monitor managed devices. The NMS examines different variables that are maintained by managed devices.
■ write—Used by an NMS to control managed devices. The NMS changes the values of variables stored within managed devices.
■ trap—Used by managed devices to asynchronously report events to the NMS. For example, Cisco IOS routers can be configured to report errors, such as emergencies alerts, to the NMS for urgent action, such as low memory resources or unauthorized access. When certain types of events occur, a managed device sends a trap to the NMS.
The value of an MIB object can be changed or retrieved using SNMP commands, usually through a GUI network management system. Cisco supports a number of defined and proprietary MIB commands.
NOTE Be aware that newer and more functional Cisco IOS releases have new features and new added options. For this book, we are using the common features found in version 12.2. The CCIE Security candidate sitting for the written exam is not expected to remember the entire range of options available. Just be aware when you sit for the lab exam that you may have additional options.
Refer to http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122cgcr/ffun_r/ ffrprt3/frf014.htm#wp1056809 for more details. For example, in 12.0.3(T) there are additional options with the snmp community host command defined as:
version 3 [auth | noauth | priv] hsrp
Example 2-7 configures a Cisco IOS (12.2 mainline) router for SNMP support.
Example 2-7 Sample SNMP Configuration snmp-server community public RO snmp-server enable traps config snmp-server host 131.108.255.254 isdn
The Cisco IOS command snmp-server community public RO enables SNMP on a Cisco router. This command is also used to restrict access via SNMP. The community string is defined as public and acts as a password protection mechanism against unauthorized users. The community string is sent in every SNMP packet, so an incorrect community string results in no authorized access to the SNMP agent. The read-only attribute means that no configuration changes will be permitted via an SNMP management station. Security administrators should never use the well-known community string "public". SNMPvl and SNMPv2 (easily spoofed) send information in clear text. SNMPv3 is the most secure model, because it allows packet encryption.
The Cisco IOS command snmp-server enable traps config advises the NMS of any configuration changes. The Cisco IOS command snmp-server host 131.108.255.254 isdn alerts the host 131.108.254.254 of any ISDN traps which can include link flapping or high link usage, for example.
To specify the recipient of an SNMP notification operation, use the snmp-server host global configuration command. To remove the specified host, use the no form of this command.
snmp-server host host-addr [traps | informs] [version {1 | 2c | 3 [auth | noauth | priv]}] community-string [udp-port port] [notification-type]
Table 2-3 expands the snmp-server host Cisco IOS command and presents the full range of options, including MD5 authentication.
|
Syntax Description |
Meaning |
|
host-addr |
Name or Internet address of the host (the targeted recipient). |
|
traps |
(Optional) Sends trap messages to this host. This is the default. |
|
informs |
(Optional) Sends inform messages to this host. |
|
version |
(Optional) Version of the SNMP used to send the traps. Version 3 is the most secure model because it allows packet encryption with the priv keyword. If you use the version keyword, one of the following must be specified: 1—SNMPvl (not available with informs) 2c—SNMPv2C 3—SNMPv3 The following three optional keywords can follow the 3 keywords: auth—(Optional) Enables Message Digest 5 (MD5) and Secure Hash Algorithm (SHA) packet authentication. This is known as authNoPriv. noauth—(Default) The noAuthNoPriv security level. This is the default if the [auth | noauth | priv] keyword choice is not specified. priv—(Optional) Enables Data Encryption Standard (DES) packet encryption (also called privacy). This is known as authPriv. |
|
community-string |
Password-like community string sent with the notification operation. Although you can set this string using the snmp-server host command by itself, it is recommended that you define this string using the snmp-server community command prior to using the snmp-server host command. |
|
udp-port port |
(Optional) UDP port of the host to use. The default is 162. |
Table 2-3 snmp-server host Command* (Continued)
Author Query:
is this correct?
Table 2-3 snmp-server host Command* (Continued)
|
Syntax Description |
Meaning |
|
notification-type |
(Optional) Type of notification to be sent to the host. If no type is specified, all notifications are sent. The notification type can be one or more of the following keywords: bgp—Sends Border Gateway Protocol (BGP) state change notifications. calltracker—Sends Call Tracker call-start/call-end notifications. config—Sends configuration notifications. dspu—Sends downstream physical unit (DSPU) notifications. entity—Sends Entity MIB modification notifications. envmon—Sends Cisco enterprise-specific environmental monitor notifications when an environmental threshold is exceeded. frame-relay—Sends Frame Relay notifications. hsrp—Sends Hot Standby Routing Protocol (HSRP) notifications. isdn—Sends Integrated Services Digital Network (ISDN) notifications. llc2—Sends Logical Link Control, type 2 (LLC2) notifications. repeater—Sends standard repeater (hub) notifications. rsrb—Sends remote source-route bridging (RSRB) notifications. rsvp—Sends Resource Reservation Protocol (RSVP) notifications. |
|
rtr—-Sends SA Agent (RTR) notifications. |
|
|
sdlc—Sends Synchronous Data Link Control (SDLC) Protocol notifications. sdllc—Sends Synchronous Data Logical Link Control (SDLLC) notifications. snmp—Sends any enabled RFC 1157 SNMP linkUp, linkDown, authenticationFailure, warmStart, and coldStart notifications. stun—Sends serial tunnel (STUN) notifications. syslog—Sends error message notifications (Cisco Syslog MIB). Specify the level of messages to be sent with the logging history level command. tty—Sends Cisco enterprise-specific notifications when a TCP connection closes. voice—Sends SNMP poor quality of voice traps when used with the snmp enable peer-trap poor qov command. x25—Sends X.25 event notifications. Note in version 12.2T and higher the options have been extended to include such protocols as BGP, HSRP, and more. Refer to Cisco.com for details. |
*From http://www.cisco.com/univercd/cc/td/doc/product/software/ios121/121cgcr/fun_r/frprt3/ frd3001.htm#xtocid65591l.
*From http://www.cisco.com/univercd/cc/td/doc/product/software/ios121/121cgcr/fun_r/frprt3/ frd3001.htm#xtocid65591l.
SNMP is disabled by default on Cisco IOS routers. SNMP Examples
The following example assigns the SimonisCool string to SNMP, allowing read-only access, and specifies that IP access list 4 can use the community string:
R1(config)# snmp-server community SimonisCool ro 4 R1(config)# access-list 4 permit 131.108.1.0 0.0.0.255
The hosts on network 131.108.1.0/24 are permitted SNMP access if the read-only string is set to SimonisCool. This enables an added feature which ensures that devices that source SNMP information are from a trusted or internal network.
The following example assigns the string SnR to SNMP, allowing read-write access to the objects in the restricted view (read-write):
R1(config)# snmp-server community SnR view restricted rw
The following example disables all versions of SNMP: R1(config)# no snmp-server
The following example enables the router to send all traps to the host, host.cisco.com, using the community string "publiC":
R1(config)# snmp-server enable traps R1(config)# snmp-server host host.cisco.com public
In the following example, the BGP traps are enabled for all hosts, but only the ISDN traps are enabled to be sent to an actual host named simon:
R1(config)# snmp-server enable traps bgp R1(config)# snmp-server host simon public isdn
The following example enables the router to send all inform requests to the host test.cisco.com using the community string publiC:
R1(config)# snmp-server enable traps
R1(config)# snmp-server host test.cisco.com informs public
Continue reading here: Simple Mail Transfer Protocol
Was this article helpful?