Figure 167 Outof Band Management with PVLANs and Firewall
The main benefits of an OOB management design are as follows:
• Production traffic is not impacted by management traffic (and vice versa).
• An attacker on the production network, or accessing the production network, has no ability to access the management network without first compromising a device that is managed OOB, and even then, the only directly reachable IP on the OOB network is the firewall interface.
• Because of this lack of attacker access, insecure management protocols can be used on the OOB network with a much higher degree of assurance.
Although the OOB design is as secure a management network as I can think of, there are certainly downsides that prevent its comprehensive use for most networks:
• An additional interface is required on every managed device (see the next section).
• There is significant added cost in building out an OOB network.
• Not all devices support OOB management (systems that are interface constrained such as WLAN APs, for example).
• A compromise or implementation flaw of PVLANs breaks down the security of the OOB network.
• Topology-sensitive network management systems cannot run OOB because all systems would look directly reachable. Faults in the production network might never be detected.
• Multisite OOB management is problematic (more on this later).
• Managing routing protocols to prevent OOB network advertisements on the production network is required (more detail later).
Continue reading here: Threats and Attack Mitigation
Was this article helpful?