| |
|LCV LES PCV CCV PES CES PSES CSES SEFS UAS CCV CES CSES SEFS UAS|
+----------------------------------------------------------------+
Note that if such a procedure is adopted there is no current interval
data for the first ten seconds after a system comes up.
noSuchInstance must be returned if a management station attempts to
access the current interval counters during this time.
It is an implementation-specific matter whether an agent assumes that
the initial state of the interface is available or unavailable.
6. Acknowledgments
This document was produced by the AToM MIB Working Group. The Editor
would like to dedicate a special thanks to C. Mike Heard for
providing a top notch doctor review and many helpful suggestions, and
to acknowledge D. Fowler, Editor of RFC 2496, T. Cox and K. Tesink
Editors of RFC 1407.
7. References
7.1. Normative References
[RFC2578] McCloghrie, K., Perkins, D., and J. Schoenwaelder,
"Structure of Management Information Version 2
(SMIv2)", STD 58, RFC 2578, April 1999.
[RFC2579] McCloghrie, K., Perkins, D., and J. Schoenwaelder,
"Textual Conventions for SMIv2", STD 58, RFC 2579,
April 1999.
[RFC2580] McCloghrie, K., Perkins, D., and J. Schoenwaelder,
"Conformance Statements for SMIv2", STD 58, RFC
2580, April 1999.
[RFC2863] McCloghrie, K. and F. Kastenholz, "The Interfaces
Group MIB", RFC 2863, June 2000.
[ANSI-T1.102] American National Standard for telecommunications
- digital hierarchy - electrical interfaces, ANSI
T1.102-1987.
[ANSI-T1.107] American National Standard for telecommunications
- digital hierarchy - formats specification, ANSI
T1.107- 1988.
[ANSI-T1.107a] ANSI T1.107a-1990.
[ANSI-T1.404] American National Standard for telecommunications
- Carrier-to-Customer Installation - DS3 Metallic
Interface, ANSI T1.404-1989.
[ANSI-T1.231] American National Standard for Telecommunications
-- Layer 1 In- Service Digital Transmission
Performance Monitoring T1.231, Sept 1993.
[CCITT-G.751] CCITT - Digital Multiplex Equipment Operating at
the Third Order Bit Rate of 34 368 Kbit/s and the
Forth Order Bit Rate of 139 264 Kbit/s and Using
Positive Justification, G.751
[ETSI-T/NA(91)18] European Telecommunications Standards Institute --
ETS "34M" -- Metropolitan Area Network Physical
Convergence Layer Procedure for 34.368 Megabits
per Second, T/NA(91)18, May 1991.
[RFC3593] Tesink, K., "Textual Conventions for MIB Modules
Using Performance History Based on 15 Minute
Intervals", RFC 3593, September 2003.
[ITU-T-M.1400] ITU-T M.1400: Designation For Interconnections
Among Network Operators, October 2001.
7.2. Informative References
[RFC1213] McCloghrie, K. and M. Rose, "Management
Information Base for Network Management of
TCP/IP-based internets:MIB-II", STD 17, RFC 1213,
March 1991.
[RFC1407] Cox, T. and K. Tesink, "Definitions of Managed
Objects for the DS3/E3 Interface Type", RFC 1407,
January 1993.
[RFC2496] Fowler, D., "Definitions of Managed Object for the
DS3/E3 Interface Type", RFC 2496, January 1999.
[RFC3895] Nicklass, O., Ed., "Definitions of Managed Objects
for the DS1, E1, DS2, and E2 Interface Types", RFC
3895, September 2004.
[RFC3592] Tesink, K., "Definitions of Managed Objects for
the Synchronous Optical Network/Synchronous
Digital Hierarchy (SONET/SDH) Interface Type", RFC
3592, September 2003.
[RFC2494] Fowler, D., "Definitions of Managed Objects for
the DS0 and DS0 Bundle Interface Type", RFC 2494,
January 1999.
[RFC3410] Case, J., Mundy, R., Partain, D., and B. Stewart,
"Introduction and Applicability Statements for
Internet-Standard Management Framework", RFC 3410,
December 2002.
8. Security Considerations
There are a number of management objects defined in this MIB module
with a MAX-ACCESS clause of read-write. Such objects may be
considered sensitive or vulnerable in some network environments. The
support for SET operations in a non-secure environment without proper
protection can have a negative effect on network operations. The
specific the objects and their sensitivities/vulnerabilities are as
follows.
Setting the following objects to incorrect values may result in
traffic interruptions:
dsx3LineType
dsx3LineCoding
dsx3SendCode
dsx3LoopbackConfig
dsx3TransmitClockSource
dsx3LineLength
dsx3Channelization
dsx3Ds1ForRemoteLoop
In the case of dsx3LineType, for example, both ends of a DS3/E3 must
have the same value in order for traffic to flow. In the case of
dsx3SendCode and dsx3LoopbackConfig, for another example, traffic may
stop transmitting when particular loopbacks are applied.
Setting the following objects to an incorrect value will result in
the remote end receiving an incorrect Path Identification message,
which may result in a connectivity inconsistency:
dsx3FarEndEquipCode
dsx3FarEndLocationIDCode
dsx3FarEndFrameIDCode
dsx3FarEndUnitCode
dsx3FarEndFacilityIDCode
Setting the following object to an incorrect value will not harm the
traffic, but it may cause a circuit to be mis-identified and thereby
create difficulties for service personnel when attempting to
troubleshoot a problem:
dsx3CircuitIdentifier
Setting the following object can cause an increase in the number of
traps received by the network management station:
dsx3LineStatusChangeTrapEnable
The readable objects in this MIB module (i.e., the objects with a
MAX-ACCESS other than not-accessible) may be considered sensitive in
some environments since, collectively, they provide extensive
information about the performance of interfaces in DS3/E3 equipment
or networks and can reveal some aspects of their configuration. In
such environments it is important to control even GET and NOTIFY
access to these objects and possibly to encrypt the values of these
objects when sending them over the network via SNMP.
SNMP versions prior to SNMPv3 did not include adequate security.
Even if the network itself is secure (for example by using IPSec),
even then, there is no control as to who on the secure network is
allowed to access and GET/SET (read/change/create/delete) the objects
in this MIB module.
It is RECOMMENDED that implementers consider the security features as
provided by the SNMPv3 framework (see [RFC3410], section 8),
including full support for the SNMPv3 cryptographic mechanisms (for
authentication and privacy).
Further, deployment of SNMP versions prior to SNMPv3 is NOT
RECOMMENDED. Instead, it is RECOMMENDED to deploy SNMPv3 and to
enable cryptographic security. It is then a customer/operator
responsibility to ensure that the SNMP entity giving access to an
instance of this MIB module is properly configured to give access to
the objects only to those principals (users) that have legitimate
rights to indeed GET or SET (change/create/delete) them.
9. Author’s Address
Orly Nicklass (editor)
RAD Data Communications, Ltd.
Ziv Tower, 24 Roul Walenberg
Tel Aviv, Israel, 69719
Phone: 9723-765-9969
EMail: orly_n@rad.com
10. Full Copyright Statement
Copyright (C) The Internet Society (2004).
This document is subject to the rights, licenses and restrictions
contained in BCP 78, and except as set forth therein, the authors
retain all their rights.
This document and the information contained herein are provided on an
"AS IS" basis and THE CONTRIBUTOR, THE ORGANIZATION HE/S HE
REPRESENTS OR IS SPONSORED BY (IF ANY), THE INTERNET SOCIETY AND THE
INTERNET ENGINEERING TASK FORCE DISCLAIM ALL WARRANTIES, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF
THE INFORMATION HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED
WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE.
Intellectual Property
The IETF takes no position regarding the validity or scope of any
Intellectual Property Rights or other rights that might be claimed to
pertain to the implementation or use of the technology described in
this document or the extent to which any license under such rights
might or might not be available; nor does it represent that it has
made any independent effort to identify any such rights. Information
on the IETF’s procedures with respect to rights in IETF Documents can
be found in BCP 78 and BCP 79.
Copies of IPR disclosures made to the IETF Secretariat and any
assurances of licenses to be made available, or the result of an
attempt made to obtain a general license or permission for the use of
such proprietary rights by implementers or users of this
specification can be obtained from the IETF on-line IPR repository at
http://www.ietf.org/ipr.
The IETF invites any interested party to bring to its attention any
copyrights, patents or patent applications, or other proprietary
rights that may cover technology that may be required to implement
this standard. Please address the information to the IETF at ietf-
ipr@ietf.org.
Acknowledgement
Funding for the RFC Editor function is currently provided by the
Internet Society.