to even encrypt the values of these objects when sending them over
the network via SNMP. These are the tables and objects and their
sensitivity/vulnerability:
o hdsl2ShdslInventoryTable
Access to these objects would allow an intruder to obtain
information about which vendor’s equipment is in use on the
network. Further, such information is considered sensitive in
many environments for competitive reasons.
* hdsl2ShdslInvVendorID
* hdsl2ShdslInvVendorModelNumber
* hdsl2ShdslInvVendorSerialNumber
* hdsl2ShdslInvVendorEOCSoftwareVersion
* hdsl2ShdslInvStandardVersion
* hdsl2ShdslInvVendorListNumber
* hdsl2ShdslInvVendorIssueNumber
* hdsl2ShdslInvVendorSoftwareVersion
* hdsl2ShdslInvEquipmentCode
* hdsl2ShdslInvVendorOther
* hdsl2ShdslInvTransmissionModeCapability
SNMP versions prior to SNMPv3 did not include adequate security.
Even if the network itself is secure (for example by using IPsec),
even then, there is no control as to who on the secure network is
allowed to access and GET/SET (read/change/create/delete) the objects
in this MIB module.
It is RECOMMENDED that implementers consider the security features as
provided by the SNMPv3 framework (see [RFC3410], Section 8),
including full support for the SNMPv3 cryptographic mechanisms (for
authentication and privacy).
Further, deployment of SNMP versions prior to SNMPv3 is NOT
RECOMMENDED. Instead, it is RECOMMENDED to deploy SNMPv3 and to
enable cryptographic security. It is then a customer/operator
responsibility to ensure that the SNMP entity giving access to an
instance of this MIB module is properly configured to give access to
the objects only to those principals (users) that have legitimate
rights to indeed GET or SET (change/create/delete) them.
6. Acknowledgements
The authors are deeply grateful to the authors of the ADSL LINE MIB
(RFC 2662 [RFC2662]), Gregory Bathrick and Faye Ly, as much of the
text and structure of this document originate in their documents.
The authors are also grateful to the authors of FR MFR MIB (RFC 3020
[RFC3020]), Prayson Pate, Bob Lynch, and Kenneth Rehbehn, as the
majority of the Security Considerations section was lifted from their
document.
The authors also acknowledge the importance of the contributions and
suggestions regarding interface indexing structures received from
David Horton of CITR.
The authors are extremely thankful to Bert Wijnen, Randy Presuhn, and
C. M. Heard for their extensive review and the many suggestions they
provided.
Other contributions were received from the following:
Matt Beanland (Extel Communications)
Philip Bergstresser (Adtran)
Steve Blackwell (Centillium)
Umberto Bonollo (NEC Australia)
John Egan (Metalink BroadBand)
Yagal Hachmon (RAD)
Mark Johnson (Red Point)
Sharon Mantin (Orckit)
Moti Morgenstern (ECI)
Raymond Murphy (Ericsson)
Lee Nipper (Verilink)
Randy Presuhn (BMC Software)
Katy Sherman (Orckit)
Mike Sneed (ECI)
Jon Turney (DSL Solutions)
Aron Wahl (Memotec)
Bert Wijnen (Lucent)
Jim Wilson (for Mindspeed)
Michael Wrobel (Memotec)
7. References
7.1. Normative References
[G.991.2] Blackwell, S., "Single-Pair High-Speed Digital Subscriber
Line (SHDSL) Transceivers", ITU-T G.991.2, December 2003.
[RFC2119] Bradner, S., "Key words for use in RFCs to Indicate
Requirement Levels", BCP 14, RFC 2119, March 1997.
[RFC2578] McCloghrie, K., Perkins, D., and J. Schoenwaelder,
"Structure of Management Information Version 2 (SMIv2)",
STD 58, RFC 2578, April 1999.
[RFC2579] McCloghrie, K., Perkins, D., and J. Schoenwaelder,
"Textual Conventions for SMIv2", STD 58, RFC 2579, April
1999.
[RFC2580] McCloghrie, K., Perkins, D., and J. Schoenwaelder,
"Conformance Statements for SMIv2", STD 58, RFC 2580,
April 1999.
[RFC2863] McCloghrie, K. and F. Kastenholz, "The Interfaces Group
MIB", RFC 2863, June 2000.
[RFC3411] Harrington, D., Presuhn, R., and B. Wijnen, "An
Architecture for Describing Simple Network Management
Protocol (SNMP) Management Frameworks", STD 62, RFC 3411,
December 2002.
[RFC3593] Tesink, K., "Textual Conventions for MIB Modules Using
Performance History Based on 15 Minute Intervals", RFC
3593, September 2003.
[T1E1.4] American National Standards Institute, "ANSI T1E1.4/2000-
006", February 2000.
7.2. Informative References
[RFC2662] Bathrick, G. and F. Ly, "Definitions of Managed Objects
for the ADSL Lines", RFC 2662, August 1999.
[RFC3020] Pate, P., Lynch, B., and K. Rehbehn, "Definitions of
Managed Objects for Monitoring and Controlling the UNI/NNI
Multilink Frame Relay Function", RFC 3020, December 2000.
[RFC3276] Ray, B. and R. Abbi, "Definitions of Managed Objects for
High Bit-Rate DSL - 2nd generation (HDSL2) and Single-Pair
High-Speed Digital Subscriber Line (SHDSL) Lines
Processing", RFC 3276, May 2002.
[RFC3410] Case, J., Mundy, R., Partain, D., and B. Stewart,
"Introduction and Applicability Statements for Internet-
Standard Management Framework", RFC 3410, December 2002.
[RFC3418] Presuhn, R., "Management Information Base (MIB) for the
Simple Network Management Protocol (SNMP)", STD 62, RFC
3418, December 2002.
Authors’ Addresses
Clay Sikes
Zhone Technologies, Inc.
Florida Design Center
8454 126th Ave. N.
Largo, FL 33773
US
Phone: +1 727 530 8257
Fax: +1 727 532 5698
EMail: csikes@zhone.com
Bob Ray
PESA Switching Systems, Inc.
330-A Wynn Drive
Huntsville, AL 35805
US
Phone: +1 256 726 9200 ext. 142
Fax: +1 256 726 9271
EMail: rray@pesa.com
Rajesh Abbi
Alcatel USA
2301 Sugar Bush Road
Raleigh, NC 27612
US
Phone: +1 919-850-6194
Fax: +1 919-850-6670
EMail: Rajesh.Abbi@alcatel.com
Full Copyright Statement
Copyright (C) The Internet Society (2005).
This document is subject to the rights, licenses and restrictions
contained in BCP 78, and except as set forth therein, the authors
retain all their rights.
This document and the information contained herein are provided on an
"AS IS" basis and THE CONTRIBUTOR, THE ORGANIZATION HE/SHE REPRESENTS
OR IS SPONSORED BY (IF ANY), THE INTERNET SOCIETY AND THE INTERNET
ENGINEERING TASK FORCE DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED,
INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE
INFORMATION HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED
WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE.
Intellectual Property
The IETF takes no position regarding the validity or scope of any
Intellectual Property Rights or other rights that might be claimed to
pertain to the implementation or use of the technology described in
this document or the extent to which any license under such rights
might or might not be available; nor does it represent that it has
made any independent effort to identify any such rights. Information
on the procedures with respect to rights in RFC documents can be
found in BCP 78 and BCP 79.
Copies of IPR disclosures made to the IETF Secretariat and any
assurances of licenses to be made available, or the result of an
attempt made to obtain a general license or permission for the use of
such proprietary rights by implementers or users of this
specification can be obtained from the IETF on-line IPR repository at
http://www.ietf.org/ipr.
The IETF invites any interested party to bring to its attention any
copyrights, patents or patent applications, or other proprietary
rights that may cover technology that may be required to implement
this standard. Please address the information to the IETF at ietf-
ipr@ietf.org.
Acknowledgement
Funding for the RFC Editor function is currently provided by the
Internet Society.