RFC 4368 - Multiprotocol Label Switching (MPLS) Label-Contro(2)

时间:2006-11-02 来源: 作者: 点击:
; mplsLcFrStdMIBMODULE-IDENTITY LAST-UPDATED"200601120000Z"--12January2006 ORGANIZATION"MultiprotocolLabelSwitching(MPLS)WorkingGroup" CONTACT-INFO "ThomasD.Nadeau CiscoSystems,Inc. Email:tnadeau@cis
  
      ;
   mplsLcFrStdMIB MODULE-IDENTITY

      LAST-UPDATED "200601120000Z"  -- 12 January 2006
      ORGANIZATION "Multiprotocol Label Switching (MPLS) Working Group"
      CONTACT-INFO
          "        Thomas D. Nadeau
                   Cisco Systems, Inc.
           Email:  tnadeau@cisco.com

                   Subrahmanya Hegde
           Email:  subrah@cisco.com

           General comments should be sent to mpls@uu.net
          "
      DESCRIPTION
          "This MIB module contains managed object definitions for
           MPLS Label-Controlled Frame-Relay interfaces as defined
           in (RFC3034).

           Copyright (C) The Internet Society (2006).  This
           version of this MIB module is part of RFC 4368; see
           the RFC itself for full legal notices."

      -- Revision history.
      REVISION
           "200601120000Z"  -- 12 January 2006
      DESCRIPTION
          "Initial revision, published as part of RFC 4368."
      ::= { mplsStdMIB 10 }

   -- Top level components of this MIB module.
   -- Tables, Scalars, Notifications, Conformance

   mplsLcFrStdNotifications OBJECT IDENTIFIER ::= { mplsLcFrStdMIB 0 }
   mplsLcFrStdObjects       OBJECT IDENTIFIER ::= { mplsLcFrStdMIB 1 }
   mplsLcFrStdConformance   OBJECT IDENTIFIER ::= { mplsLcFrStdMIB 2 }

   -- MPLS LC-FR Interface Configuration Table.
   mplsLcFrStdInterfaceConfTable  OBJECT-TYPE
      SYNTAX        SEQUENCE OF MplsLcFrStdInterfaceConfEntry
      MAX-ACCESS    not-accessible
      STATUS        current
      DESCRIPTION
          "This table specifies per-interface MPLS LC-FR
           capability and associated information.  In particular,
           this table sparsely extends the MPLS-LSR-STD-MIB’s
           mplsInterfaceConfTable."
      ::= { mplsLcFrStdObjects 1 }

   mplsLcFrStdInterfaceConfEntry OBJECT-TYPE
      SYNTAX        MplsLcFrStdInterfaceConfEntry
      MAX-ACCESS    not-accessible
      STATUS        current
      DESCRIPTION
          "An entry in this table is created by an LSR for
           every interface capable of supporting MPLS LC-FR.
           Each entry in this table will exist only if a
           corresponding entry in ifTable and mplsInterfaceConfTable
           exists.  If the associated entries in ifTable and
           mplsInterfaceConfTable are deleted, the corresponding
           entry in this table must also be deleted shortly
           thereafter."
      INDEX       { mplsInterfaceIndex }
         ::= { mplsLcFrStdInterfaceConfTable 1 }

   MplsLcFrStdInterfaceConfEntry ::= SEQUENCE {
      mplsLcFrStdTrafficMinDlci           DLCI,
      mplsLcFrStdTrafficMaxDlci           DLCI,
      mplsLcFrStdCtrlMinDlci              DLCI,
      mplsLcFrStdCtrlMaxDlci              DLCI,
      mplsLcFrStdInterfaceConfRowStatus   RowStatus,

      mplsLcFrStdInterfaceConfStorageType StorageType
   }

   mplsLcFrStdTrafficMinDlci OBJECT-TYPE
      SYNTAX        DLCI
      MAX-ACCESS    read-create
      STATUS        current
      DESCRIPTION
          "This is the minimum DLCI value over which this
           LSR is willing to accept traffic on this
           interface."
      ::= { mplsLcFrStdInterfaceConfEntry 1 }

   mplsLcFrStdTrafficMaxDlci OBJECT-TYPE
      SYNTAX        DLCI
      MAX-ACCESS    read-create
      STATUS        current
      DESCRIPTION
          "This is the max DLCI value over which this
           LSR is willing to accept traffic on this
           interface."
      ::= { mplsLcFrStdInterfaceConfEntry 2 }

   mplsLcFrStdCtrlMinDlci OBJECT-TYPE
      SYNTAX        DLCI
      MAX-ACCESS    read-create
      STATUS        current
      DESCRIPTION
          "This is the min DLCI value over which this
           LSR is willing to accept control traffic
           on this interface."
      ::= { mplsLcFrStdInterfaceConfEntry 3 }

   mplsLcFrStdCtrlMaxDlci OBJECT-TYPE
      SYNTAX        DLCI
      MAX-ACCESS    read-create
      STATUS        current
      DESCRIPTION
          "This is the max DLCI value over which this
           LSR is willing to accept control traffic
           on this interface."
      ::= { mplsLcFrStdInterfaceConfEntry 4 }

   mplsLcFrStdInterfaceConfRowStatus OBJECT-TYPE
      SYNTAX        RowStatus
      MAX-ACCESS    read-create
      STATUS        current
      DESCRIPTION

          "This object is used to create and
           delete entries in this table.  When configuring
           entries in this table, the corresponding ifEntry and
           mplsInterfaceConfEntry MUST exist beforehand.  If a manager
           attempts to create an entry for a corresponding
           mplsInterfaceConfEntry that does not support LC-FR,
           the agent MUST return an inconsistentValue error.
           If this table is implemented read-only, then the
           agent must set this object to active(1) when this
           row is made active.  If this table is implemented
           writable, then an agent MUST not allow modification
           to its objects once this value is set to active(1),
           except to mplsLcFrStdInterfaceConfRowStatus and
           mplsLcFrStdInterfaceConfStorageType."
      ::= { mplsLcFrStdInterfaceConfEntry 5 }

    mplsLcFrStdInterfaceConfStorageType OBJECT-TYPE
      SYNTAX        StorageType
      MAX-ACCESS    read-create
      STATUS        current
      DESCRIPTION
          "The storage type for this conceptual row.
           Conceptual rows having the value ’permanent(4)’
           need not allow write-access to any columnar
           objects in the row."
      DEFVAL { nonVolatile }
      ::= { mplsLcFrStdInterfaceConfEntry 6 }

   -- End of mplsLcFrStdInterfaceConfTable

   -- Module compliance.

   mplsLcFrStdCompliances
      OBJECT IDENTIFIER ::= { mplsLcFrStdConformance 1 }

   mplsLcFrStdGroups
      OBJECT IDENTIFIER ::= { mplsLcFrStdConformance 2 }

   -- Compliance requirement for full compliance

   mplsLcFrStdModuleFullCompliance MODULE-COMPLIANCE
      STATUS current
      DESCRIPTION
          "Compliance statement for agents that provide
           full support for MPLS-LC-FR-STD-MIB.  Such
           devices can be monitored and also be configured
           using this MIB module."

      MODULE -- this module
         MANDATORY-GROUPS {
            mplsLcFrStdIfGroup
         }

         OBJECT       mplsLcFrStdInterfaceConfRowStatus
         SYNTAX       RowStatus { active(1), notInService(2) }
         WRITE-SYNTAX RowStatus { active(1), notInService(2),
                                  createAndGo(4), destroy(6)
                                }
         DESCRIPTION "Support for createAndWait and notReady is
                      not required."

      ::= { mplsLcFrStdCompliances 1 }

   -- Compliance requirement for read-only implementations.

   mplsLcFrStdModuleReadOnlyCompliance MODULE-COMPLIANCE
      STATUS current
      DESCRIPTION
          "Compliance requirement for implementations that only
           provide read-only support for MPLS-LC-FR-STD-MIB.
           Such devices can be monitored but cannot be configured
           using this MIB module.
          "

      MODULE -- this module
         MANDATORY-GROUPS {
            mplsLcFrStdIfGroup
         }

         -- mplsLcFrStdInterfaceConfTable

         OBJECT     mplsLcFrStdTrafficMinDlci
         MIN-ACCESS  read-only
         DESCRIPTION
             "Write access is not required."

         OBJECT     mplsLcFrStdTrafficMaxDlci
         MIN-ACCESS  read-only
         DESCRIPTION
             "Write access is not required."

         OBJECT      mplsLcFrStdCtrlMinDlci
         MIN-ACCESS  read-only
         DESCRIPTION
             "Write access is not required."

         OBJECT      mplsLcFrStdCtrlMaxDlci
         MIN-ACCESS  read-only
         DESCRIPTION
             "Write access is not required."

         OBJECT       mplsLcFrStdInterfaceConfRowStatus
         SYNTAX       RowStatus { active(1) }
         MIN-ACCESS   read-only
         DESCRIPTION "Write access is not required."

         OBJECT      mplsLcFrStdInterfaceConfStorageType
         MIN-ACCESS  read-only
         DESCRIPTION
             "Write access is not required."
      ::= { mplsLcFrStdCompliances 2 }

   -- Units of conformance.

   mplsLcFrStdIfGroup OBJECT-GROUP
      OBJECTS {
           mplsLcFrStdTrafficMinDlci,
           mplsLcFrStdTrafficMaxDlci,
           mplsLcFrStdCtrlMinDlci,
           mplsLcFrStdCtrlMaxDlci,
           mplsLcFrStdInterfaceConfRowStatus,
           mplsLcFrStdInterfaceConfStorageType
       }
      STATUS  current

      DESCRIPTION
             "Collection of objects needed for MPLS LC-FR
              interface configuration."
      ::= { mplsLcFrStdGroups 1 }

   END

9.  Acknowledgments

   We wish to thank Joan Cucchiara and Carlos Pignataro for their
   comments on this document.

10.  Security Considerations

   It is clear that these MIB modules are potentially useful for
   monitoring MPLS LSRs supporting LC-ATM and/or LC-FR.  These MIBs can
   also be used for configuration of certain objects, and anything that
   can be configured can be incorrectly configured, with potentially
   disastrous results.

   There are a number of management objects defined in this MIB module
   with a MAX-ACCESS clause of read-write and/or read-create.  Such
   objects may be considered sensitive or vulnerable in some network
   environments.  The support for SET operations in a non-secure
   environment without proper protection can have a negative effect on
   network operations.  These are the tables and objects and their
   sensitivity/vulnerability:

   o    the MplsLcAtmStdInterfaceConfTable and
        mplsLcFrStdInterfaceConfTable collectively contain objects that
        may be used to provision MPLS LC or FR-enabled interfaces.
        Unauthorized access to objects in these tables could result in
        disruption of traffic on the network.  This is especially true
        if traffic has been established over these interfaces.  The use
        of stronger mechanisms such as SNMPv3 security should be
        considered where possible.  Specifically, SNMPv3 VACM and USM
        MUST be used with any v3 agent that implements this MIB module.
        Administrators should consider whether read access to these
        objects should be allowed, since read access may be undesirable
        under certain circumstances.

   Some of the readable objects in this MIB module (i.e., objects with a
   MAX-ACCESS other than not-accessible) may be considered sensitive or
   vulnerable in some network environments.  It is thus important to
   control even GET and/or NOTIFY access to these objects and possibly
   to even encrypt the values of these objects when sending them over
   the network via SNMP.  These are the tables and objects and their
   sensitivity/vulnerability:

   o    the MplsLcAtmStdInterfaceConfTable and
        mplsLcFrStdInterfaceConfTable collectively show the LC-ATM
        and/or LC-FR interfaces, their associated configurations, and
        their linkages to other MPLS-related configuration and/or
        performance statistics.  Administrators not wishing to reveal

        this information should consider these objects
        sensitive/vulnerable and take precautions so they are not
        revealed.

   SNMP versions prior to SNMPv3 did not include adequate security.
   Even if the network itself is secure (for example by using IPSec),
   even then, there is no control as to who on the secure network is
   allowed to access and GET/SET (read/change/create/delete) the objects
   in this MIB module.

   It is RECOMMENDED that implementers consider the security features as
   provided by the SNMPv3 framework (see [RFC3410], section 8),
   including full support for the SNMPv3 cryptographic mechanisms (for
   authentication and privacy).

   Further, deployment of SNMP versions prior to SNMPv3 is NOT
   RECOMMENDED.  Instead, it is RECOMMENDED to deploy SNMPv3 and to
   enable cryptographic security.  It is then a customer/operator
   responsibility to ensure that the SNMP entity giving access to an
   instance of this MIB module, is properly configured to give access to
   the objects only to those principals (users) that have legitimate
   rights to indeed GET or SET (change/create/delete) them.

11.  IANA Considerations

   As described in and as requested in the MPLS-TC-STD-MIB [RFC3811],
   MPLS-related standards track MIB modules should be rooted under the
   mplsStdMIB subtree.  There are 2 MPLS MIB modules contained in this
   document; each of the following "IANA Considerations" subsections
   requested from IANA a new assignment under the mplsStdMIB subtree.
   New assignments can only be made via a Standards Action as specified
   in [RFC2434].

11.1.  IANA Considerations for MPLS-LC-ATM-STD-MIB

   The IANA has assigned { mplsStdMIB 9 } to the MPLS-LC-ATM-STD-MIB
   module specified in this document.

11.2.  IANA Considerations for MPLS-LC-FR-STD-MIB

   The IANA has assigned { mplsStdMIB 10 } to the MPLS-LC-FR-STD-MIB
   module specified in this document.

12.  References

12.1.  Normative References

   [RFC3034]   Conta, A., Doolan, P., and A. Malis, "Use of Label
               Switching on Frame Relay Networks Specification", RFC
               3034, January 2001.

   [RFC3035]   Davie, B., Lawrence, J., McCloghrie, K., Rosen, E.,
               Swallow, G., Rekhter, Y., and P. Doolan, "MPLS using LDP
               and ATM VC Switching", RFC 3035, January 2001.

   [RFC2115]   Brown, C. and F. Baker, "Management Information Base for
               Frame Relay DTEs Using SMIv2", RFC 2115, September 1997.

   [RFC2514]   Noto, M., Spiegel, E., and K. Tesink, "Definitions of
               Textual Conventions and OBJECT-IDENTITIES for ATM
               Management", RFC 2514, February 1999.

   [RFC2863]   McCloghrie, K. and F. Kastenholz, "The Interfaces Group
               MIB", RFC 2863, June 2000.

   [RFC3031]   Rosen, E., Viswanathan, A., and R. Callon, "Multiprotocol
               Label Switching Architecture", RFC 3031, January 2001.

   [RFC3811]   Nadeau, T. and J. Cucchiara, "Definitions of Textual
               Conventions (TCs) for Multiprotocol Label Switching
               (MPLS) Management", RFC 3811, June 2004.

   [RFC3812]   Srinivasan, C., Viswanathan, A., and T. Nadeau,
               "Multiprotocol Label Switching (MPLS) Traffic Engineering
               (TE) Management Information Base (MIB)", RFC 3812, June
               2004.

   [RFC3813]   Srinivasan, C., Viswanathan, A., and T. Nadeau,
               "Multiprotocol Label Switching (MPLS) Label Switching
               Router (LSR) Management Information Base (MIB)", RFC
               3813, June 2004.

   [RFC2119]   Bradner, S., "Key words for use in RFCs to Indicate
               Requirement Levels", BCP 14, RFC 2119, March 1997.

   [RFC2578]   McCloghrie, K., Perkins, D., Schoenwaelder, J., Case, J.,
               Rose, M., and S. Waldbusser, "Structure of Management
               Information Version 2 (SMIv2)", STD 58, RFC 2578, April
               1999.

   [RFC2579]   McCloghrie, K., Perkins, D., Schoenwaelder, J., Case, J.,
               Rose, M., and S. Waldbusser, "Textual Conventions for
               SMIv2", STD 58, RFC 2579, April 1999.

   [RFC2580]   McCloghrie, K., Perkins, D., Schoenwaelder, J., Case, J.,
               Rose, M., and S. Waldbusser, "Conformance Statements for
               SMIv2", STD 58, RFC 2580, April 1999.

12.2.  Informative References

   [RFC2434]   Narten, T. and H. Alvestrand, "Guidelines for Writing an
               IANA Considerations Section in RFCs", BCP 26, RFC 2434,
               October 1998.

   [RFC3410]   Case, J., Mundy, R., Partain, D., and B. Stewart,
               "Introduction and Applicability Statements for Internet-
               Standard Management Framework", RFC 3410, December 2002.

   [RFC3815]   Cucchiara, J., Sjostrand, H., and J. Luciani,
               "Definitions of Managed Objects for the Multiprotocol
               Label Switching (MPLS), Label Distribution Protocol
               (LDP)", RFC 3815, June 2004.

Authors’ Addresses

   Thomas D. Nadeau
   Cisco Systems, Inc.
   300 Beaver Brook Road
   Boxboro, MA 01719

   Phone: +1-978-936-1470
   EMail: tnadeau@cisco.com

   Subrahmanya Hegde
   Cisco Systems, Inc.
   225 East Tazman Drive
   San Jose, CA 95134

   Phone: +1-408-525-6562
   EMail: subrah@cisco.com

Full Copyright Statement

   Copyright (C) The Internet Society (2006).

   This document is subject to the rights, licenses and restrictions
   contained in BCP 78, and except as set forth therein, the authors
   retain all their rights.

   This document and the information contained herein are provided on an
   "AS IS" basis and THE CONTRIBUTOR, THE ORGANIZATION HE/SHE REPRESENTS
   OR IS SPONSORED BY (IF ANY), THE INTERNET SOCIETY AND THE INTERNET
   ENGINEERING TASK FORCE DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED,
   INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE
   INFORMATION HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED
   WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE.

Intellectual Property

   The IETF takes no position regarding the validity or scope of any
   Intellectual Property Rights or other rights that might be claimed to
   pertain to the implementation or use of the technology described in
   this document or the extent to which any license under such rights
   might or might not be available; nor does it represent that it has
   made any independent effort to identify any such rights.  Information
   on the procedures with respect to rights in RFC documents can be
   found in BCP 78 and BCP 79.

   Copies of IPR disclosures made to the IETF Secretariat and any
   assurances of licenses to be made available, or the result of an
   attempt made to obtain a general license or permission for the use of
   such proprietary rights by implementers or users of this
   specification can be obtained from the IETF on-line IPR repository at
   http://www.ietf.org/ipr.

   The IETF invites any interested party to bring to its attention any
   copyrights, patents or patent applications, or other proprietary
   rights that may cover technology that may be required to implement
   this standard.  Please address the information to the IETF at
   ietf-ipr@ietf.org.

Acknowledgement

   Funding for the RFC Editor function is provided by the IETF
   Administrative Support Activity (IASA).
------分隔线----------------------------
顶一下
(0)
0%
踩一下
(0)
0%
------分隔线----------------------------
最新评论 查看所有评论
发表评论 查看所有评论
请自觉遵守互联网相关的政策法规,严禁发布色情、暴力、反动的言论。
评价:
表情:
用户名: 密码: 验证码:
推荐内容