DESCRIPTION
"A collection of objects containing information about
currently assigned addresses within a domain."
::= { t11FamMIBGroups 4 }
t11FamCacheGroup OBJECT-GROUP
OBJECTS { t11FamMaxFcIdCacheSize,
t11FamFcIdCacheAreaIdPortId,
t11FamFcIdCachePortIds
}
STATUS current
DESCRIPTION
"A collection of objects containing information about
recently-released Fibre Channel Address Identifiers."
::= { t11FamMIBGroups 5 }
t11FamNotificationGroup NOTIFICATION-GROUP
NOTIFICATIONS { t11FamDomainIdNotAssignedNotify,
t11FamNewPrincipalSwitchNotify,
t11FamFabricChangeNotify }
STATUS current
DESCRIPTION
"A collection of notifications for status monitoring
and notification."
::= { t11FamMIBGroups 6 }
END
7. Acknowledgements
This document began life as a work item of the INCITS Task Group
T11.5. We wish to acknowledge the many contributions and comments
from the INCITS Technical Committee T11, including the following:
T11 Chair: Robert Snively, Brocade
T11 Vice Chair: Claudio DeSanti, Cisco Systems
T11.5 Chair: Roger Cummings, Symantec
T11.5 members, especially:
Ken Hirata, Emulex
Scott Kipp, McData
Michael O’Donnell, McData
Elizabeth G. Rodriguez, Dot Hill
Steven L. Wilson, Brocade
Thanks also to Orly Nicklass of RAD Data Communications, Bert Wijnen
of Lucent, and those members of the IMSS WG who provided review
comments.
8. Normative References
[RFC2578] McCloghrie, K., Perkins, D., and J. Schoenwaelder,
"Structure of Management Information Version 2 (SMIv2)",
STD 58, RFC 2578, April 1999.
[RFC2579] McCloghrie, K., Perkins, D., and J. Schoenwaelder,
"Textual Conventions for SMIv2", STD 58, RFC 2579, April
1999.
[RFC2580] McCloghrie, K., Perkins, D., and J. Schoenwaelder,
"Conformance Statements for SMIv2", STD 58, RFC 2580,
April 1999.
[IF-MIB] McCloghrie, K. and F. Kastenholz, "The Interfaces Group
MIB", RFC 2863, June 2000.
[FC-MGMT] McCloghrie, K., "Fibre Channel Management MIB", RFC 4044,
May 2005.
[FC-SW-3] "Fibre Channel - Switch Fabric - 3 (FC-SW-3)", ANSI INCITS
384-2004, June 2004.
[FC-SW-4] "Fibre Channel - Switch Fabric - 4 (FC-SW-4)", ANSI INCITS
418-2006, 2006.
[FC-FS] "Fibre Channel - Framing and Signaling (FC-FS)" ANSI
INCITS 373-2003, April 2003.
9. Informative References
[RFC2837] Teow, K., "Definitions of Managed Objects for the Fabric
Element in Fibre Channel Standard", RFC 2837, May 2000.
[RFC3410] Case, J., Mundy, R., Partain, D., and B. Stewart,
"Introduction and Applicability Statements for Internet-
Standard Management Framework", RFC 3410, December 2002.
[FC-MI] "Fibre Channel - Methodologies for Interconnects (FC-MI)",
INCITS TR-30-2002, November 2002.
10. IANA Considerations
IANA has made two MIB OID assignments, one for the T11-TC-MIB module
and one for the T11-FC-FABRIC-ADDR-MGR-MIB module, under the
appropriate subtree(s).
11. Security Considerations
There are a number of management objects defined in this MIB module
with a MAX-ACCESS clause of read-write and/or read-create. Such
objects may be considered sensitive or vulnerable in some network
environments. The support for SET operations in a non-secure
environment without proper protection can have a negative effect on
network operations. These are the tables and objects and their
sensitivity/vulnerability:
t11FamConfigDomainId, t11FamConfigDomainIdType and
t11FamContiguousAllocation -- ability to change the address
allocation policy.
t11FamRestart and t11FamAutoReconfigure -- ability to cause a
fabric reconfiguration, e.g., on certain error conditions.
t11FamPriority -- ability to affect which switch becomes the
Principal Switch.
t11FamRcFabricNotifyEnable -- ability to enable/disable a
notification.
t11FamIfRcfReject -- ability to change the switch’s behavior on
receipt of an RCF.
t11FamIfRowStatus -- ability to change an interface
configuration parameter.
Some of the readable objects in this MIB module (i.e., objects with a
MAX-ACCESS other than not-accessible) may also be considered
sensitive or vulnerable in some network environments. It is thus
important to control even GET and/or NOTIFY access to these objects
and possibly to even encrypt the values of these objects when sending
them over the network via SNMP. These are the tables and objects and
their sensitivity/vulnerability:
t11FamTable and t11FamIfTable -- contain the configuration,
status, and statistics of the Fabric Address Manager.
t11FamAreaTable, t11FamDatabaseTable and t11FamFcIdCacheTable
-- contain information on currently assigned or recently-
released addresses.
SNMP versions prior to SNMPv3 did not include adequate security.
Even if the network itself is secure (for example by using IPsec),
even then, there is no control as to who on the secure network is
allowed to access and GET/SET (read/change/create/delete) the objects
in this MIB module.
It is RECOMMENDED that implementors consider the security features as
provided by the SNMPv3 framework (see [RFC3410], section 8),
including full support for the SNMPv3 cryptographic mechanisms (for
authentication and privacy).
Further, deployment of SNMP versions prior to SNMPv3 is NOT
RECOMMENDED. Instead, it is RECOMMENDED to deploy SNMPv3 and to
enable cryptographic security. It is then a customer/operator
responsibility to ensure that the SNMP entity giving access to an
instance of this MIB module is properly configured to give access to
the objects only to those principals (users) that have legitimate
rights to indeed GET or SET (change/create/delete) them.
Authors’ Addresses
Claudio DeSanti
Cisco Systems, Inc.
170 West Tasman Drive
San Jose, CA 95134 USA
Phone: +1 408 853-9172
EMail: cds@cisco.com
Vinay Gaonkar
Cisco Systems, Inc.
170 West Tasman Drive
San Jose, CA 95134 USA
Phone: +1 408 527-8576
EMail: vgaonkar@cisco.com
Keith McCloghrie
Cisco Systems, Inc.
170 West Tasman Drive
San Jose, CA USA 95134
Phone: +1 408-526-5260
EMail: kzm@cisco.com
Silvano Gai
Retired
Full Copyright Statement
Copyright (C) The Internet Society (2006).
This document is subject to the rights, licenses and restrictions
contained in BCP 78, and except as set forth therein, the authors
retain all their rights.
This document and the information contained herein are provided on an
"AS IS" basis and THE CONTRIBUTOR, THE ORGANIZATION HE/SHE REPRESENTS
OR IS SPONSORED BY (IF ANY), THE INTERNET SOCIETY AND THE INTERNET
ENGINEERING TASK FORCE DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED,
INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE
INFORMATION HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED
WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE.
Intellectual Property
The IETF takes no position regarding the validity or scope of any
Intellectual Property Rights or other rights that might be claimed to
pertain to the implementation or use of the technology described in
this document or the extent to which any license under such rights
might or might not be available; nor does it represent that it has
made any independent effort to identify any such rights. Information
on the procedures with respect to rights in RFC documents can be
found in BCP 78 and BCP 79.
Copies of IPR disclosures made to the IETF Secretariat and any
assurances of licenses to be made available, or the result of an
attempt made to obtain a general license or permission for the use of
such proprietary rights by implementers or users of this
specification can be obtained from the IETF on-line IPR repository at
http://www.ietf.org/ipr.
The IETF invites any interested party to bring to its attention any
copyrights, patents or patent applications, or other proprietary
rights that may cover technology that may be required to implement
this standard. Please address the information to the IETF at
ietf-ipr@ietf.org.
Acknowledgement
Funding for the RFC Editor function is provided by the IETF
Administrative Support Activity (IASA).