rfc2571.txt
来自「RFC 的详细文档!」· 文本 代码 · 共 1,528 行 · 第 1/5 页
TXT
1,528 行
3.1.1.1. snmpEngineID
Within an administrative domain, an snmpEngineID is the unique and
unambiguous identifier of an SNMP engine. Since there is a one-to-one
association between SNMP engines and SNMP entities, it also uniquely
and unambiguously identifies the SNMP entity within that
administrative domain. Note that it is possible for SNMP entities in
different administrative domains to have the same value for
snmpEngineID. Federation of administrative domains may necessitate
assignment of new values.
3.1.1.2. Dispatcher
There is only one Dispatcher in an SNMP engine. It allows for
concurrent support of multiple versions of SNMP messages in the SNMP
engine. It does so by:
- sending and receiving SNMP messages to/from the network,
- determining the version of an SNMP message and interacting with
the corresponding Message Processing Model,
- providing an abstract interface to SNMP applications for
delivery of a PDU to an application.
- providing an abstract interface for SNMP applications that
allows them to send a PDU to a remote SNMP entity.
SNMPv3 Working Group Standards Track [Page 17]
RFC 2571 Architecture for SNMP Frameworks April 1999
3.1.1.3. Message Processing Subsystem
The Message Processing Subsystem is responsible for preparing
messages for sending, and extracting data from received messages.
The Message Processing Subsystem potentially contains multiple
Message Processing Models as shown in the next figure.
* One or more Message Processing Models may be present.
+------------------------------------------------------------------+
| |
| Message Processing Subsystem |
| |
| +------------+ +------------+ +------------+ +------------+ |
| | * | | * | | * | | * | |
| | SNMPv3 | | SNMPv1 | | SNMPv2c | | Other | |
| | Message | | Message | | Message | | Message | |
| | Processing | | Processing | | Processing | | Processing | |
| | Model | | Model | | Model | | Model | |
| | | | | | | | | |
| +------------+ +------------+ +------------+ +------------+ |
| |
+------------------------------------------------------------------+
3.1.1.3.1. Message Processing Model
Each Message Processing Model defines the format of a particular
version of an SNMP message and coordinates the preparation and
extraction of each such version-specific message format.
3.1.1.4. Security Subsystem
The Security Subsystem provides security services such as the
authentication and privacy of messages and potentially contains
multiple Security Models as shown in the following figure
SNMPv3 Working Group Standards Track [Page 18]
RFC 2571 Architecture for SNMP Frameworks April 1999
* One or more Security Models may be present.
+------------------------------------------------------------------+
| |
| Security Subsystem |
| |
| +----------------+ +-----------------+ +-------------------+ |
| | * | | * | | * | |
| | User-Based | | Other | | Other | |
| | Security | | Security | | Security | |
| | Model | | Model | | Model | |
| | | | | | | |
| +----------------+ +-----------------+ +-------------------+ |
| |
+------------------------------------------------------------------+
3.1.1.4.1. Security Model
A Security Model specifies the threats against which it protects, the
goals of its services, and the security protocols used to provide
security services such as authentication and privacy.
3.1.1.4.2. Security Protocol
A Security Protocol specifies the mechanisms, procedures, and MIB
objects used to provide a security service such as authentication or
privacy.
3.1.2. Access Control Subsystem
The Access Control Subsystem provides authorization services by means
of one or more (*) Access Control Models.
+------------------------------------------------------------------+
| |
| Access Control Subsystem |
| |
| +---------------+ +-----------------+ +------------------+ |
| | * | | * | | * | |
| | View-Based | | Other | | Other | |
| | Access | | Access | | Access | |
| | Control | | Control | | Control | |
| | Model | | Model | | Model | |
| | | | | | | |
| +---------------+ +-----------------+ +------------------+ |
| |
+------------------------------------------------------------------+
SNMPv3 Working Group Standards Track [Page 19]
RFC 2571 Architecture for SNMP Frameworks April 1999
3.1.2.1. Access Control Model
An Access Control Model defines a particular access decision function
in order to support decisions regarding access rights.
3.1.3. Applications
There are several types of applications, including:
- command generators, which monitor and manipulate management
data,
- command responders, which provide access to management data,
- notification originators, which initiate asynchronous messages,
- notification receivers, which process asynchronous messages,
and
- proxy forwarders, which forward messages between entities.
These applications make use of the services provided by the SNMP
engine.
3.1.3.1. SNMP Manager
An SNMP entity containing one or more command generator and/or
notification receiver applications (along with their associated SNMP
engine) has traditionally been called an SNMP manager.
SNMPv3 Working Group Standards Track [Page 20]
RFC 2571 Architecture for SNMP Frameworks April 1999
* One or more models may be present.
(traditional SNMP manager)
+-------------------------------------------------------------------+
| +--------------+ +--------------+ +--------------+ SNMP entity |
| | NOTIFICATION | | NOTIFICATION | | COMMAND | |
| | ORIGINATOR | | RECEIVER | | GENERATOR | |
| | applications | | applications | | applications | |
| +--------------+ +--------------+ +--------------+ |
| ^ ^ ^ |
| | | | |
| v v v |
| +-------+--------+-----------------+ |
| ^ |
| | +---------------------+ +----------------+ |
| | | Message Processing | | Security | |
| Dispatcher v | Subsystem | | Subsystem | |
| +-------------------+ | +------------+ | | | |
| | PDU Dispatcher | | +->| v1MP * |<--->| +------------+ | |
| | | | | +------------+ | | | Other | | |
| | | | | +------------+ | | | Security | | |
| | | | +->| v2cMP * |<--->| | Model | | |
| | Message | | | +------------+ | | +------------+ | |
| | Dispatcher <--------->+ | | | |
| | | | | +------------+ | | +------------+ | |
| | | | +->| v3MP * |<--->| | User-based | | |
| | Transport | | | +------------+ | | | Security | | |
| | Mapping | | | +------------+ | | | Model | | |
| | (e.g RFC1906) | | +->| otherMP * |<--->| +------------+ | |
| +-------------------+ | +------------+ | | | |
| ^ +---------------------+ +----------------+ |
| | |
| v |
+-------------------------------------------------------------------+
+-----+ +-----+ +-------+
| UDP | | IPX | . . . | other |
+-----+ +-----+ +-------+
^ ^ ^
| | |
v v v
+------------------------------+
| Network |
+------------------------------+
SNMPv3 Working Group Standards Track [Page 21]
RFC 2571 Architecture for SNMP Frameworks April 1999
3.1.3.2. SNMP Agent
An SNMP entity containing one or more command responder and/or
notification originator applications (along with their associated
SNMP engine) has traditionally been called an SNMP agent.
+------------------------------+
| Network |
+------------------------------+
^ ^ ^
| | |
v v v
+-----+ +-----+ +-------+
| UDP | | IPX | . . . | other |
+-----+ +-----+ +-------+ (traditional SNMP agent)
+-------------------------------------------------------------------+
| ^ |
| | +---------------------+ +----------------+ |
| | | Message Processing | | Security | |
| Dispatcher v | Subsystem | | Subsystem | |
| +-------------------+ | +------------+ | | | |
| | Transport | | +->| v1MP * |<--->| +------------+ | |
| | Mapping | | | +------------+ | | | Other | | |
| | (e.g. RFC1906) | | | +------------+ | | | Security | | |
| | | | +->| v2cMP * |<--->| | Model | | |
| | Message | | | +------------+ | | +------------+ | |
| | Dispatcher <--------->| +------------+ | | +------------+ | |
| | | | +->| v3MP * |<--->| | User-based | | |
| | | | | +------------+ | | | Security | | |
| | PDU Dispatcher | | | +------------+ | | | Model | | |
| +-------------------+ | +->| otherMP * |<--->| +------------+ | |
| ^ | +------------+ | | | |
| | +---------------------+ +----------------+ |
| v |
| +-------+-------------------------+---------------+ |
| ^ ^ ^ |
| | | | |
| v v v |
| +-------------+ +---------+ +--------------+ +-------------+ |
| | COMMAND | | ACCESS | | NOTIFICATION | | PROXY * | |
| | RESPONDER |<->| CONTROL |<->| ORIGINATOR | | FORWARDER | |
| | application | | | | applications | | application | |
| +-------------+ +---------+ +--------------+ +-------------+ |
⌨️ 快捷键说明
复制代码Ctrl + C
搜索代码Ctrl + F
全屏模式F11
增大字号Ctrl + =
减小字号Ctrl + -
显示快捷键?