Study ¡Ð °á®Ñ

¬°¤°»ò­n°á®Ñ©O¡H¥D­n¦³¨â­Ó­ì¦]¡G²Ä¤@­Ó¬O§Ú­Ì­n¨Ï¥ÎSNMP³o­Ó§Þ³N¡A©Ò¥H·íµM¦b¨Ï¥Î¤§«e­n¥ýª¾¹D³o­Ó§Þ³N¬O®³¨Ó§@¤°»ò¥Îªº¡H¦³¤°»òªF¦è¥i¥H¥Î¡H¥Î¤°»ò¤èªk¥h¹ê»Ú¦bºô¸ô¤W­±¶Ç°e³o¨Ç¨à¦³·N¸q¦³¥Îªº¸ê°T¡A¦]¬°§Ú­Ì¹ïSNMP±o¤F¸Ñ¶V¦hªº¸Ü¡A§Ú­Ì©Ò¯à°µªºÀ³¥Î´N¶V¦h¡AÁ|­Ó²³æªº¨Ò¤l¡A¦b­è¶}©lªº®É­Ô¡A§Ú¦Û¤v¹ï©óSNMPªº¤F¸Ñ¶È­­©ó§Ú­Ì±`¥Î¨Ó¬Ý¬y¶q²Î­pªº³nÅéMRTG¡A¦]¬°MRTG¸Ì­±¬O³z¹LSNMP¥h¹ï©Ò­nºÊ´ú

ªº¾÷¾¹°µ°O¿ý¡AµM«á§@¦¨§Ú­Ì©Ò¬Ý¨ìªº¹Ïªí(¤W¹Ï)¡A©Ò¥H­è¶}©l§Ú¥H¬°SNMP¶È¥i¥H¨º¨Ó°µ²Î­p¥H¤Î¶¡ºÊ´ú¦Ó¤w¡A¦ý¬O¦b©À¹LSNMP°ò¥»ªºv1¥H¤Îv2¤§«á¡A¤~ª¾¹DMRTG¥u¬OÀ³¥Î¤FSNMP¸Ì­±³Ì°ò¥»ªº¥\¯à¡A·N«ä´N¬O»¡§Ú­Ì¬O¥i¥H°µ§ó¦h¨Æ±¡ªº¡A¦]¬°¦pªG¥u¬O°ßŪªº¨ó©wªº¸Ü¡A´N¯uªº¥u¯à®³¨Ó§@ºÊ´ú¦ý¬O¦pªGÁÙ¥i¥H§â¤@¨Ç¨à§Ú­Ì©Ò«ü©wªº¸ê®Æ¼g¦^¥hªº¸Ü¡A´N¥i¥H°µ¨ì»·ºÝºÞ²z¡A©Ò¥H§Ú­Ì´N¥»µÛ³o­Ó¤ßºAÄ~Äò§âSNMP§Ú­Ì©Ò¤£ª¾¹Dªº¦a¤è¬Ý§¹¡AµM«á°µ¥X¤@¨Ç²³æªº¾ã²z¡G

(1) Ãö©óSNMPª©¥»ªº°ÝÃD

SNMPªºª©¥»­è¶}©l´N¬O§Ú­Ì©Ò¼ôª¾ªºv1¡A±µµÛ¦]¬°v1ªº¥\¯àÁöµM«Ü²«K¡A¦Ó¥B¸Ó¦³ªº³£¦³¡A³ôºÙ¤p¦Ó¬ü¥B¤­Å¦­Ñ¥þ¡A¦ý¬O¥Ñ©ó¯Ê¥FUser-BasedªºÆ[©À¦A¥[¤W¨S¦³ªñ¥N¤j®a©ÒÃö¤ßªº¦w¥þ»{ÃÒ¡A¬Æ¦Ü©ó¥[±KªºÆ[©À¡A©Ò¥H­ì¥»ªºSNMP´N¶}©l©¹¨â­Ó¤è¦V¨«¡A¦p¤W¹Ï©Ò¥Ü¤@­Ó©¹§ï¶i­ì¥»ªºSNMP¤º³¡µ²ºc¦ÓÅܦ¨¤FSNMPv2¡A¦Ó¥t¤@­Ó«hÅܦ¨Secure SNMP¡AµM«á¦b«á¨Ó²×©ó­n¾ã¦X¦¨SNMPv2¡A¥u¬O¦]¬°ºØºØªº­ì¦]¡A¦bv2¥X¨Ó¤§«e¤S¤À¬°v2c(without secure)©Mv2u,v2*(secure)¡A¦Ó¦b¤§«áªºv3´N²×©ó§â³o¨â¶ô¾ã¦X°_¨Ó¡C

(2) SNMP°ò¥»ªº«ü¥O¥H¤Î¥\¯à

1. snmpget

„« ±o¨ìagent¤W­±¡A§Ú­Ì©Ò»Ý­nªºdata(manager ¥hquery agent)

2. snmpset

„« ±N§Ú­Ì©Ò»Ý­nªºdata¦s¦^agent¤W­±(manager ¥h query agent)

3. snmptrap

„« ±Nagent¤W­±ªºdataª½±µ¥áµ¹manager(¤£¸g¹Lmanagerªºquery)

(3) MIB

1. MIB±q¥~­±¨Ó¬Ý¡A¬Ý°_¨Ó¹³¬O¤@­ÓÃe¤jªº¨t²Î¸ê°T¸ê®Æ®w

2. MIB±q¸Ì­±¨Ó¬Ý¡A¨S¦³·Q¹³¤¤ªºÂ²³æ¡A¨Ã¤£¬O³æ³æ¤@­ÓÃe¤jªº¸ê®Æ®w´N¥i¥H¸Ñ¨Mªº

3. MIB¬O¤@­ÓÃe¤jªº¶°¦X¡A¸Ì­±ªº¥ô¦ó¤@­Ó¤¸¯À³£¬O¦b¨t²Î¸Ì­±¶]ªºµ{¦¡

4. §Ú­Ì±qmanagerºÝ¥hquery agentºÝªº®É­Ô¡A¤£¬O¦p¦P§Ú­Ì­è¶}©l·Q¹³ªº¡A§Ï©»¥h¸ê®Æ®w¸Ì­±¨ú¸ê®Æ¥X¨Ó¡A¦Ó¬Oagent·|¥ý¥h³B¸Ì§Ú­Ì¥á¥X¥hªºquery°Ý¥y¡AµM«á¥h¶]¬Û¹ïÀ³ªºµ{¦¡¡AµM«á¦A§â©Ò±o¨ìªº¬Û¹ïÀ³data¶Ç¦^¨Óµ¹manager

5. ©w¸qMIB¤]¬O¤@¼Ëªº¡AÁöµM­ì¥»ªºMIB»yªk­n¼g¦ý¬O¬Û¹ïÀ³ªºµ{¦¡¤]­n¼g¡A³o¼Ë¤@²Õ¹ïÀ³ªºagent ¡ö¡÷ manager¤~¯à¬Û¤¬§@¥Î

µ²½×¡G§Ú­Ì­n§ïMIB³o¤@¶ô¯uªº­n§ï«Ü¤[ ¡K.

(4) SNMPv3

1. ·sªº¬[ºc

¤W¹Ï¬OSNMPv3ªºmanagerºÝªº¬[ºc¡A¥i¥H¬Ý¨ì¦b¬[ºc¤W­±´N§ï¤F¤£¤ÖªF¦è¡A­ì¥»³æ¯ÂªºSNMP¬[ºc³Q¤Á¦¨¤F¦n´X¶ô¡A¦Ó¥B¬°¤F¬Û®e­ì¥»ªºª©¥»¡A©Ò¥H¦b¤ÀªR§¹message¤§«á¡A¬O¥i¥H¦P®É¨Ã¦æªº¶]¦U­ÓSNMPªºª©¥»¡A¥u¬O¦bSNMPªºª©¥»«á­±ªº¨º¶ô¦³ÃöSecurityªº³¡¥÷¥Ø«e¬°¤î´N¥u¦³v3¦³¤ä´©¡A©Ò¥H¹ï©óv1©Mv2¦Ó¨¥´N¨S¤°»òÃö«Y¡A·íµM«á­±ªºSecurity Subsystem¤]¬Ov3ªº¯S¦â¡C

¤W¹Ï¬OSNMPv3ªºagentºÝªº¬[ºc¡A¥i¥H¬Ý¨ì³o­Ó¬[ºc©MmanagerºÝªº¬[ºc®t¤£¦h¡A¨ä¹ê­ì¥»managerºÝ©MagentºÝªº¬[ºc´N¤£·|®t¤Ó¦h¡A©Ò¥H¤~·|¬Ý°_¨Óªø±o³o»ò¹³¡A¦ý¬O¥i¥H¬Ý¨ìagentºÝªº«á­±¦³¤@¶ô¬OAccess Control Subsystem¡A³o­Ó³¡¥÷¦]¬°¬O¨Ì¾ÌµÛMIB¦Ó¦s¦bµÛªº¡A©Ò¥H¤~·|¥u¦³agentºÝ¦³¦ÓmanagerºÝ¨S¦³¡C

2. ·sªºmessage format

¤W¹Ï¬OSNMPv3¬y³qµÛªºmessageªº®æ¦¡¡A¥i¥H¬Ý¨ì¦³¤@°ï®æ¤lªºµù¸Ñ¸Ì­±³£¦³µÛ¡¨Security¡¨³o­Ó¦r¡A¨ä¹ê§â¤¤¶¡ÃC¦â¤ñ¸û²`ªº¨º¤@¶ô¥h±¼¸Ü¡A´N¬O­ì¥»v1©Mv2ªºmessage formate¡A¨º¥Ñ³o­Ó¦a¤è´N¬Ý±o¥XSNMPv3¸Ì­±­«µøSecurityªº³¡¥÷¡C

¨º¦b³o¸Ì²³æªº¸ÑÄÀ¤@¤U¤¤¶¡¨º¤@¶ô¦³­þ¨Ç¨àªF¦è¡A¸Ì­±¦³User,Password,¥H¤Î¤@¨Ç¦w¥þ©Ê¤Wªº¤p¤â¸}¡A¨º¥D­n±j½Õªº¬O³o¨Ç¦w¥þ©Êªº±¹¬I¥H¤Î§Ú­Ì©Ò­«µøªºUser-Basedªº¾÷¨î¡A¦]¬°¦b¤§«e¨Ã¨S¦³³o¨Ç¨à¾÷¨î(¤§«eªºv1,v2¦³­Ócommunity¡A¦Ó¥B¤]´N¥u¦³³o­Ócommunity¡Aµ¥©ó¬O¦³User¦ý¬O¨S¦³Password¡A©Ò¥Hµ¥©ó¬O¥u­nª¾¹DUser´N¥i¥H¶i¤J¥h°µ¦s¨úªº°Ê§@¡A¥i·Q¦Óª¾¬O«D±`ªº¤£¦w¥þ¡A¨ºv3¦b³o­Ó¦a¤è°µ¤F¬Û·í¤jªº§ï¶i¡A¦]¬°¦³¤F¥[±K¹LªºPassword¡C

3. ·sªº Process Diagram

¦p¤W¹Ï¡A¥ªÃä¬OmanagerºÝ¡A¦Ó¥kÃä¬OagentºÝ¡A§Ú­Ì¥i¥H¥ý¬Ý¬Ý¥ªÃ䪺¹Ï¡A¦pªGª½µÛ¬Ý¡A´N·|µo²{¥D­n¦³¨â¦æªF¦è¡A¤@¦æ¬O¥D­nªºprocess¡A¦Ó®ÇÃä´N·|¦³­ì¥»ªºprocess¤§¥~¡AÃB¥~ªºªF¦è¡A¨ºÂ²³æªº»¡¡A¥D­nªº¨º¤@¦æ´N¬Ov1,v2¦b¶]ªºprocess¡A¦Ó¦h¥X¨Óªº¨º¨â­Ócircle«h¬Ov3¥[¶i¥hªº¦w¥þ¤WªºªF¦è¡A¨º¥D­n¤]¬O°Ý­n¤£­n¥[±K¥H¤Î­n¤£­n©ñ¤W¦w¥þ©Êªº¤@¨Ç¸ê®Æ¡C

4. ·sªºSecurity Model

a. User-based security model(USM)

²³æªº»¡´N¬O­ì¥»ªºv1,v2¨S¦³User-BasedªºÆ[©À¡A©Ò¥H¥u¥ÎCommunity¨Ó·í§@User¥h¦s¨úagent¡A¦Óv3´N¦b³o¸Ì¥[¤F±b¸¹ªº¾÷¨î¡A¬Ý°_¨Ó´N¸û¦³¨t²ÎÂI¨à¡A¦Ó¥B¤]¥i¥H°µ¤À¤u¡A¤£¦Pªº¤u§@ªÌ¦³µÛ¤£¦PªºÅv­­¡C

b. View-based access control model(VACM)

³o­Ómodel¬Obased on«e­±ªºUSM¥H¤ÎMIB¡A¦]¬°³o­Ómodelªº·N«ä´N¬O¤£¦PªºUser¦b³]©w¹LÅv­­¤§«á¡A´N¥i¥H¦s¨ú³Q³]©w¹LÅv­­ªºMIB¡C