ELEC3506

Topics

Application LayerLecture 8 PDF15 min

Network management and SNMP

The components of network management, the three operator approaches (CLI, SNMP with MIB, NETCONF with YANG), and how SNMP, SMI and the MIB work together using eight PDU types.

By the end of this page you should be able to

  • Define network management and name its components
  • Compare the CLI, SNMP/MIB and NETCONF/YANG approaches to managing devices
  • Describe the manager and agent roles and the three basic ideas of SNMP
  • Say what SNMP, SMI and the MIB each define
  • List the eight SNMPv3 PDU types and give the direction and function of each

The idea

A network has hundreds of routers, switches and hosts. Logging in to each one to read its counters or change its settings does not scale. Network management gives operators a way to ask devices questions, change their settings and hear from them when something goes wrong, from one place.

This page covers the oldest standard way to do it, SNMP, and the vocabulary that the newer NETCONF approach in the next topic shares.

How it works

Definition and components

Network management is monitoring, testing, configuring and troubleshooting network components to meet a set of requirements.

The lecture’s components are:

  • Managing server: an application, typically with network managers (humans) in the loop.
  • Managed device: equipment with manageable, configurable hardware and software components.
  • Data: the device state, made of configuration data, operational data and device statistics.
  • Network management protocol: used by the managing server to query, configure and manage devices, and by devices to inform the managing server of data and events.

How it works

Operator approaches to management

The lecture gives three.

  • CLI (command line interface): the operator issues commands, typed or scripted, directly to individual devices, for example via ssh.
  • SNMP/MIB: the operator queries and sets device data (the MIB) using the Simple Network Management Protocol.
  • NETCONF/YANG: more abstract, network-wide and holistic, with emphasis on multi-device configuration management. YANG is a data modelling language and NETCONF communicates YANG-compatible actions and data to, from and among remote devices.

How it works

SNMP

SNMP is an application layer protocol for managing devices in the Internet using the TCP/IP protocol suite.

  • The manager is a host that runs the SNMP client program.
  • The agent is a router or host that runs the SNMP server program.

SNMP rests on three basic ideas:

  1. The manager checks an agent by requesting information from it.
  2. The manager forces the agent to perform a task by resetting values in the agent database.
  3. The agent warns the manager of an unusual situation.

How it works

The three management protocols

Internet management needs three things working together.

  • SNMP defines the format of the packets exchanged between a manager and an agent, and reads and changes the status of objects in SNMP packets.
  • Structure of Management Information (SMI) defines the general rules for naming objects, defines object types, and defines how to encode objects and values.
  • Management Information Base (MIB) creates a collection of named objects, their types and their relationships.

How it works

The MIB

A managed device’s operational data, and some configuration data, is gathered into a device MIB module. The lecture says about 400 MIB modules are defined in RFCs, with many more vendor-specific MIBs. SMI is the data definition language used to describe them.

The lecture’s example is a set of MIB variables for the UDP protocol:

Object IDNameTypeComment
1.3.6.1.2.1.7.1UDPInDatagrams32-bit counterTotal number of datagrams delivered
1.3.6.1.2.1.7.2UDPNoPorts32-bit counterNumber of undeliverable datagrams (no application at the port)
1.3.6.1.2.1.7.3UDPInErrors32-bit counterNumber of undeliverable datagrams (all other reasons)
1.3.6.1.2.1.7.4UDPOutDatagrams32-bit counterTotal number of datagrams sent
1.3.6.1.2.1.7.5udpTableSEQUENCEOne entry for each port currently in use
The slide prints the third name as UDInErrors, which looks like a typo for UDPInErrors.

How it works

Two ways to convey MIB information

SNMP carries MIB information and commands in two modes.

  • Request/response mode: the managing server sends a request and the managed device returns a response.
  • Trap mode: the agent sends an unsolicited message, a trap message, without being asked.

How it works

SNMP operations

SNMPv3 defines eight types of packets, called protocol data units (PDUs): GetRequest, GetNextRequest, GetBulkRequest, SetRequest, Response, Trap, InformRequest and Report.

Message typeDirectionFunction
GetRequestManager to agentRetrieve the value of variables (an instance)
GetNextRequestManager to agentRetrieve the value of variables (the next in the list)
GetBulkRequestManager to agentRetrieve the value of variables (a block)
SetRequestManager to agentSet the value in a variable
ResponseAgent to managerGive the value of the variables requested by the manager
TrapAgent to managerInform the manager of an exceptional event
InformRequestManager to managerGet the value of variables from an agent under the control of a remote manager
ReportManager to managerReport errors between managers
Rebuilt from a table whose columns extracted out of alignment. The three Get messages share one function cell on the slide, split here by the instance, next and block words.

Aside

Table layout in the extraction

The slide’s table lost its row alignment, so the direction of each message was matched to its function by the order of the six directions printed and by what each function means. The match is consistent, but the extraction does not mark it row by row. Check the slide if a question hinges on one direction.

Aside

Transport

The SNMP slides do not name a transport protocol. The UDP topic in module 8 lists SNMP among the management processes that use UDP.

Where marks get lost

A trap is not an answer to a request. Responses reply to manager requests. Traps are sent by the agent on its own when something exceptional happens, so the manager does not have to poll for it.

In the exam

  • Definition: monitoring, testing, configuring and troubleshooting network components to meet a set of requirements.
  • Roles: manager runs the SNMP client, agent runs the SNMP server.
  • The three ideas: request information, force a task by resetting values, warn of an unusual situation.
  • SNMP, SMI, MIB: packet format, naming and encoding rules, and the collection of named objects.
  • Eight PDUs with direction. Be ready to sort them into manager to agent, agent to manager and manager to manager.

Check yourself

  • Network management means monitoring, testing, configuring and troubleshooting devices from a managing server.
  • Three approaches: CLI, SNMP/MIB, NETCONF/YANG.
  • SNMP has a manager (client) and agent (server), and works in request/response mode or trap mode.
  • SNMP formats packets, SMI names and encodes objects, MIB holds them.
  • Eight PDUs: GetRequest, GetNextRequest, GetBulkRequest, SetRequest, Response, Trap, InformRequest, Report.

Check yourself

  1. Which approach has the operator issue commands directly to individual devices, for example over ssh?
  2. What triggers an SNMP Trap?
  3. Which SNMP PDU is used to set the value of a variable?
  4. Which component defines the general rules for naming objects and how to encode them?
  5. Between which two parties do InformRequest and Report messages travel?