19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Communications Remarks<br />

____________________________________________________________________ .........................................<br />

administrator as, otherwise, unsupervised changes to the WINS configuration<br />

are possible.<br />

SNMP (Simple Network Management Protocol)<br />

SNMP is used for supervision and administration of a TCP/IP-based network.<br />

<strong>The</strong> SNMP service is installed if the appropriate options are selected when<br />

installing Windows NT TCP/IP. Following installation the SNMP service<br />

must be configured with valid information for SNMP to be operational.<br />

Only members of the administrator group of the local computer may configure<br />

SNMP. During configuration, Communities and Trap-Targets will be defined:<br />

- A Community is a group of hosts to which one server belongs which<br />

executes the SNMP service. <strong>The</strong> Windows NT system on which SNMP has<br />

been installed will send Traps to one or more entered Communities. <strong>The</strong><br />

name of the community will be recorded in the SNMP packet when<br />

sending Traps. If the SNMP service receives a request which does not<br />

contain the correct Community name and does not correspond to any of the<br />

accepted hosts, the SNMP service can send a trap to the Trap-Target(s)<br />

drawing attention to the fact that the confirmation of authenticity failed.<br />

- Trap-Targets are the names or IP addresses of hosts to whom the SNMP<br />

service will send traps, i.e. messages of pre-defined events, with the<br />

selected Community names.<br />

Note: In principal, SNMP should be configured in such a way that it only<br />

accepts requests from the defined Communities (and if possible not the predefined<br />

Community public).<br />

SNMP security allows Communities and Hosts to be defined from which a<br />

computer accepts requests. Furthermore, it can be defined whether a<br />

confirmation of authenticity Trap is sent if a Community or Host requests<br />

information without authority. <strong>The</strong>se determinations must be carefully<br />

planned and the possibility to send Traps must be used. <strong>The</strong> resulting logs<br />

must be checked regularly.<br />

Additional controls:<br />

- Are only the minimal necessary network services installed / activated?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!