Are you ready to take advantage of the new security features of SNMPv3 (Simple Network Management Protocol)? Many users of SNMP know that SNMPv3 is more secure than the previous versions, SNMPv1 and SNMPv2c, but may not know the details about SNMPv3 and/or the key steps to successfully implementing the protocol.

A Little Bit About SNMPv3

The release of SNMPv3 is set to address security deficiencies and provide a proper framework for securing access, authentication and control. SNMPv3 is not a stand-alone replacement for version 1 or 2, but rather an added security ability to be used in conjunction with SNMPv2 (ideal) or SNMPv1. Additionally, it is important to understand the primary or core responsibilities of SNMP and the associated agents. The device agent is tasked to collect and maintain information about the local environment. The agent will provide that information to a manager in the form of a response to a request or in an unsolicited method when something significant happens to the device. Lastly, the agent can respond to a manager’s command to alter the device’s configuration or operating parameter.

One of the key components of SNMP is the Management Information Base (MIB) which is a virtual database used for managing devices on a given network. This virtual database can refer to the complete collection of management information on a certain device. Typically, a Network Management System (NMS), such as NeuralStar that provides full SNMPv3 support can query or look-up information on a device’s MIB and retrieve metrics or other analytics. When adopting or implementing SNMPv3 the security subsystem of the protocol can prevent unauthorized users from accessing a MIB or parts of a MIB. Additionally, usage of version 3 can ensure that authorized users retrieve and update information from only the parts of the MIB that they are allowed to view. With that background out of the way, here is a list of recommended or supplemental procedures for implementing SNMPv3.

Keys to Successfully Implementing SNMPv3

1. Disable SNMPv1 and SNMPv2c/2.5 from any critical or network edge devices

2. Update network devices or servers to ensure full compatibly with SNMPv3

3. Develop role based management system where restriction or access to configurations, monitoring, metrics, or reporting is based upon an operating role

4. Develop a separate management VLAN to be used locally and to transport all SNMPv3 traffic back and forth between the agents and managers

5. Ensure the SNMPv3 implementation meets guidelines set forth by regulatory demands such as HIPAA, PCI, FERPA, SOX, GBLA, DoD, FIPS/NIST, and FISMA (including setting privacy to AES 256)

6. Filter ingress/egress SNMP traffic at the network edge and limit internal SNMP traffic with Access Control Lists (ACLs)

7. If possible, make any critical network device and especially edge device MIBs read-only

8. Verify that no “public” or “private” community strings still exist on any network device, including printers or other headless devices

Let us know if you have any specific recommendations we didn’t mention or if you have any questions about SNMPv3, contact us at info@kratosnetworks.com.

TAGGED UNDER

network management, network monitoring, snmp, it,

When seconds add up to minutes and minutes count in your busy day, consider a free tool that can save you valuable time. Download our desktop utility called the LaunchPAD that centralizes your admin tools to make the process of IT management easier. This free download helps you cut down on the amount of time it takes to perform routine tasks individually. The desktop utility comes pre-configured with links to the most commonly used network administrator tools including: 

  • Perfmon
  • Trace Route
  • Telnet
  • Ping
  • Remote Desktop 
  • Add your own tools

 The LaunchPAD can be set to load automatically when your computer boots up, so you always have single-click access to your management tools from the desktop. You can also add new tools and links in seconds. Give it a try, its free after all. Download the LaunchPAD or any of Kratos’ other IT management tools today!

TAGGED UNDER

network management, network monitoring, it, network tools, it tools, free it tools,

Increase Your Cybersecurity Readiness and Awareness…

Posted on - 7 comments

Are you as prepared as you can be to face the looming cybersecurity challenges in today’s rapidly evolving threat, technology and compliance landscape? Is your system in compliance with FISMA and OMB requirements?  If you are looking to increase your cybersecurity readiness, consider proven and industry leading training from SecureInfo, A Kratos company

Our cybersecurity instructors are industry veterans who educate students using a combination of "lessons learned" and analytical course content. In our interactive setting, we recommend practical solutions to the everyday problems presented by Security Authorization (or C&A) audits and cybersecurity program management.

Thousands of security professionals from around the world, including the Department of Homeland Security, US Air Force, US Army and many large commercial organizations, have attended our cybersecurity classes.

Check out our upcoming schedule of training events and register for a class today! Training classes are conducted in our training centers in Alexandria, VA and San Antonio, TX. On-site classes at your location are also available.

For more information, view our complete line-up of cybersecurity courses: 

    AFCAP/eMASS Workshop 3-Day

    DIACAP Essentials

    DIACAP Workshop

    eMASS

    NIST Continuous Monitoring 1-Day

    NIST Continuous Monitoring 3-Day

    NIST Organizational Risk Management

    NIST RMF Workshop 3-Day

    NIST Security Controls Workshop 3-Day

    Nuclear Cyber Security Controls Assessment Workshop

    Nuclear Cyber Security Plan Workshop

    RMS Product Training

If you have any questions, don’t hesitate to contact us at training@secureinfo.com for more information.

TAGGED UNDER

it, cyber security, cybersecurity, information assurance, fisma,

Free IT Tools for the Holiday Season – Download Today!

Posted on - 36 comments

Give yourself a gift this holiday season. You deserve it! Download one of our nine free IT and network management tools today.
 
These stand alone IT and network management utilities provide monitoring solutions for specific problem areas like network traffic, servers, applications, website bottlenecks and much more. You can use these utilities right from your desktop without the need to launch a full blown management program.
 
The series of utilities has logged over 100,000 downloads. Download one today, save some effort and spend more time enjoying the holiday season.
 
1. Network Traffic Monitor – Track Inbound and Outbound Bandwidth
 
2. Exchange Monitor – Monitor Exchange Health
 
3. Device Monitor – Troubleshoot Device Problems
 
4. LaunchPAD - Access Network Tools Quickly
 
5. Syslog Alarm Monitor - Monitor Most Alarmed Devices
 
6. Server Performance Monitor - Check Server Efficiency
 
7. Service Level Monitor - Track Service Level Performance
 
8. Website Monitor - Monitor Website Bottlenecks
 
9. Video Surveillance Monitor - Ensure Availaiblity of Cisco Video Surveillance Servers
 

TAGGED UNDER

network management, network monitoring, it, it management,

Army IT Day – The Future of the Army Enterprise

Posted on - 12 comments

Kratos sponsored AFCEA’s Army IT Day last week and got a glimpse into the future. Army IT Day is an annual one-day conference focused on issues and challenges facing the future Army. The focus of the day was on how the Army’s enterprise would become more effective, affordable and defensible into the year 2020. Kratos along with other industry partners were eager to participate and hear from the Army.
 
All the big names were in attendance. Senior leaders described the Army’s vision, operational requirements, acquisition strategies and potential opportunities for industry.
 
The topics included:
 
•The Army’s Network of 2020 initiatives and the critical changes it will drive across the enterprise
•How the Network Integration Evaluation (NIE) is accelerating capabilities delivered to the Warfighter
•The Army’s challenges in maintaining and defending the network
 
Kratos continues its commitment to support the Army’s enterprise mission. From participating in the recent Network Integration Evaluation (NIE) where NeuralStar became the first network management system to become fully operational to supporting a strong network defense posture with our cybersecurity capabilities.
 
The event was a great success with 900 people attending. We look forward to next year’s event.

TAGGED UNDER

network management, network monitoring, it, army network management, cyber security, it management,