6. IANA 考虑事项
6. IANA 考虑事项 (IANA Considerations)
本文档定义了若干由 Internet Assigned Numbers Authority (IANA) 管理的注册表. 本节描述这些注册表, 以及从中分配取值的策略.
6.1. 安全模型 (Security Models)
SNMP 架构允许存在多个 Security Model. 每个 Security Model 由唯一的 securityModel 值标识. securityModel 值的分配由 IANA 管理.
securityModel 值是范围为 0 到 2147483647 的 INTEGER.
取值按如下方式分配:
| 取值范围 (Value Range) | 分配策略 (Allocation Policy) | 描述 (Description) |
|---|---|---|
| 0 | Reserved | 不标识任何安全模型 |
| 1 | Standards Action | SNMPv1 security model |
| 2 | Standards Action | SNMPv2c security model |
| 3 | Standards Action | User-based Security Model (USM) |
| 4-255 | Standards Action | 为标准轨道 Security Models 保留 |
| 256+ | First Come First Served | 企业特定 Security Models |
Standards Action 表示该范围内的取值只能通过发布由 IESG 批准的 RFC 来分配.
First Come First Served 表示该范围内的取值根据企业的 enterprise ID 分配给企业. 公式为:
securityModel = (enterpriseID * 256) + security model within enterprise
例如, 如果 enterprise ID 1 定义了一个安全模型, 且这是该企业的第四个安全模型, 其值为:
securityModel = (1 * 256) + 4 = 260
当前分配:
- 0: Reserved (any)
- 1: SNMPv1 (RFC 3584)
- 2: SNMPv2c (RFC 3584)
- 3: User-based Security Model (USM) (RFC 3414)
6.2. 消息处理模型 (Message Processing Models)
SNMP 架构允许存在多个 Message Processing Model. 每个 Message Processing Model 由唯一的 messageProcessingModel 值标识. messageProcessingModel 值的分配由 IANA 管理.
messageProcessingModel 值是范围为 0 到 2147483647 的 INTEGER.
取值按如下方式分配:
| 取值范围 (Value Range) | 分配策略 (Allocation Policy) | 描述 (Description) |
|---|---|---|
| 0 | Standards Action | SNMPv1 message processing |
| 1 | Standards Action | SNMPv2c message processing |
| 2 | Standards Action | SNMPv2u (historic, not used) |
| 3 | Standards Action | SNMPv3 message processing |
| 4-255 | Standards Action | 为标准轨道 Message Processing Models 保留 |
| 256+ | First Come First Served | 企业特定 Message Processing Models |
Standards Action 表示该范围内的取值只能通过发布由 IESG 批准的 RFC 来分配.
First Come First Served 表示该范围内的取值根据企业的 enterprise ID 分配给企业. 公式为:
messageProcessingModel = (enterpriseID * 256) + model within enterprise
当前分配:
- 0: SNMPv1 (RFC 3584)
- 1: SNMPv2c (RFC 3584)
- 2: SNMPv2u (historic)
- 3: SNMPv3 (RFC 3412)
6.3. SnmpEngineID 格式 (SnmpEngineID Formats)
snmpEngineID 用于唯一标识 SNMP engine. 为确保全局唯一性, 对 snmpEngineID 值推荐使用特定格式.
snmpEngineID 是长度为 5 到 32 个八位字节的 OCTET STRING.
前四个八位字节定义如下:
Octet 1-4: Enterprise ID
第一个比特指示其余八位字节的格式:
-
Bit 1 = 0: 格式为:
Octets: [1-4: Enterprise ID] [5: format] [6-32: format-specific] -
Bit 1 = 1: 格式为:
Octets: [1-4: IANA Enterprise Number] [5-32: enterprise-specific]
对于第一个八位字节的第一个比特为 0 的 snmpEngineID 值, 第五个八位字节是格式标识符. 当前定义的格式如下:
| 格式值 (Format Value) | 描述 (Description) |
|---|---|
| 0 | Reserved, unused |
| 1 | IPv4 地址 (4 个八位字节) |
| 2 | IPv6 地址 (16 个八位字节) |
| 3 | MAC 地址 (6 个八位字节) |
| 4 | 管理分配的文本 (0-27 个八位字节) |
| 5 | 管理分配的八位字节 (0-27 个八位字节) |
| 6-127 | Reserved, unused |
| 128-255 | 企业特定格式 |
格式示例:
-
Format 1 (IPv4 address):
[0-3: Enterprise ID (bit 1 = 0)]
[4: 0x01]
[5-8: IPv4 address] -
Format 2 (IPv6 address):
[0-3: Enterprise ID (bit 1 = 0)]
[4: 0x02]
[5-20: IPv6 address] -
Format 3 (MAC address):
[0-3: Enterprise ID (bit 1 = 0)]
[4: 0x03]
[5-10: MAC address] -
Format 4 (Text):
[0-3: Enterprise ID (bit 1 = 0)]
[4: 0x04]
[5-31: Administratively assigned text] -
Format 5 (Octets):
[0-3: Enterprise ID (bit 1 = 0)]
[4: 0x05]
[5-31: Administratively assigned octets]
要求:
- snmpEngineID 值必须在管理域内唯一.
- snmpEngineID 值必须在重启之间保持不变.
- snmpEngineID 值应当存储在非易失性存储中.
- snmpEngineID 值禁止全为零.
- snmpEngineID 值禁止全为
0xFF(所有比特置位). - snmpEngineID 值禁止为空 (零长度).
建议:
- 使用 format 1, 2 或 3 时, 地址应当是永久分配给设备的地址.
- 使用 format 4 或 5 时, 取值应当以确保唯一性的方式由管理员分配.
- 如果一个设备具有多个 SNMP engine, 每个 SNMP engine 都必须具有唯一的 snmpEngineID.
IANA 操作:
IANA 维护 snmpEngineID 格式值 (格式标识符八位字节) 注册表. 6-127 范围内的新格式值需要 Standards Action. 128-255 范围内的格式值可供企业特定使用, 无需注册.