SimpleSnmpProxy™
Provides SNMP version translation in intranet and across firewalls
Overview
Network Management Systems (NMS) using the Simple Network Management
Protocol (SNMP) are widely deployed to manage today's corporate networks.
As the three versions of SNMP (v1,v2c and v3) can all be found in these
heterogeneous networks, sometimes there is a mismatch between the versions
supported by the NMS and those supported by the device. In addition,
firewalls which break up these networks into zones with varying levels
of security are often set up to block UDP/SNMP traffic. This makes the
resources in the cordoned off zones, invisible to the NMS.
SimpleSnmpProxy™ is an easy-to-deploy, software
solution that provides a solution to both these problems. It provides
protocol translation between the various versions of SNMP allowing
an SNMPv1 NMS to manage a SNMPv2c or v3 device or SNMPv3 application
to manage a SNMPv1 device. In addition, it securely
provides management visibility to the resources within cordoned-off
zones like the DMZ. Your existing NMS can now be leveraged to manage
devices with unsupported SNMP versions and critical resources like
eCommerce servers within the DMZ without compromising security.
SimpleSnmpProxy is made up of "iProxy"
that runs on intranet side. It does the protocol translation and
demultiplexing when communicating with intranet devices. For managing
devices in the restricted zone, the "iProxy" communicates
over an encrypted TCP connection with a
"zProxy" that runs within the restricted zone. Only a
single port/rule is required to be added to the firewall to enable UDP
based management traffic like SNMP, NetFlow, sFlow and sysLog to be securely forwarded to the management and collector systems in the
intranet.
If you need to not only translate but also configure users, passwords
and privileges on SNMPv3 devices when using an existing SNMPv1/v2 NMS,
please take a look at our SimpleSecureProxy product.
Benefits
- Translation of all versions of SNMP(v1/v2c/v3) requests and traps/notifications.
- Leveraging your existing intranet NMS to securely manage critical resources
int restricted zones.
- Proactively monitor the status/events of DMZ resources without
compromising security.
- Just a single port/rule allowing encrypted TCP traffic, enables management
of restricted zones like DMZ.
- Same solution works for securely managing remote offices over restricted WAN links.
Features
- Proxy can be co-located on the same machine as the NMS.
- Redundant zProxies are also supported.
- DES based encryption is included. Use of SSL with openSSH is also easily configurable.
- Traps and Syslog events received from the restricted zone can be securely forwarded.
- Netflow/sFlow packets received from the restricted zone can be securely forwarded to
specified collectors.
- A local, easy-to-use graphical utility is included for configuration.
- A command line utility for configuration is also available.
System Requirements
SimpleSnmpProxy is available on:
- Microsoft Windows 2000/XP/2003
|
|
|