SNMP-Gate
|

|
| SNMP-GATE establishes a controlled link between two SNMP based Network Management Systems (NMS). As application firewall, the SNMP-GATE exclusively administrates port 161 and port 162 to manage the entire SNMP communication. All other ports are organized through an external upstream firewall. As a result, a global SNMP network can be segmented into several insulated nets with individual NMS requirements according to Boolean terms. |
 |
|
Independent from each other, different NMSs can supervise and control their SNMP agents simultaneously via one single network, without affecting their respective security policies. As to Boolean terms, the different Management Systems are fully decoupled.
The disconnection of communication is secured via the firewall functionality through allocation of virtual IP addresses to the SNMP agents to be protected. Additionally, the different OIDs and their respective values are configured explicitly as release parameters. This special feature ensures that it is only possible to poll (get) and control (set) specific SNMP agents with specific parameters. . The Trap Queue takes over the assignment of the agent traps to the virtual IP addresses. Incoming SNMP traps and informs are cached and transmitted to their appropriate destination NMS as SNMP trap or inform respectively.
|

- Virtual SNMP interface between two Network Management Systems
- Virtual IP address to secure the outward shield of the SNMP agents
- Each virtual SNMP agent provides exactly the same data like the original SNMP agent does
- The SNMP commands of the Management System are converted through the virtual IP address and
transmitted to the real agent.
- The response of the agent as well as SNMP traps and informs are converted reversely.
- The access via the SNMP commands "get" and "set" is configurable.
- SNMP access to the SNMP agents can be limited temporarily (DoS)
- Supported protocols: SNMPv1, NMPv2 and SNMPv3 (optional)
- Protocol conversion between SNMPv1 and SNMPv2c
- Protocol conversion between SNMPv1 trap, SNMPv2 trap and SNMPv2 inform
- Persistent trap storage on HDD for time-delayed transmission of traps to the NMS
- Secured transmission of SNMPv1 trap and SNMPv2 trap out of the Trap Queue
- Trap Processor to avoid event storms
- Configuration of user-defined MIBs for an individual access authorization
- SNMP agent for the NMS integration
- Configuration via web interface
- Cisco ROSA driver available
| SNMP-Gate (Firewall) |
SNMP-Queue |
- Up to 250 SNMP agents
- Up to 32 agent types
- 32 OID groups (MIB tree) per agent type
- Virtual IP network
- IP Packet supervision
- SNMP access monitor trap
|
- Trap Filter for up to 64 agent types
- Up to 8 Trap Queues
- Trap conversion SNMPv1 trap/SNMPv2 trap/SNMPv2 inform
- Configurable trap severity level
- Trap Buffer up to 1GB per queue
- Secured transmission (ping/ICMP echo)
- Trap-Forward-Trigger (severity, time, volume)
- Virtual / original trap IP address assignment
- Trap Logging per queue
- Up to 16 Trap Processors to avoid event storms
|
- Embedded x86 Platform (Linux)
- SATA-HDD
- Ethernet 1x 100Mbit/s, 1x 1Gbit/s
|
- Dimensions: W=19", H=2HU, D=660mm
- 2 redundant power supply units
- Power consumption 40W
|
|
|
| Data Sheet SNMP-Gate |
|

|