[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Central point for configuration management using netconf?



Thank you Wes.

Wes Hardaker wrote:

On Wed, 21 Apr 2004 17:24:29 -0400, "Kathleen M. Moriarty" <moriarty@ll.mit.edu> said:


Kathleen> I am working on a draft in the INCH working group, RID
Kathleen> http://www.ietf.org/internet-drafts/draft-ietf-inch-rid-00.txt,
Kathleen> and need to provide a hand off for mitigating or stopping traffic when
Kathleen> the source of a security incident is identified.

note: you might look into the Distributed firewall working group, as
well as the IPSP working group for further information on
accomplishing your end goals in a standardized fashion.

I will take a look at the working groups you mentioned.

Kathleen> Would the idea of netconf be to allow any management system Kathleen> to directly configure devices if they have the appropriate Kathleen> access controls, authentication, etc.? Or would there be a Kathleen> central server that the requests must be filtered through to Kathleen> make sure the network configuration changes are documented Kathleen> and a sanity check is performed?

netconf does not require a central server and devices can be directly
manipulated by anyone with proper authentication and authorization.
Authentication is defined by leveraging the transport upon which the
netconf stream is sent over.  Note that netconf is in its infancy and
authorization (or even any standardized data model or data to actually
manage such as a standardized firewall control mechanism) have yet to
be defined.  If you need immediate standardized results to build off
of, netconf isn't there yet (its so far only a protocol).

I was not aware of anything available beside management stations from vendors, but wanted to see if it was just that I was not aware of such efforts by asking those well versed in the topic/area.

Thanks for your help.

-Kathleen



--
to unsubscribe send a message to netconf-request@ops.ietf.org with
the word 'unsubscribe' in a single line as the message text body.
archive: <http://ops.ietf.org/lists/netconf/>