Protocols About 3 min read

Monitoring and secure administration

Health monitoring and remote administration require different permissions. Separate collection accounts from configuration access and record administrative sessions.

Sources and scopeSource record 25 August 2026

Technical source record: 25 August 2026. Check the linked documentation for current product requirements.

Protocol and operational baseline; product MIBs, command sets, SSH algorithms, log schemas, and retention policy remain system specific.

Verification and testing

Overview#

Monitoring observes a system; administration changes it. Keep those identities, network paths, credentials, authorisation, and audit streams separate. Don't expose management services merely because a device's operational protocol must be reachable.

SNMP#

SNMP uses managers, agents, MIB modules and object identifiers. Polling, notifications, and SET operations have different failure and consequence models. The SNMP architecture is defined by RFC 3411; SNMPv3 User based Security Model (USM) is RFC 3414.12

  • Prefer SNMPv3 with authentication and privacy (authPriv) when the product supports it. RFC 7860 defines SHA 2 authentication protocols for USM, and RFC 3826 defines AES privacy; verify the exact product combinations and key localization lifecycle rather than treating SNMPv3 as one fixed suite.34 SNMPv1/v2c community strings are reusable cleartext equivalent secrets, not modern identities.
  • Give each manager a least privilege view. Disable SET or use a separate tightly controlled identity unless a documented operational need exists.
  • Preserve OID, syntax, units, scale, counter width/wrap, source, poll time, response status, and quality. Vendor MIB revision is part of the schema.
  • Treat a trap as unacknowledged delivery; an inform has protocol acknowledgement, not proof that the incident system processed it.
  • Protect authoritative engine ID and engine boots/time state. Cloned/replaced SNMP engines and counter resets require explicit handling.
  • Bound walks and table sizes. Broad GETBULK requests can overload small embedded agents.

Syslog#

RFC 5424 defines a structured syslog message with facility, severity, timestamp, host/application/process/message identifiers, structured data, and message. RFC 5425 maps syslog over TLS.56 Preserve raw bounded records or tamper evident references plus parsed fields. Vendor severity isn't automatically incident severity.

Define transport/framing, TLS identity, maximum message, queue/disk limits, reconnect/backoff, loss counters, clock quality handling, parsing version, retention, privacy/redaction, and backpressure. UDP syslog can lose/reorder/duplicate; TCP delivery can still be lost before durable ingestion; TLS protects a hop, not downstream storage integrity.

SSH and SFTP#

SSH architecture is RFC 4251.7 Pin or validate host keys through an approved provisioning channel; never accept a changed host key silently. Use named service accounts, public key or hardware backed authentication, algorithms consistent with the current RFC 9142 recommendations, and RSA/SHA 2 signatures from RFC 8332 where RSA remains necessary.89 Restrict commands/subsystems and sources, keep sessions short, and retain complete administrative audit. Disable password/default accounts where operational recovery permits.

SFTP is the SSH File Transfer Protocol subsystem, not FTP over SSH and not necessarily SCP. Its later protocol versions remained IETF Internet Drafts rather than an RFC; confirm the implemented SFTP version and extensions for both products.10 Upload configuration atomically where supported, validate size/hash/schema, protect permissions, and retain rollback. A successful file transfer isn't proof the device safely applied the configuration.

Management plane#

Place operator/admin clients, jump hosts, update repositories, AAA, time, logging, and device management endpoints in explicit management conduits. Record emergency access, credential escrow, offline recovery, certificate/key rotation, configuration backup, four eyes approval for high impact commands, session recording policy, and vendor support expiry. Never test restart, reset, firmware upload, configuration import, SNMP SET, or log flood behaviour on live physical security devices.

Primary sources#

Section overview · Wiki home

  1. RFC Editor, RFC 3411, SNMP management architecture ↩

  2. RFC Editor, RFC 3414, SNMPv3 USM ↩

  3. RFC Editor, RFC 7860, HMAC SHA 2 authentication protocols in USM ↩

  4. RFC Editor, RFC 3826, AES privacy protocol in USM ↩

  5. RFC Editor, RFC 5424, syslog protocol ↩

  6. RFC Editor, RFC 5425, TLS transport mapping for syslog ↩

  7. RFC Editor, RFC 4251, SSH architecture ↩

  8. RFC Editor, RFC 9142, SSH key exchange method recommendations ↩

  9. RFC Editor, RFC 8332, RSA keys with SHA 2 signatures in SSH ↩

  10. IETF Datatracker, SSH File Transfer Protocol draft 13 ↩