CISCOSB-BRIDGE-SECURITY

File: CISCOSB-BRIDGE-SECURITY.mib (27850 bytes)

Imported modules

SNMPv2-SMI IF-MIB SNMPv2-TC
Q-BRIDGE-MIB CISCOSB-MIB

Imported symbols

MODULE-IDENTITY OBJECT-TYPE Unsigned32
IpAddress Counter32 InterfaceIndex
ifIndex RowStatus TEXTUAL-CONVENTION
MacAddress DisplayString TruthValue
VlanId switch001

Defined Types

RlIpDhcpSnoopStaticEntry  
SEQUENCE    
  rlIpDhcpSnoopStaticVLANTag VlanId
  rlIpDhcpSnoopStaticMACAddress MacAddress
  rlIpDhcpSnoopStaticIPAddress IpAddress
  rlIpDhcpSnoopStaticPortInterface InterfaceIndex
  rlIpDhcpSnoopStaticRowStatus RowStatus

RlIpDhcpSnoopType  
TEXTUAL-CONVENTION    
  current INTEGER learnedByProtocol(1), deletedByTimeout(2), static(3)

RlIpDhcpSnoopEntry  
SEQUENCE    
  rlIpDhcpSnoopVLANTag VlanId
  rlIpDhcpSnoopMACAddress MacAddress
  rlIpDhcpSnoopType RlIpDhcpSnoopType
  rlIpDhcpSnoopLeaseTime Unsigned32
  rlIpDhcpSnoopIPAddress IpAddress
  rlIpDhcpSnoopPortInterface InterfaceIndex
  rlIpDhcpSnoopRowStatus RowStatus

RlIpDhcpSnoopEnableVlanEntry  
SEQUENCE    
  rlIpDhcpSnoopEnableVlanTag VlanId
  rlIpDhcpSnoopEnableVlanRowStatus RowStatus

RlIpDhcpSnoopTrustedPortEntry  
SEQUENCE    
  rlIpDhcpSnoopTrustedPortRowStatus RowStatus

RlIpSourceGuardPortEntry  
SEQUENCE    
  rlIpSourceGuardPortRowStatus RowStatus

RlIpSourceGuardType  
TEXTUAL-CONVENTION    
  current INTEGER dynamic(1), static(2)

RlIpSourceGuardStatus  
TEXTUAL-CONVENTION    
  current INTEGER active(1), inactive(2)

RlIpSourceGuardFailReason  
TEXTUAL-CONVENTION    
  current INTEGER noProblem(1), noResource(2), noSnoopVlan(3), trustPort(4)

RlIpSourceGuardEntry  
SEQUENCE    
  rlIpSourceGuardIPAddress IpAddress
  rlIpSourceGuardVLANTag VlanId
  rlIpSourceGuardMACAddress MacAddress
  rlIpSourceGuardType RlIpSourceGuardType
  rlIpSourceGuardStatus RlIpSourceGuardStatus
  rlIpSourceGuardFailReason RlIpSourceGuardFailReason

RlIpSourceGuardPermittedRuleCounterEntry  
SEQUENCE    
  rlIpSourceGuardPermittedRuleCounterVLANTag VlanId
  rlIpSourceGuardPermittedRuleCounterNumOfStaticRules Counter32
  rlIpSourceGuardPermittedRuleCounterNumOfDhcpRules Counter32

RlIpArpInspectListNameType  
TEXTUAL-CONVENTION    
  current DisplayString Size(1..32)

RlIpArpInspectListEntry  
SEQUENCE    
  rlIpArpInspectListName RlIpArpInspectListNameType
  rlIpArpInspectListIPAddress IpAddress
  rlIpArpInspectListMACAddress MacAddress
  rlIpArpInspectListRowStatus RowStatus

RlIpArpInspectEnableVlanEntry  
SEQUENCE    
  rlIpArpInspectEnableVlanTag VlanId
  rlIpArpInspectAssignedListName RlIpArpInspectListNameType
  rlIpArpInspectEnableVlanRowStatus RowStatus
  rlIpArpInspectVlanNumOfArpForwarded Counter32
  rlIpArpInspectVlanNumOfArpDropped Counter32
  rlIpArpInspectVlanNumOfArpMismatched Counter32
  rlIpArpInspectVlanClearCountersAction TruthValue

RlIpArpInspectTrustedPortEntry  
SEQUENCE    
  rlIpArpInspectTrustedPortRowStatus RowStatus

ProtocolFilteringMap  
TEXTUAL-CONVENTION    
  current BITS all(0), cdp(1), vtp(2), dtp(3), udld(4), pagp(5), sstp(6)

RlProtocolFilteringEntry  
SEQUENCE    
  rlProtocolFilteringList ProtocolFilteringMap
  rlProtocolFilteringRowStatus RowStatus

Defined Values

rlBridgeSecurity 1.3.6.1.4.1.9.6.1.101.112
The private MIB module definition for DHCP Snoop, ARP Inspection and Ip source Guard features.
MODULE-IDENTITY    

rlIpDhcpSnoop 1.3.6.1.4.1.9.6.1.101.112.1
OBJECT IDENTIFIER    

rlIpSourceGuard 1.3.6.1.4.1.9.6.1.101.112.2
OBJECT IDENTIFIER    

rlIpArpInspect 1.3.6.1.4.1.9.6.1.101.112.3
OBJECT IDENTIFIER    

rlProtocolFiltering 1.3.6.1.4.1.9.6.1.101.112.4
OBJECT IDENTIFIER    

rlIpDhcpSnoopMibVersion 1.3.6.1.4.1.9.6.1.101.112.1.1
MIB's version, the current version is 1.
OBJECT-TYPE    
  INTEGER  

rlIpDhcpSnoopEnable 1.3.6.1.4.1.9.6.1.101.112.1.2
Specifies a system DHCP Snoop enable state.
OBJECT-TYPE    
  INTEGER enable(1), disable(2)  

rlIpDhcpSnoopFileEnable 1.3.6.1.4.1.9.6.1.101.112.1.3
Specifies a system DHCP Snoop file enable state.
OBJECT-TYPE    
  INTEGER enable(1), disable(2)  

rlIpDhcpSnoopClearAction 1.3.6.1.4.1.9.6.1.101.112.1.4
Used to clear DHCP Snoop Table.
OBJECT-TYPE    
  INTEGER noAction(1), clearNow(2)  

rlIpDhcpSnoopFileUpdateTime 1.3.6.1.4.1.9.6.1.101.112.1.5
Configures in seconds the period of time between file updates. The valid range is 600 - 86400.
OBJECT-TYPE    
  INTEGER 600..86400  

rlIpDhcpSnoopVerifyMacAddress 1.3.6.1.4.1.9.6.1.101.112.1.6
Configures on an un-trusted port whether the source MAC address in a DHCP packet matches the client hardware address.
OBJECT-TYPE    
  INTEGER enable(1), disable(2)  

rlIpDhcpSnoopCurrentEntiresNumber 1.3.6.1.4.1.9.6.1.101.112.1.7
Contain the current number of DHCP snooping entries for all types.
OBJECT-TYPE    
  INTEGER  

rlIpDhcpOpt82InsertionEnable 1.3.6.1.4.1.9.6.1.101.112.1.8
Specifies a DHCP option 82 insertion enable state.
OBJECT-TYPE    
  INTEGER enable(1), disable(2)  

rlIpDhcpOpt82RxOnUntrustedEnable 1.3.6.1.4.1.9.6.1.101.112.1.9
Specifies a DHCP option 82 receive on untrusted port enable state.
OBJECT-TYPE    
  INTEGER enable(1), disable(2)  

rlIpDhcpSnoopStaticTable 1.3.6.1.4.1.9.6.1.101.112.1.10
The table specifies all DHCP Snoop Static (configured by user) entries. The entry contains a local IP address of the DHCP client, a Port interface to which a DHCP client is connected to the switch.
OBJECT-TYPE    
  SEQUENCE OF  
    RlIpDhcpSnoopStaticEntry

rlIpDhcpSnoopStaticEntry 1.3.6.1.4.1.9.6.1.101.112.1.10.1
The row definition for this table.
OBJECT-TYPE    
  RlIpDhcpSnoopStaticEntry  

rlIpDhcpSnoopStaticVLANTag 1.3.6.1.4.1.9.6.1.101.112.1.10.1.1
A DHCP Snoop Static entry vlan tag.
OBJECT-TYPE    
  VlanId  

rlIpDhcpSnoopStaticMACAddress 1.3.6.1.4.1.9.6.1.101.112.1.10.1.2
A DHCP Snoop Static entry mac address
OBJECT-TYPE    
  MacAddress  

rlIpDhcpSnoopStaticIPAddress 1.3.6.1.4.1.9.6.1.101.112.1.10.1.3
A DHCP Snoop Static entry IP address.
OBJECT-TYPE    
  IpAddress  

rlIpDhcpSnoopStaticPortInterface 1.3.6.1.4.1.9.6.1.101.112.1.10.1.4
A DHCP Snoop Static entry Port interface.
OBJECT-TYPE    
  InterfaceIndex  

rlIpDhcpSnoopStaticRowStatus 1.3.6.1.4.1.9.6.1.101.112.1.10.1.5
A status can be destroy, active or createAndGo
OBJECT-TYPE    
  RowStatus  

rlIpDhcpSnoopTable 1.3.6.1.4.1.9.6.1.101.112.1.11
DHCP Snoop entry. Use to add/delete a dynamic entries and to view all entries (dynamic and static)
OBJECT-TYPE    
  SEQUENCE OF  
    RlIpDhcpSnoopEntry

rlIpDhcpSnoopEntry 1.3.6.1.4.1.9.6.1.101.112.1.11.1
The row definition for this table.
OBJECT-TYPE    
  RlIpDhcpSnoopEntry  

rlIpDhcpSnoopVLANTag 1.3.6.1.4.1.9.6.1.101.112.1.11.1.1
A DHCP Snoop entry vlan tag.
OBJECT-TYPE    
  VlanId  

rlIpDhcpSnoopMACAddress 1.3.6.1.4.1.9.6.1.101.112.1.11.1.2
A DHCP Snoop entry mac address
OBJECT-TYPE    
  MacAddress  

rlIpDhcpSnoopType 1.3.6.1.4.1.9.6.1.101.112.1.11.1.3
A DHCP Snoop entry type: static or dynamic.
OBJECT-TYPE    
  RlIpDhcpSnoopType  

rlIpDhcpSnoopLeaseTime 1.3.6.1.4.1.9.6.1.101.112.1.11.1.4
A DHCP Snoop lease time. For static entry the lease time is 0xFFFFFFFF
OBJECT-TYPE    
  Unsigned32  

rlIpDhcpSnoopIPAddress 1.3.6.1.4.1.9.6.1.101.112.1.11.1.5
The IP address of the DHCP client referred to in this table entry.
OBJECT-TYPE    
  IpAddress  

rlIpDhcpSnoopPortInterface 1.3.6.1.4.1.9.6.1.101.112.1.11.1.6
Identifies the port Interface ifindex, which connected to DHCP client identified with the entry.
OBJECT-TYPE    
  InterfaceIndex  

rlIpDhcpSnoopRowStatus 1.3.6.1.4.1.9.6.1.101.112.1.11.1.7
Entry status. A valid status is CreateandGo or Delete.
OBJECT-TYPE    
  RowStatus  

rlIpDhcpSnoopEnableVlanTable 1.3.6.1.4.1.9.6.1.101.112.1.12
An Ip Dhcp Snooping enabled VLAN table.
OBJECT-TYPE    
  SEQUENCE OF  
    RlIpDhcpSnoopEnableVlanEntry

rlIpDhcpSnoopEnableVlanEntry 1.3.6.1.4.1.9.6.1.101.112.1.12.1
An Ip Dhcp Snooping enabled VLAN entry.
OBJECT-TYPE    
  RlIpDhcpSnoopEnableVlanEntry  

rlIpDhcpSnoopEnableVlanTag 1.3.6.1.4.1.9.6.1.101.112.1.12.1.1
A DHCP Snoop entry vlan tag.
OBJECT-TYPE    
  VlanId  

rlIpDhcpSnoopEnableVlanRowStatus 1.3.6.1.4.1.9.6.1.101.112.1.12.1.2
Entry status. A valid status is CreateandGo and Delete.
OBJECT-TYPE    
  RowStatus  

rlIpDhcpSnoopTrustedPortTable 1.3.6.1.4.1.9.6.1.101.112.1.13
DHCP Snoop Trusted ports entry. The entry created when port is configured as trusted.
OBJECT-TYPE    
  SEQUENCE OF  
    RlIpDhcpSnoopTrustedPortEntry

rlIpDhcpSnoopTrustedPortEntry 1.3.6.1.4.1.9.6.1.101.112.1.13.1
The row definition for this table.
OBJECT-TYPE    
  RlIpDhcpSnoopTrustedPortEntry  

rlIpDhcpSnoopTrustedPortRowStatus 1.3.6.1.4.1.9.6.1.101.112.1.13.1.2
Entry status. A valid status is CreateandGo or Delete.
OBJECT-TYPE    
  RowStatus  

rlIpSourceGuardMibVersion 1.3.6.1.4.1.9.6.1.101.112.2.1
MIB's version, the current version is 1.
OBJECT-TYPE    
  INTEGER  

rlIpSourceGuardEnable 1.3.6.1.4.1.9.6.1.101.112.2.2
FALSE - There is no Ip Source Guard in the system. TRUE - Ip Source Guard is enabled on system.
OBJECT-TYPE    
  INTEGER enable(1), disable(2)  

rlIpSourceGuardRetryToInsert 1.3.6.1.4.1.9.6.1.101.112.2.3
When setted to retryToInsertNow all IP Source Guard inactive entries due to resource problem reinserted in the Policy. On get always return noAction.
OBJECT-TYPE    
  INTEGER noAction(0), retryToInsertNow(1)  

rlIpSourceGuardRetryTime 1.3.6.1.4.1.9.6.1.101.112.2.4
Configures in seconds the period of time the application retries to insert inactive by resource problem rules. The actual range is 10-600. 0 used to sign that the timer is not active.
OBJECT-TYPE    
  INTEGER 0..600  

rlIpSourceGuardPortTable 1.3.6.1.4.1.9.6.1.101.112.2.5
IP Source Guard ports entry. The entry created when IP Source Guard enabled on port.
OBJECT-TYPE    
  SEQUENCE OF  
    RlIpSourceGuardPortEntry

rlIpSourceGuardPortEntry 1.3.6.1.4.1.9.6.1.101.112.2.5.1
The row definition for this table.
OBJECT-TYPE    
  RlIpSourceGuardPortEntry  

rlIpSourceGuardPortRowStatus 1.3.6.1.4.1.9.6.1.101.112.2.5.1.2
Entry status. A valid status is CreateAndGo or Delete.
OBJECT-TYPE    
  RowStatus  

rlIpSourceGuardTable 1.3.6.1.4.1.9.6.1.101.112.2.6
IP Source Guard entry. Use to view all entries (dynamic and static)
OBJECT-TYPE    
  SEQUENCE OF  
    RlIpSourceGuardEntry

rlIpSourceGuardEntry 1.3.6.1.4.1.9.6.1.101.112.2.6.1
The row definition for this table.
OBJECT-TYPE    
  RlIpSourceGuardEntry  

rlIpSourceGuardIPAddress 1.3.6.1.4.1.9.6.1.101.112.2.6.1.1
The IP address of the Ip Source Guard entry.
OBJECT-TYPE    
  IpAddress  

rlIpSourceGuardVLANTag 1.3.6.1.4.1.9.6.1.101.112.2.6.1.2
A Ip Source Guard entry vlan tag.
OBJECT-TYPE    
  VlanId  

rlIpSourceGuardMACAddress 1.3.6.1.4.1.9.6.1.101.112.2.6.1.3
A Ip Source Guard entry mac address
OBJECT-TYPE    
  MacAddress  

rlIpSourceGuardType 1.3.6.1.4.1.9.6.1.101.112.2.6.1.4
A Ip Source Guard entry type: static or dynamic.
OBJECT-TYPE    
  RlIpSourceGuardType  

rlIpSourceGuardStatus 1.3.6.1.4.1.9.6.1.101.112.2.6.1.5
Identifies the status of Ip Source Guard entry.
OBJECT-TYPE    
  RlIpSourceGuardStatus  

rlIpSourceGuardFailReason 1.3.6.1.4.1.9.6.1.101.112.2.6.1.6
Identifies the reason for in-activity of Ip Source Guard entry.
OBJECT-TYPE    
  RlIpSourceGuardFailReason  

rlIpSourceGuardPermittedRuleCounterTable 1.3.6.1.4.1.9.6.1.101.112.2.7
The table includes, per vlan, the IP Source Guard permitted rules counters.
OBJECT-TYPE    
  SEQUENCE OF  
    RlIpSourceGuardPermittedRuleCounterEntry

rlIpSourceGuardPermittedRuleCounterEntry 1.3.6.1.4.1.9.6.1.101.112.2.7.1
The row definition for this table.
OBJECT-TYPE    
  RlIpSourceGuardPermittedRuleCounterEntry  

rlIpSourceGuardPermittedRuleCounterVLANTag 1.3.6.1.4.1.9.6.1.101.112.2.7.1.1
Ip Source Guard permitted rules counters entry Vlan tag.
OBJECT-TYPE    
  VlanId  

rlIpSourceGuardPermittedRuleCounterNumOfStaticRules 1.3.6.1.4.1.9.6.1.101.112.2.7.1.2
Number of static rules added by IP Source Guard for the permitted Hosts
OBJECT-TYPE    
  Counter32  

rlIpSourceGuardPermittedRuleCounterNumOfDhcpRules 1.3.6.1.4.1.9.6.1.101.112.2.7.1.3
Number of rules added by IP Source Guard for the permitted Hosts, as a result of DHCP Snooping dynamic information.
OBJECT-TYPE    
  Counter32  

rlIpArpInspectMibVersion 1.3.6.1.4.1.9.6.1.101.112.3.1
MIB's version, the current version is 1.
OBJECT-TYPE    
  INTEGER  

rlIpArpInspectEnable 1.3.6.1.4.1.9.6.1.101.112.3.2
Specifies a system ARP Inspection enable state.
OBJECT-TYPE    
  INTEGER enable(1), disable(2)  

rlIpArpInspectLogInterval 1.3.6.1.4.1.9.6.1.101.112.3.3
Specify the minimal interval between successive ARP SYSLOG messages. 0 - message is immediately generated. 0xFFFFFFFF - messages would not be generated. A legal range is 0-86400.
OBJECT-TYPE    
  Unsigned32  

rlIpArpInspectValidation 1.3.6.1.4.1.9.6.1.101.112.3.4
Defined a specific check on incoming ARP packets: Source MAC: Compare the source MAC address in the Ethernet header against the sender MAC address in the ARP body. This check is performed on both ARP requests and responses. Destination MAC: Compare the destination MAC address in the Ethernet header against the target MAC address in ARP body. This check is performed for ARP responses. IP addresses: Compare the ARP body for invalid and unexpected IP addresses. Addresses include 0.0.0.0, 255.255.255.255, and all IP multicast addresses.
OBJECT-TYPE    
  INTEGER enable(1), disable(2)  

rlIpArpInspectListTable 1.3.6.1.4.1.9.6.1.101.112.3.5
The table specifies all ARP Inspection List entries. The entry contains a list name, list IP address, a list Mac address.
OBJECT-TYPE    
  SEQUENCE OF  
    RlIpArpInspectListEntry

rlIpArpInspectListEntry 1.3.6.1.4.1.9.6.1.101.112.3.5.1
The row definition for this table.
OBJECT-TYPE    
  RlIpArpInspectListEntry  

rlIpArpInspectListName 1.3.6.1.4.1.9.6.1.101.112.3.5.1.1
The Name of the Access List.
OBJECT-TYPE    
  RlIpArpInspectListNameType  

rlIpArpInspectListIPAddress 1.3.6.1.4.1.9.6.1.101.112.3.5.1.2
ARP Inspection List IP address.
OBJECT-TYPE    
  IpAddress  

rlIpArpInspectListMACAddress 1.3.6.1.4.1.9.6.1.101.112.3.5.1.3
ARP Inspection List mac address
OBJECT-TYPE    
  MacAddress  

rlIpArpInspectListRowStatus 1.3.6.1.4.1.9.6.1.101.112.3.5.1.4
A status can be destroy, active or createAndGo
OBJECT-TYPE    
  RowStatus  

rlIpArpInspectEnableVlanTable 1.3.6.1.4.1.9.6.1.101.112.3.6
An Ip ARP Inspection enabled VLAN table.
OBJECT-TYPE    
  SEQUENCE OF  
    RlIpArpInspectEnableVlanEntry

rlIpArpInspectEnableVlanEntry 1.3.6.1.4.1.9.6.1.101.112.3.6.1
An Ip ARP Inspection enabled VLAN entry.
OBJECT-TYPE    
  RlIpArpInspectEnableVlanEntry  

rlIpArpInspectEnableVlanTag 1.3.6.1.4.1.9.6.1.101.112.3.6.1.1
An Ip ARP Inspection entry vlan tag.
OBJECT-TYPE    
  VlanId  

rlIpArpInspectAssignedListName 1.3.6.1.4.1.9.6.1.101.112.3.6.1.2
An Ip ARP Inspection assigned ACL name.
OBJECT-TYPE    
  RlIpArpInspectListNameType  

rlIpArpInspectEnableVlanRowStatus 1.3.6.1.4.1.9.6.1.101.112.3.6.1.3
Entry status. A valid status is CreateandGo and Delete.
OBJECT-TYPE    
  RowStatus  

rlIpArpInspectVlanNumOfArpForwarded 1.3.6.1.4.1.9.6.1.101.112.3.6.1.4
Total number of forwarded ARP packets, packets which were validated by ARP inspection
OBJECT-TYPE    
  Counter32  

rlIpArpInspectVlanNumOfArpDropped 1.3.6.1.4.1.9.6.1.101.112.3.6.1.5
Number of dropped ARP packets, which were validated by ARP inspection (mismatch , not-found and dropped for any reason)
OBJECT-TYPE    
  Counter32  

rlIpArpInspectVlanNumOfArpMismatched 1.3.6.1.4.1.9.6.1.101.112.3.6.1.6
Number of dropped ARP packets, which were validated by ARP inspection and inconsistency was found for IP and MAC (mismatch)
OBJECT-TYPE    
  Counter32  

rlIpArpInspectVlanClearCountersAction 1.3.6.1.4.1.9.6.1.101.112.3.6.1.7
If true, clear (set to zero) all Arp Inspection counters: rlIpArpInspectVlanNumOfArpForwarded , rlIpArpInspectVlanNumOfArpDropped and rlIpArpInspectVlanNumOfArpMismatched
OBJECT-TYPE    
  TruthValue  

rlIpArpInspectTrustedPortTable 1.3.6.1.4.1.9.6.1.101.112.3.7
ARP Inspection Trusted ports entry. The entry created when port is configured as trusted.
OBJECT-TYPE    
  SEQUENCE OF  
    RlIpArpInspectTrustedPortEntry

rlIpArpInspectTrustedPortEntry 1.3.6.1.4.1.9.6.1.101.112.3.7.1
The row definition for this table.
OBJECT-TYPE    
  RlIpArpInspectTrustedPortEntry  

rlIpArpInspectTrustedPortRowStatus 1.3.6.1.4.1.9.6.1.101.112.3.7.1.2
Entry status. A valid status is CreateandGo or Delete.
OBJECT-TYPE    
  RowStatus  

rlIpArpInspectClearCountersAction 1.3.6.1.4.1.9.6.1.101.112.3.8
If true, clear (set to zero) on all vlans: all Arp Inspection counters: rlIpArpInspectVlanNumOfArpForwarded , rlIpArpInspectVlanNumOfArpDropped and rlIpArpInspectVlanNumOfArpMismatched
OBJECT-TYPE    
  TruthValue  

rlProtocolFilteringTable 1.3.6.1.4.1.9.6.1.101.112.4.1
Protocol filter configuration entry
OBJECT-TYPE    
  SEQUENCE OF  
    RlProtocolFilteringEntry

rlProtocolFilteringEntry 1.3.6.1.4.1.9.6.1.101.112.4.1.1
The row definition for this table.
OBJECT-TYPE    
  RlProtocolFilteringEntry  

rlProtocolFilteringList 1.3.6.1.4.1.9.6.1.101.112.4.1.1.1
The list of protocol to be filtered.
OBJECT-TYPE    
  ProtocolFilteringMap  

rlProtocolFilteringRowStatus 1.3.6.1.4.1.9.6.1.101.112.4.1.1.2
A status can be destroy, active or createAndGo
OBJECT-TYPE    
  RowStatus