All MIBs › A3COM-HUAWEI-DOT11-WIDS-MIB
Organization: Hangzhou H3C Technologies Co., Ltd.
Last Updated: 2010-05-31
Category: VPN and Security, Vendor: H3C/HH3C, Wireless and WLAN
Description: Monitors the H3C 802.11 Wireless Intrusion Detection System, tracking rogue APs and attack event counters.
Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.
What Is A3COM-HUAWEI-DOT11-WIDS-MIB?
A3COM-HUAWEI-DOT11-WIDS-MIB is a Hangzhou H3C Technologies proprietary MIB implementing WIDS (Wireless Intrusion Detection Sensor), detecting rogue APs, spoofing, and other wireless attacks. Its objects cover scan mode/channel list, countermeasure mode, device-aging time, dynamic-blacklist enable/lifetime, flood/spoof/weak-IV attack-detection enables, reset actions for rogue-history/history/statistics/blacklists/detected-rogue-AP-station/adhoc/device/SSID lists, flood interval, blacklist threshold, SSID/BSSID filter on-off flags, and a permitted-vendor table. As a configuration/security MIB it lets an administrator confirm WIDS attack-detection settings and clear stale rogue-device history on an H3C wireless controller. It is deployed on Hangzhou H3C Technologies wireless controllers/access points. Engineers can download the A3COM-HUAWEI-DOT11-WIDS-MIB file directly to load it into their MIB browser.
IPNetwork Monitor allows you to monitor SNMP objects defined in A3COM-HUAWEI-DOT11-WIDS-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.
Supported Devices
- Hangzhou H3C Technologies wireless controllers/access points
Monitoring Examples
An administrator checks h3cDot11FloodAtkDctEnable and h3cDot11SpoofAtkDctEnable to confirm wireless attack-detection features are active on an H3C WIDS-enabled controller.
What Can Be Monitored
- WIDS attack-detection configuration and rogue-device history
This MIB depends on
Related MIBs
Imported Objects
From A3COM-HUAWEI-DOT11-REF-MIB
| H3cDot11ChannelScopeType | |
| H3cDot11ObjectIDType | |
| H3cDot11RadioScopeType | |
| H3cDot11RadioType | |
| H3cDot11SSIDStringType | |
| h3cDot11 | MODULE-IDENTITY |
From SNMPv2-SMI
| Integer32 | |
| MODULE-IDENTITY | |
| NOTIFICATION-TYPE | |
| OBJECT-TYPE | |
| TimeTicks | |
| Unsigned32 |
From SNMPv2-TC
| DateAndTime | |
| MacAddress | |
| RowStatus | |
| TEXTUAL-CONVENTION | |
| TruthValue |
OIDs
| OID symbolic | OID numeric | Type | Access | Description |
|---|---|---|---|---|
| T/F h3cDot11AttackAPStatus | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.2.1.5 | TruthValue | read-only | Represents whether monitor AP have taken countermeasure on the rogue AP. |
| T/F h3cDot11AttackDevDetected | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.5.1.3 | TruthValue | read-only | Represents whether the assigned MAC address in attack list is detected or not. |
| MAC h3cDot11AttackDeviceMac | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.5.1.1 | MacAddress | not-accessible | Represents the MAC address of rogue AP or rogue station, and the countermeasure will be taken for it. |
| H3C h3cDot11AttackDevType | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.5.1.4 | H3cDot11WIDSDevType | read-only | Represents the type of detected MAC address in attack list. If the MAC address is not detected, it will return unknown(5) for get operation. |
| ROW h3cDot11AttackListRowStatus | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.5.1.2 | RowStatus | read-create | The status of this table entry. |
| T/F h3cDot11AttackStaStatus | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.4.1.4 | TruthValue | read-only | Represents whether monitor AP have taken countermeasure for the rogue station. |
| h3cDot11BlackListEntry | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.11.1 | not-accessible | Each entry contains information of blacklist. | |
| MAC h3cDot11BlackListMAC | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.11.1.1 | MacAddress | not-accessible | This object represents the MAC address of the device inserted into the table. |
| OCT h3cDot11BlackListReason | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.11.1.3 | OCTET STRING | read-only | Represents the reason why the entry was added into the blacklist. |
| ROW h3cDot11BlackListRowStatus | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.11.1.4 | RowStatus | read-create | This object represents the status of this table entry. |
| h3cDot11BlackListTable | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.11 | not-accessible | This table contains information of blacklist entries, including dynamic and static. | |
| U32 h3cDot11BlackListTime | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.11.1.2 | Unsigned32 | read-only | Represents the time elapsed since the entry was last updated. If it is static blacklist, the value is always 0. |
| TIK h3cDot11BlackListTimeTicks | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.11.1.5 | TimeTicks | read-only | Represents the time elapsed since the entry was last updated in timetick. If it is static blacklist, the value is always 0. |
| INT h3cDot11BSSIDFilterOnOff | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.1.24 | INTEGER | read-write | Represents whether the BSSID permit feature is enabled or not. |
| BIT h3cDot11CntMsrMode | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.1.3 | Bits | read-write | Represents the countermeasures mode. |
| H3C h3cDot11DetectAPByChannel | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.2.1.3 | H3cDot11ChannelScopeType | read-only | Represents on which radio channel that WIDS monitor AP detected the rogue AP. |
| H3C h3cDot11DetectAPByRadioID | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.2.1.4 | H3cDot11RadioScopeType | read-only | Represents on which radio the monitor AP has detected the rogue AP. |
| TIK h3cDot11DetectAPFirstTm | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.2.1.6 | TimeTicks | read-only | Represents the time that monitor AP detected the rogue AP for the first time. |
| TIK h3cDot11DetectAPLastTm | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.2.1.7 | TimeTicks | read-only | Represents the time that monitor AP detected the rogue AP for the last time. |
| I32 h3cDot11DetectCurAPSigStrength | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.2.1.2 | Integer32 | read-only | Represents the current value of signal strength that WIDS monitor AP received from the rogue AP. |
| I32 h3cDot11DetectCurStaSigStrength | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.4.1.1 | Integer32 | read-only | Represents the current value of signal strength that WIDS monitor AP received from the rogue station. |
| H3C h3cDot11DetectStaByChannel | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.4.1.2 | H3cDot11ChannelScopeType | read-only | Represents on which radio channel the maximal signal strength was received. |
| H3C h3cDot11DetectStaByRadioID | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.4.1.3 | H3cDot11RadioScopeType | read-only | Represents which radio on the monitor AP has detected the rogue station. |
| TIK h3cDot11DetectStaFirstTm | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.4.1.5 | TimeTicks | read-only | Represents the time that monitor AP detected the rogue station for the first time. |
| TIK h3cDot11DetectStaLastTm | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.4.1.6 | TimeTicks | read-only | Represents the time that monitor AP detected the rogue station for the last time. |
| I32 h3cDot11DevAgingTime | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.1.4 | Integer32 | read-write | Represents the age time for entries in the detected device table. If an entry is not detected within the interval, it is deleted from the detected device table. If the deleted entry is that of a rogue, it is added into the rogue history table. |
| h3cDot11DynBlackListEntry | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.7.1 | not-accessible | Each entry contains information of dynamic blacklist. | |
| MAC h3cDot11DynBlackListMAC | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.7.1.1 | MacAddress | not-accessible | Represents the MAC address of the device inserted into the dynamic blacklist. |
| OCT h3cDot11DynBlackListReason | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.7.1.3 | OCTET STRING | read-only | Represents the reason why the entry was added into the dynamic blacklist. |
| T/F h3cDot11DynBlackListReset | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.7.1.4 | TruthValue | read-write | This object is used to remove designated entry from the dynamic blacklist. The value which read from this object always is false. |
| h3cDot11DynBlackListTable | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.7 | not-accessible | This table contains information of dynamic blacklist entries. | |
| U32 h3cDot11DynBlackListTime | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.7.1.2 | Unsigned32 | read-only | Represents the time elapsed since the entry was last updated. |
| TIK h3cDot11DynBlackListTimeTicks | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.7.1.5 | TimeTicks | read-only | Represents the time elapsed since the entry was last updated in units TimeTicks. |
| T/F h3cDot11DynBlkListEnable | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.1.5 | TruthValue | read-write | Represents whether the dynamic blacklist feature is enabled or not. 'true' : Enable the dynamic blacklist feature to filter out unwanted clients, which will not get associated. 'false' : Disable the dynamic blacklist feature. |
| I32 h3cDot11DynBlkListLifeTime | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.1.6 | Integer32 | read-write | Represents the lifetime for dynamic blacklist entries. If a dynamic blacklist entry is not detected within the lifetime, the entry will be removed from the dynamic blacklist. The lifetime becomes active only if dynamic blacklist feature is enabled. |
| T/F h3cDot11FloodAtkDctEnable | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.1.7 | TruthValue | read-write | Represents whether detection of flood attack is enabled or not. 'true' : Enable the detection of flood attack. 'false' : Disable the detection of flood attack. |
| H3C h3cDot11IgnoreDevType | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.4.1.4 | H3cDot11WIDSDevType | read-only | Represents the type of the MAC address detected. The value of this object always is unknown if the MAC address is not detected. |
| ROW h3cDot11IgnoreListRowStatus | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.4.1.2 | RowStatus | read-create | The status of this table entry. |
| MAC h3cDot11IgnoreMAC | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.4.1.1 | MacAddress | not-accessible | Represents the MAC address of station or AP, and WIDS always take it as legal station or AP. |
| T/F h3cDot11IgnoreMACDetected | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.4.1.3 | TruthValue | read-only | Represents whether the MAC address detected or not. |
| H3C h3cDot11MonitorAPID | 1.3.6.1.4.1.43.45.1.10.2.75.5.3.2.6 | H3cDot11ObjectIDType | accessible-for-notify | Represents monitor AP's APID. |
| H3C h3cDot11MonitorApRadioID | 1.3.6.1.4.1.43.45.1.10.2.75.5.3.2.7 | H3cDot11RadioScopeType | accessible-for-notify | Represents monitor AP's radio ID |
| MAC h3cDot11PermitBSSID | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.8.1.1 | MacAddress | not-accessible | Represents the permitted BSSID in the wireless network. |
| T/F h3cDot11PermitBSSIDDetected | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.8.1.2 | TruthValue | read-only | Represents whether the permitted BSSID is detected or not. |
| ROW h3cDot11PermitBSSIDRowStatus | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.8.1.3 | RowStatus | read-create | Represents the row status of permit BSSID table. |
| STR h3cDot11PermitSSID | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.3.1.1 | H3cDot11SSIDStringType | not-accessible | Represents the permitted SSID in the wireless network. |
| T/F h3cDot11PermitSSIDDetected | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.3.1.3 | TruthValue | read-only | Represents whether the permitted SSID is detected or not. |
| ROW h3cDot11PermitSSIDRowStatus | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.3.1.2 | RowStatus | read-create | The status of this table entry. |
| ROW h3cDot11PermitVendorRowStatus | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.2.1.2 | RowStatus | read-create | The status of this table entry. |
| T/F h3cDot11ResetAllDctAdhoc | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.1.18 | TruthValue | read-write | This object is used to clear the information of all detected ad hoc devices. It will return false for get operation. |
| T/F h3cDot11ResetAllDctDevice | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.1.19 | TruthValue | read-write | This object is used to clear the information of all detected devices. It will return false for get operation. |
| T/F h3cDot11ResetAllDctRogueAP | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.1.16 | TruthValue | read-write | This object is used to clear the information of all detected rogue APs. It will return false for get operation. |
| T/F h3cDot11ResetAllDctRogueSta | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.1.17 | TruthValue | read-write | This object is used to clear the information of all detected rogue clients. It will return false for get operation. |
| T/F h3cDot11ResetAllDctSSID | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.1.20 | TruthValue | read-write | This object is used to clear the information of all detected SSIDs. It will return false for get operation. |
| T/F h3cDot11ResetAllDynBlkList | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.1.13 | TruthValue | read-write | This object is used to remove all entries from the dynamic blacklist. It will return false for get operation. |
| T/F h3cDot11ResetAllStcBlkList | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.1.14 | TruthValue | read-write | This object is used to remove all entries from the static blacklist. It will return false for get operation. |
| T/F h3cDot11ResetAllWhtBlkList | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.1.15 | TruthValue | read-write | This object is used to remove all entries from the static whitelist. It will return false for get operation. |
| T/F h3cDot11ResetWIDSHistroy | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.1.11 | TruthValue | read-write | This object is used to clear the history information of attacks detected in the WLAN system. It will return false for get operation. |
| T/F h3cDot11ResetWIDSRogueHistory | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.1.10 | TruthValue | read-write | This object is used to clear all entries from the rogue history table. It will return false for get operation. |
| T/F h3cDot11ResetWIDSStatistics | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.1.12 | TruthValue | read-write | This object is used to clear the statistics of attacks detected in the WLAN system. It will return false for get operation. |
| T/F h3cDot11RogueAPAttackedStatus | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.1.1.10 | TruthValue | read-only | Represents whether the countermeasure have taken for the rogue AP. |
| I32 h3cDot11RogueAPBeaconInterval | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.1.1.9 | Integer32 | read-only | Represents the interval for Beacon management frame of rogue AP. |
| MAC h3cDot11RogueAPBSSMAC | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.1.1.1 | MacAddress | not-accessible | Represents the BSS MAC address of rogue AP. |
| H3C h3cDot11RogueAPChannel | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.1.1.8 | H3cDot11ChannelScopeType | read-only | Represents on which radio channel of the rogue AP the maximal signal strength was received. |
| T/F h3cDot11RogueAPEncryptStatus | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.1.1.12 | TruthValue | read-only | Represents whether the rogue AP encrypt the frame or not. |
| TIK h3cDot11RogueAPFirstDetectTm | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.1.1.4 | TimeTicks | read-only | Represents the time that AP was detected as a rogue AP for the first time. |
| OCT h3cDot11RogueAPFirstDetectTmStr | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.1.1.14 | OCTET STRING | read-only | Represents the time that AP was detected as a rogue AP for the first time. |
| TIK h3cDot11RogueAPLastDetectTm | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.1.1.5 | TimeTicks | read-only | Represents the time that AP was detected as a rogue AP for the last time. |
| OCT h3cDot11RogueAPLastDetectTmStr | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.1.1.15 | OCTET STRING | read-only | Represents the time that AP was detected as a rogue AP for the last time. |
| I32 h3cDot11RogueAPMaxSigStrength | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.1.1.7 | Integer32 | read-only | Represents the maximal value of signal strength that WIDS received from the rogue AP. |
| I32 h3cDot11RogueAPMonitorNum | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.1.1.3 | Integer32 | read-only | Represents the number of monitor APs which detected the rogue AP. |
| T/F h3cDot11RogueAPReset | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.1.1.13 | TruthValue | read-write | This object is used to clear information of assigned AP. The information of AP which detect assigned rogue AP will be cleared together. It will return false for get operation. |
| STR h3cDot11RogueAPSSID | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.1.1.6 | H3cDot11SSIDStringType | read-only | Represents the SSID broadcasted by rogue AP. |
| T/F h3cDot11RogueAPToIgnore | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.1.1.11 | TruthValue | read-write | Represents whether the rogue AP will be taken as a rogue AP. If the value is true, NMS should not display the rogue AP as NMS display rogue AP list, and the MAC address will be automatically added into h3cDot11WIDSIgnoreListTable. If the value is false, NMS will take it as a rogue AP. |
| OCT h3cDot11RogueAPVendorName | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.1.1.2 | OCTET STRING | read-only | Represents the vendor name of rogue AP. |
| MAC h3cDot11RogueStaAccessBSSID | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.3.1.6 | MacAddress | read-only | Represents BSS MAC address that rogue station try to access. |
| T/F h3cDot11RogueStaAdHocStatus | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.3.1.11 | TruthValue | read-only | Represents whether the rogue station work on the Ad Hoc mode or not. |
| T/F h3cDot11RogueStaAttackedStatus | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.3.1.9 | TruthValue | read-only | Represents whether the countermeasure have taken for the rogue station. |
| H3C h3cDot11RogueStaChannel | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.3.1.8 | H3cDot11ChannelScopeType | read-only | Represents on which radio channel the maximal signal strength was received. |
| TIK h3cDot11RogueStaFirstDetectTm | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.3.1.4 | TimeTicks | read-only | Represents the time that station was detected as a rogue station for the first time. |
| OCT h3cDot11RogueStaFirstDetectTmStr | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.3.1.13 | OCTET STRING | read-only | Represents the time that station was detected as a rogue station for the first time. |
| TIK h3cDot11RogueStaLastDetectTm | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.3.1.5 | TimeTicks | read-only | Represents the time that station was detected as a rogue station for the last time. |
| OCT h3cDot11RogueStaLastDetectTmStr | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.3.1.14 | OCTET STRING | read-only | Represents the time that station was detected as a rogue station for the last time. |
| MAC h3cDot11RogueStaMAC | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.3.1.1 | MacAddress | not-accessible | Represents the MAC address of rogue station. |
| I32 h3cDot11RogueStaMaxSigStrength | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.3.1.7 | Integer32 | read-only | Represents the maximal value of signal strength that WIDS received from the rogue station. |
| I32 h3cDot11RogueStaMonitorNum | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.3.1.3 | Integer32 | read-only | Represents the number of monitor APs which detected the rogue station. |
| T/F h3cDot11RogueStaReset | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.3.1.12 | TruthValue | read-write | This object is used to clear information of assigned station. The information of AP which detects assigned rogue station will be cleared together. It will return false for get operation. |
| T/F h3cDot11RogueStaToIgnore | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.3.1.10 | TruthValue | read-write | Represents whether the rogue AP will be taken as a rogue station. If the value is true, NMS should not display the rogue station as NMS display rogue station list, and the MAC address will be automatically added into h3cDot11WIDSIgnoreListTable. If the value is false, NMS will take it as a rogue station. |
| OCT h3cDot11RogueStaVendorName | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.3.1.2 | OCTET STRING | read-only | Represents the vendor name of rogue station. |
| T/F h3cDot11SpoofAtkDctEnable | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.1.8 | TruthValue | read-write | Represents whether detection of Spoof attack is enabled or not. 'true' : Enable the detection of Spoof attack. 'false' : Disable the detection of Spoof attack. |
| INT h3cDot11SSIDFilterOnOff | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.1.23 | INTEGER | read-write | Represents whether the SSID permit feature is enabled or not. |
| h3cDot11StaticBlackListEntry | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.7.1 | not-accessible | Each entry contains the information of static blacklist. | |
| MAC h3cDot11StaticBlackListMAC | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.7.1.1 | MacAddress | not-accessible | Represents the MAC addresses in static blacklist. |
| ROW h3cDot11StaticBlackListRowStatus | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.7.1.2 | RowStatus | read-create | The status of this table entry. |
| h3cDot11StaticBlackListTable | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.7 | not-accessible | The table provides the information of static blacklist. | |
| h3cDot11StaticWhiteListEntry | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.6.1 | not-accessible | Each entry contains the information of whitelist. | |
| MAC h3cDot11StaticWhiteListMAC | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.6.1.1 | MacAddress | not-accessible | Represents the MAC addresses in whitelist. |
| ROW h3cDot11StaticWhiteListRowStatus | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.6.1.2 | RowStatus | read-create | The status of this table entry. |
| h3cDot11StaticWhiteListTable | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.6 | not-accessible | The table provides the information of whitelist. | |
| STR h3cDot11UnauthorSSIDName | 1.3.6.1.4.1.43.45.1.10.2.75.5.3.2.5 | H3cDot11SSIDStringType | accessible-for-notify | Represents an unauthorized SSID. |
| OCT h3cDot11VendorName | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.2.1.3 | OCTET STRING | read-only | Represents the vendor name of the wireless device. |
| OCT h3cDot11VendorOUI | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.2.1.1 | OCTET STRING | not-accessible | Represents the vendor OUI information of the wireless device. |
| T/F h3cDot11WeakIVAtkDctEnable | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.1.9 | TruthValue | read-write | Represents whether detection of weak-iv attack is enabled or not. 'true' : Enable the detection of weak-iv attack. 'false' : Disable the detection of weak-iv attack. |
| h3cDot11WIDS | 1.3.6.1.4.1.43.45.1.10.2.75.5 | This MIB provides information about WIDS feature. GLOSSARY Wireless Intrusion Detection Sensor (WIDS) WIDS is designed to be employed in an area that is serviced by an existing wireless network. It aids in the early detection of malicious outsider attacks and intrusions via wireless networks. Rogue AP A rogue access point is any Wi-Fi access point connected to the network without authorization. As it is not authorized, if there is any weakness in the AP, the hacker will have chance to compromise the network. Rogue Station It is similiar to Rogue AP, while it is a station. Monitor AP An AP will scan or listen to the air, and try to detect wireless attack in the network. Some AP products will work only in monitor role, while some AP products could switch between normal AP role (only provide wireless access service)and monitor AP role. Ad Hoc Mode Station could work under Ad hoc mode, then they could directly do peer-to-peer communication without other device support. | ||
| MAC h3cDot11WIDSAdHocMAC | 1.3.6.1.4.1.43.45.1.10.2.75.5.3.2.4 | MacAddress | accessible-for-notify | Represents the MAC address of Ad hoc station. |
| NTF h3cDot11WIDSAdHocTrap | 1.3.6.1.4.1.43.45.1.10.2.75.5.3.1.2 | The notification represents a rogue Ad hoc station was detected. | ||
| H3C h3cDot11WIDSAPID | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.2.1.1 | H3cDot11ObjectIDType | not-accessible | To uniquely identify each AP, and relation-ship between h3cDot11WIDSAPID and AP device will be static. |
| H3C h3cDot11WIDSAtkChannel | 1.3.6.1.4.1.43.45.1.10.2.75.5.3.2.10 | H3cDot11ChannelScopeType | accessible-for-notify | Represents attack channel. |
| MAC h3cDot11WIDSAtkDestMac | 1.3.6.1.4.1.43.45.1.10.2.75.5.3.2.12 | MacAddress | accessible-for-notify | Represents mac address of attack destination. |
| OCT h3cDot11WIDSAtkFrameType | 1.3.6.1.4.1.43.45.1.10.2.75.5.3.2.9 | OCTET STRING | accessible-for-notify | Represents attack frame type. |
| OCT h3cDot11WIDSAtkHisAPName | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.9.1.7 | OCTET STRING | read-only | Represents the name of the AP which detected this attack. |
| H3C h3cDot11WIDSAtkHisChl | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.9.1.4 | H3cDot11ChannelScopeType | read-only | Represents the channel in which the attack was detected. |
| DAT h3cDot11WIDSAtkHisDctTime | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.9.1.6 | DateAndTime | read-only | Represents the time at which this attack was detected. |
| I32 h3cDot11WIDSAtkHisIndex | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.9.1.1 | Integer32 | not-accessible | Represents index of this entry. |
| MAC h3cDot11WIDSAtkHisMAC | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.9.1.2 | MacAddress | read-only | Represents the Mac address. In case of spoof attacks, this field provides the BSSID which was spoofed. In case of other attacks, this field provides the MAC address of the device which initiated the attack. |
| I32 h3cDot11WIDSAtkHisRSSI | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.9.1.5 | Integer32 | read-only | Represents the average RSSI of the designated attack. |
| h3cDot11WIDSAtkHistroyEntry | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.9.1 | not-accessible | Each entry contains information of the history of attacks detected in the WLAN system. | |
| h3cDot11WIDSAtkHistroyTable | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.9 | not-accessible | This table contains information of the history of attacks detected in the WLAN system. | |
| H3C h3cDot11WIDSAtkHisType | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.9.1.3 | H3cDot11WIDSAtkType | read-only | Represents the type of attack. |
| MAC h3cDot11WIDSAtkMac | 1.3.6.1.4.1.43.45.1.10.2.75.5.3.2.8 | MacAddress | accessible-for-notify | Represents mac address of attack source. |
| U32 h3cDot11WIDSAtkStasCurCnt | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.10.2.1.2 | Unsigned32 | read-only | Represents the count of attacks detected since the time specified by the current attack tracking time. The current attack tracking time is started at the system startup and is refreshed each hour subsequently. |
| h3cDot11WIDSAtkStasEntry | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.10.2.1 | not-accessible | Each entry contains information of the counts of attacks detected. | |
| DAT h3cDot11WIDSAtkStasStartTime | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.10.1 | DateAndTime | read-only | Represents current attack tracking time. It is started at the system startup and is refreshed each hour subsequently. |
| h3cDot11WIDSAtkStasTable | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.10.2 | not-accessible | This table contains information of the counts of attacks detected. | |
| U32 h3cDot11WIDSAtkStasTotalCnt | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.10.2.1.3 | Unsigned32 | read-only | Represents the total count of the attacks detected since the system startup. |
| H3C h3cDot11WIDSAtkStasType | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.10.2.1.1 | H3cDot11WIDSAtkType | not-accessible | Represents the type of attack. |
| h3cDot11WIDSAtkStatis | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.10 | |||
| OCT h3cDot11WIDSAtkTime | 1.3.6.1.4.1.43.45.1.10.2.75.5.3.2.11 | OCTET STRING | accessible-for-notify | Represents when attacking happened. |
| h3cDot11WIDSAttackListEntry | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.5.1 | not-accessible | Each entry contains the MAC address of rogue AP or rogue station, and the countermeasure will be taken for it. | |
| h3cDot11WIDSAttackListTable | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.5 | not-accessible | The table provides the MAC address list of rogue APs or rogue stations, the WIDS will take countermeasure as per the MAC address list. | |
| U32 h3cDot11WidsBlackListThreshold | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.1.22 | Unsigned32 | read-write | When flood attack exceeds the value of this node, the MAC address will be added into black list. |
| h3cDot11WIDSConfigGroup | 1.3.6.1.4.1.43.45.1.10.2.75.5.1 | |||
| NTF h3cDot11WIDSDetectAttack | 1.3.6.1.4.1.43.45.1.10.2.75.5.3.1.5 | This notification occurs when some type of attack is detected. | ||
| h3cDot11WIDSDetectedDevEntry | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.5.1 | not-accessible | Each entry contains information of detected devices. | |
| h3cDot11WIDSDetectedDevTable | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.5 | not-accessible | This Table contains information of detected devices. | |
| h3cDot11WIDSDetectGroup | 1.3.6.1.4.1.43.45.1.10.2.75.5.2 | |||
| NTF h3cDot11WIDSDetectRogueTrap | 1.3.6.1.4.1.43.45.1.10.2.75.5.3.1.1 | The notification represents that a rogue AP or a station was detected by WIDS. The NMS would refer to MIB table under h3cDot11WIDSDetectGroup group to get more detailed information. | ||
| NTF h3cDot11WIDSDetectWBridge | 1.3.6.1.4.1.43.45.1.10.2.75.5.3.1.6 | This notification occurs whenever a detected device is classified as rogue wireless-bridge. | ||
| I32 h3cDot11WIDSDevBeaconIntvl | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.5.1.10 | Integer32 | read-only | Represents the beacon interval for the detected AP. |
| MAC h3cDot11WIDSDevBSSID | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.5.1.7 | MacAddress | read-only | Represents the basic service set identifier of the detected device. |
| H3C h3cDot11WIDSDevChannel | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.5.1.8 | H3cDot11ChannelScopeType | read-only | Represents the channel in which the device was last detected. |
| DAT h3cDot11WIDSDevFstDctTime | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.5.1.11 | DateAndTime | read-only | Represents the time at which the device was first detected. |
| DAT h3cDot11WIDSDevLstDctTime | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.5.1.12 | DateAndTime | read-only | Represents the time at which the rogue AP was detected last time. |
| MAC h3cDot11WIDSDevMAC | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.5.1.1 | MacAddress | not-accessible | Represents MAC address of the device detected. |
| I32 h3cDot11WIDSDevMaxRSSI | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.5.1.9 | Integer32 | read-only | Represents the maximum detected RSSI of the device. |
| I32 h3cDot11WIDSDevMonitorNum | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.5.1.5 | Integer32 | read-only | Represents the number of active APs that detect the device. |
| H3C h3cDot11WIDSDevPermitType | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.5.1.3 | H3cDot11WIDSDevPermitType | read-only | Represents whether the device detected is a rogue device or not. |
| T/F h3cDot11WIDSDevReset | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.5.1.13 | TruthValue | read-write | This object is used to clears the information of the device detected in the WLAN. It will return false for get operation. |
| I32 h3cDot11WIDSDevSnr | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.5.1.14 | Integer32 | read-only | Represents SNR of the device detected. |
| OCT h3cDot11WIDSDevSSID | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.5.1.6 | OCTET STRING | read-only | Represents the service set identifier for the ESS of the device. |
| H3C h3cDot11WIDSDevType | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.5.1.2 | H3cDot11WIDSDevType | read-only | Represents type of the device detected. |
| OCT h3cDot11WIDSDevVendor | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.5.1.4 | OCTET STRING | read-only | Represents Vendor of the detected device. |
| NTF h3cDot11WIDSDisappearRogueTrap | 1.3.6.1.4.1.43.45.1.10.2.75.5.3.1.4 | The notification represents that a rogue device has aged out and moved to history table or the device type has been changed to friendly. The notification will be sent to NMS whenever a rogue disappears. | ||
| TIK h3cDot11WIDSFirstTrapTime | 1.3.6.1.4.1.43.45.1.10.2.75.5.3.2.13 | TimeTicks | accessible-for-notify | Represents the first trap time. |
| U32 h3cDot11WidsFloodInterval | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.1.21 | Unsigned32 | read-write | The interval of WIDS flood detection. |
| NTF h3cDot11WIDSFloodTrap | 1.3.6.1.4.1.43.45.1.10.2.75.5.3.1.7 | This notification occurs when flood attack is detected. | ||
| h3cDot11WIDSGlobalConfigGroup | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.1 | |||
| h3cDot11WIDSIgnoreListEntry | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.4.1 | not-accessible | Each entry contains the MAC address of station or AP, and WIDS always take it as legal station or AP. | |
| h3cDot11WIDSIgnoreListTable | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.4 | not-accessible | The table provides the MAC address list of stations or APs, and WIDS always take them as legal stations or APs. | |
| MAC h3cDot11WIDSMonitorMAC | 1.3.6.1.4.1.43.45.1.10.2.75.5.3.2.3 | MacAddress | accessible-for-notify | Represents which monitor detected the rogue AP or station. |
| h3cDot11WIDSNotifyGroup | 1.3.6.1.4.1.43.45.1.10.2.75.5.3 | |||
| h3cDot11WIDSPermitBSSIDEntry | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.8.1 | not-accessible | Each entry provides the information of permitted BSSID. | |
| h3cDot11WIDSPermitBSSIDTable | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.8 | not-accessible | The table represents the list of BSSID could be permitted in the wireless network. | |
| h3cDot11WIDSPermitSSIDEntry | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.3.1 | not-accessible | Each entry provides the information of permitted SSID. | |
| h3cDot11WIDSPermitSSIDTable | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.3 | not-accessible | The table represents the list of SSID could be permitted in the wireless network. | |
| h3cDot11WIDSPermitVendorEntry | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.2.1 | not-accessible | Each entry provides the information of permitted vendor. | |
| h3cDot11WIDSPermitVendorTable | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.2 | not-accessible | The table provides the permitted vendor list, and each vendor will be identified by OUI. The legal device should be made by the permitted vendors. | |
| h3cDot11WIDSRogueAPEntry | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.1.1 | not-accessible | Each entry contains possible BSS information of each rogue AP detected by WIDS. | |
| h3cDot11WIDSRogueAPExtEntry | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.2.1 | not-accessible | Each entry contains information of the rogue AP detected by each monitor AP. | |
| h3cDot11WIDSRogueAPExtTable | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.2 | not-accessible | As each rogue AP could be detected by multiple monitor APs, each monitor AP could have some kind of detailed information about a specific rogue AP. In the h3cDot11WIDSRogueAPTable table, the detailed information for a specific rogue AP will be summarized from information in the h3cDot11WIDSRogueAPExtTable table. For example, multiple monitor APs could receive RF signal of one rogue AP, and each monitor AP has its maximum signal strength by itself. The information will be kept as h3cDot11DetectMaxAPSigStrength in the h3cDot11WIDSRogueAPExtTable table. While only the maximum value among all the h3cDot11DetectMaxAPSigStrength for each monitor AP will be kept in the h3cDot11WIDSRogueAPTable as h3cDot11RogueAPMaxSigStrength. | |
| h3cDot11WIDSRogueAPTable | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.1 | not-accessible | The table represents the list of possible BSS information for rogue APs detected by the WIDS. | |
| H3C h3cDot11WIDSRogueHisChl | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.8.1.5 | H3cDot11ChannelScopeType | read-only | Represents the channel in which the device was last detected. |
| I32 h3cDot11WIDSRogueHisIndex | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.8.1.1 | Integer32 | not-accessible | Represents index of this entry. |
| DAT h3cDot11WIDSRogueHisLastDctTime | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.8.1.7 | DateAndTime | read-only | Represents the time at which the device was last detected. |
| MAC h3cDot11WIDSRogueHisMAC | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.8.1.2 | MacAddress | read-only | Represents the MAC address of the device. |
| OCT h3cDot11WIDSRogueHisSSID | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.8.1.6 | OCTET STRING | read-only | Represents the service set identifier for the ESS of the device. |
| h3cDot11WIDSRogueHistoryEntry | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.8.1 | not-accessible | Each entry contains information of an expired rogue device which has been deleted from the list of detected rogue devices because they could not be detected within the device aging duration. | |
| h3cDot11WIDSRogueHistoryTable | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.8 | not-accessible | This table contains information of all expired rogue devices which have been deleted from the list of detected rogue devices because they could not be detected within the device aging duration. | |
| H3C h3cDot11WIDSRogueHisType | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.8.1.4 | H3cDot11WIDSDevType | read-only | Represents the type of the device. |
| OCT h3cDot11WIDSRogueHisVendor | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.8.1.3 | OCTET STRING | read-only | Represents the vendor for the device. |
| MAC h3cDot11WIDSRogueMAC | 1.3.6.1.4.1.43.45.1.10.2.75.5.3.2.1 | MacAddress | accessible-for-notify | Represents which rogue AP or station. |
| h3cDot11WIDSRogueStaEntry | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.3.1 | not-accessible | Each entry contains information of each rogue station. | |
| h3cDot11WIDSRogueStaExtEntry | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.4.1 | not-accessible | Each entry contains information of rogue station detected by each monitor AP. | |
| h3cDot11WIDSRogueStaExtTable | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.4 | not-accessible | As each rogue station could be detected by multiple monitor APs, each monitor AP could have some kind of detailed information about a specific rogue station. In the h3cDot11WIDSRogueStaTable table, the detailed information for a specific rogue station will be summarized from information in the h3cDot11WIDSRogueStaExtTable table. For example, multiple monitor APs could receive RF signal of one rogue station, and each monitor AP has its maximum signal strength by itself. The information will be kept as h3cDot11DetectMaxStaSigStrength in the h3cDot11WIDSRogueStaExtTable table. While only the maximum value among all the h3cDot11DetectMaxStaSigStrength for each monitor AP will be kept in the h3cDot11WIDSRogueStaTable as h3cDot11RogueStaMaxSigStrength. | |
| h3cDot11WIDSRogueStaTable | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.3 | not-accessible | The table represents the list of rogue stations detected by the WIDS. | |
| INT h3cDot11WIDSRogueType | 1.3.6.1.4.1.43.45.1.10.2.75.5.3.2.2 | INTEGER | accessible-for-notify | Represents the rogue type. The following value are supported rogueAp(1) - A rogue AP rogueStation(2) - A rogue Station |
| h3cDot11WIDSRptAPEntry | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.6.1 | not-accessible | Each entry contains information of the AP which detected device in the WLAN. | |
| DAT h3cDot11WIDSRptAPFstDctTime | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.6.1.5 | DateAndTime | read-only | Represents the time at which the rogue AP was detected first time. |
| DAT h3cDot11WIDSRptAPLstDctTime | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.6.1.6 | DateAndTime | read-only | Represents the time at which the rogue AP was detected last time. |
| MAC h3cDot11WIDSRptAPMAC | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.6.1.1 | MacAddress | not-accessible | Represents the MAC address of the AP that detected the device. |
| I32 h3cDot11WIDSRptAPMaxRSSI | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.6.1.4 | Integer32 | read-only | Represents the maximum detected RSSI of the device. |
| OCT h3cDot11WIDSRptAPName | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.6.1.2 | OCTET STRING | read-only | Represents the name of the AP that detected the device. |
| H3C h3cDot11WIDSRptAPRadioID | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.6.1.3 | H3cDot11RadioScopeType | read-only | Represents the radio index of the AP that detected the device. |
| h3cDot11WIDSRptAPTable | 1.3.6.1.4.1.43.45.1.10.2.75.5.2.6 | not-accessible | This Table contains information of the AP which detected device in the WLAN. | |
| OCT h3cDot11WIDSScanChannelList | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.1.2 | OCTET STRING | read-write | Represents the channel scope to be scanned when h3cDot11WIDSScanMode is configurated as channelSpec mode. Each channel value will be separated by comma character. |
| INT h3cDot11WIDSScanMode | 1.3.6.1.4.1.43.45.1.10.2.75.5.1.1.1 | INTEGER | read-write | Represents the scope of channels to be scanned. The following value are supported all(1) - Do scan on all the channels. auto(2) - Do scan for the channels that automatically selected by WIDS. |
| NTF h3cDot11WIDSSpoofTrap | 1.3.6.1.4.1.43.45.1.10.2.75.5.3.1.8 | This notification occurs when spoof attack is detected. | ||
| h3cDot11WIDSTraps | 1.3.6.1.4.1.43.45.1.10.2.75.5.3.1 | |||
| h3cDot11WIDSTrapVarObjects | 1.3.6.1.4.1.43.45.1.10.2.75.5.3.2 | |||
| NTF h3cDot11WIDSUnauthorSSIDTrap | 1.3.6.1.4.1.43.45.1.10.2.75.5.3.1.3 | The notification represents which unauthorized SSID are accessed in the network. The notification will be sent to NMS when an unauthorized SSID is detected on the network for the first time. | ||
| NTF h3cDot11WIDSWeakIVTrap | 1.3.6.1.4.1.43.45.1.10.2.75.5.3.1.9 | This notification occurs when weak IV attack is detected. |
RFC description
H3C wireless intrusion detection system MIB for detecting rogue access points, spoofing attacks, and unauthorized devices.
Start monitoring H3C wireless controllers and APs with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.