All MIBs › AIRESPACE-WIRELESS-MIB › bsnRadiusAuthKeyWrapEnable
bsnRadiusAuthKeyWrapEnable
Module: AIRESPACE-WIRELESS-MIB
OID (symbolic): AIRESPACE-WIRELESS-MIB::bsnRadiusAuthKeyWrapEnable
OID (numeric): 1.3.6.1.4.1.14179.2.5.12
Node type: OBJECT-TYPE
Type: TruthValue
Access: read-write
Description: When keyWrap is enable then for 801.1X and 802.11i client Authentication, request is sent to those radius servers which has KEK and MACK keys are configured.
Radius servers are widely used for user authentications. In 802.11i and 802.1X type authentication, the controller recives Pairwise Master KEy(PMK) from RADIUS sever using vendor specific RADIUS attributes, which uses MPPE RFC3078. Since MPPE uses RC4 algorithm to provide data confidentiality, it is not FIPS approved. For this RADIUS key WRAP attributes, bsnRadiusAuthServerKeyWrap and bsnRadiusAuthServerKeyWrapMACKkey have been added, which are used to securely transfer encryption keys using non-proprietary techniques.
What is bsnRadiusAuthKeyWrapEnable?
Enables or disables RADIUS key wrap encryption for 802.1X and 802.11i client authentication, which requires RADIUS servers to have KEK and MACK keys configured. When enabled, authentication requests are only sent to RADIUS servers that support this enhanced key protection mechanism.
Examples
Walk all instances (SNMPv2c):
snmpwalk -v2c -c public <target> 1.3.6.1.4.1.14179.2.5.12 snmpwalk -v2c -c public <target> AIRESPACE-WIRELESS-MIB::bsnRadiusAuthKeyWrapEnable
Get a specific instance (index 1):
snmpget -v2c -c public <target> 1.3.6.1.4.1.14179.2.5.12.1 snmpget -v2c -c public <target> AIRESPACE-WIRELESS-MIB::bsnRadiusAuthKeyWrapEnable.1
Set instance 1 (SNMPv2c):
snmpset -v2c -c private <target> 1.3.6.1.4.1.14179.2.5.12.1 s <value>
Start monitoring Cisco (Airespace) Wireless LAN Controllers (legacy) with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the AIRESPACE-WIRELESS-MIB::bsnRadiusAuthKeyWrapEnable OID value, configure state conditions and alerts, and monitor any Cisco (Airespace) Wireless LAN Controllers (legacy) from a single console.
OID Breakdown
Upper-level ancestors (7 from the standard OID tree / other modules)
| Numeric OID | Name | Module |
|---|---|---|
| 1 | iso | LANART-AGENT |
| 1.3 | org | AirPair-MIB |
| 1.3.6 | dod | AirPair-MIB |
| 1.3.6.1 | internet | AirPair-MIB |
| 1.3.6.1.4 | private | AirPair-MIB |
| 1.3.6.1.4.1 | enterprises | AirPair-MIB |
| 1.3.6.1.4.1.14179 | airespace | AIRESPACE-REF-MIB |
| Numeric OID | Name | Module |
|---|---|---|
| 1.3.6.1.4.1.14179.2 | bsnWireless | AIRESPACE-WIRELESS-MIB |
| 1.3.6.1.4.1.14179.2.5 | bsnAAA | AIRESPACE-WIRELESS-MIB |
| 1.3.6.1.4.1.14179.2.5.12 | bsnRadiusAuthKeyWrapEnable | AIRESPACE-WIRELESS-MIB |