ARISTA-SNMP-TRANSPORTS-MIB

MIB Reference — IPNetwork Monitor

All MIBsARISTA-SNMP-TRANSPORTS-MIB

Organization: Arista Networks, Inc.

Last Updated: 2014-08-15

Category: Vendor: Arista

Description:

Arista EOS SNMP transport configuration including TCP and UDP domain management.

Imported Objects

From ARISTA-SMI-MIB

aristaMibsOBJECT-IDENTITY

From SNMPv2-CONF

MODULE-COMPLIANCE
OBJECT-GROUP

From SNMPv2-SMI

MODULE-IDENTITY
OBJECT-IDENTITY
OBJECT-TYPE

From SNMPv2-TC

TAddress
TDomain
TEXTUAL-CONVENTION

What Is ARISTA-SNMP-TRANSPORTS-MIB?

This is an Arista Networks (EOS) enterprise MIB defining SNMP transport domain configuration, specifically Arista-specific SNMP transport addressing objects and an authentication-failure trap mechanism. It exposes objects describing the transport domain and source address of SNMP authentication-failure events (aristaAuthFailTrapTDomain, aristaAuthFailTrapSrcTAddress), used to notify management stations when an unauthorized or misconfigured SNMP client attempts access. Rather than hardware/environmental monitoring, its value is in monitoring the software health and security posture of the SNMP management subsystem itself, alerting operators to failed authentication attempts that could indicate misconfiguration or a security probing attempt. It extends the standard SNMP transport-domain/transport-address conventions with Arista-specific trap semantics. It's typically deployed on Arista EOS switches wherever SNMP-based management is used and administrators want visibility into SNMP authentication failures. Network engineers evaluating or troubleshooting this functionality can download the ARISTA-SNMP-TRANSPORTS-MIB file directly to load it into their MIB browser.

IPNetwork Monitor allows you to monitor SNMP objects defined in ARISTA-SNMP-TRANSPORTS-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

What Can Be Monitored

  • SNMP authentication failure events
  • source transport address of failed SNMP requests
  • SNMP transport domain used

Supported Devices

  • Arista Networks EOS switches

Monitoring Examples

A monitoring station would subscribe to traps carrying aristaAuthFailTrapObjects, including the aristaAuthFailTrapSrcTAddress of the offending client and the aristaAuthFailTrapTDomain, e.g., UDP/IP, over which the failed request arrived. Repeated authentication-failure traps from the same source address would indicate either an SNMP client with a stale community string/credentials or a potential unauthorized access attempt against the switch.

OIDs
OID symbolicOID numericTypeAccessDescription
aristaSnmpTransportMIB1.3.6.1.4.1.30065.3.10The Arista Networks specific SNMP transport domains.
aristaUDPNSDomain1.3.6.1.4.1.30065.3.10.1The SNMP over UDP transport domain. The corresponding socket is opened in a specific namespace.
aristaTCPNSDomain1.3.6.1.4.1.30065.3.10.2The SNMP over TCP transport domain. The corresponding socket is opened in a specific namespace.
aristaUDPNS6Domain1.3.6.1.4.1.30065.3.10.3The SNMP over UDP6 transport domain. The corresponding socket is opened in a specific namespace.
aristaTCPNS6Domain1.3.6.1.4.1.30065.3.10.4The SNMP over TCP6 transport domain. The corresponding socket is opened in a specific namespace.
aristaAuthFailTrapObjects1.3.6.1.4.1.30065.3.10.5
TDO aristaAuthFailTrapTDomain1.3.6.1.4.1.30065.3.10.5.1TDomainread-onlyTransport Domain of the offending request that caused this trap
ADR aristaAuthFailTrapSrcTAddress1.3.6.1.4.1.30065.3.10.5.2TAddressread-onlySource Transport Address of the offending request that caused this trap
aristaTransportConformance1.3.6.1.4.1.30065.3.10.6
aristaAuthFailTrapGroups1.3.6.1.4.1.30065.3.10.6.1
aristaAuthFailTrapObjectsGroup1.3.6.1.4.1.30065.3.10.6.1.1Collections of objects for Authentication Failure Trap.
aristaAuthFailCompliances1.3.6.1.4.1.30065.3.10.6.2
aristaAuthFailCompliance1.3.6.1.4.1.30065.3.10.6.2.1The compliance statement for SNMP entities which implement the ARISTA AuthFailure MIB.

RFC description

Defines Arista-specific SNMP transport domains and connection protocols for network management.

Start monitoring Arista Networks switches with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download ARISTA-SNMP-TRANSPORTS-MIB