BAYSTACK-IPV6-FIRST-HOP-SEC-MIB

MIB Reference — IPNetwork Monitor · Updated September 09, 2026

All MIBsBAYSTACK-IPV6-FIRST-HOP-SEC-MIB

Organization: Avaya

Last Updated: 2015-04-08

Category: Device Management, VPN and Security, Vendor: Avaya

Description: Manages IPv6 first-hop security features including RA guard, DHCPv6 snooping, and ND inspection on Avaya/Nortel switches.

Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

What Is BAYSTACK-IPV6-FIRST-HOP-SEC-MIB?

BAYSTACK-IPV6-FIRST-HOP-SEC-MIB is an Avaya/Nortel proprietary MIB for configuring IPv6 First Hop Security features on BayStack ERS switches, protecting against threats between directly-connected nodes on the same segment. It exposes admin enable flags for the overall feature, RA Guard, DHCPv6 Guard, and ND Inspection, along with binding-table size/lifetime parameters and an IPv6 access-list table. Its monitoring value is security/configuration status: confirming these protections are enabled and that the dynamic binding table (used to track legitimate IPv6 neighbors) isn't overflowing, since a table overflow (bsIpv6FHSSbtTblOverFlow) could indicate an attack or a need to raise limits. It is built on top of the standard IPv6 neighbor discovery and DHCPv6 protocols it is designed to police. It is deployed on Avaya/Nortel ERS switches in IPv6-enabled networks needing protection against rogue RAs, DHCPv6 servers, or ND spoofing. Network engineers evaluating or troubleshooting this functionality can download the BAYSTACK-IPV6-FIRST-HOP-SEC-MIB file directly to load it into their MIB browser.

IPNetwork Monitor allows you to monitor SNMP objects defined in BAYSTACK-IPV6-FIRST-HOP-SEC-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • Avaya/Nortel BayStack Ethernet Routing Switch (ERS)

Monitoring Examples

An administrator would check bsIpv6FHSAdmin, bsIpv6FHSRagAdmin, bsIpv6FHSDhcpv6gAdmin and bsIpv6FHSNdInspectAdmin to confirm which first-hop security features are enabled on a switch, and monitor bsIpv6FHSSbtTblOverFlow alongside bsIpv6FHSMaxDynSbtEntries to detect if the dynamic binding table is filling up, which could signal an active spoofing attempt. Reviewing bsIpv6FHSIpv6AccessListTable/bsIpv6FHSIpv6AccessListEntry entries confirms the correct access-list policy is applied.

What Can Be Monitored

  • first-hop security admin state
  • RA guard status
  • DHCPv6 guard status
  • ND inspection status
  • binding table overflow
  • access list configuration
Imported Objects

From IF-MIB

InterfaceIndex

From IPV6-TC

Ipv6Address

From SNMPv2-SMI

Counter32
Integer32
MODULE-IDENTITY
NOTIFICATION-TYPE
OBJECT-TYPE

From SNMPv2-TC

DisplayString
MacAddress
RowStatus
TEXTUAL-CONVENTION
TruthValue

From SYNOPTICS-ROOT-MIB

bayStackMibsOBJECT-IDENTITY

How to Use in IPNetwork Monitor

Example using bsIpv6FHSSbtTblOverFlow OID:

Select an Avaya/Nortel BayStack Ethernet Routing Switch (ERS) (legacy) as the target host to create a monitor — the SNMP service should be up and running on it. Click New Monitor, then check SNMP Custom on the Favorites tab, click Next, and confirm the host. On the next page, click Select... to open the built-in SNMP MIB Browser and type bsIpv6FHSSbtTblOverFlow into the Find box to locate it in the OID tree, then select it and click OK. It reports sBT Table Overflow due to the maximum SBT entry restriction. On the monitor's Main parameters page you can set the target's SNMP port (default 161), credentials, polling interval, and other settings — see the SNMP Monitor help for details. On the State conditions and Alerting tabs, configure when the monitor should change state and trigger an alert; since this is a Counter32-type OID, Value bounds is the most useful condition here — trigger an alert if the counter increases sharply between polls relative to its normal baseline, since an unexpected spike often reflects a real change in traffic or activity. Click Finish to create the monitor; you can adjust any parameter later.
OIDs

RFC description

Configures IPv6 First Hop Security features including RA Guard, DHCPv6 Guard, ND Inspection, and Source Guard.

Start monitoring Avaya/Nortel BayStack Ethernet Routing Switch (ERS) (legacy) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download BAYSTACK-IPV6-FIRST-HOP-SEC-MIB