| OID symbolic | OID numeric | Type | Access | Description |
| bayStackIpv6FirstHopSecMib | 1.3.6.1.4.1.45.5.45 | | | This MIB module is used for IPv6 First Hop Security configuration.
The purpose of First Hop Security feature is to take care of the treats
caused by the immediate node to another immediate node attached to the same
First Hop Security device. |
| T/F bsIpv6FHSAdmin | 1.3.6.1.4.1.45.5.45.1.1.1 | TruthValue | read-write | First Hop Security Global Admin status |
| T/F bsIpv6FHSDhcpv6gAdmin | 1.3.6.1.4.1.45.5.45.1.1.3 | TruthValue | read-write | DHCPv6 guard Global Admin status |
| FHS bsIpv6FHSDhcpv6gDeviceRole | 1.3.6.1.4.1.45.5.45.1.5.1.2 | FhsDhcpv6GuardDeviceRole | read-write | This is the device role of
the received port. If the
device role is client and if
it receives DHCPv6 reply then
those packets should be
dropped |
| bsIpv6FHSDhcpv6gPolicyListEntry | 1.3.6.1.4.1.45.5.45.1.5.1 | | not-accessible | Entry contains the list of
DHCPv6 guard Policies used for
Hop Security Feature. |
| ROW bsIpv6FHSDhcpv6gPolicyListRowStatus | 1.3.6.1.4.1.45.5.45.1.5.1.7 | RowStatus | read-write | DHCPv6 guard policy row status |
| bsIpv6FHSDhcpv6gPolicyListTable | 1.3.6.1.4.1.45.5.45.1.5 | | not-accessible | Table contains the list of
DHCPv6 guard Policies used for
Hop Security Feature. |
| FHS bsIpv6FHSDhcpv6gPolicyName | 1.3.6.1.4.1.45.5.45.1.5.1.1 | FhsListName | not-accessible | This is the DHCPv6
guard Policy Name |
| I32 bsIpv6FHSDhcpv6gPrefLimitMax | 1.3.6.1.4.1.45.5.45.1.5.1.6 | Integer32 | read-write | This is check against the
DHCPv6 server / relay
router preference. If
the received router
preference is greater
than the configured
router preference than
drop the packet |
| I32 bsIpv6FHSDhcpv6gPrefLimitMin | 1.3.6.1.4.1.45.5.45.1.5.1.5 | Integer32 | read-write | This is check against the
DHCPv6 server / relay
router preference. If
the received router
preference is less
than the configured
router preference than
drop the packet |
| FHS bsIpv6FHSDhcpv6gReplyPrefixListName | 1.3.6.1.4.1.45.5.45.1.5.1.4 | FhsListName | read-write | Validate the prefix
information in the DHCPv6
reply against the configured
reply prefix list. |
| FHS bsIpv6FHSDhcpv6gServerAccessListName | 1.3.6.1.4.1.45.5.45.1.5.1.3 | FhsListName | read-write | This is the IPv6 access list which
will be validating source
IPv6 address of the DHCPv6 Reply
packet from the server |
| FHS bsIpv6FHSIpv6AccessListAccessType | 1.3.6.1.4.1.45.5.45.1.2.1.6 | FhsAccessType | read-write | IPv6 IP Access Type
Allow or Deny |
| bsIpv6FHSIpv6AccessListEntry | 1.3.6.1.4.1.45.5.45.1.2.1 | | not-accessible | Entry contains the list of
IPv6 Access List used for Frist
Hop Security Feature. |
| I32 bsIpv6FHSIpv6AccessListMaskLenFrom | 1.3.6.1.4.1.45.5.45.1.2.1.4 | Integer32 | read-write | IPv6 Prefix mask length range from |
| I32 bsIpv6FHSIpv6AccessListMaskLenTo | 1.3.6.1.4.1.45.5.45.1.2.1.5 | Integer32 | read-write | IPv6 Prefix mask length range to |
| FHS bsIpv6FHSIpv6AccessListName | 1.3.6.1.4.1.45.5.45.1.2.1.1 | FhsListName | not-accessible | IPv6 Access List Name |
| ADR bsIpv6FHSIpv6AccessListPrefix | 1.3.6.1.4.1.45.5.45.1.2.1.2 | Ipv6Address | not-accessible | IPv6 Prefix attached to this IPv6 access list Id |
| I32 bsIpv6FHSIpv6AccessListPrefixMaskLen | 1.3.6.1.4.1.45.5.45.1.2.1.3 | Integer32 | not-accessible | IPv6 Prefix mask length attached to this IPv6 access list Id |
| ROW bsIpv6FHSIpv6AccessListRowStatus | 1.3.6.1.4.1.45.5.45.1.2.1.7 | RowStatus | read-write | IPv6 IP Access List row status |
| bsIpv6FHSIpv6AccessListTable | 1.3.6.1.4.1.45.5.45.1.2 | | not-accessible | Table contains the list of
IPv6 Access List used for Frist
Hop Security Feature. |
| FHS bsIpv6FHSMacAccessListAccessType | 1.3.6.1.4.1.45.5.45.1.3.3.3 | FhsAccessType | read-write | MAC Access Type
Allow or Deny |
| bsIpv6FHSMacAccessListEntry | 1.3.6.1.4.1.45.5.45.1.3.3 | | not-accessible | Entry contains the list of
MAC Access List used for Frist
Hop Security Feature. |
| MAC bsIpv6FHSMacAccessListMac | 1.3.6.1.4.1.45.5.45.1.3.3.2 | MacAddress | not-accessible | MAC address attached to this MAC access list Id |
| FHS bsIpv6FHSMacAccessListName | 1.3.6.1.4.1.45.5.45.1.3.3.1 | FhsListName | not-accessible | MAC Access List Name |
| ROW bsIpv6FHSMacAccessListRowStatus | 1.3.6.1.4.1.45.5.45.1.3.3.4 | RowStatus | read-write | MAC Access List row status |
| bsIpv6FHSMacAccessListTable | 1.3.6.1.4.1.45.5.45.1.3 | | not-accessible | Table contains the list of
MAC Access List used for Frist
Hop Security Feature. |
| I32 bsIpv6FHSMaxDynSbtEntries | 1.3.6.1.4.1.45.5.45.1.1.5 | Integer32 | read-write | Maximum Dynamic SBT entries allowed |
| T/F bsIpv6FHSNdInspectAdmin | 1.3.6.1.4.1.45.5.45.1.1.4 | TruthValue | read-write | ND Inspection Global Admin status |
| NUM bsIpv6FHSNDInterfaceIndex | 1.3.6.1.4.1.45.5.45.1.8.3 | InterfaceIndex | accessible-for-notify | This value indicates the unit and port number of a dropped ND inspection packet. |
| ADR bsIpv6FHSNDIpv6Address | 1.3.6.1.4.1.45.5.45.1.8.4 | Ipv6Address | accessible-for-notify | This value indicates the Ipv6 source address of a dropped ND inspection packet. |
| I32 bsIpv6FHSNDVlanID | 1.3.6.1.4.1.45.5.45.1.8.5 | Integer32 | accessible-for-notify | This value indicates the Vlan ID of a dropped ND inspection packet. |
| T/F bsIpv6FHSPolicyPortMapClearDhcpGuardStats | 1.3.6.1.4.1.45.5.45.1.4.1.12 | TruthValue | read-write | First Hop security clear stats:
bsIpv6FHSPolicyPortMapTotDhcpv6PktRcv and
bsIpv6FHSPolicyPortMapTotDhcpv6PktDropped |
| T/F bsIpv6FHSPolicyPortMapClearNDInspectStats | 1.3.6.1.4.1.45.5.45.1.4.1.14 | TruthValue | read-write | First Hop security clear stats:
bsIpv6FHSPolicyPortMapTotNdPktRcv,
bsIpv6FHSPolicyPortMapTotNdPktDropped and
bsIpv6FHSPolicyPortMapTotSbtEntDropped |
| T/F bsIpv6FHSPolicyPortMapClearRaGuardStats | 1.3.6.1.4.1.45.5.45.1.4.1.13 | TruthValue | read-write | First Hop security clear stats:
bsIpv6FHSPolicyPortMapTotRaPktRcv and
bsIpv6FHSPolicyPortMapTotRaPktDropped |
| FHS bsIpv6FHSPolicyPortMapDhcpv6gPolicyName | 1.3.6.1.4.1.45.5.45.1.4.1.2 | FhsListName | read-write | DHCPv6 guard policy name |
| bsIpv6FHSPolicyPortMapEntry | 1.3.6.1.4.1.45.5.45.1.4.1 | | not-accessible | Entry contains the list of
First Hop security Policies
attached to the interface. |
| NUM bsIpv6FHSPolicyPortMapIfIndex | 1.3.6.1.4.1.45.5.45.1.4.1.1 | InterfaceIndex | not-accessible | Interface index number |
| T/F bsIpv6FHSPolicyPortMapNDAdmin | 1.3.6.1.4.1.45.5.45.1.4.1.4 | TruthValue | read-write | Enable/Disable ND-inspection |
| FHS bsIpv6FHSPolicyPortMapRagPolicyName | 1.3.6.1.4.1.45.5.45.1.4.1.3 | FhsListName | read-write | RA guard policy name |
| ROW bsIpv6FHSPolicyPortMapRowStatus | 1.3.6.1.4.1.45.5.45.1.4.1.15 | RowStatus | read-write | First Hop security row status |
| T/F bsIpv6FHSPolicyPortMapSbtDynLearnAdmin | 1.3.6.1.4.1.45.5.45.1.4.1.5 | TruthValue | read-write | Enable/Disable learning dynamic SBT entry |
| bsIpv6FHSPolicyPortMapTable | 1.3.6.1.4.1.45.5.45.1.4 | | not-accessible | Table contains the list of
First Hop security Policies
attached to the interface. |
| C32 bsIpv6FHSPolicyPortMapTotDhcpv6PktDropped | 1.3.6.1.4.1.45.5.45.1.4.1.7 | Counter32 | read-only | Total Number of Dhcpv6
packets dropped |
| C32 bsIpv6FHSPolicyPortMapTotDhcpv6PktRcv | 1.3.6.1.4.1.45.5.45.1.4.1.6 | Counter32 | read-only | Total Number of Dhcpv6
packets Received |
| C32 bsIpv6FHSPolicyPortMapTotNdPktDropped | 1.3.6.1.4.1.45.5.45.1.4.1.11 | Counter32 | read-only | Total Number of ND Packets Dropped |
| C32 bsIpv6FHSPolicyPortMapTotNdPktRcv | 1.3.6.1.4.1.45.5.45.1.4.1.10 | Counter32 | read-only | Total Number of ND Packets Received |
| C32 bsIpv6FHSPolicyPortMapTotRaPktDropped | 1.3.6.1.4.1.45.5.45.1.4.1.9 | Counter32 | read-only | Total Number of RA
packets dropped |
| C32 bsIpv6FHSPolicyPortMapTotRaPktRcv | 1.3.6.1.4.1.45.5.45.1.4.1.8 | Counter32 | read-only | Total Number of RA
packets Received |
| T/F bsIpv6FHSRagAdmin | 1.3.6.1.4.1.45.5.45.1.1.2 | TruthValue | read-write | RA guard Global Admin status |
| FHS bsIpv6FHSRagDeviceRole | 1.3.6.1.4.1.45.5.45.1.6.1.2 | FhsRaGuardDeviceRole | read-write | This is the device role to
be checked against |
| I32 bsIpv6FHSRagHopLimitMax | 1.3.6.1.4.1.45.5.45.1.6.1.9 | Integer32 | read-write | This is the maximum value check for
the hop limit value present in the
RA packet. If the value is greater
than configured maximum value then drop
the RA packet |
| I32 bsIpv6FHSRagHopLimitMin | 1.3.6.1.4.1.45.5.45.1.6.1.8 | Integer32 | read-write | This is the minimum value check for
the hop limit value present in the
RA packet. If the value is less
than configured minimum value then drop
the RA packet |
| FHS bsIpv6FHSRagIpv6AccessListName | 1.3.6.1.4.1.45.5.45.1.6.1.3 | FhsListName | read-write | This is the IPv6 access list which
will be validating the source
IPv6 address of the RA packet |
| FHS bsIpv6FHSRagIpv6PrefixListName | 1.3.6.1.4.1.45.5.45.1.6.1.4 | FhsListName | read-write | This is the IPv6 access list which
will be validating the Prefix
present in the RA packet |
| FHS bsIpv6FHSRagMacListName | 1.3.6.1.4.1.45.5.45.1.6.1.5 | FhsListName | read-write | This is the MAC access list which
will be validating the source
MAC of the received RA packet |
| FHS bsIpv6FHSRagManagedConfigFlag | 1.3.6.1.4.1.45.5.45.1.6.1.6 | FhsRaManagedConfigFlag | read-write | In the RA packets, there is an M flag
(Managed Address configuration Flag)
which is set indicating that the address
assignments are available via DHCPv6.
This means that DHCPv6 would take care
of the interface address assignment
in that LAN segment. If filtering policy
is enabled then all the RA packets with
M flag not set will be dropped.
By default this check will be ignored |
| bsIpv6FHSRagPolicyListEntry | 1.3.6.1.4.1.45.5.45.1.6.1 | | not-accessible | Entry contains the list of
RA guard Policies used for
Hop Security Feature. |
| ROW bsIpv6FHSRagPolicyListRowStatus | 1.3.6.1.4.1.45.5.45.1.6.1.10 | RowStatus | read-write | RA guard policy row status |
| bsIpv6FHSRagPolicyListTable | 1.3.6.1.4.1.45.5.45.1.6 | | not-accessible | Table contains the list of
RA guard Policies used for
Hop Security Feature. |
| FHS bsIpv6FHSRagPolicyName | 1.3.6.1.4.1.45.5.45.1.6.1.1 | FhsListName | not-accessible | RA guard policy Name |
| FHS bsIpv6FHSRagRouterPrefMax | 1.3.6.1.4.1.45.5.45.1.6.1.7 | FhsRaRouterPrefMax | read-write | In the RA packet there is router
preference information is available
in the Flags. This could be HIGH
or LOW or MEDIUM. This filtering
policy option would verify that
the advertised default router
preference parameter value is lower
than or equal to a specified limit |
| I32 bsIpv6FHSSbtDownLifeTime | 1.3.6.1.4.1.45.5.45.1.1.8 | Integer32 | read-write | SBT Down state life time in seconds starts from 30 till 86400. Configure timer as 0 will not expire this timer |
| NUM bsIpv6FHSSbtInterfaceIndex | 1.3.6.1.4.1.45.5.45.1.7.1.1 | InterfaceIndex | not-accessible | Derive unit and port number from this ifindex |
| I32 bsIpv6FHSSbtLearnAge | 1.3.6.1.4.1.45.5.45.1.7.1.8 | Integer32 | read-only | Time Elapsed after being in this state |
| I32 bsIpv6FHSSbtLearnPriority | 1.3.6.1.4.1.45.5.45.1.7.1.6 | Integer32 | read-only | SBT Entry priority |
| FHS bsIpv6FHSSbtLearnState | 1.3.6.1.4.1.45.5.45.1.7.1.7 | FhsSbtState | read-only | SBT Entry state |
| FHS bsIpv6FHSSbtLearnType | 1.3.6.1.4.1.45.5.45.1.7.1.5 | FhsSbtType | read-only | SBT Entry Type |
| MAC bsIpv6FHSSbtLinkLayerAddress | 1.3.6.1.4.1.45.5.45.1.7.1.4 | MacAddress | read-write | Link Layer MAC address |
| bsIpv6FHSSbtListEntry | 1.3.6.1.4.1.45.5.45.1.7.1 | | not-accessible | Entry contains the list of
SBT entries. |
| I32 bsIpv6FHSSbtReachLifeTime | 1.3.6.1.4.1.45.5.45.1.1.6 | Integer32 | read-write | SBT Reachable state life time in seconds starts from 30 till 86400. Configure timer as 0 will not expire this timer |
| ROW bsIpv6FHSSbtRowStatus | 1.3.6.1.4.1.45.5.45.1.7.1.9 | RowStatus | read-write | SBT entry row status |
| ADR bsIpv6FHSSbtSrcIp | 1.3.6.1.4.1.45.5.45.1.7.1.3 | Ipv6Address | not-accessible | Source IPv6 Address |
| I32 bsIpv6FHSSbtStaleLifeTime | 1.3.6.1.4.1.45.5.45.1.1.7 | Integer32 | read-write | SBT Stale state life time in seconds starts from 30 till 86400. Configure timer as 0 will not expire this timer |
| bsIpv6FHSSbtTable | 1.3.6.1.4.1.45.5.45.1.7 | | not-accessible | Table contains the list of
SBT entries learnt
Dynamically and statically
configure. |
| C32 bsIpv6FHSSbtTblOverFlowEx | 1.3.6.1.4.1.45.5.45.1.1.9 | Counter32 | read-only | SBT Table Overflow due to the maximum SBT entry restriction |
| I32 bsIpv6FHSSbtVlan | 1.3.6.1.4.1.45.5.45.1.7.1.2 | Integer32 | not-accessible | VLAN |
| bsIpv6FHSScalVar | 1.3.6.1.4.1.45.5.45.1.1 | | | |
| bsIpv6FHSSourceGuardBindingEntry | 1.3.6.1.4.1.45.5.45.1.10.1 | | not-accessible | An entry of this table. |
| bsIpv6FHSSourceGuardBindingTable | 1.3.6.1.4.1.45.5.45.1.10 | | not-accessible | List of IPv6 Source Guard binding entries for each
Source Guard enabled interface. |
| T/F bsIpv6FHSSourceGuardClearOverflowCount | 1.3.6.1.4.1.45.5.45.1.9.1.5 | TruthValue | read-write | This object clears counter object bsIpv6FHSSourceGuardOverflowCount. |
| NUM bsIpv6FHSSourceGuardEntryIfIndex | 1.3.6.1.4.1.45.5.45.1.10.1.1 | InterfaceIndex | not-accessible | Interface index number. |
| ADR bsIpv6FHSSourceGuardEntryIpv6Addr | 1.3.6.1.4.1.45.5.45.1.10.1.2 | Ipv6Address | read-only | IPv6 address allowed on the interface. |
| NUM bsIpv6FHSSourceGuardIfIndex | 1.3.6.1.4.1.45.5.45.1.9.1.1 | InterfaceIndex | not-accessible | Interface index number. |
| bsIpv6FHSSourceGuardInterfaceConfigEntry | 1.3.6.1.4.1.45.5.45.1.9.1 | | not-accessible | An entry of this table. |
| bsIpv6FHSSourceGuardInterfaceConfigTable | 1.3.6.1.4.1.45.5.45.1.9 | | not-accessible | IPv6 Source Guard Interface table. |
| T/F bsIpv6FHSSourceGuardInterfaceState | 1.3.6.1.4.1.45.5.45.1.9.1.2 | TruthValue | read-write | IPv6 Source Guard Admin state of an interface. |
| I32 bsIpv6FHSSourceGuardMaxAddr | 1.3.6.1.4.1.45.5.45.1.9.1.3 | Integer32 | read-write | Maximum allowed IPv6 Source Addresses on an interface. |
| C32 bsIpv6FHSSourceGuardOverflowCount | 1.3.6.1.4.1.45.5.45.1.9.1.4 | Counter32 | read-only | Number of times the SBT entries could not be added
to the allowed list. |
| bsIpv6FirstHopSecNotifications | 1.3.6.1.4.1.45.5.45.0 | | | |
| bsIpv6FirstHopSecObjects | 1.3.6.1.4.1.45.5.45.1 | | | |
| MAC bsIpv6NDInspectionNotificationClientMACAddr | 1.3.6.1.4.1.45.5.45.1.8.1 | MacAddress | accessible-for-notify | This value indicates the source MAC Address of a dropped ND inspection packet. |
| INT bsIpv6NDInspectionNotificationMsgType | 1.3.6.1.4.1.45.5.45.1.8.2 | INTEGER | accessible-for-notify | This value indicates the message type of a dropped ND packet. |
| NTF bsIpv6NDNotificationsUntrustedPort | 1.3.6.1.4.1.45.5.45.0.2 | | | This notification is generated when an ND message is suspected
to be generated by the untrusted system/host. |
| NTF bsIpv6NDSBTTableFull | 1.3.6.1.4.1.45.5.45.0.1 | | | This notification is generated when an attempt is made to add a new
SBT entry when the Secure Binding Table is full. The value of
bsIpv6NDInspectionNotificationClientMACAddr represents the MAC address that
could not be added to the SBT table. This notification also
indicates that additional packets will not be added to
the SBT and will be dropped. |
| bsIpv6NDTrapNotificationObjects | 1.3.6.1.4.1.45.5.45.1.8 | | | |