All MIBs › CIENA-CES-TACACS-CLIENT-MIB › cienaCesTacacsClientGlobalAuthorizationAccessRejects
cienaCesTacacsClientGlobalAuthorizationAccessRejects
Module: CIENA-CES-TACACS-CLIENT-MIB
OID (symbolic): CIENA-CES-TACACS-CLIENT-MIB::cienaCesTacacsClientGlobalAuthorizationAccessRejects
OID (numeric): 1.3.6.1.4.1.1271.2.3.2.1.1.3.1.1.13
Node type: OBJECT-TYPE
Type: Counter32
Access: read-only
Description: The number of TACACS Access-Reject packets (valid or invalid) received from this server.
What is cienaCesTacacsClientGlobalAuthorizationAccessRejects?
This counter records outright denials of authorization requests, meaning the TACACS+ server is up and responding but is refusing to let the switch execute the specific command a logged-in user just attempted. Unlike an authentication reject, which blocks a login entirely, an authorization reject lets the admin see other command output but throws a command-authorization-failed error on that one specific command, so a spike here usually maps to privilege-level or command-set restrictions rather than a bad password. For example, this would increment every time a level-7 operator tries to run a level-15 'reload' command that TACACS+ policy blocks.
Examples
Walk all instances (SNMPv2c):
snmpwalk -v2c -c public <target> 1.3.6.1.4.1.1271.2.3.2.1.1.3.1.1.13 snmpwalk -v2c -c public <target> CIENA-CES-TACACS-CLIENT-MIB::cienaCesTacacsClientGlobalAuthorizationAccessRejects
Get a specific instance (index 1):
snmpget -v2c -c public <target> 1.3.6.1.4.1.1271.2.3.2.1.1.3.1.1.13.1 snmpget -v2c -c public <target> CIENA-CES-TACACS-CLIENT-MIB::cienaCesTacacsClientGlobalAuthorizationAccessRejects.1
Start monitoring Ciena CES (Carrier Ethernet Switch) platforms with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the CIENA-CES-TACACS-CLIENT-MIB::cienaCesTacacsClientGlobalAuthorizationAccessRejects OID value, configure state conditions and alerts, and monitor any Ciena CES (Carrier Ethernet Switch) platforms from a single console.
OID Breakdown
Upper-level ancestors (9 from the standard OID tree / other modules)
| Numeric OID | Name | Module |
|---|---|---|
| 1 | iso | LANART-AGENT |
| 1.3 | org | AirPair-MIB |
| 1.3.6 | dod | AirPair-MIB |
| 1.3.6.1 | internet | AirPair-MIB |
| 1.3.6.1.4 | private | AirPair-MIB |
| 1.3.6.1.4.1 | enterprises | AirPair-MIB |
| 1.3.6.1.4.1.1271 | ciena | CIENA-SMI |
| 1.3.6.1.4.1.1271.2 | cienaCes | CIENA-SMI |
| 1.3.6.1.4.1.1271.2.3 | cienaCesStatistics | CIENA-SMI |
| Numeric OID | Name | Module |
|---|---|---|
| 1.3.6.1.4.1.1271.2.3.2 | cienaCesTacacsClientMIB | CIENA-CES-TACACS-CLIENT-MIB |
| 1.3.6.1.4.1.1271.2.3.2.1 | cienaCesTacacsClientMIBObjects | CIENA-CES-TACACS-CLIENT-MIB |
| 1.3.6.1.4.1.1271.2.3.2.1.1 | cienaCesTacacsClient | CIENA-CES-TACACS-CLIENT-MIB |
| 1.3.6.1.4.1.1271.2.3.2.1.1.3 | cienaCesTacacsClientGlobalStatistics | CIENA-CES-TACACS-CLIENT-MIB |
| 1.3.6.1.4.1.1271.2.3.2.1.1.3.1 | cienaCesTacacsClientGlobalStatisticsTable | CIENA-CES-TACACS-CLIENT-MIB |
| 1.3.6.1.4.1.1271.2.3.2.1.1.3.1.1 | cienaCesTacacsClientGlobalStatisticsEntry | CIENA-CES-TACACS-CLIENT-MIB |
| 1.3.6.1.4.1.1271.2.3.2.1.1.3.1.1.13 | cienaCesTacacsClientGlobalAuthorizationAccessRejects | CIENA-CES-TACACS-CLIENT-MIB |