CIENA-CES-TACACS-CLIENT-MIB :: cienaCesTacacsClientGlobalAuthorizationAccessRejects

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCIENA-CES-TACACS-CLIENT-MIBcienaCesTacacsClientGlobalAuthorizationAccessRejects

cienaCesTacacsClientGlobalAuthorizationAccessRejects

Module: CIENA-CES-TACACS-CLIENT-MIB

OID (symbolic): CIENA-CES-TACACS-CLIENT-MIB::cienaCesTacacsClientGlobalAuthorizationAccessRejects

OID (numeric): 1.3.6.1.4.1.1271.2.3.2.1.1.3.1.1.13

Node type: OBJECT-TYPE

Type: Counter32

Access: read-only

Description: The number of TACACS Access-Reject packets (valid or invalid) received from this server.

What is cienaCesTacacsClientGlobalAuthorizationAccessRejects?

This counter records outright denials of authorization requests, meaning the TACACS+ server is up and responding but is refusing to let the switch execute the specific command a logged-in user just attempted. Unlike an authentication reject, which blocks a login entirely, an authorization reject lets the admin see other command output but throws a command-authorization-failed error on that one specific command, so a spike here usually maps to privilege-level or command-set restrictions rather than a bad password. For example, this would increment every time a level-7 operator tries to run a level-15 'reload' command that TACACS+ policy blocks.

Examples

Walk all instances (SNMPv2c):

snmpwalk -v2c -c public <target> 1.3.6.1.4.1.1271.2.3.2.1.1.3.1.1.13
snmpwalk -v2c -c public <target> CIENA-CES-TACACS-CLIENT-MIB::cienaCesTacacsClientGlobalAuthorizationAccessRejects

Get a specific instance (index 1):

snmpget -v2c -c public <target> 1.3.6.1.4.1.1271.2.3.2.1.1.3.1.1.13.1
snmpget -v2c -c public <target> CIENA-CES-TACACS-CLIENT-MIB::cienaCesTacacsClientGlobalAuthorizationAccessRejects.1

Start monitoring Ciena CES (Carrier Ethernet Switch) platforms with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the CIENA-CES-TACACS-CLIENT-MIB::cienaCesTacacsClientGlobalAuthorizationAccessRejects OID value, configure state conditions and alerts, and monitor any Ciena CES (Carrier Ethernet Switch) platforms from a single console.

OID Breakdown

Upper-level ancestors (9 from the standard OID tree / other modules)
Numeric OIDNameModule
1isoLANART-AGENT
1.3orgAirPair-MIB
1.3.6dodAirPair-MIB
1.3.6.1internetAirPair-MIB
1.3.6.1.4privateAirPair-MIB
1.3.6.1.4.1enterprisesAirPair-MIB
1.3.6.1.4.1.1271cienaCIENA-SMI
1.3.6.1.4.1.1271.2cienaCesCIENA-SMI
1.3.6.1.4.1.1271.2.3cienaCesStatisticsCIENA-SMI
Numeric OIDNameModule
1.3.6.1.4.1.1271.2.3.2cienaCesTacacsClientMIBCIENA-CES-TACACS-CLIENT-MIB
1.3.6.1.4.1.1271.2.3.2.1cienaCesTacacsClientMIBObjectsCIENA-CES-TACACS-CLIENT-MIB
1.3.6.1.4.1.1271.2.3.2.1.1cienaCesTacacsClientCIENA-CES-TACACS-CLIENT-MIB
1.3.6.1.4.1.1271.2.3.2.1.1.3cienaCesTacacsClientGlobalStatisticsCIENA-CES-TACACS-CLIENT-MIB
1.3.6.1.4.1.1271.2.3.2.1.1.3.1cienaCesTacacsClientGlobalStatisticsTableCIENA-CES-TACACS-CLIENT-MIB
1.3.6.1.4.1.1271.2.3.2.1.1.3.1.1cienaCesTacacsClientGlobalStatisticsEntryCIENA-CES-TACACS-CLIENT-MIB
1.3.6.1.4.1.1271.2.3.2.1.1.3.1.1.13cienaCesTacacsClientGlobalAuthorizationAccessRejectsCIENA-CES-TACACS-CLIENT-MIB