| OID symbolic | OID numeric | Type | Access | Description |
| NTF ciscoLwappWapiAddressRedirectAttackTrap | 1.3.6.1.4.1.9.9.9997.4.5 | | | This notification will be sent when AP received an address redirect attack trap.
Radio interface information (MAC), BSSID, SSID, Mac of station |
| ciscoLwappWapiCertificateObjects | 1.3.6.1.4.1.9.9.9997.3 | | | |
| ciscoLwappWapiConfig | 1.3.6.1.4.1.9.9.9997.2 | | | |
| ciscoLwappWapiMIB | 1.3.6.1.4.1.9.9.9997 | | | cisco WiFi Controller Snmp agent support for Wapi.
WAPI is a Chinese National Standard for Wireless LAN (GB 15629.11-2003)
GLOSSARY:
WAPI - WLAN Authentication and Privacy Infrastructures
WAI - WLAN Authentication Interface
WLAN - Wireless Local Area Network
WPI - Wireless Privacy Interface
MSK - multicast session key
AKM - authentication and key management
BKID - Base Key IDentification |
| ciscoLwappWapiMIBNotifObjects | 1.3.6.1.4.1.9.9.9997.4 | | | |
| ciscoLwappWapiMIBObjects | 1.3.6.1.4.1.9.9.9997.1 | | | |
| NTF ciscoLwappWapiReplayAttackTrap | 1.3.6.1.4.1.9.9.9997.4.3 | | | This notification will be sent when AP received an AE challenge is different with that of AP received before. |
| NTF ciscoLwappWapiSecurityLowAttackTrap | 1.3.6.1.4.1.9.9.9997.4.2 | | | This notification will be sent when AP received a fake Unicast Key
Negotiation Response frame of which the WIE_AUSE is different with that
of AP sent before. |
| NTF ciscoLwappWapiTamperAttackTrap | 1.3.6.1.4.1.9.9.9997.4.4 | | | This notification will be sent when AP received an invaild Message Authentication Code. |
| NTF ciscoLwappWapiUserInvalidCertificateNetworkTrap | 1.3.6.1.4.1.9.9.9997.4.1 | | | This notification will be sent when the WAPI
Client is installed with invalid certificates. |
| STR cLApWAPIReplayAttack | 1.3.6.1.4.1.9.9.9997.2.19 | DisplayString | read-only | This object represents the WAPI replay attack notification information. |
| STR cLApWAPISecurityLowAttack | 1.3.6.1.4.1.9.9.9997.2.14 | DisplayString | read-only | This object represents the WAPI security low attack notification
information. |
| STR cLApWAPITamperAttack | 1.3.6.1.4.1.9.9.9997.2.20 | DisplayString | read-only | This object represents the WAPI tamper attack notification information. |
| STR clWapiAddressRedirectAttack | 1.3.6.1.4.1.9.9.9997.2.21 | DisplayString | read-only | This object represents the WAPI redirect attack notification information. |
| cLWapiAPEntry | 1.3.6.1.4.1.9.9.9997.1.4.1 | | not-accessible | An entry in the cLWapiAPTable Table. |
| cLWapiAPTable | 1.3.6.1.4.1.9.9.9997.1.4 | | not-accessible | This table maintains the WAPI details and
configurations for each AP connected. |
| T/F clWapiASCertificateStatus | 1.3.6.1.4.1.9.9.9997.3.3 | TruthValue | read-only | This object represents the installation
state of Auth Server Certificate. True means the AS certificate
is installed. False means it is uninstalled. |
| IP clWapiASIpAddress | 1.3.6.1.4.1.9.9.9997.2.1 | IpAddress | read-write | This object represents the IP address of the WAPI authentication server. |
| I32 clWapiASPortNumber | 1.3.6.1.4.1.9.9.9997.2.2 | Integer32 | read-write | This object represents the UDP port number for WAPI authentication server. |
| I32 clWapiASRequestTimeout | 1.3.6.1.4.1.9.9.9997.2.3 | Integer32 | read-write | This object represents timeout value for the packets sent to Auth Server. |
| T/F clWapiCACertificateStatus | 1.3.6.1.4.1.9.9.9997.3.2 | TruthValue | read-only | This object represents the installation
state of Certificate Authority Certificate. True means the CA certificate
is installed. False means it is uninstalled |
| cLWapiCiphers | 1.3.6.1.4.1.9.9.9997.1.6 | | not-accessible | This table maintains the unicast cipher suites supported by this entity.
It allows enabling and disabling of each unicast cipher suite by network management.
The unicast cipher suite list in the WAPI Parameter Set information
element is formed using the information in this table. |
| cLWapiCiphersEntry | 1.3.6.1.4.1.9.9.9997.1.6.1 | | not-accessible | An entry in the cLWapiCiphers Table. |
| cLWapiClientStats | 1.3.6.1.4.1.9.9.9997.1.2 | | not-accessible | This table maintains the WAPI statistics for each client connected to a WLAN on which WAPI is configured as the security protocol. |
| cLWapiClientStatsEntry | 1.3.6.1.4.1.9.9.9997.1.2.1 | | not-accessible | An entry in the cLWapiClientStats Table |
| U32 clWapiConfigCertificateUpdateCount | 1.3.6.1.4.1.9.9.9997.2.8 | Unsigned32 | read-write | This object represents the number of times messages in the WAPI hhandshake protocol will be retried per certificate handshake attempt. |
| INT clWapiConfigControlledPortControl | 1.3.6.1.4.1.9.9.9997.2.12 | INTEGER | read-only | This object indicates the value of the Controlled
port. If the value is 0 which means automatic, the
current behaviour. The state of the controlled port
shall be based on the result of authentication. |
| U32 clWapiConfigMulticastUpdateCount | 1.3.6.1.4.1.9.9.9997.2.9 | Unsigned32 | read-write | This object represents the number of times message 1 in the WAPI muticast key announcement handshake will be retried per MSK handshake attempt. |
| U32 clWapiConfigSATimeout | 1.3.6.1.4.1.9.9.9997.2.18 | Unsigned32 | read-write | This object represents the maximum time a security association shall take to set up. |
| U32 clWapiConfigUnicastUpdateCount | 1.3.6.1.4.1.9.9.9997.2.10 | Unsigned32 | read-write | This object represents the number of times message 1 and message 3 in the WAPI unicast key announcement handshake will be retried per USK handshake attempt. |
| U32 clWapiMulticastRekeyMessages | 1.3.6.1.4.1.9.9.9997.2.6 | Unsigned32 | read-write | This object represents the message count in thousands after which the WAPI MSK will be refreshed. The message counter will start the moment the MSK was set using the MLME-SETWPIKEYS request primitive. |
| INT clWapiMulticastRekeyMethod | 1.3.6.1.4.1.9.9.9997.2.4 | INTEGER | read-write | This object selects a mechanism for rekeying the WAPI MSK. The default is time-based, once per day. Rekeying the MSK is only applicable to an entry acting in the AE role. |
| T/F clWapiMulticastRekeyStrict | 1.3.6.1.4.1.9.9.9997.2.7 | TruthValue | read-write | This object signals that the MSK shall be refreshed whenever a STA leaves the BSS that possesses the MSK. |
| U32 clWapiMulticastRekeyTime | 1.3.6.1.4.1.9.9.9997.2.5 | Unsigned32 | read-write | This object represents the time in seconds after which the WAPI MSK will be refreshed. The timer will start the moment the MSK was set using the MLME-SETWPIKEYS request primitive. |
| U32 clWapiUnicastRekeyMessage | 1.3.6.1.4.1.9.9.9997.2.17 | Unsigned32 | read-write | This object represents the message count in thousands
after which the WAPI USK will be refreshed.
The message counter will start the moment the USK was set
using the MLME-SETWPIKEYS request primitive. This MIB will be
configurable od of TIME or TIME&PACKET |
| INT clWapiUnicastRekeyMethod | 1.3.6.1.4.1.9.9.9997.2.15 | INTEGER | read-write | This object selects a mechanism for rekeying the WAPI USK.
The default is time-based, once per day. Rekeying the USK
is only applicable to an entry acting in the AE role.
Method 1 (disabled) will temporarily stop the unicast rekeying |
| U32 clWapiUnicastRekeyTime | 1.3.6.1.4.1.9.9.9997.2.16 | Unsigned32 | read-write | This object represents the time in seconds after which the
WAPI USK will be refreshed. The timer will start the
moment the USK was set using the MLME-SETWPIKEYS
request primitive. |
| STR clWapiUserInvalidCertificationInbreakNetwork | 1.3.6.1.4.1.9.9.9997.2.13 | DisplayString | read-only | This object represents the WAPI user with
invalid certification. |
| cLWapiWlanAKMSuitesConfigEntry | 1.3.6.1.4.1.9.9.9997.1.5.1 | | not-accessible | An entry in the cLWapiWlanAKMSuitesConfig Table |
| cLWapiWlanAKMSuitesConfigTable | 1.3.6.1.4.1.9.9.9997.1.5 | | not-accessible | This table maintains the WAPI config entry for the WLAN. |
| cLWapiWlanConfig | 1.3.6.1.4.1.9.9.9997.1.3 | | not-accessible | This table maintains the WAPI config entry for the WLAN. |
| cLWapiWlanConfigEntrty | 1.3.6.1.4.1.9.9.9997.1.3.1 | | not-accessible | An entry in the cLWapiWlanConfig Table |
| cLWapiWlanStats | 1.3.6.1.4.1.9.9.9997.1.1 | | not-accessible | This table maintains the WAPI statistics for each WLAN on which WAPI is configured as the security protocol. |
| cLWapiWlanStatsEntry | 1.3.6.1.4.1.9.9.9997.1.1.1 | | not-accessible | An entry in the cLWWSW Table |
| T/F clWapiWLCCertificateStatus | 1.3.6.1.4.1.9.9.9997.3.1 | TruthValue | read-only | This object represents the installation
state of WLC Certificate. True means the WLC certificate
is installed. False means it is uninstalled. |
| OCT cLWCSWAIAuthenticationSuiteRequested | 1.3.6.1.4.1.9.9.9997.1.2.1.13 | OCTET STRING | read-only | This object specificies the last AKM suite requested from client.
0x 00 14 72 01 : cert
0x 00 14 72 02 : psk |
| C32 cLWCSWAIAuthResultFailures | 1.3.6.1.4.1.9.9.9997.1.2.1.4 | Counter32 | read-only | This counter shall increment when the WAI authentication is unsuccessful |
| OCT cLWCSWAIBKIDUsed | 1.3.6.1.4.1.9.9.9997.1.2.1.14 | OCTET STRING | read-only | This value represents the selector of the last BKID used in the last Unicast Key Negotiation Handshake |
| C32 cLWCSWAICertHandshakeFailures | 1.3.6.1.4.1.9.9.9997.1.2.1.8 | Counter32 | read-only | This counter shall increment when the WAI Certificate Authentication is unsuccessful |
| T/F cLWCSWAICtrPortState | 1.3.6.1.4.1.9.9.9997.1.2.1.15 | TruthValue | read-only | This value represents the state of client controlled port entity,
true means authenticated, false means not authenticated |
| C32 cLWCSWAIDiscardCounters | 1.3.6.1.4.1.9.9.9997.1.2.1.5 | Counter32 | read-only | This counter shall increment when the received WAI message is discarded |
| C32 cLWCSWAIFormatErrors | 1.3.6.1.4.1.9.9.9997.1.2.1.7 | Counter32 | read-only | This counter shall increment when there exists format error in the WAI message |
| C32 cLWCSWAIHMACErrors | 1.3.6.1.4.1.9.9.9997.1.2.1.3 | Counter32 | read-only | This counter shall increment when the message authentication code in the received WAI message is incorrect |
| OCT cLWCSWAIMcastCipherSuite | 1.3.6.1.4.1.9.9.9997.1.2.1.12 | OCTET STRING | read-only | This value represents the Client Multicast Cipher Suite in use, of which obtained from Assoc req frame |
| C32 cLWCSWAIMulticastHandshakeFailures | 1.3.6.1.4.1.9.9.9997.1.2.1.10 | Counter32 | read-only | This counter shall increment when the WAI Multicast Key Negotiation is unsuccessful |
| C32 cLWCSWAISignatureErrors | 1.3.6.1.4.1.9.9.9997.1.2.1.2 | Counter32 | read-only | This counter shall increment when the signature in the received WAI message is incorrect |
| C32 cLWCSWAITimeoutCounters | 1.3.6.1.4.1.9.9.9997.1.2.1.6 | Counter32 | read-only | This counter shall increment when the WAI message is timeout |
| OCT cLWCSWAIUnicastCipherSuite | 1.3.6.1.4.1.9.9.9997.1.2.1.11 | OCTET STRING | read-only | This value represents the Client Unicast Cipher Suite in use, of which obtained from Assoc req frame |
| C32 cLWCSWAIUnicastHandshakeFailures | 1.3.6.1.4.1.9.9.9997.1.2.1.9 | Counter32 | read-only | This counter shall increment when the WAI Unicast Key Negotiation is unsuccessful |
| I32 cLWCSWapiAPMaxUnicastKeysSupport | 1.3.6.1.4.1.9.9.9997.1.4.1.1 | Integer32 | read-only | This object represents the maximum number of USK's that an AP can support. |
| I32 cLWCSWapiClientVersion | 1.3.6.1.4.1.9.9.9997.1.2.1.1 | Integer32 | read-only | This object represents the WAPI draft version used by the WAPI client |
| I32 cLWCSWapiConfigureVersion | 1.3.6.1.4.1.9.9.9997.2.11 | Integer32 | read-only | This object represents the WAPI configuration version |
| U32 cLWCSWlanBKLifeTime | 1.3.6.1.4.1.9.9.9997.1.3.1.9 | Unsigned32 | read-write | This object is used to configure the maximum lifetime of a BK in the BK cache. |
| U32 cLWCSWlanBKReauthThreshold | 1.3.6.1.4.1.9.9.9997.1.3.1.10 | Unsigned32 | read-write | This object is used to configure the percentage of the BK lifetime that should expire before a WAI reauthentication occurs. |
| T/F cLWCSWlanCipherEnabled | 1.3.6.1.4.1.9.9.9997.1.6.1.2 | TruthValue | read-write | This object represents enables or disables the unicast cipher. |
| U32 cLWCSWlanCipherIndex | 1.3.6.1.4.1.9.9.9997.1.6.1.1 | Unsigned32 | not-accessible | This object represents auxiliary index of the CiscoWapiCiphersEntry. |
| INT cLWCSWlanWapiAkmKeyMgmtMode | 1.3.6.1.4.1.9.9.9997.1.3.1.2 | INTEGER | read-write | This object is used to enable the AKM type to be used for the WAPI WLAN. |
| OCT cLWCSWlanWapiAuthenticationSuite | 1.3.6.1.4.1.9.9.9997.1.5.1.2 | OCTET STRING | read-only | This object is used to indicate the AKM suite octects on the WLAN. |
| T/F cLWCSWlanWapiAuthenticationSuiteEnable | 1.3.6.1.4.1.9.9.9997.1.5.1.3 | TruthValue | read-write | This object is used to enable the AKM suites on the WLAN. |
| INT cLWCSWlanWapiAuthenticationSuiteIndex | 1.3.6.1.4.1.9.9.9997.1.5.1.1 | INTEGER | not-accessible | This object is used to a index for AKM suites on the WLAN. |
| OCT cLWCSWlanWapiAuthenticationSuiteSelected | 1.3.6.1.4.1.9.9.9997.1.3.1.12 | OCTET STRING | read-only | This object represents the selector of the last AKM suite negotiated. |
| OCT cLWCSWlanWapiConfigMulticastCipher | 1.3.6.1.4.1.9.9.9997.1.3.1.11 | OCTET STRING | read-write | This object indicates the multicast cipher suite that this entity must adopt. The WAPI Parameter
Set information element shall adopt the value of this variable, which contains a 3-octet OUI and
a one-octet cipher suite identifier. |
| OCT cLWCSWlanWapiConfigUnicasCiphersEntry | 1.3.6.1.4.1.9.9.9997.1.3.1.6 | OCTET STRING | read-only | The selector of a supported unicast cipher suite. It consists of an OUI (the first 3 octets)
and a cipher suite identifier (the last octet). |
| U32 cLWCSWlanWapiConfigUnicastCipherSize | 1.3.6.1.4.1.9.9.9997.1.3.1.7 | Unsigned32 | read-only | This object indicates the length in bit of the USK. This should be 256 for SMS4.
The first 128bits is the UEK and the last 128bits is the UCK. |
| T/F cLWCSWlanWapiEnable | 1.3.6.1.4.1.9.9.9997.1.3.1.1 | TruthValue | read-write | This object is used to enable the WAPI security on the WLAN. |
| BIT cLWCSWlanWapiEncryptType | 1.3.6.1.4.1.9.9.9997.1.3.1.3 | Bits | read-write | This object is used to enable the encryption type for WAPI WLAN. |
| U32 cLWCSWlanWapiMcastCipherSize | 1.3.6.1.4.1.9.9.9997.1.3.1.8 | Unsigned32 | read-only | This object indicates the length in bit of the MSK. This should be 256 for in SMS4.
The first 128bits is the MEK and the last 128bits is the MCK. |
| OCT cLWCSWlanWapiMulticastCipherSelected | 1.3.6.1.4.1.9.9.9997.1.3.1.14 | OCTET STRING | read-only | This object indicates the selector of the last multicast cipher suite negotiated. |
| T/F cLWCSWlanWapiPreauthenticationState | 1.3.6.1.4.1.9.9.9997.1.3.1.15 | TruthValue | read-only | This object represents the state of Preauthentication
in WAPI and currently it is not supported. |
| OCT cLWCSWlanWapiPsk | 1.3.6.1.4.1.9.9.9997.1.3.1.5 | OCTET STRING | read-write | This object is used to configure the Pre-Shared Key for WAI PSK authentication for the WLAN.
The key can be in ASCII or HEX format.
'ascii' 8-40 characters
'hex' 4-40 octets. |
| CLS cLWCSWlanWapiPskFmt | 1.3.6.1.4.1.9.9.9997.1.3.1.4 | CLSecKeyFormat | read-write | This object indicates the type of the authentication preshared key
configured through the object cLWCSWlanWapiPskSetkey.
Note that the key configuration is applicable only when psk is configured
as the key management mechanism through the cLWCSWlanWapiAkmKeyMgmtMode object. |
| OCT cLWCSWlanWapiUnicastCipherSelected | 1.3.6.1.4.1.9.9.9997.1.3.1.13 | OCTET STRING | read-only | This object indicates the selector of the last unicast cipher suite negotiated. |
| C32 cLWWSWAIAuthResultFailures | 1.3.6.1.4.1.9.9.9997.1.1.1.3 | Counter32 | read-only | This counter shall increment when the WAI authentication is unsuccessful |
| C32 cLWWSWAICertHandshakeFailures | 1.3.6.1.4.1.9.9.9997.1.1.1.7 | Counter32 | read-only | This counter shall increment when the WAI Certificate Authentication is unsuccessful |
| C32 cLWWSWAIDiscardCounters | 1.3.6.1.4.1.9.9.9997.1.1.1.4 | Counter32 | read-only | This counter shall increment when the received WAI message is discarded |
| C32 cLWWSWAIFormatErrors | 1.3.6.1.4.1.9.9.9997.1.1.1.6 | Counter32 | read-only | This counter shall increment when there exists format error in the WAI message |
| C32 cLWWSWAIHMACErrors | 1.3.6.1.4.1.9.9.9997.1.1.1.2 | Counter32 | read-only | This counter shall increment when the message authentication code in the received WAI message is incorrect |
| C32 cLWWSWAIMulticastHandshakeFailures | 1.3.6.1.4.1.9.9.9997.1.1.1.9 | Counter32 | read-only | This counter shall increment when the WAI Multicast Key Negotiation is unsuccessful |
| C32 cLWWSWAISignatureErrorsEx | 1.3.6.1.4.1.9.9.9997.1.1.1.1 | Counter32 | read-only | This counter shall increment when the signature in the received WAI message is incorrect |
| C32 cLWWSWAITimeoutCounters | 1.3.6.1.4.1.9.9.9997.1.1.1.5 | Counter32 | read-only | This counter shall increment when the WAI message is timeout |
| C32 cLWWSWAIUnicastHandshakeFailures | 1.3.6.1.4.1.9.9.9997.1.1.1.8 | Counter32 | read-only | This counter shall increment when the WAI Unicast Key Negotiation is unsuccessful |
| C64 cLWWSWPIRXDecryptErrorCounters | 1.3.6.1.4.1.9.9.9997.1.1.1.12 | Counter64 | read-only | This counter shall increment when the WPI Decryption is error |
| C64 cLWWSWPIRXMicErrorCounters | 1.3.6.1.4.1.9.9.9997.1.1.1.11 | Counter64 | read-only | This counter shall increment when the WPI MIC is error |
| C32 cLWWSWPIRXReplayCounters | 1.3.6.1.4.1.9.9.9997.1.1.1.10 | Counter32 | read-only | This counter shall increment when the WPI RX replay check is unsuccessful |