CISCO-NAC-TC-MIB

MIB Reference — IPNetwork Monitor

All MIBsCISCO-NAC-TC-MIB

Organization: Cisco Systems, Inc.

Last Updated: 2006-05-31

Category: Cisco Devices, Textual Conventions and Registries, VPN and Security

Description:

Defines textual conventions for Network Admission Control (NAC) data types used in Cisco NAC MIB modules.

Imported Objects

From CISCO-SMI

ciscoMgmtOBJECT-IDENTITY

From SNMPv2-SMI

MODULE-IDENTITY

From SNMPv2-TC

TEXTUAL-CONVENTION

What Is CISCO-NAC-TC-MIB?

CISCO-NAC-TC-MIB is a Cisco-specific textual-conventions module supporting the Cisco Network Admission Control (NAC) security architecture, which performs endpoint posture validation—checking device compliance (patch level, antivirus status, etc.) before granting production network access. Rather than defining monitorable objects itself, it establishes the shared SNMP data types that other Cisco NAC MIBs use to represent posture states, compliance results, and related NAC concepts consistently across the product line. Because it carries no runtime instances, it plays no direct role in reporting hardware health like CPU, memory, or temperature—its contribution to monitoring is indirect, standardizing how NAC-aware MIBs describe endpoint compliance status, so looking up a CISCO-NAC-TC-MIB OID in isolation rarely reveals anything about actual posture state without also consulting the sibling MIB that instantiates it. It is a required dependency for the broader Cisco NAC MIB family (posture-validation and admission-control MIBs) that import its conventions. It is typically deployed in Cisco network-access-control environments involving Cisco IOS routers/switches and Cisco NAC appliances enforcing endpoint posture policy.

IPNetwork Monitor allows you to monitor SNMP objects defined in CISCO-NAC-TC-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • Cisco Identity Services Engine (ISE) on Secure Network Server (SNS) 3600-series appliances — current successor platform; standalone Cisco NAC Appliance hardware (e.g. SNS 3415/3495) reached end-of-sale/end-of-life by 2016

Monitoring Examples

This module defines only textual conventions (enumerated syntaxes) for the Cisco NAC MIB family and has no object or table instances of its own to poll. Monitoring of actual NAC posture-validation state happens through the sibling MIBs that import these conventions, not through this module directly. It would be inaccurate to describe a runtime polling scenario for CISCO-NAC-TC-MIB itself.

OIDs
OID symbolicOID numericTypeAccessDescription
ciscoNacTcMIB1.3.6.1.4.1.9.9.530This module defines the textual conventions for Cisco Network Admission Control(NAC) system. The Cisco Network Admission Control security solution offers a systems approach to customers for ensuring endpoint device compliancy and vulnerability checks prior to production access to the network. Cisco refers to these compliancy checks as posture validations. The intent of this systems approach is to prevent the spread of works, viruses, and rogue applications across the network. This systems approach requires integration with third party end point security applications, as well as endpoint security servers. Terminology used: EOU - Extensible Authentication Protocol over UDP. UCT - Un Conditional Transition. CTA - Cisco Trust Agent. EAP - Extensible Authentication Protocol. An extension to PPP. ACS/AAA - Cisco Secure Access Control Server. The primary authorization server that is the network policy decision point and is extended to support posture validation. NAD - Network Access Device that enforces network access control policies through layer 2 or layer 3 challenge-responses with a network enabled Endpoint device.

RFC description

Defines textual conventions for Cisco Network Admission Control (NAC) system supporting endpoint security posture validation and compliance checks.

Start monitoring Cisco Identity Services Engine (ISE) / NAC Appliance (legacy) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download CISCO-NAC-TC-MIB