CISCO-PAE-MIB

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-PAE-MIB

Organization: Cisco System, Inc.

Last Updated: 2009-12-10

Category: Cisco Devices, VPN and Security

Description: Extends IEEE 802.1X Port Access Entity management with Cisco-specific supplicant and authenticator objects.

Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

What Is CISCO-PAE-MIB?

CISCO-PAE-MIB is a Cisco vendor-specific MIB that extends the standard IEEE8021-PAE-MIB with Cisco-specific 802.1X Port Access Entity (PAE) objects, covering both authenticator and supplicant roles as well as MAC Authentication Bypass (MAB), web authentication, and guest/auth-fail VLAN handling — a broader scope than the hint's narrow framing, since the module also manages host tracking, EAPoL testing, and posture/NAC integration rather than just supplicant/authenticator basics. It exposes per-port state via cpaePortTable and cpaeAuthConfigTable, authenticated-host inventory via cpaeHostInfoTable and cpaeAuthFailUserTable, MAB status via cpaeMacAuthBypassPortTable, and web-auth session data via cpaeWebAuthHostTable/cpaeWebAuthPortTable. It depends on IEEE8021-PAE-MIB (dot1xPaePortEntry, dot1xAuthPaeState), IF-MIB's InterfaceIndex, CISCO-VTP-MIB's VlanIndex, and CISCO-NAC-TC-MIB for posture-token types, reflecting deep integration with Cisco's Identity-Based Networking Services. It is deployed on Cisco Catalyst and similar switches performing 802.1X/MAB/web authentication at the access edge, and network engineers researching cisco pae will find this module documents the vendor extensions layered on top of standard 802.1X port state.

IPNetwork Monitor allows you to monitor SNMP objects defined in CISCO-PAE-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • Cisco Catalyst switches and other Cisco access-layer platforms supporting IEEE 802.1X

Monitoring Examples

An operator polls cpaePortTable and cpaeHostInfoTable to confirm a connected endpoint's cpaeAuthConfigTable entry reached an authorized state; entries persisting in cpaeAuthFailUserTable or cpaeMacAuthBypassPortTable showing repeated MAB attempts would indicate an endpoint failing 802.1X and falling back to (or failing) MAC-based authentication.

What Can Be Monitored

  • per-port 802.1X authentication state
  • authenticated/failed host inventory
  • MAC Authentication Bypass (MAB) port status
  • web-authentication host/port sessions
  • guest and auth-fail VLAN assignment
  • EAPoL test results
Imported Objects

From CISCO-NAC-TC-MIB

CnnEouPostureToken
CnnEouPostureTokenString

From CISCO-POLICY-GROUP-MIB

CpgPolicyNameOrEmpty

From CISCO-SMI

ciscoMgmtOBJECT-IDENTITY

From CISCO-TC

CiscoURLString

From CISCO-VTP-MIB

VlanIndex

From IEEE8021-PAE-MIB

PaeControlledPortStatus
dot1xAuthConfigEntryOBJECT-TYPE
dot1xAuthPaeStateOBJECT-TYPE
dot1xPaePortEntryOBJECT-TYPE
dot1xPaePortNumberOBJECT-TYPE

From IF-MIB

InterfaceIndex

From INET-ADDRESS-MIB

InetAddress
InetAddressType

From SNMP-FRAMEWORK-MIB

SnmpAdminString

From SNMPv2-CONF

MODULE-COMPLIANCE
NOTIFICATION-GROUP
OBJECT-GROUP

From SNMPv2-SMI

MODULE-IDENTITY
NOTIFICATION-TYPE
OBJECT-TYPE
Unsigned32

From SNMPv2-TC

MacAddress
RowStatus
TEXTUAL-CONVENTION
TruthValue
OIDs

RFC description

Cisco vendor-private MIB for Port Access Entity (802.1X) port-based network access control.

Start monitoring Cisco Catalyst switches / access-layer platforms (802.1X) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download CISCO-PAE-MIB