All MIBs › CISCO-SSG-MIB
Category: Cisco Devices, RADIUS and AAA
Description: Manages the Service Selection Gateway (SSG) providing per-subscriber policy and service selection for ISP deployments.
Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.
What Is CISCO-SSG-MIB?
CISCO-SSG-MIB manages the Service Selection Gateway (SSG), a Cisco feature used by service providers to offer subscribers dynamic, per-user selection of network services such as internet access or VPN destinations. It belongs to Cisco's subscriber-management/service-provider MIB family and exposes global configuration switches controlling SSG behavior: whether the service is enabled, auto-domain selection, local forwarding, RADIUS proxy, TCP redirection, port-bundle host key, and auto-logoff timers and retry counts. Its monitoring value is around software/service status and configuration correctness: confirming cssgCfgSsgEnabled is on, checking cssgCfgAutoLogOffInterval and cssgCfgAutoLogOffIcmpRetries to ensure idle subscribers are logged off as expected, and validating cssgCfgMaxServicesPerUser against actual subscriber usage. It depends on RADIUS (via cssgCfgRadiusProxyEnabled) for subscriber authentication/accounting integration. It is deployed by ISPs and broadband providers running Cisco edge routers that terminate and manage subscriber sessions, making the CISCO-SSG-MIB MIB central to configuring and monitoring service-selection behavior on those deployments.
IPNetwork Monitor allows you to monitor SNMP objects defined in CISCO-SSG-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.
Supported Devices
- Cisco broadband/edge routers (Service Selection Gateway)
Monitoring Examples
An administrator would check cssgCfgSsgEnabled and cssgCfgAutoDomainMode to confirm the gateway is active and correctly selecting subscriber domains, then review cssgCfgAutoLogOffInterval alongside cssgCfgAutoLogOffIcmpRetries to verify idle subscribers are being logged off per policy. If cssgCfgRadiusProxyEnabled is set but subscribers are failing to authenticate, or cssgCfgMaxServicesPerUser is being hit by heavy users, these settings would point to a misconfigured or overloaded SSG deployment.
What Can Be Monitored
- SSG service enabled state
- auto-domain and local-forwarding mode
- RADIUS proxy enabled state
- auto-logoff interval and ICMP retry count
- maximum services per subscriber
This MIB depends on
Related MIBs
Imported Objects
From CISCO-SMI
| ciscoMgmt | OBJECT-IDENTITY |
From CISCO-TC
| CiscoPort |
From IF-MIB
| InterfaceIndex |
From INET-ADDRESS-MIB
| InetAddress | |
| InetAddressType |
From RFC-1212
| OBJECT-TYPE |
From RFC-1215
| TRAP-TYPE |
From RFC1155-SMI
| Counter | |
| Gauge |
From SNMPv2-TC-v1
| DateAndTime | |
| DisplayString | |
| RowStatus | |
| TimeInterval | |
| TruthValue |
OIDs
| OID symbolic | OID numeric | Type | Access | Description |
|---|---|---|---|---|
| ciscoSsgCfgGroup | 1.3.6.1.4.1.9.9.260.3.2.1 | |||
| ciscoSsgCfgGroupRev1 | 1.3.6.1.4.1.9.9.260.3.2.10 | |||
| ciscoSsgExclusionsGroup | 1.3.6.1.4.1.9.9.260.3.2.4 | |||
| ciscoSsgMIB | 1.3.6.1.4.1.9.9.260 | |||
| ciscoSsgMIBCompliance | 1.3.6.1.4.1.9.9.260.3.1.1 | |||
| ciscoSsgMIBComplianceRev1 | 1.3.6.1.4.1.9.9.260.3.1.2 | |||
| ciscoSsgMIBCompliances | 1.3.6.1.4.1.9.9.260.3.1 | |||
| ciscoSsgMIBConformance | 1.3.6.1.4.1.9.9.260.3 | |||
| ciscoSsgMIBGroups | 1.3.6.1.4.1.9.9.260.3.2 | |||
| ciscoSsgMIBNotifications | 1.3.6.1.4.1.9.9.260.0 | |||
| ciscoSsgMIBObjects | 1.3.6.1.4.1.9.9.260.1 | |||
| ciscoSsgNotificationGroup | 1.3.6.1.4.1.9.9.260.3.2.9 | |||
| ciscoSsgPortMapGroup | 1.3.6.1.4.1.9.9.260.3.2.8 | |||
| NTF ciscoSsgRadiusAAAServerDown | 1.3.6.1.4.1.9.9.260.0.2 | The notification is sent when the connectivity to AAA is lost or when AAA Server is down. | ||
| NTF ciscoSsgRadiusClientReboot | 1.3.6.1.4.1.9.9.260.0.1 | The notification is sent when the connectivity to GGSN is lost. | ||
| ciscoSsgRadiusClientsGroup | 1.3.6.1.4.1.9.9.260.3.2.7 | |||
| ciscoSsgServiceInterfaceGroup | 1.3.6.1.4.1.9.9.260.3.2.6 | |||
| ciscoSsgServicesGroup | 1.3.6.1.4.1.9.9.260.3.2.3 | |||
| ciscoSsgStatsGroup | 1.3.6.1.4.1.9.9.260.3.2.2 | |||
| ciscoSsgTalUserInfoGroup | 1.3.6.1.4.1.9.9.260.3.2.11 | |||
| ciscoSsgTcpRedirectGroup | 1.3.6.1.4.1.9.9.260.3.2.5 | |||
| T/F cssgCfgAAAServerDownNotifEnabled | 1.3.6.1.4.1.9.9.260.1.1.26 | TruthValue | read-write | An indication of whether SSG generates notification if connectivity to AAA is lost or if it goes down. |
| T/F cssgCfgAccountingEnabled | 1.3.6.1.4.1.9.9.260.1.1.13 | TruthValue | read-write | An indication of whether Acccounting is enabled in SSG. If enabled, SSG generates Accounting Records and sends to AAA Server. |
| GAU cssgCfgAccountingInterval | 1.3.6.1.4.1.9.9.260.1.1.19 | Gauge | read-write | The interval at which Accounting records are sent to AAA Server. |
| INT cssgCfgAutoDomainMode | 1.3.6.1.4.1.9.9.260.1.1.2 | INTEGER | read-write | An indication of whether Auto-Domain feature is enabled. This feature allows a user to be automatically connected to a service based on the APN or structured username. |
| T/F cssgCfgAutoDomainNatEnabled | 1.3.6.1.4.1.9.9.260.1.1.7 | TruthValue | read-write | An indication of whether NAT(Network Address Translation) is enabled for autodomain users. This feature determines whether the subscriber gets the autodomain service assigned IP Address. |
| GAU cssgCfgAutoLogOffIcmpRetries | 1.3.6.1.4.1.9.9.260.1.1.11 | Gauge | read-write | The number of ICMP ping retries SSG does to check connectivity to a host. |
| NUM cssgCfgAutoLogOffInterval | 1.3.6.1.4.1.9.9.260.1.1.10 | TimeInterval | read-write | The time-interval at which connectivity to a host is checked. If the host is not reachable, SSG logs off the host if auto-logff feature is enabled. |
| INT cssgCfgAutoLogOffMode | 1.3.6.1.4.1.9.9.260.1.1.4 | INTEGER | read-write | An indication of whether Auto Logoff feature is enabled. This feature enables SSG to initiate logoff if connectivity to a host is lost. Connectivity to a host is checked using ARP or ICMP ping mechanisms. |
| IP cssgCfgDefaultNetwork | 1.3.6.1.4.1.9.9.260.1.1.15 | InetAddress | read-write | The IP Address or subnet that users will be able to access without authentication. This is the address where the Cisco SSD/SESM resides. |
| IPt cssgCfgDefaultNetworkType | 1.3.6.1.4.1.9.9.260.1.1.14 | InetAddressType | read-write | A value that represents the type of the IP Address stored in the object cssgCfgDefaultNetwork. |
| T/F cssgCfgLocalForwardingEnabled | 1.3.6.1.4.1.9.9.260.1.1.3 | TruthValue | read-write | An indication of whether Local Forwarding is enabled. This feature enables SSG to forward packets locally between connected subscribers. |
| GAU cssgCfgMaxServicesPerUser | 1.3.6.1.4.1.9.9.260.1.1.12 | Gauge | read-write | The maximum number of services allowed per user. |
| cssgCfgObjects | 1.3.6.1.4.1.9.9.260.1.1 | |||
| T/F cssgCfgPortBundleHostKeyEnabled | 1.3.6.1.4.1.9.9.260.1.1.8 | TruthValue | read-write | An indication of whether PortBundle-Host Key feature is enabled. This feature enables SESM to identify subscribers based on the PortBundle(combination of IP Address, and a range of ports) assigned by the SSG. |
| CIS cssgCfgRadiusAccountingPort | 1.3.6.1.4.1.9.9.260.1.1.17 | CiscoPort | read-write | The port on which SSG receives accounting packets from Radius clients. |
| CIS cssgCfgRadiusAuthenPort | 1.3.6.1.4.1.9.9.260.1.1.16 | CiscoPort | read-write | The port on which SSG receives access request packets from Radius clients. |
| T/F cssgCfgRadiusClntRbtNotifEnabled | 1.3.6.1.4.1.9.9.260.1.1.25 | TruthValue | read-write | An indication of whether SSG generates notification if a Radius Client reboots. |
| T/F cssgCfgRadiusFwdAcctPktsEnabled | 1.3.6.1.4.1.9.9.260.1.1.18 | TruthValue | read-write | An indication of whether SSG forwards Accounting Packets received from Radius Clients to AAA Server. |
| T/F cssgCfgRadiusProxyEnabled | 1.3.6.1.4.1.9.9.260.1.1.5 | TruthValue | read-write | An indication of whether Radius-Proxy feature is enabled. This feature allows SSG to act as a generic Radius Proxy for non-SSD clients such as GGSN. |
| T/F cssgCfgSsgEnabled | 1.3.6.1.4.1.9.9.260.1.1.1 | TruthValue | read-write | An indication of whether SSG Service is enabled. |
| T/F cssgCfgTalEnabled | 1.3.6.1.4.1.9.9.260.1.1.27 | TruthValue | read-write | An indication of whether Transparent Auto Logon feature is enabled on SSG. |
| T/F cssgCfgTcpRedirectEnabled | 1.3.6.1.4.1.9.9.260.1.1.6 | TruthValue | read-write | An indication of whether TCP redirect is enabled. This feature redirects certain TCP packets to captive portals. |
| STR cssgCfgTcpRedirGrpForAdvCapt | 1.3.6.1.4.1.9.9.260.1.1.24 | DisplayString | read-write | The TCP Redirect Group for advertising captivation. |
| STR cssgCfgTcpRedirGrpForInitialCapt | 1.3.6.1.4.1.9.9.260.1.1.23 | DisplayString | read-write | The TCP Redirect Group for initial captivation. |
| STR cssgCfgTcpRedirGrpForSMTP | 1.3.6.1.4.1.9.9.260.1.1.22 | DisplayString | read-write | TCP Redirect Group to which SMTP traffic is redirected. |
| STR cssgCfgTCPRedirGrpForUnAuthServ | 1.3.6.1.4.1.9.9.260.1.1.21 | DisplayString | read-write | The TCP Redirect Group to which unauthorized service access users are directed. |
| STR cssgCfgTCPRedirGrpForUnAuthUsers | 1.3.6.1.4.1.9.9.260.1.1.20 | DisplayString | read-write | The TCP Redirect Group to which Unauthenticated users are directed. |
| T/F cssgCfgTransPassThroughEnabled | 1.3.6.1.4.1.9.9.260.1.1.9 | TruthValue | read-write | An indication of whether Transparent pass through feature is enabled. This feature allows an unauthenticated subscriber traffic to be routed through SSG in either direction. |
| cssgExcludedAPN | 1.3.6.1.4.1.9.9.260.1.4 | |||
| cssgExcludedAPNEntry | 1.3.6.1.4.1.9.9.260.1.4.1.1 | not-accessible | Information concerning an APN. | |
| STR cssgExcludedAPNName | 1.3.6.1.4.1.9.9.260.1.4.1.1.1 | DisplayString | not-accessible | The name of the excluded APN. |
| ROW cssgExcludedAPNRowStatus | 1.3.6.1.4.1.9.9.260.1.4.1.1.2 | RowStatus | read-write | The status of this table entry. This object can also be used to create or delete conceptual row in this table. To create a row, set this object to 'createAndGo'. There are no mandatory objects in a create request. To delete a row, set this object to 'destroy'. |
| cssgExcludedAPNTable | 1.3.6.1.4.1.9.9.260.1.4.1 | not-accessible | A list of APNs excluded from using auto-main feature of SSG. | |
| cssgExcludedDomain | 1.3.6.1.4.1.9.9.260.1.5 | |||
| cssgExcludedDomainEntry | 1.3.6.1.4.1.9.9.260.1.5.1.1 | not-accessible | Information concerning an excluded Domain. | |
| STR cssgExcludedDomainName | 1.3.6.1.4.1.9.9.260.1.5.1.1.1 | DisplayString | not-accessible | The name of the excluded Domain. |
| ROW cssgExcludedDomainRowStatus | 1.3.6.1.4.1.9.9.260.1.5.1.1.2 | RowStatus | read-write | The status of this table entry. This object can also be used to create or delete conceptual row in this table. To create a row, set this object to 'createAndGo'. There are no mandatory objects in a create request. To delete a row, set this object to 'destroy'. |
| cssgExcludedDomainTable | 1.3.6.1.4.1.9.9.260.1.5.1 | not-accessible | A list of Domain names excluded from using auto-domain feature of SSG. | |
| cssgNetworkGrpEntry | 1.3.6.1.4.1.9.9.260.1.6.2.1 | not-accessible | Detailed information concerning a network group entry. | |
| STR cssgNetworkGrpName | 1.3.6.1.4.1.9.9.260.1.6.2.1.1 | DisplayString | not-accessible | The name of the network group. A network group, which is a group of networks, is associated with a Server group for traffic redirection i.e., packets to the networks in the network group will be directed to the servers in the server group. |
| IP cssgNetworkGrpNetIpAddr | 1.3.6.1.4.1.9.9.260.1.6.2.1.3 | InetAddress | not-accessible | The IP address of a network in this network group. |
| IPt cssgNetworkGrpNetIpType | 1.3.6.1.4.1.9.9.260.1.6.2.1.2 | InetAddressType | not-accessible | A value that represents the type of the IP Address in the object cssgNetworkGrpNetIpAddr. |
| IP cssgNetworkGrpNetMask | 1.3.6.1.4.1.9.9.260.1.6.2.1.5 | InetAddress | not-accessible | Indicate the mask to be ANDed with the destination address before being compared to the value in cssgNetworkGrpNetIpAddr. |
| IPt cssgNetworkGrpNetMaskType | 1.3.6.1.4.1.9.9.260.1.6.2.1.4 | InetAddressType | not-accessible | A value that represents the type of the address stored in cssgNetworkGrpNetMask. |
| ROW cssgNetworkGrpNetRowStatus | 1.3.6.1.4.1.9.9.260.1.6.2.1.6 | RowStatus | read-write | The status of this table entry. This object can also be used to create or delete conceptual row in this table. To create a row, set this object to 'createAndGo'. There are no mandatory objects in a create request. To delete a row, set this object to 'destroy'. |
| cssgNetworkGrpTable | 1.3.6.1.4.1.9.9.260.1.6.2 | not-accessible | A list of network groups. When a network-group, a list of networks, associated with a TCP Redirect group, subscribers attempting to connect to these networks will be redirected to the TCP redirect group. | |
| cssgPortGrpEntry | 1.3.6.1.4.1.9.9.260.1.6.3.1 | not-accessible | A Port group entry. | |
| STR cssgPortGrpName | 1.3.6.1.4.1.9.9.260.1.6.3.1.1 | DisplayString | not-accessible | The name of the port group. The port group defines a list of ports traffic to whom can be redirected to a TCP Redirect group. |
| CIS cssgPortGrpPortNo | 1.3.6.1.4.1.9.9.260.1.6.3.1.2 | CiscoPort | not-accessible | A port in the port group. |
| ROW cssgPortGrpPortRowStatus | 1.3.6.1.4.1.9.9.260.1.6.3.1.3 | RowStatus | read-write | The status of this table entry. This object can also be used to create or delete conceptual row in this table. To create a row, set this object to 'createAndGo'. To delete a row, set this object to 'destroy'. |
| cssgPortGrpTable | 1.3.6.1.4.1.9.9.260.1.6.3 | not-accessible | A list of port groups. | |
| cssgPortMap | 1.3.6.1.4.1.9.9.260.1.9 | |||
| cssgPortMapEntry | 1.3.6.1.4.1.9.9.260.1.9.2.1 | not-accessible | An entry in the cssgPortMapTable. | |
| GAU cssgPortMapLength | 1.3.6.1.4.1.9.9.260.1.9.1 | Gauge | read-write | The length of the port-bundle i.e, no of ports in a bundle. |
| CIS cssgPortMapPortRangeFrom | 1.3.6.1.4.1.9.9.260.1.9.2.1.3 | CiscoPort | read-write | The lower limit of the range ports in the Port Map. |
| CIS cssgPortMapPortRangeTo | 1.3.6.1.4.1.9.9.260.1.9.2.1.4 | CiscoPort | read-write | The upper limit of the range ports in the Port Map. |
| ROW cssgPortMapRowStatus | 1.3.6.1.4.1.9.9.260.1.9.2.1.5 | RowStatus | read-write | The status of this table entry. This object can also be used to create or delete conceptual row in this table. To create a row, set this object to 'createAndGo'. cssgPortMapPortRangeFrom and cssgPortMapPortRangeTo are mandatory objects in a create request. To delete a row, set this object to 'destroy'. |
| IP cssgPortMapSourceIp | 1.3.6.1.4.1.9.9.260.1.9.2.1.2 | InetAddress | not-accessible | Specifies SSG source IP addresses to be used while NATting packets from downstream traffic i.e., traffic from Subscriber to SSG. |
| IPt cssgPortMapSourceIpType | 1.3.6.1.4.1.9.9.260.1.9.2.1.1 | InetAddressType | not-accessible | A value that represents the type of the IP address stored in cssgPortMapSourceIP object. |
| cssgPortMapTable | 1.3.6.1.4.1.9.9.260.1.9.2 | not-accessible | The list of TCP Port-maps. | |
| IP cssgRadiusClientAddr | 1.3.6.1.4.1.9.9.260.1.8.1.1.2 | InetAddress | not-accessible | The network layer address of the Radius client to which SSG acts as Radius Proxy. |
| IPt cssgRadiusClientAddrType | 1.3.6.1.4.1.9.9.260.1.8.1.1.1 | InetAddressType | not-accessible | The type of the address stored in cssgRadiusClientAddr. |
| cssgRadiusClientEntry | 1.3.6.1.4.1.9.9.260.1.8.1.1 | not-accessible | Detailed information concerning a Radius client entry. | |
| ROW cssgRadiusClientRowStatus | 1.3.6.1.4.1.9.9.260.1.8.1.1.3 | RowStatus | read-write | The status of this table entry. This object can also be used to create or delete conceptual row in this table. To create a row, set this object to 'createAndGo'. There are no mandatory objects in a create request. To delete a row, set this object to 'destroy'. |
| cssgRadiusClients | 1.3.6.1.4.1.9.9.260.1.8 | |||
| cssgRadiusClientTable | 1.3.6.1.4.1.9.9.260.1.8.1 | not-accessible | A list of non-SSD clients to which SSG act as Radius proxy. | |
| cssgService | 1.3.6.1.4.1.9.9.260.1.3 | |||
| GAU cssgServiceActiveSessions | 1.3.6.1.4.1.9.9.260.1.3.1.1.6 | Gauge | read-only | The active number of connections to this service. |
| IP cssgServiceDNSPrimary | 1.3.6.1.4.1.9.9.260.1.3.1.1.8 | InetAddress | read-only | The primary DNS server for this service. |
| IPt cssgServiceDNSPrimaryIpType | 1.3.6.1.4.1.9.9.260.1.3.1.1.7 | InetAddressType | read-only | The IP address type of Primary DNS Server for this service. |
| IP cssgServiceDNSSecondary | 1.3.6.1.4.1.9.9.260.1.3.1.1.10 | InetAddress | read-only | The Secondary DNS Server for this service. |
| IPt cssgServiceDNSSecondaryIpType | 1.3.6.1.4.1.9.9.260.1.3.1.1.9 | InetAddressType | read-only | The IP Address type of Secondary DNS Server for this service. |
| T/F cssgServiceDownStreamQOSEnabled | 1.3.6.1.4.1.9.9.260.1.3.1.1.12 | TruthValue | read-only | An indication of whether downstream policing is enabled for this service. |
| cssgServiceEntry | 1.3.6.1.4.1.9.9.260.1.3.1.1 | not-accessible | Detailed information concerning a Service. | |
| GAU cssgServiceIdleTimeout | 1.3.6.1.4.1.9.9.260.1.3.1.1.4 | Gauge | read-only | The idle timeout of a session in seconds. A value of 0 indicates that there is no timeout. |
| cssgServiceIfBindEntry | 1.3.6.1.4.1.9.9.260.1.7.1.1 | not-accessible | A Interface-Service Bind entry. | |
| cssgServiceIfBinds | 1.3.6.1.4.1.9.9.260.1.7 | |||
| cssgServiceIfBindTable | 1.3.6.1.4.1.9.9.260.1.7.1 | not-accessible | In SSG, a Service can be configured to use a particular interface/ip address. This table is a list of services and the interface to which they are bound. | |
| NUM cssgServiceIfIndex | 1.3.6.1.4.1.9.9.260.1.7.1.1.1 | InterfaceIndex | read-write | The interface index to which the Service is bound. |
| ROW cssgServiceIfRowStatus | 1.3.6.1.4.1.9.9.260.1.7.1.1.2 | RowStatus | read-write | The status of this table entry. This object can also be used to create or delete conceptual row in this table. To create a row, set this object to 'createAndGo'. cssgServiceIfIndex is a mandatory object for a create request. To delete a row, set this object to 'destroy'. |
| INT cssgServiceMode | 1.3.6.1.4.1.9.9.260.1.3.1.1.2 | INTEGER | read-only | An optional attribute which defines whether the user is able to log in to a service while simultaneously connected to other services (concurrent) or cannot access any other services while using this service (sequential). The default is concurrent. |
| STR cssgServiceName | 1.3.6.1.4.1.9.9.260.1.3.1.1.1 | DisplayString | not-accessible | The name of the service profile. |
| T/F cssgServiceOpenGarden | 1.3.6.1.4.1.9.9.260.1.3.1.1.13 | TruthValue | read-only | An indication of whether this is a Open Garden service. An Open Garden Service is a service that can be accessed without authentication. |
| T/F cssgServicePrepaid | 1.3.6.1.4.1.9.9.260.1.3.1.1.14 | TruthValue | read-only | An indication of whether this service is a prepaid service. |
| IP cssgServiceRouteAddr | 1.3.6.1.4.1.9.9.260.1.3.2.1.2 | InetAddress | not-accessible | The IP Address of the networks available to the user of this service. |
| cssgServiceRouteEntry | 1.3.6.1.4.1.9.9.260.1.3.2.1 | not-accessible | An entry in Services Route Table. | |
| IP cssgServiceRouteMask | 1.3.6.1.4.1.9.9.260.1.3.2.1.4 | InetAddress | not-accessible | Indicate the mask to be ANDed with the destination address before being compared to the value in cssgServiceRouteAddr. |
| IPt cssgServiceRouteMaskType | 1.3.6.1.4.1.9.9.260.1.3.2.1.3 | InetAddressType | not-accessible | A value that represents the type of the address stored in cssgServiceServRouteMask. |
| INT cssgServiceRoutePermission | 1.3.6.1.4.1.9.9.260.1.3.2.1.5 | INTEGER | read-only | Indicates the action on packets, when the destination address matches with the cssgServiceRouteAddr. |
| cssgServiceRouteTable | 1.3.6.1.4.1.9.9.260.1.3.2 | not-accessible | A list of route entries that belong to a particular service. | |
| IPt cssgServiceRouteType | 1.3.6.1.4.1.9.9.260.1.3.2.1.1 | InetAddressType | not-accessible | A value that represents the type of the address stored in cssgServiceServRouteAddr. |
| GAU cssgServiceSessionTimeout | 1.3.6.1.4.1.9.9.260.1.3.1.1.5 | Gauge | read-only | The maximum length of a session in seconds. A value of 0 indicates that there is no timeout. |
| cssgServiceTable | 1.3.6.1.4.1.9.9.260.1.3.1 | not-accessible | A list of SSG Services which subscribers have logged onto. A Service entry in this table is transient data and gets removed when the last subscriber using this Service logs off. | |
| INT cssgServiceType | 1.3.6.1.4.1.9.9.260.1.3.1.1.3 | INTEGER | read-only | This attribute indicates the type of service. pass-through - Indicates that the user authentication is not done during logon to this service. This is the default. tunnel - Indicates that this is a L2TP tunneled service. proxy - Indicates that the SSG performs user authentication during logon to this service. |
| T/F cssgServiceUpstreamQOSEnabled | 1.3.6.1.4.1.9.9.260.1.3.1.1.11 | TruthValue | read-only | An indication of whether upstream policing is enabled for this service. |
| GAU cssgStatsActiveHosts | 1.3.6.1.4.1.9.9.260.1.2.4 | Gauge | read-only | The current number of active Hosts on SSG. |
| GAU cssgStatsActiveServices | 1.3.6.1.4.1.9.9.260.1.2.5 | Gauge | read-only | The current number of active services on SSG. |
| GAU cssgStatsActiveSessions | 1.3.6.1.4.1.9.9.260.1.2.3 | Gauge | read-only | The current number of active connections on SSG. |
| CTR cssgStatsLoginAttempts | 1.3.6.1.4.1.9.9.260.1.2.1 | Counter | read-only | The number of login attempts onto SSG. |
| CTR cssgStatsLoginsSuccessful | 1.3.6.1.4.1.9.9.260.1.2.2 | Counter | read-only | The number of successful logins onto SSG. |
| cssgStatsObjects | 1.3.6.1.4.1.9.9.260.1.2 | |||
| CTR cssgStatsPODs | 1.3.6.1.4.1.9.9.260.1.2.6 | Counter | read-only | The number of Packets of Death sent to Radius Client. |
| cssgTal | 1.3.6.1.4.1.9.9.260.1.10 | |||
| GAU cssgTalCurrentAuthRate | 1.3.6.1.4.1.9.9.260.1.10.9 | Gauge | read-only | The last recorded rate of authorization requests per second, on SSG. |
| DAT cssgTalCurrentAuthRateTimestamp | 1.3.6.1.4.1.9.9.260.1.10.10 | DateAndTime | read-only | This is the local time on the SSG when cssgTalCurrentAuthRate, was recorded. |
| T/F cssgTalDropPakDuringAuthorization | 1.3.6.1.4.1.9.9.260.1.10.14 | TruthValue | read-write | The value 'true' indicates that any packets that are received from the user during user authorization would be dropped. The value 'false' indicates that the packets will not be dropped. |
| GAU cssgTalMaxAuthRate | 1.3.6.1.4.1.9.9.260.1.10.5 | Gauge | read-only | Maximum rate of authorization requests per second. At a given time, the maximum rate of authorization requests will overwrite the previous value. |
| DAT cssgTalMaxAuthRateTimestamp | 1.3.6.1.4.1.9.9.260.1.10.6 | DateAndTime | read-only | This is the local time on the SSG when the Maximum rate of authorization requests per second, indicated by cssgTalMaxAuthRate, was recorded. |
| GAU cssgTalMaxAuthReqsRate | 1.3.6.1.4.1.9.9.260.1.10.13 | Gauge | read-write | The maximum number of authorization requests per second allowed on SSG. If this value is set, SSG throttles the authorization requests sent per second as per this value. |
| GAU cssgTalMaxPendingAuthReqs | 1.3.6.1.4.1.9.9.260.1.10.12 | Gauge | read-write | The maximum number of outstanding TAL authorization requests allowed on SSG. If the number of authorization requests goes beyond this value, SSG does a SYS log message and any packets received that would result in SSG sending a new radius request will be dropped at the CEF path itself. When this value is set, it will be applicable from that point onwards. If the number of existing requests exceeds the new values, these requests will not be discarded. |
| GAU cssgTalMaxSuspectUsers | 1.3.6.1.4.1.9.9.260.1.10.16 | Gauge | read-write | The maximum number of suspect users allowed. |
| GAU cssgTalMinAuthRate | 1.3.6.1.4.1.9.9.260.1.10.7 | Gauge | read-only | Minimum rate of authorization requests per second. At a given time, the minimum rate of authorization requests will overwrite the previous value. |
| DAT cssgTalMinAuthRateTimestamp | 1.3.6.1.4.1.9.9.260.1.10.8 | DateAndTime | read-only | This is the local time on the SSG when the Minimum rate of authorization requests per second, indicated by cssgTalMinAuthRate, was recorded. |
| GAU cssgTalPassthroughUsers | 1.3.6.1.4.1.9.9.260.1.10.4 | Gauge | read-only | The number of currently existing transparent pass-through users. |
| INT cssgTalResetAuthRates | 1.3.6.1.4.1.9.9.260.1.10.11 | INTEGER | read-write | Setting this variable to 'reset' indicates that the Minimum and Maximum rates of authorization would be reset to the last recorded rate of authorization requests per second. Setting it to 'unknown' will not result in any changes. An snmp-get on this value will always return 'unknown'. |
| GAU cssgTalSuspectUsers | 1.3.6.1.4.1.9.9.260.1.10.3 | Gauge | read-only | The number of currently existing Suspect Users. |
| GAU cssgTalSuspectUserTimeout | 1.3.6.1.4.1.9.9.260.1.10.17 | Gauge | read-write | The timeout value for a suspect user in minutes. If a packet is received for a suspect user, then packets from/to this user will be dropped/tcp-redirected, until a value of cssgTalSuspectUserTimeout is reached. After this timeout, any new traffic received by SSG from the suspect user will trigger the TAL procedure all over again. |
| T/F cssgTalUnidentifiedUserAllowTraff | 1.3.6.1.4.1.9.9.260.1.10.15 | TruthValue | read-write | The value 'true' indicates that traffic from/to unidentified users would be allowed. A value of 'false' indicates that traffic from/to unidentified users will not be allowed. |
| GAU cssgTalUnidentifiedUsers | 1.3.6.1.4.1.9.9.260.1.10.2 | Gauge | read-only | The number of currently existing unidentified users. These are users for which there was no response received from AAA and hence it is not clear if they are valid users. |
| GAU cssgTalUnidentifiedUserTimeout | 1.3.6.1.4.1.9.9.260.1.10.18 | Gauge | read-write | The timeout value for an unidentified user in minutes. After this time expiry, authorization will be done again when a packet is received from this user. |
| cssgTalUserInfoEntry | 1.3.6.1.4.1.9.9.260.1.10.19.1 | not-accessible | A conceptual row in the TAL user info table. | |
| cssgTalUserInfoTable | 1.3.6.1.4.1.9.9.260.1.10.19 | not-accessible | A list of all the transparent users, along with their user-state. | |
| IP cssgTalUserIPAddress | 1.3.6.1.4.1.9.9.260.1.10.19.1.2 | InetAddress | not-accessible | IP Address of the transparent user. |
| IPt cssgTalUserIPAddressType | 1.3.6.1.4.1.9.9.260.1.10.19.1.1 | InetAddressType | not-accessible | This is the IP address type of a particular transparent user and is used as index (together with cssgTalUserIPAddress) to identify a unique entry in the Tal User Info table. |
| INT cssgTalUserState | 1.3.6.1.4.1.9.9.260.1.10.19.1.3 | INTEGER | read-only | The state of the transparent user. |
| GAU cssgTalWaitingForAuthUsers | 1.3.6.1.4.1.9.9.260.1.10.1 | Gauge | read-only | The number of currently existing users waiting for authorization. |
| cssgTcpRedirect | 1.3.6.1.4.1.9.9.260.1.6 | |||
| cssgTcpRedirectGrpEntry | 1.3.6.1.4.1.9.9.260.1.6.1.1 | not-accessible | Detailed information concerning a TCP Redirect group. | |
| STR cssgTcpRedirectGrpName | 1.3.6.1.4.1.9.9.260.1.6.1.1.1 | DisplayString | not-accessible | The name of the redirect-group. |
| ROW cssgTcpRedirectGrpRowStatus | 1.3.6.1.4.1.9.9.260.1.6.1.1.5 | RowStatus | read-write | The status of this table entry. This object can also be used to create or delete conceptual row in this table. To create a row, set this object to 'createAndGo'. There are no mandatory objects in a create request. To delete a row, set this object to 'destroy'. |
| IP cssgTcpRedirectGrpServerAddr | 1.3.6.1.4.1.9.9.260.1.6.1.1.3 | InetAddress | not-accessible | The IP address of the server in the server-group. |
| IPt cssgTcpRedirectGrpServerAddrType | 1.3.6.1.4.1.9.9.260.1.6.1.1.2 | InetAddressType | not-accessible | A value that represents the typeof the address stored in cssgTcpRedirectGrpServerAddr object. |
| CIS cssgTcpRedirectGrpServerPort | 1.3.6.1.4.1.9.9.260.1.6.1.1.4 | CiscoPort | not-accessible | The port of the server to which TCP traffic to be redirected. |
| cssgTcpRedirectGrpTable | 1.3.6.1.4.1.9.9.260.1.6.1 | not-accessible | A list of TCP Redirect group. A TCP Redirect group is a list of one more servers that make up a captive portal group. | |
| cssgTcpRedirNetworkGrpMapEntry | 1.3.6.1.4.1.9.9.260.1.6.4.1 | not-accessible | Detailed information concerning a Server and Network group association. | |
| ROW cssgTcpRedirNetworkGrpMapRowStat | 1.3.6.1.4.1.9.9.260.1.6.4.1.2 | RowStatus | read-write | The status of this table entry. This object can also be used to create or delete conceptual row in this table. To create a row, set this object to 'createAndGo'. There are no mandatory objects in a create request. To delete a row, set this object to 'destroy'. |
| cssgTcpRedirNetworkGrpMapTable | 1.3.6.1.4.1.9.9.260.1.6.4 | not-accessible | A list of Network and Server Group associations. | |
| STR cssgTcpRedirNetworkMapGrpName | 1.3.6.1.4.1.9.9.260.1.6.4.1.1 | DisplayString | read-write | A network group name. A network group is a set of network groups that can be associated with TCP Redirect for traffic redirection. |
| cssgTcpRedirPortGrpMapEntry | 1.3.6.1.4.1.9.9.260.1.6.5.1 | not-accessible | An instance of Server and Port group association. | |
| ROW cssgTcpRedirPortGrpMapRowStat | 1.3.6.1.4.1.9.9.260.1.6.5.1.2 | RowStatus | read-write | The status of this table entry. This object can also be used to create or delete conceptual row in this table. To create a row, set this object to 'createAndGo'. There are no mandatory objects in a create request. To delete a row, set this object to 'destroy'. |
| cssgTcpRedirPortGrpMapTable | 1.3.6.1.4.1.9.9.260.1.6.5 | not-accessible | A list of Server and Port Group associations. | |
| STR cssgTcpRedirPortMapGrpName | 1.3.6.1.4.1.9.9.260.1.6.5.1.1 | DisplayString | read-write | The name of the Port Group. A Port Group is a set of ports that can be associated with a TCP Redirect Group for traffic redirection. |
| CIS cssgTcpRedirPortNo | 1.3.6.1.4.1.9.9.260.1.6.6.1.1 | CiscoPort | read-write | The Port No associated with the Service Group name. |
| cssgTcpRedirPortNoMapEntry | 1.3.6.1.4.1.9.9.260.1.6.6.1 | not-accessible | An instance of a Server group and Port association. | |
| ROW cssgTcpRedirPortNoMapRowStat | 1.3.6.1.4.1.9.9.260.1.6.6.1.2 | RowStatus | read-write | The status of this table entry. This object can also be used to create or delete conceptual row in this table. To create a row, set this object to 'createAndGo'. cssgTcpRedirPortNo is a mandatory object for a create request. To delete a row, set this object to 'destroy'. |
| cssgTcpRedirPortNoMapTable | 1.3.6.1.4.1.9.9.260.1.6.6 | not-accessible | A list of Ports nos and the corresponding Server group which they are associated with. |
RFC description
Manages Cisco Service Selection Gateway devices for broadband access and multi-service subscriber management.
Start monitoring Cisco broadband/edge routers (Service Selection Gateway) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.