All MIBs › CISCO-TAP-MIB
Organization: Cisco Systems, Inc.
Last Updated: 2005-10-12
Category: Cisco Devices, VPN and Security
Description: Manages CALEA lawful intercept tap streams, target identification, and mediation device interfaces on Cisco routers.
Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.
What Is CISCO-TAP-MIB?
CISCO-TAP-MIB is a Cisco Systems, Inc. proprietary MIB managing Cisco's original lawful-intercept (mediation) feature, later superseded by CISCO-TAP2-MIB with specific filter MIBs. Its mediation table, keyed by an auto-assigned index, records content ID, destination address type/address/port, source interface, RTCP port, DSCP, data type, retransmit type, timeout, transport, notification-enable flag, status, and capabilities, alongside a stream-capabilities object and a stream-IP table (interface, address type, destination address/length). As a lawful-intercept configuration MIB it lets an authorized administrator confirm intercepted-content delivery parameters (destination, transport) on Cisco equipment. It is deployed on Cisco Systems network equipment (legacy lawful-intercept). Engineers can download the CISCO-TAP-MIB file directly to load it into their MIB browser.
IPNetwork Monitor allows you to monitor SNMP objects defined in CISCO-TAP-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.
Supported Devices
- Cisco Systems network equipment (legacy lawful-intercept)
Monitoring Examples
An authorized administrator checks cTapMediationDestAddress and cTapMediationStatus to confirm an intercepted stream is being correctly delivered to the mediation device on Cisco equipment.
What Can Be Monitored
- mediation delivery destination and status
This MIB depends on
Related MIBs
Imported Objects
From IF-MIB
| InterfaceIndexOrZero |
From INET-ADDRESS-MIB
| InetAddress | |
| InetAddressPrefixLength | |
| InetAddressType | |
| InetPortNumber |
From SNMP-FRAMEWORK-MIB
| SnmpAdminString |
From SNMPv2-CONF
| MODULE-COMPLIANCE | |
| NOTIFICATION-GROUP | |
| OBJECT-GROUP |
From SNMPv2-SMI
| Counter32 | |
| Integer32 | |
| MODULE-IDENTITY | |
| NOTIFICATION-TYPE | |
| OBJECT-TYPE | |
| Unsigned32 | |
| enterprises |
From SNMPv2-TC
| DateAndTime | |
| MacAddress | |
| RowStatus | |
| TEXTUAL-CONVENTION | |
| TruthValue |
OIDs
| OID symbolic | OID numeric | Type | Access | Description |
|---|---|---|---|---|
| cTapDebugComplianceGroup | 1.3.6.1.4.1.9.9.252.2.2.7 | These objects are necessary for debug information. | ||
| cTapDebugEntry | 1.3.6.1.4.1.9.9.252.1.3.1.1 | not-accessible | A list of the debug messages. | |
| cTapDebugGroup | 1.3.6.1.4.1.9.9.252.1.3 | |||
| U32 cTapDebugIndex | 1.3.6.1.4.1.9.9.252.1.3.1.1.1 | Unsigned32 | accessible-for-notify | Indicates an error code. |
| STR cTapDebugMessage | 1.3.6.1.4.1.9.9.252.1.3.1.1.2 | SnmpAdminString | read-only | A text string contains the description of an error code. |
| cTapDebugTable | 1.3.6.1.4.1.9.9.252.1.3.1 | not-accessible | A table that contains Lawful Intercept debug information available on this device. This table is used to map an error code to a text message for further information. | |
| BIT cTapMediationCapabilities | 1.3.6.1.4.1.9.9.252.1.1.3 | Bits | read-only | This object displays the device capabilities with respect to certain fields in Mediation Device table. This may be dependent on hardware capabilities, software capabilities. The following values may be supported: ipV4SrcInterface: SNMP ifIndex Value may be used to select the interface (denoted by cTapMediationSrcInterface) on the intercepting device from which to transmit intercepted data to an IPv4 address Mediation Device. ipV6SrcInterface: SNMP ifIndex Value may be used to select the interface (denoted by cTapMediationSrcInterface) on the intercepting device from which to transmit intercepted data to an IPv6 address Mediation Device. udp: UDP may be used as transport protocol (denoted by cTapMediationTransport) in transferring intercepted data to the Mediation Device. rtcpNack: RTP with Nack resilience may be used as transport protocol (denoted by cTapMediationTransport) in transferring intercepted data to the Mediation Device. tcp: TCP may be used as transport protocol (denoted by cTapMediationTransport) in transferring intercepted data to the Mediation Device. sctp: SCTP may be used as transport protocol (denoted by cTapMediationTransport) in transferring intercepted data to the Mediation Device. |
| cTapMediationComplianceGroup | 1.3.6.1.4.1.9.9.252.2.2.1 | These objects are necessary for description of the data streams directed to a Mediation Device. | ||
| I32 cTapMediationContentId | 1.3.6.1.4.1.9.9.252.1.1.2.1.1 | Integer32 | accessible-for-notify | cTapMediationContentId is a session identifier, from the intercept application's perspective, and a content identifier from the Mediation Device's perspective. The Mediation Device is responsible for making sure these are unique, although the SNMP RowStatus row creation process will help by not allowing it to create conflicting entries. Before creating a new entry, a value for this variable may be obtained by reading cTapMediationNewIndex to reduce the probability of a value collision. |
| cTapMediationCpbComplianceGroup | 1.3.6.1.4.1.9.9.252.2.2.6 | These objects are necessary for a description of the mediation device to select for Lawful Intercept. | ||
| I32 cTapMediationDataType | 1.3.6.1.4.1.9.9.252.1.1.2.1.8 | Integer32 | read-create | If RTP with Ack/Nack resilience is selected as a transport, the mediation process requires an RTP payload type for data transmissions, and a second RTP payload type for retransmissions. This is the RTP payload type for transmissions. This object is only effective when the value of cTapMediationTransport is 'rtpNack'. |
| NTF cTapMediationDebug | 1.3.6.1.4.1.9.9.252.0.3 | When there is intervention needed due to some events related to entries configured in cTapMediationTable, the device notifies the manager of the event. This notification may be generated in conjunction with the intercept application, which is designed to expect the notification to be sent as reliably as possible, e.g., through the use of a finite number of retransmissions until acknowledged, as and when such mechanisms are available; for example, with SNMPv3, this would be an InformRequest. | ||
| IP cTapMediationDestAddress | 1.3.6.1.4.1.9.9.252.1.1.2.1.3 | InetAddress | read-create | The IP Address of the Mediation Device's network interface to which to direct intercepted traffic. |
| IPt cTapMediationDestAddressType | 1.3.6.1.4.1.9.9.252.1.1.2.1.2 | InetAddressType | read-create | The type of cTapMediationDestAddress. |
| INE cTapMediationDestPort | 1.3.6.1.4.1.9.9.252.1.1.2.1.4 | InetPortNumber | read-create | The port number on the Mediation Device's network interface to which to direct intercepted traffic. |
| DSC cTapMediationDscp | 1.3.6.1.4.1.9.9.252.1.1.2.1.7 | Dscp | read-create | The Differentiated Services Code Point the intercepting device applies to the IP packets encapsulating the intercepted traffic. |
| cTapMediationEntry | 1.3.6.1.4.1.9.9.252.1.1.2.1 | not-accessible | The entry describes a single session maintained with an application on a Mediation Device. | |
| cTapMediationGroup | 1.3.6.1.4.1.9.9.252.1.1 | |||
| I32 cTapMediationNewIndex | 1.3.6.1.4.1.9.9.252.1.1.1 | Integer32 | read-only | This object contains a value which may be used as an index value for a new cTapMediationEntry. Whenever read, the agent will change the value to a new non-conflicting value. This is to reduce the probability of errors during creation of new cTapMediationTable entries. |
| T/F cTapMediationNotificationEnable | 1.3.6.1.4.1.9.9.252.1.1.2.1.12 | TruthValue | read-create | This variable controls the generation of any notifications or informs by the MIB agent for this table entry. |
| I32 cTapMediationRetransmitType | 1.3.6.1.4.1.9.9.252.1.1.2.1.9 | Integer32 | read-create | If RTP with Ack/Nack resilience is selected as a transport, the mediation process requires an RTP payload type for data transmissions, and a second RTP payload type for retransmissions. This is the RTP payload type for retransmissions. This object is only effective when the value of cTapMediationTransport is 'rtpNack'. |
| INE cTapMediationRtcpPort | 1.3.6.1.4.1.9.9.252.1.1.2.1.6 | InetPortNumber | read-only | The port number on the intercepting device to which the Mediation Devices directs RTCP Receiver Reports and Nacks. This object is only relevant when the value of cTapMediationTransport is 'rtpNack'. This port is assigned by the intercepting device, rather than by the Mediation Device or manager application. The value of this MIB object has no effect before activating the cTapMediationEntry. |
| NUM cTapMediationSrcInterface | 1.3.6.1.4.1.9.9.252.1.1.2.1.5 | InterfaceIndexOrZero | read-create | The interface on the intercepting device from which to transmit intercepted data. If zero, any interface may be used according to normal IP practice. |
| ROW cTapMediationStatus | 1.3.6.1.4.1.9.9.252.1.1.2.1.13 | RowStatus | read-create | The status of this conceptual row. This object is used to manage creation, modification and deletion of rows in this table. cTapMediationTimeout may be modified at any time (even while the row is active). But when the row is active, the other writable objects may not be modified without setting its value to 'notInService'. The entry may not be deleted or deactivated by setting its value to 'destroy' or 'notInService' if there is any associated entry in cTapStreamIpTable, or other such tables when such are defined. |
| cTapMediationTable | 1.3.6.1.4.1.9.9.252.1.1.2 | not-accessible | This table lists the Mediation Devices with which the intercepting device communicates. These may be on the same or different Mediation Devices. This table is written by the Mediation Device, and is always volatile. This is because intercepts may disappear during a restart of the intercepting equipment. | |
| NTF cTapMediationTimedOut | 1.3.6.1.4.1.9.9.252.0.2 | When an intercept is autonomously removed by an intercepting device, such as due to the time specified in cTapMediationTimeout arriving, the device notifies the manager of the action. | ||
| DAT cTapMediationTimeout | 1.3.6.1.4.1.9.9.252.1.1.2.1.10 | DateAndTime | read-create | The time at which this row and all related Stream Table rows should be automatically removed, and the intercept function cease. Since the initiating network manager may be the only device able to manage a specific intercept or know of its existence, this acts as a fail-safe for the failure or removal of the network manager. The object is only effective when the value of cTapMediationStatus is 'active'. |
| INT cTapMediationTransport | 1.3.6.1.4.1.9.9.252.1.1.2.1.11 | INTEGER | read-create | The protocol used in transferring intercepted data to the Mediation Device. The following protocols may be supported: udp: PacketCable udp format rtpNack: RTP with Nack resilience tcp: TCP with head of line blocking sctp: SCTP with head of line blocking |
| cTapMIB | 1.3.6.1.4.1.9.9.252 | This module manages Cisco's intercept feature. | ||
| NTF cTapMIBActive | 1.3.6.1.4.1.9.9.252.0.1 | This Notification is sent when an intercepting router or switch is first capable of intercepting a packet corresponding to a configured data stream. If the configured data stream is an IP one, the value of the corresponding cTapStreamIpStatus is included in this notification. If the configured data stream is an IEEE 802 one, the value of the corresponding cTapStream802Status is included in this notification. This notification may be generated in conjunction with the intercept application, which is designed to expect the notification to be sent as reliably as possible, e.g., through the use of a finite number of retransmissions until acknowledged, as and when such mechanisms are available; for example, with SNMPv3, this would be an InformRequest. Filter installation can take a long period of time, during which call progress may be delayed. | ||
| cTapMIBCompliance | 1.3.6.1.4.1.9.9.252.2.1.1 | The compliance statement for entities which implement the Cisco Intercept MIB | ||
| cTapMIBCompliances | 1.3.6.1.4.1.9.9.252.2.1 | |||
| cTapMIBConformance | 1.3.6.1.4.1.9.9.252.2 | |||
| cTapMIBGroups | 1.3.6.1.4.1.9.9.252.2.2 | |||
| cTapMIBNotifications | 1.3.6.1.4.1.9.9.252.0 | |||
| cTapMIBObjects | 1.3.6.1.4.1.9.9.252.1 | |||
| cTapNotificationGroup | 1.3.6.1.4.1.9.9.252.2.2.5 | These notifications are used to present status from the intercepting device to the Mediation Device. | ||
| cTapStream802ComplianceGroup | 1.3.6.1.4.1.9.9.252.2.2.4 | These objects are necessary for a description of IEEE 802 packets to select for interception. | ||
| NTF cTapStream802Debug | 1.3.6.1.4.1.9.9.252.0.5 | When there is intervention needed due to some events related to entries configured in cTapStream802Table, the device notifies the manager of the event. This notification may be generated in conjunction with the intercept application, which is designed to expect the notification to be sent as reliably as possible, e.g., through the use of a finite number of retransmissions until acknowledged, as and when such mechanisms are available; for example, with SNMPv3, this would be an InformRequest. | ||
| MAC cTapStream802DestinationAddress | 1.3.6.1.4.1.9.9.252.1.2.3.1.4 | MacAddress | read-create | The Destination address used in packet selection. |
| I32 cTapStream802DestinationLlcSap | 1.3.6.1.4.1.9.9.252.1.2.3.1.7 | Integer32 | read-create | The value of the IEEE 802.2 Destination SAP. |
| cTapStream802Entry | 1.3.6.1.4.1.9.9.252.1.2.3.1 | not-accessible | A stream entry indicates a single data stream to be intercepted to a Mediation Device. Many selected data streams may go to the same application interface, and many application interfaces are supported. | |
| I32 cTapStream802EthernetPid | 1.3.6.1.4.1.9.9.252.1.2.3.1.6 | Integer32 | read-create | The value of the Ethernet Protocol Identifier, which may be found on Ethernet traffic or IEEE 802.2 SNAP traffic. |
| BIT cTapStream802Fields | 1.3.6.1.4.1.9.9.252.1.2.3.1.2 | Bits | read-create | This object displays what attributes must be tested to identify traffic which requires interception. The packet matches if all flagged fields match. interface: indicates that traffic on the stated interface is to be intercepted dstMacAddress: indicates that traffic destined to a given address should be intercepted srcMacAddress: indicates that traffic sourced from a given address should be intercepted ethernetPid: indicates that traffic with a stated Ethernet Protocol Identifier should be intercepted dstLlcSap: indicates that traffic with an certain 802.2 LLC Destination SAP should be intercepted srcLlcSap: indicates that traffic with an certain 802.2 LLC Source SAP should be intercepted At least one of the bits has to be set in order to activate an entry. If the bit is not on, the corresponding MIB object value has no effect, and need not be specified when creating the entry. |
| I32 cTapStream802Index | 1.3.6.1.4.1.9.9.252.1.2.3.1.1 | Integer32 | accessible-for-notify | The index of the stream itself. |
| C32 cTapStream802InterceptDrops | 1.3.6.1.4.1.9.9.252.1.2.3.1.11 | Counter32 | read-only | The number of packets matching this data stream specification that, having been intercepted, were dropped in the lawful intercept process. |
| C32 cTapStream802InterceptedPackets | 1.3.6.1.4.1.9.9.252.1.2.3.1.10 | Counter32 | read-only | The number of packets matching this data stream specification that have been intercepted. |
| T/F cTapStream802InterceptEnable | 1.3.6.1.4.1.9.9.252.1.2.3.1.9 | TruthValue | read-create | If 'true', the tap enables interception of matching traffic. If cTapStreamCapabilities flag tapEnable is zero, this may not be set to 'false'. |
| I32 cTapStream802Interface | 1.3.6.1.4.1.9.9.252.1.2.3.1.3 | Integer32 | read-create | The ifIndex value of the interface over which traffic to be intercepted is received or transmitted. The interface may be physical or virtual. If this is the only parameter specified, and it is other than -1 or 0, all traffic on the selected interface will be chosen. If the value is zero, matching traffic may be received or transmitted on any interface. Additional selection parameters must be selected to limit the scope of traffic intercepted. This is most useful on non-routing platforms or on intercepts placed elsewhere than a subscriber interface. If the value is -1, one or both of cTapStream802DestinationAddress and cTapStream802SourceAddress must be specified. Matching traffic on the interface pointed to by the dot1dTpFdbPort values associated with those values is intercepted, whichever is specified. If dot1dTpFdbPort changes, either by operator action or by protocol events, the interface will change with it. This is primarily intended for use on subscriber interfaces and other places where routing is guaranteed to be symmetrical. In both of these cases, it is possible to have the same packet selected for intersection on both its ingress and egress interface. Nonetheless, only one instance of the packet is sent to the Mediation Device. This value must be set when creating a stream entry, either to select an interface, to select all interfaces, or to select the interface that bridging learns. Some platforms may not implement the entire range of options. |
| MAC cTapStream802SourceAddress | 1.3.6.1.4.1.9.9.252.1.2.3.1.5 | MacAddress | read-create | The Source Address used in packet selection. |
| I32 cTapStream802SourceLlcSap | 1.3.6.1.4.1.9.9.252.1.2.3.1.8 | Integer32 | read-create | The value of the IEEE 802.2 Source SAP. |
| ROW cTapStream802Status | 1.3.6.1.4.1.9.9.252.1.2.3.1.12 | RowStatus | read-create | The status of this conceptual row. This object manages creation, modification, and deletion of rows in this table. cTapStream802InterceptEnable can be modified any time even the value of this entry rowStatus object is active. When other rows must be changed, cTapStream802Status must be first set to 'notInService'. |
| cTapStream802Table | 1.3.6.1.4.1.9.9.252.1.2.3 | not-accessible | The Intercept Stream 802 Table lists the IEEE 802 data streams to be intercepted. The same data stream may be required by multiple taps, and one might assume that often the intercepted stream is a small subset of the traffic that could be intercepted. This essentially provides options for packet selection, only some of which might be used. For example, if all traffic to or from a given interface is to be intercepted, one would configure an entry which lists the interface, and wild-card everything else. If all traffic to or from a given MAC Address is to be intercepted, one would configure two such entries listing the MAC Address as source and destination respectively, and wild-card everything else. The first index indicates which Mediation Device the intercepted traffic will be diverted to. The second index permits multiple classifiers to be used together, such as having a MAC address as source or destination. | |
| BIT cTapStreamCapabilities | 1.3.6.1.4.1.9.9.252.1.2.1 | Bits | read-only | This object displays what types of intercept streams can be configured on this type of device. This may be dependent on hardware capabilities, software capabilities. The following fields may be supported: interface: SNMP ifIndex Value may be used to select interception of all data crossing an interface or set of interfaces. tapEnable: set if table entries with cTapStreamIpInterceptEnable set to 'false' are used to pre-screen packets for intercept; otherwise these entries are ignored. ipV4: IPv4 Address or prefix may be used to select traffic to be intercepted. ipV6: IPv6 Address or prefix may be used to select traffic to be intercepted. l4Port: TCP/UDP Ports may be used to select traffic to be intercepted. dscp: DSCP may be used to select traffic to be intercepted. dstMacAddr: Destination MAC Address may be used to select traffic to be intercepted. srcMacAddr: Source MAC Address may be used to select traffic to be intercepted. ethernetPid: Ethernet Protocol Identifier may be used to select traffic to be intercepted. dstLlcSap: IEEE 802.2 Destination SAP may be used to select traffic to be intercepted. srcLlcSap: IEEE 802.2 Source SAP may be used to select traffic to be intercepted. |
| cTapStreamComplianceGroup | 1.3.6.1.4.1.9.9.252.2.2.2 | These objects are necessary for a description of the packets to select for interception. | ||
| cTapStreamGroup | 1.3.6.1.4.1.9.9.252.1.2 | |||
| IPt cTapStreamIpAddrType | 1.3.6.1.4.1.9.9.252.1.2.2.1.3 | InetAddressType | read-create | The type of address, used in packet selection. |
| cTapStreamIpComplianceGroup | 1.3.6.1.4.1.9.9.252.2.2.3 | These objects are necessary for a description of IPv4 and IPv6 packets to select for interception. | ||
| NTF cTapStreamIpDebug | 1.3.6.1.4.1.9.9.252.0.4 | When there is intervention needed due to some events related to entries configured in cTapStreamIpTable, the device notifies the manager of the event. This notification may be generated in conjunction with the intercept application, which is designed to expect the notification to be sent as reliably as possible, e.g., through the use of a finite number of retransmissions until acknowledged, as and when such mechanisms are available; for example, with SNMPv3, this would be an InformRequest. | ||
| IP cTapStreamIpDestinationAddress | 1.3.6.1.4.1.9.9.252.1.2.2.1.4 | InetAddress | read-create | The Destination address or prefix used in packet selection. This address will be of the type specified in cTapStreamIpAddrType. |
| ADR cTapStreamIpDestinationLength | 1.3.6.1.4.1.9.9.252.1.2.2.1.5 | InetAddressPrefixLength | read-create | The length of the Destination Prefix. A value of zero causes all addresses to match. This prefix length will be consistent with the type specified in cTapStreamIpAddrType. |
| INE cTapStreamIpDestL4PortMax | 1.3.6.1.4.1.9.9.252.1.2.2.1.13 | InetPortNumber | read-create | The maximum value that the layer-4 destination port number in the packet must have in order to match this classifier entry. This value must be equal to or greater than the value specified for this entry in cTapStreamIpDestL4PortMin. If both cTapStreamIpDestL4PortMin and cTapStreamIpDestL4PortMax are at their default values, the port number is effectively unused. |
| INE cTapStreamIpDestL4PortMin | 1.3.6.1.4.1.9.9.252.1.2.2.1.12 | InetPortNumber | read-create | The minimum value that the layer-4 destination port number in the packet must have in order to match. This value must be equal to or less than the value specified for this entry in cTapStreamIpDestL4PortMax. If both cTapStreamIpDestL4PortMin and cTapStreamIpDestL4PortMax are at their default values, the port number is effectively unused. |
| cTapStreamIpEntry | 1.3.6.1.4.1.9.9.252.1.2.2.1 | not-accessible | A stream entry indicates a single data stream to be intercepted to a Mediation Device. Many selected data streams may go to the same application interface, and many application interfaces are supported. | |
| I32 cTapStreamIpFlowId | 1.3.6.1.4.1.9.9.252.1.2.2.1.10 | Integer32 | read-create | The flow identifier in an IPv6 header. -1 indicates that the Flow Id is unused. |
| I32 cTapStreamIpIndex | 1.3.6.1.4.1.9.9.252.1.2.2.1.1 | Integer32 | accessible-for-notify | The index of the stream itself. |
| C32 cTapStreamIpInterceptDrops | 1.3.6.1.4.1.9.9.252.1.2.2.1.18 | Counter32 | read-only | The number of packets matching this data stream specification that, having been intercepted, were dropped in the lawful intercept process. |
| C32 cTapStreamIpInterceptedPackets | 1.3.6.1.4.1.9.9.252.1.2.2.1.17 | Counter32 | read-only | The number of packets matching this data stream specification that have been intercepted. |
| T/F cTapStreamIpInterceptEnable | 1.3.6.1.4.1.9.9.252.1.2.2.1.16 | TruthValue | read-create | If 'true', the tap should intercept matching traffic. If 'false', this entry is used to pre-screen packets for intercept. |
| I32 cTapStreamIpInterface | 1.3.6.1.4.1.9.9.252.1.2.2.1.2 | Integer32 | read-create | The ifIndex value of the interface over which traffic to be intercepted is received or transmitted. The interface may be physical or virtual. If this is the only parameter specified, and it is other than -1 or 0, all traffic on the selected interface will be chosen. If the value is zero, matching traffic may be received or transmitted on any interface. Additional selection parameters must be selected to limit the scope of traffic intercepted. This is most useful on non-routing platforms or on intercepts placed elsewhere than a subscriber interface. If the value is -1, one or both of cTapStreamIpDestinationAddress and cTapStreamIpSourceAddress must be specified with prefix length greater than zero. Matching traffic on the interface pointed to by ipRouteIfIndex or ipCidrRouteIfIndex values associated with those values is intercepted, whichever is specified to be more focused than a default route. If routing changes, either by operator action or by routing protocol events, the interface will change with it. This is primarily intended for use on subscriber interfaces and other places where routing is guaranteed to be symmetrical. In both of these cases, it is possible to have the same packet selected for intersection on both its ingress and egress interface. Nonetheless, only one instance of the packet is sent to the Mediation Device. This value must be set when creating a stream entry, either to select an interface, to select all interfaces, or to select the interface that routing chooses. Some platforms may not implement the entire range of options. |
| I32 cTapStreamIpProtocol | 1.3.6.1.4.1.9.9.252.1.2.2.1.11 | Integer32 | read-create | The IP protocol to match against the IPv4 protocol number or the IPv6 Next- Header number in the packet. -1 means 'any IP protocol'. |
| IP cTapStreamIpSourceAddress | 1.3.6.1.4.1.9.9.252.1.2.2.1.6 | InetAddress | read-create | The Source Address used in packet selection. This address will be of the type specified in cTapStreamIpAddrType. |
| INE cTapStreamIpSourceL4PortMax | 1.3.6.1.4.1.9.9.252.1.2.2.1.15 | InetPortNumber | read-create | The maximum value that the layer-4 destination port number in the packet must have in order to match this classifier entry. This value must be equal to or greater than the value specified for this entry in cTapStreamIpSourceL4PortMin. If both cTapStreamIpSourceL4PortMin and cTapStreamIpSourceL4PortMax are at their default values, the port number is effectively unused. |
| INE cTapStreamIpSourceL4PortMin | 1.3.6.1.4.1.9.9.252.1.2.2.1.14 | InetPortNumber | read-create | The minimum value that the layer-4 destination port number in the packet must have in order to match. This value must be equal to or less than the value specified for this entry in cTapStreamIpSourceL4PortMax. If both cTapStreamIpSourceL4PortMin and cTapStreamIpSourceL4PortMax are at their default values, the port number is effectively unused. |
| ADR cTapStreamIpSourceLength | 1.3.6.1.4.1.9.9.252.1.2.2.1.7 | InetAddressPrefixLength | read-create | The length of the Source Prefix. A value of zero causes all addresses to match. This prefix length will be consistent with the type specified in cTapStreamIpAddrType. |
| ROW cTapStreamIpStatus | 1.3.6.1.4.1.9.9.252.1.2.2.1.19 | RowStatus | read-create | The status of this conceptual row. This object manages creation, modification, and deletion of rows in this table. cTapStreamIpInterceptEnable may be modified any time even the value of this entry rowStatus object is 'active'. When other rows must be changed, cTapStreamIpStatus must be first set to 'notInService'. |
| cTapStreamIpTable | 1.3.6.1.4.1.9.9.252.1.2.2 | not-accessible | The Intercept Stream IP Table lists the IPv4 and IPv6 streams to be intercepted. The same data stream may be required by multiple taps, and one might assume that often the intercepted stream is a small subset of the traffic that could be intercepted. This essentially provides options for packet selection, only some of which might be used. For example, if all traffic to or from a given interface is to be intercepted, one would configure an entry which lists the interface, and wild-card everything else. If all traffic to or from a given IP Address is to be intercepted, one would configure two such entries listing the IP Address as source and destination respectively, and wild-card everything else. If a particular voice on a teleconference is to be intercepted, on the other hand, one would extract the multicast (destination) IP address, the source IP Address, the protocol (UDP), and the source and destination ports from the call control exchange and list all necessary information. The first index indicates which Mediation Device the intercepted traffic will be diverted to. The second index permits multiple classifiers to be used together, such as having an IP address as source or destination. | |
| I32 cTapStreamIpTosByte | 1.3.6.1.4.1.9.9.252.1.2.2.1.8 | Integer32 | read-create | The value of the TOS byte, when masked with cTapStreamIpTosByteMask, of traffic to be intercepted. If cTapStreamIpTosByte & (~cTapStreamIpTosByteMask) != 0, configuration is rejected. |
| I32 cTapStreamIpTosByteMask | 1.3.6.1.4.1.9.9.252.1.2.2.1.9 | Integer32 | read-create | The value of the TOS byte in an IPv4 or IPv6 header is ANDed with cTapStreamIpTosByteMask and compared with cTapStreamIpTosByte. If the values are equal, the comparison is equal. If the mask is zero and the TosByte value is zero, the result is to always accept. |
RFC description
Manages Cisco intercept (tap) feature for network traffic monitoring and lawful interception.
Start monitoring Cisco network equipment (legacy lawful-intercept) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.