All MIBs › CISCO-TRUSTSEC-INTERFACE-MIB
Organization: Cisco Systems, Inc.
Last Updated: 2014-01-28
Category: Cisco Devices, VPN and Security
Description: Manages Cisco TrustSec Security Group Tag (SGT) assignments and enforcement on network interfaces.
Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.
What Is CISCO-TRUSTSEC-INTERFACE-MIB?
CISCO-TRUSTSEC-INTERFACE-MIB is a Cisco Systems, Inc. proprietary MIB configuring and monitoring interfaces within Cisco TrustSec, a security architecture built on SGT (Security Group Tag) classification and MACsec link encryption negotiated via 802.1X or manual configuration. Its interface-config table records mode capability, configured mode, a cache-clear action, and a rekey action; a Dot1x table records SGT-propagation enable, reauth interval (configured/downloaded/operational), time left, SAP mode list, and row status; and a manual-config table records dynamic peer ID, static SGT (and trusted flag), SGT-propagation enable, SAP PMK (Pairwise Master Key), and SAP mode list. As a configuration/status MIB it lets an administrator confirm MACsec/SGT enforcement mode per interface on a Cisco TrustSec-enabled device. It is deployed on Cisco Systems network equipment (TrustSec). Engineers can download the CISCO-TRUSTSEC-INTERFACE-MIB file directly to load it into their MIB browser.
IPNetwork Monitor allows you to monitor SNMP objects defined in CISCO-TRUSTSEC-INTERFACE-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.
Supported Devices
- Cisco Systems network equipment (TrustSec)
Monitoring Examples
An administrator checks ctsiIfConfiguredMode and ctsiIfDot1xSgtPropagateEnabled to confirm TrustSec MACsec mode and SGT propagation on a Cisco interface.
What Can Be Monitored
- TrustSec MACsec mode and SGT propagation configuration per interface
This MIB depends on
Related MIBs
Imported Objects
From CISCO-SMI
| ciscoMgmt | OBJECT-IDENTITY |
| CtsSecurityGroupTag |
From IF-MIB
| ifIndex | OBJECT-TYPE |
| ifName | OBJECT-TYPE |
From SNMP-FRAMEWORK-MIB
| SnmpAdminString |
From SNMPv2-CONF
| MODULE-COMPLIANCE | |
| NOTIFICATION-GROUP | |
| OBJECT-GROUP |
From SNMPv2-SMI
| Counter32 | |
| Integer32 | |
| MODULE-IDENTITY | |
| NOTIFICATION-TYPE | |
| OBJECT-TYPE | |
| Unsigned32 |
From SNMPv2-TC
| DateAndTime | |
| RowStatus | |
| StorageType | |
| TEXTUAL-CONVENTION | |
| TruthValue |
How to Use in IPNetwork Monitor
Example using ctsiAuthenticationSuccess OID:
OIDs
| OID symbolic | OID numeric | Type | Access | Description |
|---|---|---|---|---|
| ciscoTrustSecIfMIB | 1.3.6.1.4.1.9.9.740 | This MIB module defines management objects for configuration and monitoring of the interfaces in Cisco Trusted Security environment. Glossary: ACS - Cisco Secure Access Control Server IFC - TrustSec Interface Controller MACSec - Media Access Control (MAC) Security PMK - Pairwise Master Key SAP - Security Association Protocol SGT - Security Group Tag. A tag identifying its source, assigned to a packet on ingress to a TrustSec cloud, and used to determine security and other policy to be applied to it along its path through the cloud. TrustSec - Cisco Trusted Security | ||
| ciscoTrustSecIfMIBAuthorizationGroup | 1.3.6.1.4.1.9.9.740.2.2.7 | A collection of objects that provides the status information for the authorization link in the system. | ||
| ciscoTrustSecIfMIBCompliance | 1.3.6.1.4.1.9.9.740.2.1.1 | The compliance statement for the CISCO-TRUSTSEC-MIB. | ||
| ciscoTrustSecIfMIBCompliance2 | 1.3.6.1.4.1.9.9.740.2.1.2 | The compliance statement for the CISCO-TRUSTSEC-MIB. | ||
| ciscoTrustSecIfMIBCompliance3 | 1.3.6.1.4.1.9.9.740.2.1.3 | The compliance statement for the CISCO-TRUSTSEC-MIB. | ||
| ciscoTrustSecIfMIBCompliances | 1.3.6.1.4.1.9.9.740.2.1 | |||
| ciscoTrustSecIfMIBConform | 1.3.6.1.4.1.9.9.740.2 | |||
| ciscoTrustSecIfMIBCriticalAuthStatusGrp | 1.3.6.1.4.1.9.9.740.2.2.14 | A collection of objects that provides the Critical-Auth status information for the Cisco Trusted Security capable interface in the system. | ||
| ciscoTrustSecIfMIBDot1xGroup | 1.3.6.1.4.1.9.9.740.2.2.2 | A collection of objects that provides the dot1x mode configuration for the Cisco Trusted Security capable interface in the system. | ||
| ciscoTrustSecIfMIBEventStatisticGroup | 1.3.6.1.4.1.9.9.740.2.2.9 | A collection of objects that provides the global statistic information for the TrustSec events. | ||
| ciscoTrustSecIfMIBGroups | 1.3.6.1.4.1.9.9.740.2.2 | |||
| ciscoTrustSecIfMIBIfConfigGroup | 1.3.6.1.4.1.9.9.740.2.2.1 | A collection of objects that provides the interface configuration for Cisco Trusted Security capable interface in the system. | ||
| ciscoTrustSecIfMIBIfcStatisticGroup | 1.3.6.1.4.1.9.9.740.2.2.8 | A collection of objects that provides the global IFC state statistic information in the system. | ||
| ciscoTrustSecIfMIBIfModeStatisticGroup | 1.3.6.1.4.1.9.9.740.2.2.10 | A collection of objects that provides the global TrustSec mode statistic information. | ||
| ciscoTrustSecIfMIBL3ForwardGroup | 1.3.6.1.4.1.9.9.740.2.2.4 | A collection of objects that provides the L3 forwarding mode configuration for the Cisco Trusted Security capable interface in the system. | ||
| ciscoTrustSecIfMIBManualGroup | 1.3.6.1.4.1.9.9.740.2.2.3 | A collection of objects that provides the manual mode configuration for the Cisco Trusted Security capable interface in the system. | ||
| ciscoTrustSecIfMIBNotifs | 1.3.6.1.4.1.9.9.740.0 | |||
| ciscoTrustSecIfMIBNotifsCtrlGrp | 1.3.6.1.4.1.9.9.740.2.2.11 | A collection of objects that provides notification control for TrustSec interfaces. | ||
| ciscoTrustSecIfMIBNotifsGrp | 1.3.6.1.4.1.9.9.740.2.2.13 | A collection of notifications for TrustSec interfaces. | ||
| ciscoTrustSecIfMIBNotifsOnlyInfoGrp | 1.3.6.1.4.1.9.9.740.2.2.12 | A collection of objects that provides the notification information for TrustSec interfaces. | ||
| ciscoTrustSecIfMIBObjects | 1.3.6.1.4.1.9.9.740.1 | |||
| ciscoTrustSecIfMIBStatisticGroup | 1.3.6.1.4.1.9.9.740.2.2.6 | A collection of objects that provides the statistic information for the Cisco Trusted Security capable interface in the system. | ||
| ciscoTrustSecIfMIBStatusGroup | 1.3.6.1.4.1.9.9.740.2.2.5 | A collection of objects that provides the status information for the Cisco Trusted Security capable interface in the system. | ||
| C32 ctsiAuthenticationFailure | 1.3.6.1.4.1.9.9.740.1.9.3 | Counter32 | read-only | The total number of times that remote peers authentication failed on this device |
| C32 ctsiAuthenticationLogoff | 1.3.6.1.4.1.9.9.740.1.9.4 | Counter32 | read-only | The total number of times that remote peer log off on this device. |
| C32 ctsiAuthenticationNoRespond | 1.3.6.1.4.1.9.9.740.1.9.5 | Counter32 | read-only | The total number of times that not received authentication respond from remote peer on this device. |
| C32 ctsiAuthenticationReject | 1.3.6.1.4.1.9.9.740.1.9.2 | Counter32 | read-only | The total number of times that remote peers authentication rejected on this device. |
| C32 ctsiAuthenticationSuccessEx | 1.3.6.1.4.1.9.9.740.1.9.1 | Counter32 | read-only | The total number of times that remote peers authentication succeed on this device. |
| CTS ctsiAuthorizationCacheDataSource | 1.3.6.1.4.1.9.9.740.1.7.1.1.7 | CtsiCasheDataSource | read-only | This object indicates the source of cached data. |
| ctsiAuthorizationEntry | 1.3.6.1.4.1.9.9.740.1.7.1.1 | not-accessible | An entry containing the management information for a particular authorized peer. An entry is created when the policy acquired from the ACS for a new peer. An entry is deleted when the authorization of the peer has expired or fails to refresh its policy. | |
| NTF ctsiAuthorizationFailNotif | 1.3.6.1.4.1.9.9.740.0.1 | A ctsiAuthorizationFailNotif is generated when the policy acquisition failed for the peer. | ||
| T/F ctsiAuthorizationFailNotifEnable | 1.3.6.1.4.1.9.9.740.1.11.1 | TruthValue | read-write | This object specifies whether the system generates the ctsiAuthorizationFailNotif. A value of 'false' will prevent ctsiAuthorizationFailNotif notifications from being generated by this system. |
| C32 ctsiAuthorizationFailure | 1.3.6.1.4.1.9.9.740.1.9.7 | Counter32 | read-only | The total number of times that remote peer TrustSec authorization failed on this device. |
| DAT ctsiAuthorizationLastRefresh | 1.3.6.1.4.1.9.9.740.1.7.1.1.4 | DateAndTime | read-only | The object indicates the date and time when the authorized peer was last refreshed. |
| ctsiAuthorizationObjects | 1.3.6.1.4.1.9.9.740.1.7 | |||
| STR ctsiAuthorizationPeerId | 1.3.6.1.4.1.9.9.740.1.7.1.1.1 | SnmpAdminString | not-accessible | This object indicates the device identity or symbolic group name of the remote peer. |
| CTS ctsiAuthorizationPeerSgt | 1.3.6.1.4.1.9.9.740.1.7.1.1.2 | CtsSecurityGroupTag | read-only | This object indicates the SGT of the remote peer. |
| C32 ctsiAuthorizationPolicyFailure | 1.3.6.1.4.1.9.9.740.1.9.8 | Counter32 | read-only | The number of time that fail to access policy or refresh the policy for TrustSec authorization on this device. |
| INT ctsiAuthorizationState | 1.3.6.1.4.1.9.9.740.1.7.1.1.3 | INTEGER | read-only | This object indicates the current state of the authorization entity. unknown - none of the following states. start - authorization entity created and initialized. waitingRespond - a policy request has been made by remote peer to the ACS and waiting for the response. assessing - the policy been received from ACS and is being assessed. complete - policy has been received and assessed. failure - failed to download the policy from the ACS. |
| INT ctsiAuthorizationStatus | 1.3.6.1.4.1.9.9.740.1.7.1.1.8 | INTEGER | read-only | This object indicates the status of this authorization peer. unknown - status not covered by any of the follow enumerations. inProgress - new authorization link created or add a new policy request for an existing link. succeeded - policy received successful. failed - policy download failed. fallbackPolicy - download policy failed apply fallback policy. incomplete - policy received incomplete. |
| C32 ctsiAuthorizationSuccess | 1.3.6.1.4.1.9.9.740.1.9.6 | Counter32 | read-only | The total number of times that remote peer authorization succeed on this device. |
| ctsiAuthorizationTable | 1.3.6.1.4.1.9.9.740.1.7.1 | not-accessible | A list of authorized remote peers on this device. | |
| I32 ctsiAuthorizationTimeLeft | 1.3.6.1.4.1.9.9.740.1.7.1.1.5 | Integer32 | read-only | This object indicates the leftover time for the current policy. A value of zero indicates that policy refresh is in progress. A value of -1 indicates that this object is not applicable on this authorization entry. |
| I32 ctsiAuthorizationTimeToRefresh | 1.3.6.1.4.1.9.9.740.1.7.1.1.6 | Integer32 | read-only | This object indicates the time left to start the policy refresh. A value of zero indicates that policy refresh is in progress. A value of -1 indicates that this object is not applicable on this authorization entry. |
| ctsiEventsStatsObjects | 1.3.6.1.4.1.9.9.740.1.9 | |||
| NTF ctsiIfAddSupplicantFailNotif | 1.3.6.1.4.1.9.9.740.0.2 | A ctsiIfAddSupplicantFailNotif is generated when the system fails to add dot1x supplicant for an interface. | ||
| T/F ctsiIfAddSupplicantFailNotifEnable | 1.3.6.1.4.1.9.9.740.1.11.2 | TruthValue | read-write | This object specifies whether the system generates the ctsiIfAddSupplicantFailNotif. A value of 'false' will prevent ctsiIfAddSupplicantFailNotif notifications from being generated by this system. |
| NTF ctsiIfAuthenticationFailNotif | 1.3.6.1.4.1.9.9.740.0.3 | A ctsiIfAuthenticationFailNotif is generated when an authentication error for the peer is detected for an interface. | ||
| T/F ctsiIfAuthenticationFailNotifEnable | 1.3.6.1.4.1.9.9.740.1.11.3 | TruthValue | read-write | This object specifies whether the system generates the ctsiIfAuthenticationFailNotif. A value of 'false' will prevent ctsiIfAuthenticationFailNotif notifications from being generated by this system. |
| C32 ctsiIfAuthenticationFailure | 1.3.6.1.4.1.9.9.740.1.6.1.1.3 | Counter32 | read-only | The number of times that peer has been failed in authentication on this interface. |
| C32 ctsiIfAuthenticationLogoff | 1.3.6.1.4.1.9.9.740.1.6.1.1.5 | Counter32 | read-only | The number of times that received authentication log off from the peer associated with this interface. |
| C32 ctsiIfAuthenticationNoResponse | 1.3.6.1.4.1.9.9.740.1.6.1.1.4 | Counter32 | read-only | The number of times that no authentication respond received from the remote peer associated with this interface. |
| C32 ctsiIfAuthenticationReject | 1.3.6.1.4.1.9.9.740.1.6.1.1.2 | Counter32 | read-only | The number of times that peer has been rejected in authentication on this interface. |
| INT ctsiIfAuthenticationStatus | 1.3.6.1.4.1.9.9.740.1.5.1.1.2 | INTEGER | read-only | This object indicates the current TrustSec authentication status of this interface. unknown - status not covered by any of the follow enumerations. succeeded - authentication is succeeded. rejected - authentication is rejected. logOff - peer logged off. noRespond - peer no respond. notApplicable - bypassing the authentication. incomplete - authentication is not completed. failed - authentication failed. |
| C32 ctsiIfAuthenticationSuccess | 1.3.6.1.4.1.9.9.740.1.6.1.1.1 | Counter32 | read-only | The number of times that peer has been successfully authenticated on this interface. |
| C32 ctsiIfAuthorizationFail | 1.3.6.1.4.1.9.9.740.1.6.1.1.8 | Counter32 | read-only | The number of times that peer has been failed in TrustSec authorization on this interface. |
| C32 ctsiIfAuthorizationPolicyFail | 1.3.6.1.4.1.9.9.740.1.6.1.1.7 | Counter32 | read-only | The number of time that fail to access policy or refresh the policy for TrustSec authorization on this interface. |
| INT ctsiIfAuthorizationStatus | 1.3.6.1.4.1.9.9.740.1.5.1.1.5 | INTEGER | read-only | This object indicates the current TrustSec authorization status of the interface. unknown - status not covered by any of the follow enumerations. inProgress - authorization in progress. succeeded - authorization succeeded. failed - authorization failed. fallBackPolicy - apply the fallback policy. incomplete - authorization aborted. peerSucceeded - apply the peer policy succeeded. rbaclSucceeded - apply the RBACL policy succeeded. policySucceeded - apply the all policy succeeded. |
| C32 ctsiIfAuthorizationSuccess | 1.3.6.1.4.1.9.9.740.1.6.1.1.6 | Counter32 | read-only | The number of times that the peer entity successfully passed the TrustSec authorization challenge on this interface. |
| T/F ctsiIfCacheClear | 1.3.6.1.4.1.9.9.740.1.1.1.1.3 | TruthValue | read-write | This object allows user to clear the cache for the specific TrustSec interface by setting the value to 'true'. Setting the value to 'false' has no effect. When read, this object always returns 'false'. |
| CTS ctsiIfCacheDataSource | 1.3.6.1.4.1.9.9.740.1.5.1.1.11 | CtsiCasheDataSource | read-only | This object indicates the source of cached data applied to the interface. |
| DAT ctsiIfCacheExpirationTime | 1.3.6.1.4.1.9.9.740.1.5.1.1.10 | DateAndTime | read-only | This object indicates the time when the current cached data applied on the interface will be expired. A value of zero indicates that the cached data will never be expired. |
| ctsiIfConfigEntry | 1.3.6.1.4.1.9.9.740.1.1.1.1 | not-accessible | An entry contains the configuration information for a particular TrustSec interface. | |
| ctsiIfConfigObjects | 1.3.6.1.4.1.9.9.740.1.1 | |||
| ctsiIfConfigTable | 1.3.6.1.4.1.9.9.740.1.1.1 | not-accessible | A list of the TrustSec capable interfaces. | |
| INT ctsiIfConfiguredMode | 1.3.6.1.4.1.9.9.740.1.1.1.1.2 | INTEGER | read-only | This object indicates the TrustSec mode currently configured on the interface. Each mode may have a corresponding entry in its corresponding configuration table. unknown - The configured TrustSec mode is none of the following. none - TrustSec is not configured in any mode. dot1x - TrustSec dot1x mode is configured for this interface. TrustSec system will use 802.1x for authentication, RADIUS for authorization and SAP negotiation for SA parameter. manual - TrustSec manual mode is configured for this interface. The authentication was bypassed in manual mode. User needs to manually to configure the policy and the SAP negotiation parameter. l3Forward - TrustSec L3 forwarding mode is configured for this interface. |
| NUM ctsiIfControllerState | 1.3.6.1.4.1.9.9.740.1.5.1.1.1 | CtsiInterfaceControllerState | read-only | This object indicates the current IFC state of this interface. |
| INT ctsiIfCriticalAuthStatus | 1.3.6.1.4.1.9.9.740.1.5.1.1.12 | INTEGER | read-only | This object indicates the CTS Critical-Auth status of interface. disable - link is not in Critical-Auth mode. cache - link is in Critical-Auth cached mode. default - link is in Critical-Auth default mode. |
| NUM ctsiIfcState | 1.3.6.1.4.1.9.9.740.1.8.1.1.1 | CtsiInterfaceControllerState | not-accessible | This object indicates the IFC state. |
| ctsiIfcStatsEntry | 1.3.6.1.4.1.9.9.740.1.8.1.1 | not-accessible | An entry containing the total number of interfaces which are currently belong to a particular IFC state. | |
| U32 ctsiIfcStatsIfCount | 1.3.6.1.4.1.9.9.740.1.8.1.1.2 | Unsigned32 | read-only | The total number of interfaces on the device which is currently in the IFC state. |
| ctsiIfcStatsObjects | 1.3.6.1.4.1.9.9.740.1.8 | |||
| ctsiIfcStatsTable | 1.3.6.1.4.1.9.9.740.1.8.1 | not-accessible | A list of IFC state statistic on this device. | |
| I32 ctsiIfDot1xDownloadReauthInterval | 1.3.6.1.4.1.9.9.740.1.2.1.1.4 | Integer32 | read-only | This object indicates the re-authentication interval which is downloaded from ACS. A value of zero indicates no re-authentication interval is downloaded from ACS. A value of -1 indicates that this object is not applicable on this interface. |
| ctsiIfDot1xEntry | 1.3.6.1.4.1.9.9.740.1.2.1.1 | not-accessible | An entry containing the TrustSec dot1x configuration for a particular interface. An entry can be created or deleted by using ctsiIfDot1xRowStatus. An entry can only be created if the value of corresponding instance of ctsiIfConfiguredMode is 'none' and the 'dot1x' BIT of corresponding instance ctsiIfModeCapability is set. | |
| ctsiIfDot1xObjects | 1.3.6.1.4.1.9.9.740.1.2 | |||
| I32 ctsiIfDot1xOperReauthInterval | 1.3.6.1.4.1.9.9.740.1.2.1.1.5 | Integer32 | read-only | This object indicates the operational re-authentication interval of the interface. A value of zero indicates that dot1x re-authentication is disabled on this interface. A value of -1 indicates that this object is not applicable on this interface. |
| INT ctsiIfDot1xPaeRole | 1.3.6.1.4.1.9.9.740.1.12.2 | INTEGER | accessible-for-notify | This object indicates dot1x PAE role information. notApplicable: Dot1x PAE role is not applicable in this notification. authenticator: PAE Authenticator. supplicant : PAE Supplicant. |
| I32 ctsiIfDot1xReauthInterval | 1.3.6.1.4.1.9.9.740.1.2.1.1.2 | Integer32 | read-create | This object specifies the re-authentication interval applied to this interface when it is not provided from the ACS. |
| I32 ctsiIfDot1xReauthTimeLeft | 1.3.6.1.4.1.9.9.740.1.2.1.1.6 | Integer32 | read-only | This object indicates the leftover time of the current authentication session. A value of zero indicates the re-authentication is in progress. A value of -1 indicates that this object is not applicable on this interface. |
| ROW ctsiIfDot1xRowStatus | 1.3.6.1.4.1.9.9.740.1.2.1.1.8 | RowStatus | read-create | The status of this conceptual row. All writable objects in this row may be modified at any time. |
| CTS ctsiIfDot1xSapModeList | 1.3.6.1.4.1.9.9.740.1.2.1.1.3 | CtsSapNegModeList | read-create | This object specifies the advertised modes for the SAP negotiation on this interface. Modes are executed in the order as specified in the mode list. Mode which is at the beginning of the method list will be executed first. Method which is at the end of mode list will be executed last. This object is not allowed to be set to a zero length string. |
| T/F ctsiIfDot1xSgtPropagateEnabled | 1.3.6.1.4.1.9.9.740.1.2.1.1.1 | TruthValue | read-create | This object specifies whether the SGT propagation is enabled on this interface. |
| STO ctsiIfDot1xStorageType | 1.3.6.1.4.1.9.9.740.1.2.1.1.7 | StorageType | read-create | The storage type for this conceptual row. |
| ctsiIfDot1xTable | 1.3.6.1.4.1.9.9.740.1.2.1 | not-accessible | A list of the interfaces which have TrustSec dot1x mode configuration information. | |
| ctsiIfL3ForwardEntry | 1.3.6.1.4.1.9.9.740.1.4.1.1 | not-accessible | An entry containing the TrustSec L3 forwarding configuration information for a particular interface. An entry can be created or deleted by using ctsiIfL3ForwardRowStatus. An entry can only be created if the value of corresponding instance of ctsiIfConfiguredMode is 'none' and the 'l3Forward' BIT of corresponding instance ctsiIfModeCapability is set. | |
| INT ctsiIfL3ForwardMode | 1.3.6.1.4.1.9.9.740.1.4.1.1.1 | INTEGER | read-create | This object specifies the type of L3 forwarding for the interface. l3Ipv4Forward - TrustSec L3 IPv4 forwarding. l3Ipv6Forward - TrustSec L3 IPv6 forwarding. l3IpForward - TrustSec L3 IPv6 and IPv4 forwarding. |
| ctsiIfL3ForwardObjects | 1.3.6.1.4.1.9.9.740.1.4 | |||
| ROW ctsiIfL3ForwardRowStatus | 1.3.6.1.4.1.9.9.740.1.4.1.1.3 | RowStatus | read-create | The status of this conceptual row. All writable objects in this row may be modified at any time. |
| STO ctsiIfL3ForwardStorageType | 1.3.6.1.4.1.9.9.740.1.4.1.1.2 | StorageType | read-create | The storage type for this conceptual row. |
| ctsiIfL3ForwardTable | 1.3.6.1.4.1.9.9.740.1.4.1 | not-accessible | A list of the interfaces which have TrustSec L3 forwarding configuration information. | |
| STR ctsiIfManualDynamicPeerId | 1.3.6.1.4.1.9.9.740.1.3.1.1.1 | SnmpAdminString | read-create | This object specifies the peer's device identity which is used to obtain the desired policy for authorization request. Setting a none-zero value on this object is not allowed if the value of ctsiIfManualStaticSgt is not set to zero. A zero length string indicates that the policy acquisition from the ACS using the peer's identity is disabled on this interface. |
| ctsiIfManualEntry | 1.3.6.1.4.1.9.9.740.1.3.1.1 | not-accessible | An entry containing the TrustSec manual configuration information for a particular interface. An entry can be created or deleted by using ctsiIfManualRowStatus. An entry can only be created if the value of corresponding instance of ctsiIfConfiguredMode is 'none' and the 'manual' BIT of corresponding instance ctsiIfModeCapability is set. | |
| ctsiIfManualObjects | 1.3.6.1.4.1.9.9.740.1.3 | |||
| ROW ctsiIfManualRowStatus | 1.3.6.1.4.1.9.9.740.1.3.1.1.8 | RowStatus | read-create | The status of this conceptual row. All writable objects in this row may be modified at any time. |
| CTS ctsiIfManualSapModeList | 1.3.6.1.4.1.9.9.740.1.3.1.1.6 | CtsSapNegModeList | read-create | This object specified the advertised modes for the SAP negotiation on this interface. Modes are executed in the order as specified in the mode list. Mode which is at the beginning of the mode list will be executed first. Mode which is at the end of mode list will be executed last. Value of this object will becomes zero length octet if SAP negotiation is disabled. This object is not allowed to be set to a zero length string. |
| OCT ctsiIfManualSapPmk | 1.3.6.1.4.1.9.9.740.1.3.1.1.5 | OCTET STRING | read-create | This object specifies the PMK used by SAP. A zero length string for this object indicates the SAP negotiation is disabled on this interface. |
| T/F ctsiIfManualSgtPropagateEnabled | 1.3.6.1.4.1.9.9.740.1.3.1.1.4 | TruthValue | read-create | This object specifies whether the SGT propagation is enabled on this interface. |
| CTS ctsiIfManualStaticSgt | 1.3.6.1.4.1.9.9.740.1.3.1.1.2 | CtsSecurityGroupTag | read-create | This object specifies the statically configured SGT for tagging the ingress traffic from the peer. Setting a none-zero value on this object is not allowed if the value of ctsiIfManualDynamicPeerId is not set to a zero length string. A value of zero indicates that no statically SGT tagging. |
| T/F ctsiIfManualStaticSgtTrusted | 1.3.6.1.4.1.9.9.740.1.3.1.1.3 | TruthValue | read-create | This object specifies the peer's SGT assignment trust state. This object only can be set when ctsiIfManualStaticSgt is none-zero. |
| STO ctsiIfManualStorageType | 1.3.6.1.4.1.9.9.740.1.3.1.1.7 | StorageType | read-create | The storage type for this conceptual row. |
| ctsiIfManualTable | 1.3.6.1.4.1.9.9.740.1.3.1 | not-accessible | A list of the interfaces which have TrustSec manual mode configuration information. | |
| BIT ctsiIfModeCapability | 1.3.6.1.4.1.9.9.740.1.1.1.1.1 | Bits | read-only | This object indicates the supported TrustSec mode on this interface. |
| ctsiIfModeStatsObjects | 1.3.6.1.4.1.9.9.740.1.10 | |||
| STR ctsiIfNotifMessage | 1.3.6.1.4.1.9.9.740.1.12.1 | SnmpAdminString | accessible-for-notify | This object indicates detail message associated with notifications. |
| ctsiIfNotifsControlObjects | 1.3.6.1.4.1.9.9.740.1.11 | |||
| ctsiIfNotifsOnlyInfoObjects | 1.3.6.1.4.1.9.9.740.1.12 | |||
| BIT ctsiIfPeerAdvCapability | 1.3.6.1.4.1.9.9.740.1.5.1.1.4 | Bits | read-only | This object indicates the advertised capabilities of the remote peer associated with this interface. |
| STR ctsiIfPeerId | 1.3.6.1.4.1.9.9.740.1.5.1.1.3 | SnmpAdminString | read-only | This object indicates the device identity or symbolic group name of the remote peer. |
| CTS ctsiIfPeerSgt | 1.3.6.1.4.1.9.9.740.1.5.1.1.6 | CtsSecurityGroupTag | read-only | This object indicates the SGT value of the remote peer. |
| T/F ctsiIfPeerSgtTrusted | 1.3.6.1.4.1.9.9.740.1.5.1.1.7 | TruthValue | read-only | This object indicates whether the SGT of the remote peer is trusted. |
| T/F ctsiIfRekey | 1.3.6.1.4.1.9.9.740.1.1.1.1.4 | TruthValue | read-write | This object allows user to re-generate the SAP key for the specific TrustSec interface by setting the value to 'true'. Setting the value to 'false' has no effect. When read, this object always returns 'false'. |
| C32 ctsiIfSapFail | 1.3.6.1.4.1.9.9.740.1.6.1.1.10 | Counter32 | read-only | The number of times that SAP negotiation has failed on this interface. |
| CTS ctsiIfSapNegModeList | 1.3.6.1.4.1.9.9.740.1.5.1.1.9 | CtsSapNegModeList | read-only | This object indicates the operational SAP negotiation mode list on this interface. |
| NTF ctsiIfSapNegotiationFailNotif | 1.3.6.1.4.1.9.9.740.0.4 | A ctsiIfSapNegotiationFailNotif is generated when a SAP negotiation error with the peer is detected for an interface. | ||
| T/F ctsiIfSapNegotiationFailNotifEnable | 1.3.6.1.4.1.9.9.740.1.11.4 | TruthValue | read-write | This object specifies whether the system generates the ctsiIfSapNegotiationFailNotif. A value of 'false' will prevent ctsiIfSapNegotiationFailNotif notifications from being generated by this system. |
| INT ctsiIfSapNegotiationStatus | 1.3.6.1.4.1.9.9.740.1.5.1.1.8 | INTEGER | read-only | This object indicates the SAP negotiation status on this interface. notApplicable - SAP disabled on local or remote peer is not SAP capable. unknown - status not covered by any of the follow enumerations. inProgress - SAP negotiation in progress. succeeded - SAP negotiation completed. failed - SAP negotiation failed. licenseError - No MACSec software license. |
| C32 ctsiIfSapSuccess | 1.3.6.1.4.1.9.9.740.1.6.1.1.9 | Counter32 | read-only | The number of times that SAP negotiation is succeed on this interface. |
| ctsiIfStatsEntry | 1.3.6.1.4.1.9.9.740.1.6.1.1 | not-accessible | An entry contains the statistics information of a particular TrustSec interface. An entry created by system for each interface is TrustSec enabled. An entry deleted by system for each interface is TrustSec disabled. | |
| ctsiIfStatsObjects | 1.3.6.1.4.1.9.9.740.1.6 | |||
| ctsiIfStatsTable | 1.3.6.1.4.1.9.9.740.1.6.1 | not-accessible | A list of Cisco Trusted Security capable interface. | |
| ctsiIfStatusEntry | 1.3.6.1.4.1.9.9.740.1.5.1.1 | not-accessible | An entry contains the information of the specific TrustSec interface. A entry is created by system when TrustSec is enabled for an interface. An entry is deleted by system if TrustSec is disabled for an interface. | |
| ctsiIfStatusObjects | 1.3.6.1.4.1.9.9.740.1.5 | |||
| ctsiIfStatusTable | 1.3.6.1.4.1.9.9.740.1.5.1 | not-accessible | A list of TrustSec enabled interfaces. | |
| NTF ctsiIfUnauthorizedNotif | 1.3.6.1.4.1.9.9.740.0.5 | A ctsiIfUnauthorizedNotif is generated when a interface becomes unauthorized on the Cisco TrustSec link. | ||
| T/F ctsiIfUnauthorizedNotifEnable | 1.3.6.1.4.1.9.9.740.1.11.5 | TruthValue | read-write | This object specifies whether the system generates the ctsiIfUnauthorizedNotif. A value of 'false' will prevent ctsiIfUnauthorizedNotif notifications from being generated by this system. |
| U32 ctsiInDot1xModeIfCount | 1.3.6.1.4.1.9.9.740.1.10.1 | Unsigned32 | read-only | The total number of interfaces on the device which is in TrustSec 802.1X mode. |
| U32 ctsiInL3ForwardModeIfCount | 1.3.6.1.4.1.9.9.740.1.10.3 | Unsigned32 | read-only | The total number of interfaces on the device which is in TrustSec Layer 3 forwarding mode. |
| U32 ctsiInManualModeIfCount | 1.3.6.1.4.1.9.9.740.1.10.2 | Unsigned32 | read-only | The total number of interfaces on the device which is in TrustSec Manual mode. |
| C32 ctsiSapNegotiationFailure | 1.3.6.1.4.1.9.9.740.1.9.10 | Counter32 | read-only | The total number of times that TrustSec SAP negotiation failure on this device. |
| C32 ctsiSapNegotiationSuccess | 1.3.6.1.4.1.9.9.740.1.9.9 | Counter32 | read-only | The total number of times that TrustSec SAP negotiation succeed on this device. |
RFC description
Vendor-private MIB for Cisco TrustSec port-based network access control; defines objects for managing interface-level 802.1X authentication and Security Group tagging.
Start monitoring Cisco network equipment (TrustSec interfaces) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.