CISCO-TRUSTSEC-MIB

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-TRUSTSEC-MIB

Organization: Cisco Systems, Inc.

Last Updated: 2014-01-30

Category: Cisco Devices, VPN and Security

Description: Manages Cisco TrustSec security including Security Group Tags (SGT), SGACL enforcement, and PAC provisioning.

Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

What Is CISCO-TRUSTSEC-MIB?

CISCO-TRUSTSEC-MIB manages Cisco TrustSec, a network security fabric feature that authenticates and authorizes devices at the network edge and enforces encryption, authentication, and replay protection hop-by-hop, using constructs like EAP-FAST and Protected Access Credentials (PAC). It primarily exposes configuration and security-state data: Security Group Tag (SGT) assignment, device identity/password/keystore settings, and cache management rather than raw traffic counters. From a monitoring perspective it is most useful for software/security status: tracking keystore firmware version (ctsKeystoreFwVersion), firmware alert and reset counts (ctsKeystoreFwAlerts, ctsKeystoreFwResets), and SGT cache state to confirm the TrustSec control plane is healthy and credentials remain valid. It depends conceptually on RFC 4851 (EAP-FAST) and Cisco's broader AAA/802.1X security infrastructure for full context. It is deployed on Cisco switches and routers acting as TrustSec-enabled network access devices in secure enterprise/campus environments, where CISCO-TRUSTSEC-MIB SNMP monitoring confirms the security fabric's control plane stays healthy.

IPNetwork Monitor allows you to monitor SNMP objects defined in CISCO-TRUSTSEC-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • Cisco switches
  • Cisco routers with TrustSec support

Monitoring Examples

An operator would check ctsDeviceId, ctsDevicePasswordType, and ctsKeystoreFwVersion to confirm a switch's TrustSec identity and firmware are correctly provisioned, and monitor ctsKeystoreFwAlerts/ctsKeystoreFwResets for unexpected spikes indicating keystore corruption or repeated re-provisioning. Polling ctsCacheEnabled and ctsCacheNvStorage together with ctsSecurityGroupTagId helps verify that SGT-to-cache bindings persist correctly across reboots. A non-fault-tolerant SGT assignment method (ctsSgtAssignmentMethod) unexpectedly changing could signal a misconfiguration in the TrustSec authorization policy.

What Can Be Monitored

  • Security Group Tag (SGT) assignment
  • device identity and password/keystore configuration
  • keystore firmware version and alerts
  • keystore reset counts
  • SGT cache state
Imported Objects

From CISCO-SMI

ciscoMgmtOBJECT-IDENTITY

From CISCO-TRUSTSEC-TC-MIB

CtsAcsAuthorityIdentity
CtsCredentialRecordType
CtsGenerationId
CtsPasswordEncryptionType
CtsSecurityGroupTag

From SNMP-FRAMEWORK-MIB

SnmpAdminString

From SNMPv2-CONF

MODULE-COMPLIANCE
NOTIFICATION-GROUP
OBJECT-GROUP

From SNMPv2-SMI

Counter32
MODULE-IDENTITY
NOTIFICATION-TYPE
OBJECT-TYPE
Unsigned32

From SNMPv2-TC

DateAndTime
RowStatus
TruthValue

How to Use in IPNetwork Monitor

Example using ctsKeystoreFwAlerts OID:

Select a Cisco switches/routers with TrustSec support as the target host to create a monitor — the SNMP service should be up and running on it. Click New Monitor, then check SNMP Custom on the Favorites tab, click Next, and confirm the host. On the next page, click Select... to open the built-in SNMP MIB Browser and type ctsKeystoreFwAlerts into the Find box to locate it in the OID tree, then select it and click OK. This object indicates the number of hardware keystore alerts that occurred. On the monitor's Main parameters page you can set the target's SNMP port (default 161), credentials, polling interval, and other settings — see the SNMP Monitor help for details. On the State conditions and Alerting tabs, configure when the monitor should change state and trigger an alert; since this is a Counter32-type OID, Value bounds is the most useful condition here — trigger an alert if the counter increases sharply between polls relative to its normal baseline, since an unexpected spike often reflects a real change in traffic or activity. Click Finish to create the monitor; you can adjust any parameter later.
OIDs

RFC description

Cisco TrustSec authentication and authorization for network device access and fabric security.

Start monitoring Cisco switches/routers with TrustSec support with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download CISCO-TRUSTSEC-MIB