CISCO-TRUSTSEC-POLICY-MIB

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-TRUSTSEC-POLICY-MIB

Organization: Cisco Systems, Inc.

Last Updated: 2012-12-19

Category: Cisco Devices, VPN and Security

Description: Manages Cisco TrustSec SGACL policy download, binding, and enforcement for security group-based access control.

Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

What Is CISCO-TRUSTSEC-POLICY-MIB?

This MIB module is part of Cisco's TrustSec security architecture, providing managed objects for configuring and monitoring Security Group Access Control List (SGACL) policy enforcement on Cisco switches and routers. It exposes configuration data for enabling SGACL enforcement on Layer 2/3 interfaces and VLANs, administrative and operational mappings between Security Group Tags (SGTs) and policies, and statistics counters for traffic subject to enforcement. From a monitoring perspective it is used mainly to track software/policy status rather than hardware health, as administrators poll it to confirm SGACL enforcement is active per VLAN, verify SGT-to-ACL mapping consistency, and watch drop/permit traffic counters (including NetFlow-monitored drops) that reveal policy violations or misconfigurations. It depends on the broader Cisco TrustSec infrastructure and often works alongside interface and VLAN MIBs for correlating enforcement state to specific network segments. It is typically deployed in enterprise campus and data center networks using Cisco Catalyst or Nexus switches to enforce identity-based network segmentation. Engineers can download the CISCO-TRUSTSEC-POLICY-MIB file directly to load it into their MIB browser.

IPNetwork Monitor allows you to monitor SNMP objects defined in CISCO-TRUSTSEC-POLICY-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • Cisco Catalyst switches
  • Cisco Nexus switches
  • Cisco routers supporting TrustSec

Monitoring Examples

An administrator would poll ctspVlanConfigTable / ctspVlanConfigEntry to check ctspVlanConfigSgaclEnforcement and ctspVlanSviActive for each VLAN, confirming enforcement is enabled where expected. Combined with ctspSgaclIpv4DropNetflowMonitor and ctspSgaclIpv6DropNetflowMonitor, a sudden spike in dropped packets could reveal an SGT mapping error or a policy blocking legitimate traffic. The ctspConfigSgaclMappingTable would be checked to verify SGT-to-ACL bindings are correctly downloaded from the policy server.

What Can Be Monitored

  • SGACL enforcement status per VLAN
  • SGT-to-ACL policy mappings
  • SVI active state
  • IPv4/IPv6 dropped-packet NetFlow counters
  • VLAN configuration row status
Imported Objects

From CISCO-SMI

ciscoMgmtOBJECT-IDENTITY

From CISCO-TC

Cisco2KVlanList
CiscoVrfName

From CISCO-TRUSTSEC-TC-MIB

CtsAclList
CtsAclListOrEmpty
CtsAclName
CtsAclNameOrEmpty
CtsGenerationId
CtsSecurityGroupTag
CtsSgaclMonitorMode

From IF-MIB

ifIndexOBJECT-TYPE

From INET-ADDRESS-MIB

InetAddress
InetAddressPrefixLength
InetAddressType

From Q-BRIDGE-MIB

VlanIndex

From SNMP-FRAMEWORK-MIB

SnmpAdminString

From SNMPv2-CONF

MODULE-COMPLIANCE
NOTIFICATION-GROUP
OBJECT-GROUP

From SNMPv2-SMI

Counter64
MODULE-IDENTITY
NOTIFICATION-TYPE
OBJECT-TYPE
Unsigned32

From SNMPv2-TC

DateAndTime
RowStatus
StorageType
TruthValue

How to Use in IPNetwork Monitor

Example using ctspStatsIpSwDropPkts OID:

Select a Cisco Catalyst/Nexus switch or router (TrustSec SGACL) as the target host to create a monitor — the SNMP service should be up and running on it. Click New Monitor, then check SNMP Custom on the Favorites tab, click Next, and confirm the host. On the next page, click Select... to open the built-in SNMP MIB Browser and type ctspStatsIpSwDropPkts into the Find box to locate it in the OID tree, selecting the specific row/instance you want to monitor since this is a table column, then select it and click OK. This object indicates the number of software-forwarded IP packets which are dropped by SGACL. On the monitor's Main parameters page you can set the target's SNMP port (default 161), credentials, polling interval, and other settings — see the SNMP Monitor help for details. On the State conditions and Alerting tabs, configure when the monitor should change state and trigger an alert; since this is a Counter64-type OID, Value bounds is the most useful condition here — trigger an alert if the counter increases between polls, since a rising count of errors, failures, or discards often points to a real underlying problem. Click Finish to create the monitor; you can adjust any parameter later.
OIDs

RFC description

Cisco Trusted Security policy management MIB for zone configuration, topology, and access control lists.

Start monitoring Cisco Catalyst/Nexus switches and routers (TrustSec SGACL) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download CISCO-TRUSTSEC-POLICY-MIB