CISCO-TRUSTSEC-SXP-MIB

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-TRUSTSEC-SXP-MIB

Organization: Cisco Systems, Inc.

Last Updated: 2013-07-29

Category: Cisco Devices, VPN and Security

Description: Monitors Cisco TrustSec SXP (SGT Exchange Protocol) peer connections and IP-to-SGT binding propagation.

Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

What Is CISCO-TRUSTSEC-SXP-MIB?

This MIB supports Cisco's TrustSec SXP (SGT Exchange Protocol over TCP), which propagates IP-address-to-Security-Group-Tag bindings between network devices that don't natively support SGT tagging in the data plane. It exposes configuration objects (default passwords, source addresses, retry/reconnect timers) and status/statistics objects tracking SXP peer connections and SGT binding table state. Its monitoring role is chiefly software/protocol status, as administrators use it to confirm SXP peering is enabled and healthy, watch retry and reconnection periods for flapping peer sessions, and check binding expansion counters against limits to detect when the binding table is approaching capacity. It depends on and complements CISCO-TRUSTSEC-POLICY-MIB and the broader TrustSec architecture for SGT-based policy enforcement. Typical deployment is in enterprise networks propagating identity-based tags across mixed hardware/software TrustSec domains. Network engineers evaluating or troubleshooting this functionality can download the CISCO-TRUSTSEC-SXP-MIB file directly to load it into their MIB browser.

IPNetwork Monitor allows you to monitor SNMP objects defined in CISCO-TRUSTSEC-SXP-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • Cisco Catalyst switches
  • Cisco Nexus switches
  • Cisco routers supporting TrustSec SXP

Monitoring Examples

An operator would poll ctsxSxpEnable to confirm SXP is active and ctsxSxpRetryPeriod / ctsxSxpReconPeriod to understand reconnection behavior after a peer link failure. Watching ctsxSgtMapExpansionCount against ctsxSgtMapExpansionLimit reveals whether the device is nearing its maximum SGT-to-IP binding capacity, an early warning sign before bindings start getting dropped. ctsxSxpBindingChangesLogEnable indicates whether binding change events are being logged for audit and troubleshooting.

What Can Be Monitored

  • SXP protocol enable state
  • peer retry/reconnect timers
  • SGT-to-IP binding expansion count vs limit
  • binding change logging status
  • default source address configuration
Imported Objects

From CISCO-SMI

ciscoMgmtOBJECT-IDENTITY

From CISCO-TC

CiscoVrfName

From CISCO-TRUSTSEC-TC-MIB

CtsPassword
CtsPasswordEncryptionType
CtsSecurityGroupTag
CtsSxpConnectionStatus

From IF-MIB

InterfaceIndexOrZero

From INET-ADDRESS-MIB

InetAddress
InetAddressPrefixLength
InetAddressType

From SNMP-FRAMEWORK-MIB

SnmpAdminString

From SNMPv2-CONF

MODULE-COMPLIANCE
NOTIFICATION-GROUP
OBJECT-GROUP

From SNMPv2-SMI

Gauge32
MODULE-IDENTITY
NOTIFICATION-TYPE
OBJECT-TYPE
Unsigned32

From SNMPv2-TC

RowStatus
StorageType
TruthValue
OIDs

RFC description

Manages Security Group Tag Exchange Protocol for role-based access control and network segmentation.

Start monitoring Cisco Catalyst/Nexus switches and routers (TrustSec SXP) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download CISCO-TRUSTSEC-SXP-MIB