All MIBs › CISCOSB-AAA
Organization: Cisco Small Business
Last Updated: 2010-06-21
Category: RADIUS and AAA, Vendor: RADLAN/Cisco SB
Description: Manages Cisco Small Business switch AAA (Authentication, Authorization, Accounting) configuration.
Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.
What Is CISCOSB-AAA?
CISCOSB-AAA is a Cisco Small Business (formerly Linksys, "rl" tree) private MIB for configuring Authentication, Authorization, and Accounting (AAA) on small-business switches. It exposes configuration objects controlling whether RADIUS, TACACS+, local user database, system password, or line password authentication methods are enabled, along with related retry timers and fallback behavior such as an "always succeed" mode. Rather than hardware health, its monitoring value is primarily in security/configuration-state visibility: administrators can verify which authentication backends are active and supported on the device, confirm retry settings, and detect a risky fallback state. It has an implicit dependency on standard RADIUS/TACACS+ protocol concepts and coexists with the device's separate TACACS+-specific subtree. It is deployed on Cisco Small Business (Cisco SB) switches used in SMB network closets where centralized AAA is configured for administrative login control. Engineers can download the CISCOSB-AAA file directly to load it into their MIB browser.
IPNetwork Monitor allows you to monitor SNMP objects defined in CISCOSB-AAA. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.
Supported Devices
- Cisco Small Business (Cisco SB) switches
Monitoring Examples
An administrator would poll rlAAARadiusEnabled and rlAAATacacsEnabled to confirm the intended authentication backend is active, and check rlAAARetries to ensure retry counts match policy. Discovering rlAAAAlwaysSuccessEnabled set to true would be a critical security finding since it means authentication is configured to always pass, and rlAAATest could be used to validate connectivity to a configured AAA server before relying on it in production.
What Can Be Monitored
- enabled AAA authentication methods (RADIUS/TACACS+/local)
- authentication retry count
- always-succeed fallback state
- system/line password authentication state
This MIB depends on
Related MIBs
Imported Objects
From CISCOSB-MIB
| rlAAAEap | OBJECT-IDENTITY |
| rlRadius | OBJECT-IDENTITY |
| switch001 | MODULE-IDENTITY |
From INET-ADDRESS-MIB
| InetAddress | |
| InetAddressIPv6 | |
| InetAddressType |
From SNMPv2-SMI
| Counter32 | |
| IpAddress | |
| MODULE-IDENTITY | |
| OBJECT-TYPE | |
| Unsigned32 |
From SNMPv2-TC
| DateAndTime | |
| DisplayString | |
| RowStatus | |
| TEXTUAL-CONVENTION | |
| TimeStamp | |
| TruthValue |
How to Use in IPNetwork Monitor
Example using rlAAALineConsFailedLogins OID:
OIDs
| OID symbolic | OID numeric | Type | Access | Description |
|---|---|---|---|---|
| rlAAA | 1.3.6.1.4.1.9.6.1.101.79 | The private MIB module definition for Authentication, Authorization and Accounting in CISCOSB devices. | ||
| RLA rlAAAAccountingDot1xMethod | 1.3.6.1.4.1.9.6.1.101.79.56 | RlAAAAccountingMethod | read-write | Method, used for accounting of 802.1x sessions, none denotes Accounting is disabled. |
| RLA rlAAAAccountingMngMethod | 1.3.6.1.4.1.9.6.1.101.79.55 | RlAAAAccountingMethod | read-write | Method, used for accounting of management sessions, none denotes Accounting is disabled. |
| T/F rlAAAAlwaysSuccessEnabled | 1.3.6.1.4.1.9.6.1.101.79.8 | TruthValue | read-write | Specifies whether AAA will use the always success method. When to use that method exactly depends on its position in the methods list. |
| T/F rlAAAAuditingEnable | 1.3.6.1.4.1.9.6.1.101.79.41 | TruthValue | read-write | Controls whether SysLog messages should be issued on login events |
| STR rlAAACreationDateSystemPasswordLevel15 | 1.3.6.1.4.1.9.6.1.101.79.69 | DisplayString | read-only | The date on which the system Password for level 15 was created. Otherwise zero size string |
| STR rlAAAEapCurrentMethodList | 1.3.6.1.4.1.9.6.1.101.97.2 | DisplayString | read-write | Specifies the method list that will be used for authentication. |
| rlAAAEapMethodListEntry | 1.3.6.1.4.1.9.6.1.101.97.1.1 | not-accessible | The row definition for this table. | |
| STR rlAAAEapMethodListName | 1.3.6.1.4.1.9.6.1.101.97.1.1.1 | DisplayString | read-write | Line Method List Name |
| ROW rlAAAEapMethodListStatus | 1.3.6.1.4.1.9.6.1.101.97.1.1.7 | RowStatus | read-write | method list status can be destroy or createAndGo |
| rlAAAEapMethodListTable | 1.3.6.1.4.1.9.6.1.101.97.1 | not-accessible | The table specifies all methods list per method name. | |
| RLA rlAAAEapMethodType1 | 1.3.6.1.4.1.9.6.1.101.97.1.1.2 | RlAAAEapMethodtype | read-write | first method type that will be used in the method linked list. |
| RLA rlAAAEapMethodType2 | 1.3.6.1.4.1.9.6.1.101.97.1.1.3 | RlAAAEapMethodtype | read-write | second method type that will be used in the method linked list. |
| RLA rlAAAEapMethodType3 | 1.3.6.1.4.1.9.6.1.101.97.1.1.4 | RlAAAEapMethodtype | read-write | 3th method type that will be used in the method linked list. |
| RLA rlAAAEapMethodType4 | 1.3.6.1.4.1.9.6.1.101.97.1.1.5 | RlAAAEapMethodtype | read-write | 4th method type that will be used in the method linked list. |
| RLA rlAAAEapMethodType5 | 1.3.6.1.4.1.9.6.1.101.97.1.1.6 | RlAAAEapMethodtype | read-write | 5th method type that will be used in the method linked list. |
| U32 rlAAAIfIndex | 1.3.6.1.4.1.9.6.1.101.79.16.1.2 | Unsigned32 | read-write | Identifies the ifindex for which this entry can be used. If index 0 means don't care (can be used for all if indices). For port type console the value could be only 0. |
| T/F rlAAALineAlwaysSuccessSupported | 1.3.6.1.4.1.9.6.1.101.79.14 | TruthValue | read-only | This mib show whether line always success method is supported in AAA.If the value is false always success method will not be used as an authentication and accounting method. If the value is true the always success method will be used by AAA for authentication and accounting method if the the AAA was configured to do so (by setting the appropriate mibs). |
| C32 rlAAALineConsFailedLoginsEx | 1.3.6.1.4.1.9.6.1.101.79.16.1.22 | Counter32 | read-only | Number of last consecutive failed logins |
| rlAAALineEntry | 1.3.6.1.4.1.9.6.1.101.79.16.1 | not-accessible | The row definition for this table. | |
| INT rlAAALineLockedState | 1.3.6.1.4.1.9.6.1.101.79.16.1.21 | INTEGER | read-only | Line locked status |
| STR rlAAALineMethodListNameLevel1 | 1.3.6.1.4.1.9.6.1.101.79.16.1.4 | DisplayString | read-write | Method list Name for level 1 .That name points to the method list table .It is the key in method list table .in that way we can reach the methods list to be used for that line |
| STR rlAAALineMethodListNameLevel10 | 1.3.6.1.4.1.9.6.1.101.79.16.1.13 | DisplayString | read-write | Method list Name for level 10 that name points to the method list table it is the key in method list table .in that way we can reach the methods list to be used for that line |
| STR rlAAALineMethodListNameLevel11 | 1.3.6.1.4.1.9.6.1.101.79.16.1.14 | DisplayString | read-write | Method list Name for level 11 that name points to the method list table it is the key in method list table .in that way we can reach the methods list to be used for that line |
| STR rlAAALineMethodListNameLevel12 | 1.3.6.1.4.1.9.6.1.101.79.16.1.15 | DisplayString | read-write | Method list Name for level 12 that name points to the method list table it is the key in method list table .in that way we can reach the methods list to be used for that line |
| STR rlAAALineMethodListNameLevel13 | 1.3.6.1.4.1.9.6.1.101.79.16.1.16 | DisplayString | read-write | Method list Name for level 13 that name points to the method list table it is the key in method list table .in that way we can reach the methods list to be used for that line |
| STR rlAAALineMethodListNameLevel14 | 1.3.6.1.4.1.9.6.1.101.79.16.1.17 | DisplayString | read-write | Method list Name for level 14 that name points to the method list table it is the key in method list table .in that way we can reach the methods list to be used for that line |
| STR rlAAALineMethodListNameLevel15 | 1.3.6.1.4.1.9.6.1.101.79.16.1.18 | DisplayString | read-write | Method list Name for level 15 that name points to the method list table it is the key in method list table .in that way we can reach the methods list to be used for that line |
| STR rlAAALineMethodListNameLevel2 | 1.3.6.1.4.1.9.6.1.101.79.16.1.5 | DisplayString | read-write | Method list Name for level 2 that name points to the method list table it is the key in method list table .by that way we can reach the methods list to be used for that line |
| STR rlAAALineMethodListNameLevel3 | 1.3.6.1.4.1.9.6.1.101.79.16.1.6 | DisplayString | read-write | Method list Name for level 3 that name points to the method list table it is the key in method list table .by that way we can reach the methods list to be used for this line |
| STR rlAAALineMethodListNameLevel4 | 1.3.6.1.4.1.9.6.1.101.79.16.1.7 | DisplayString | read-write | Method list Name for level 4-that name points to the method list table it is the key in method list table .by that way we can reach the methods list to be used for this line |
| STR rlAAALineMethodListNameLevel5 | 1.3.6.1.4.1.9.6.1.101.79.16.1.8 | DisplayString | read-write | Method list Name for level 5 that name points to the method list table it is the key in method list table .in that way we can reach the methods list to be used for that line |
| STR rlAAALineMethodListNameLevel6 | 1.3.6.1.4.1.9.6.1.101.79.16.1.9 | DisplayString | read-write | Method list Name for level 6 that name points to the method list table it is the key in method list table .in that way we can reach the methods list to be used for that line |
| STR rlAAALineMethodListNameLevel7 | 1.3.6.1.4.1.9.6.1.101.79.16.1.10 | DisplayString | read-write | Method list Name for level 7 that name points to the method list table it is the key in method list table .in that way we can reach the methods list to be used for that line |
| STR rlAAALineMethodListNameLevel8 | 1.3.6.1.4.1.9.6.1.101.79.16.1.11 | DisplayString | read-write | Method list Name for level 8 that name points to the method list table it is the key in method list table .in that way we can reach the methods list to be used for that line |
| STR rlAAALineMethodListNameLevel9 | 1.3.6.1.4.1.9.6.1.101.79.16.1.12 | DisplayString | read-write | Method list Name for level 9 that name points to the method list table it is the key in method list table .in that way we can reach the methods list to be used for that line |
| STR rlAAALinePassLoginDateTime | 1.3.6.1.4.1.9.6.1.101.79.47.1.8 | DisplayString | read-only | Date and time in the SysLog Format: DD-MMM-YYYY HH:MM:SS |
| RLA rlAAALinePassLoginHistActServiceType | 1.3.6.1.4.1.9.6.1.101.79.47.1.5 | RlAAAServiceType | read-only | The service that the user uses. Service don't care is console terminal. |
| rlAAALinePassLoginHistEntry | 1.3.6.1.4.1.9.6.1.101.79.47.1 | not-accessible | The row definition for this table. | |
| U32 rlAAALinePassLoginHistIfIndex | 1.3.6.1.4.1.9.6.1.101.79.47.1.2 | Unsigned32 | read-write | Identifies the ifindex for which this entry can be used. If index 0 means don't care (can be used for all if indices). For port type console the value could be only 0. |
| U32 rlAAALinePassLoginHistIndex | 1.3.6.1.4.1.9.6.1.101.79.47.1.4 | Unsigned32 | not-accessible | Index in History for specific user. Lower number means more recent login. |
| RLA rlAAALinePassLoginHistInetActServiceType | 1.3.6.1.4.1.9.6.1.101.79.59.1.5 | RlAAAServiceType | read-only | The service that the user uses. Service don't care is console terminal. |
| STR rlAAALinePassLoginHistInetDateTime | 1.3.6.1.4.1.9.6.1.101.79.59.1.10 | DisplayString | read-only | Date and time in the SysLog Format: DD-MMM-YYYY HH:MM:SS |
| rlAAALinePassLoginHistInetEntry | 1.3.6.1.4.1.9.6.1.101.79.59.1 | not-accessible | The row definition for this table. | |
| U32 rlAAALinePassLoginHistInetIfIndex | 1.3.6.1.4.1.9.6.1.101.79.59.1.2 | Unsigned32 | read-write | Identifies the ifindex for which this entry can be used. If index 0 means don't care (can be used for all if indices). For port type console the value could be only 0. |
| U32 rlAAALinePassLoginHistInetIndex | 1.3.6.1.4.1.9.6.1.101.79.59.1.4 | Unsigned32 | not-accessible | Index in HistInetory for specific user. Lower number means more recent login. |
| IP rlAAALinePassLoginHistInetLocalInetAddress | 1.3.6.1.4.1.9.6.1.101.79.59.1.9 | InetAddress | read-only | local Ip Address on login. |
| IPt rlAAALinePassLoginHistInetLocalInetAddressType | 1.3.6.1.4.1.9.6.1.101.79.59.1.8 | InetAddressType | read-only | local Ip Address Type on login. |
| U32 rlAAALinePassLoginHistInetMrid | 1.3.6.1.4.1.9.6.1.101.79.59.1.11 | Unsigned32 | read-only | Mrid - indicates to which instance the connection was established |
| RLA rlAAALinePassLoginHistInetPortType | 1.3.6.1.4.1.9.6.1.101.79.59.1.1 | RlAAALinePortType | read-write | the physical port type. |
| IP rlAAALinePassLoginHistInetRemoteInetAddress | 1.3.6.1.4.1.9.6.1.101.79.59.1.7 | InetAddress | read-only | User remote IP address. |
| IPt rlAAALinePassLoginHistInetRemoteInetAddressType | 1.3.6.1.4.1.9.6.1.101.79.59.1.6 | InetAddressType | read-only | User remote IP address Type. |
| RLA rlAAALinePassLoginHistInetServiceType | 1.3.6.1.4.1.9.6.1.101.79.59.1.3 | RlAAAServiceType | read-write | the service type |
| rlAAALinePassLoginHistInetTable | 1.3.6.1.4.1.9.6.1.101.79.59 | not-accessible | The table holds successful login history for Line passwords. This table is read-only. it coexist with rlAAALinePassLoginHistTable to support IPv4 and IPv6 | |
| IP rlAAALinePassLoginHistLocalIpAddress | 1.3.6.1.4.1.9.6.1.101.79.47.1.7 | IpAddress | read-only | local Ip Address on login. |
| RLA rlAAALinePassLoginHistPortType | 1.3.6.1.4.1.9.6.1.101.79.47.1.1 | RlAAALinePortType | read-write | the physical port type. |
| IP rlAAALinePassLoginHistRemoteIpAddress | 1.3.6.1.4.1.9.6.1.101.79.47.1.6 | IpAddress | read-only | User remote IP address. |
| RLA rlAAALinePassLoginHistServiceType | 1.3.6.1.4.1.9.6.1.101.79.47.1.3 | RlAAAServiceType | read-write | the service type |
| rlAAALinePassLoginHistTable | 1.3.6.1.4.1.9.6.1.101.79.47 | not-accessible | The table holds successful login history for Line passwords. This table is read-only. | |
| U32 rlAAALinePassLoginMrid | 1.3.6.1.4.1.9.6.1.101.79.47.1.9 | Unsigned32 | read-only | Mrid - indicates to which instance the connection was established |
| STR rlAAALinePassword | 1.3.6.1.4.1.9.6.1.101.79.16.1.19 | DisplayString | read-write | Line Password. Zero length password is considered as no password. Password with zero length means that in case this password is the method to be used a method fail is returned and no other method is being used. allowed formats: a. Display string starting with '$' for clear text b. Encrypted password: starts with # sign followed by 32 octets representing Hex Decimal value(in the 0-9 a-f A-F range) the $ and # as first octet are a directive to indicate what is the type of password and are not not part of it |
| T/F rlAAALinePasswordEnabled | 1.3.6.1.4.1.9.6.1.101.79.7 | TruthValue | read-write | Specifies whether AAA will use the line password. When to use the passwords exactly depends on its position in the methods list. |
| STR rlAAALinePasswordExpieryDate | 1.3.6.1.4.1.9.6.1.101.79.16.1.24 | DisplayString | read-only | If Line password aging is active, the date on which The current password will expire. Otherwise zero size string |
| T/F rlAAALinePasswordSupported | 1.3.6.1.4.1.9.6.1.101.79.13 | TruthValue | read-only | This mib show whether line password is supported in AAA. If the value is false line password will not be used as an authentication and accounting method. If the value is true the line password will be used by AAA for authentication and accounting method if the the AAA was configured to do so (by setting the appropriate mibs). |
| U32 rlAAALinePasswordValidTime | 1.3.6.1.4.1.9.6.1.101.79.16.1.23 | Unsigned32 | read-write | The period of time in days, during which the password, is considered valid for login. Value of 0 means never expired. The actual range is product specific. After this time the system may allow limited number of logins to change the password. |
| RLA rlAAALinePortType | 1.3.6.1.4.1.9.6.1.101.79.16.1.1 | RlAAALinePortType | read-write | the physical port type . |
| ROW rlAAALineStatus | 1.3.6.1.4.1.9.6.1.101.79.16.1.20 | RowStatus | read-write | Line status can be destroy or createAndGo |
| rlAAALineTable | 1.3.6.1.4.1.9.6.1.101.79.16 | not-accessible | The table specifies all lines, their passwords and their authorizations level .the table ordered lexicography by the line name. when a new line is being authenticate the search in line table is from the first entry in table till it find the first entry that fit application input line parameters . | |
| C32 rlAAALocalConsFailedLogins | 1.3.6.1.4.1.9.6.1.101.79.17.1.6 | Counter32 | read-only | Number of last consecutive failed logins |
| ROW rlAAALocalHostStatus | 1.3.6.1.4.1.9.6.1.101.79.17.1.4 | RowStatus | read-write | Local User status |
| INT rlAAALocalLockedState | 1.3.6.1.4.1.9.6.1.101.79.17.1.5 | INTEGER | read-only | Local User locked status |
| STR rlAAALocalLoginDateTime | 1.3.6.1.4.1.9.6.1.101.79.46.1.6 | DisplayString | read-only | Date and time in the SysLog Format: DD-MMM-YYYY HH:MM:SS |
| rlAAALocalLoginHistEntry | 1.3.6.1.4.1.9.6.1.101.79.46.1 | not-accessible | The row definition for this table. | |
| U32 rlAAALocalLoginHistIndex | 1.3.6.1.4.1.9.6.1.101.79.46.1.2 | Unsigned32 | not-accessible | Index in History for specific user. Lower number means more recent login. |
| STR rlAAALocalLoginHistInetDateTime | 1.3.6.1.4.1.9.6.1.101.79.58.1.8 | DisplayString | read-only | Date and time in the SysLog Format: DD-MMM-YYYY HH:MM:SS |
| rlAAALocalLoginHistInetEntry | 1.3.6.1.4.1.9.6.1.101.79.58.1 | not-accessible | The row definition for this table. | |
| U32 rlAAALocalLoginHistInetIndex | 1.3.6.1.4.1.9.6.1.101.79.58.1.2 | Unsigned32 | not-accessible | Index in History for specific user. Lower number means more recent login. |
| IP rlAAALocalLoginHistInetLocalIpAddress | 1.3.6.1.4.1.9.6.1.101.79.58.1.7 | InetAddress | read-only | local Ip Address on login. |
| IPt rlAAALocalLoginHistInetLocalIpAddressType | 1.3.6.1.4.1.9.6.1.101.79.58.1.6 | InetAddressType | read-only | local Ip Address Type on login. |
| U32 rlAAALocalLoginHistInetMrid | 1.3.6.1.4.1.9.6.1.101.79.58.1.9 | Unsigned32 | read-only | Mrid - indicates to which instance the connection was established |
| STR rlAAALocalLoginHistInetName | 1.3.6.1.4.1.9.6.1.101.79.58.1.1 | DisplayString | read-only | User Name |
| IP rlAAALocalLoginHistInetRemoteIpAddress | 1.3.6.1.4.1.9.6.1.101.79.58.1.5 | InetAddress | read-only | User remote IP address. |
| IPt rlAAALocalLoginHistInetRemoteIpAddressType | 1.3.6.1.4.1.9.6.1.101.79.58.1.4 | InetAddressType | read-only | User remote IP address Type. |
| RLA rlAAALocalLoginHistInetServiceType | 1.3.6.1.4.1.9.6.1.101.79.58.1.3 | RlAAAServiceType | read-only | The service that the user uses. Service don't care is console terminal. |
| rlAAALocalLoginHistInetTable | 1.3.6.1.4.1.9.6.1.101.79.58 | not-accessible | The table holds successful login history for all users. This table is read-only. it coexist with rlAAALocalLoginHistTable to support IPv4 and IPv6 | |
| IP rlAAALocalLoginHistLocalIpAddress | 1.3.6.1.4.1.9.6.1.101.79.46.1.5 | IpAddress | read-only | local Ip Address on login. |
| STR rlAAALocalLoginHistName | 1.3.6.1.4.1.9.6.1.101.79.46.1.1 | DisplayString | read-only | User Name |
| IP rlAAALocalLoginHistRemoteIpAddress | 1.3.6.1.4.1.9.6.1.101.79.46.1.4 | IpAddress | read-only | User remote IP address. |
| RLA rlAAALocalLoginHistServiceType | 1.3.6.1.4.1.9.6.1.101.79.46.1.3 | RlAAAServiceType | read-only | The service that the user uses. Service don't care is console terminal. |
| rlAAALocalLoginHistTable | 1.3.6.1.4.1.9.6.1.101.79.46 | not-accessible | The table holds successful login history for all users. This table is read-only. | |
| U32 rlAAALocalLoginMrid | 1.3.6.1.4.1.9.6.1.101.79.46.1.7 | Unsigned32 | read-only | Mrid - indicates to which instance the connection was established |
| STR rlAAALocalPasswordCreationDate | 1.3.6.1.4.1.9.6.1.101.79.17.1.9 | DisplayString | read-only | The date on which the current password was created. Otherwise zero size string |
| STR rlAAALocalPasswordExpieryDate | 1.3.6.1.4.1.9.6.1.101.79.17.1.8 | DisplayString | read-only | If User password aging is active, the date on which The current password will expire. Otherwise zero size string |
| U32 rlAAALocalPasswordValidTime | 1.3.6.1.4.1.9.6.1.101.79.17.1.7 | Unsigned32 | read-write | The period of time in days, during which the password, is considered valid for login. Value of 0 means never expired. The actual range is product specific. After this time the system may allow limited number of logins to change the password. |
| STR rlAAALocalUserConfirmNewPassword | 1.3.6.1.4.1.9.6.1.101.79.68.1.4 | DisplayString | read-write | Local user new password for confirmation. |
| T/F rlAAALocalUserEnabled | 1.3.6.1.4.1.9.6.1.101.79.5 | TruthValue | read-write | Specifies whether AAA will use the local users table. When to use the table exactly depends on its position in the methods list. |
| rlAAALocalUserEntry | 1.3.6.1.4.1.9.6.1.101.79.17.1 | not-accessible | The row definition for this table. | |
| STR rlAAALocalUserName | 1.3.6.1.4.1.9.6.1.101.79.17.1.1 | DisplayString | read-write | Local User Name |
| STR rlAAALocalUserNameString | 1.3.6.1.4.1.9.6.1.101.79.68.1.1 | DisplayString | read-write | Local user name. |
| STR rlAAALocalUserPassword | 1.3.6.1.4.1.9.6.1.101.79.17.1.2 | DisplayString | read-write | Local User Password .The password can be null allowed formats: a. Display string starting with '$' for clear text b. Encrypted password: starts with # sign followed by 32 octets representing Hex Decimal value(in the 0-9 a-f A-F range) the $ and # as first octet are a directive to indicate what is the type of password and are not not part of it |
| rlAAALocalUserPasswordVerificationAndSettingEntry | 1.3.6.1.4.1.9.6.1.101.79.68.1 | not-accessible | The row of local user password verification and setting table. | |
| rlAAALocalUserPasswordVerificationAndSettingTable | 1.3.6.1.4.1.9.6.1.101.79.68 | not-accessible | The table specifies per every local user, old and new passwords. Serves for verification the old password and setting a new password. | |
| INT rlAAALocalUserPrivilage | 1.3.6.1.4.1.9.6.1.101.79.17.1.3 | INTEGER | read-write | Local User Privilage |
| STR rlAAALocalUserSettingNewPassword | 1.3.6.1.4.1.9.6.1.101.79.68.1.3 | DisplayString | read-write | Local user new password to be set. |
| T/F rlAAALocalUserSupported | 1.3.6.1.4.1.9.6.1.101.79.11 | TruthValue | read-only | This mib show whether the local users db is supported in AAA.If the value is false the local users db will not be used as an authentication and accounting method. If the value is true the local users db will be used by AAA for authentication and accounting method if the the AAA was configured to do so (by setting the appropriate mibs). |
| rlAAALocalUserTable | 1.3.6.1.4.1.9.6.1.101.79.17 | not-accessible | The table specifies all usernames, their passwords and their authorizations. | |
| STR rlAAALocalUserVerificationOldPassword | 1.3.6.1.4.1.9.6.1.101.79.68.1.2 | DisplayString | read-write | Local user old password to be verified. |
| rlAAALockedLineEntry | 1.3.6.1.4.1.9.6.1.101.79.53.1 | not-accessible | The row definition for this table. | |
| U32 rlAAALockedLineIfIndex | 1.3.6.1.4.1.9.6.1.101.79.53.1.2 | Unsigned32 | read-write | Identifies the ifindex for which this entry can be used. If index 0 means don't care (can be used for all if indices). For port type console the value could be only 0. |
| RLA rlAAALockedLinePortType | 1.3.6.1.4.1.9.6.1.101.79.53.1.1 | RlAAALinePortType | read-write | the physical port type . |
| RLA rlAAALockedLineServiceType | 1.3.6.1.4.1.9.6.1.101.79.53.1.3 | RlAAAServiceType | read-write | the service type |
| INT rlAAALockedLineStatus | 1.3.6.1.4.1.9.6.1.101.79.53.1.4 | INTEGER | read-write | The entry exists only if a line exist. Setting this field to value usable results in resetting the password failure counter, and unlock a locked user. |
| rlAAALockedLineTable | 1.3.6.1.4.1.9.6.1.101.79.53 | not-accessible | The table specifies lines statuses. Users cannot access the product from remote based on a password of the locked line. This table enables to unlock lines. | |
| INT rlAAAMaxNumLogAttmpts | 1.3.6.1.4.1.9.6.1.101.79.50 | INTEGER | read-write | The number of consecutive unsuccessful login attempts before user is locked. Value of 0 means no limit. The actual range is product specific. TIC requirement is 3. |
| rlAAAMethodListEntry | 1.3.6.1.4.1.9.6.1.101.79.15.1 | not-accessible | The row definition for this table. | |
| STR rlAAAMethodListName | 1.3.6.1.4.1.9.6.1.101.79.15.1.1 | DisplayString | read-write | Line Method List Name |
| ROW rlAAAMethodListStatus | 1.3.6.1.4.1.9.6.1.101.79.15.1.9 | RowStatus | read-write | method list status can be destroy or createAndGo |
| rlAAAMethodListTable | 1.3.6.1.4.1.9.6.1.101.79.15 | not-accessible | The table specifies all methods list per method name. | |
| RLA rlAAAMethodType1 | 1.3.6.1.4.1.9.6.1.101.79.15.1.2 | RlAAAMethodtype | read-write | first method type that will be used in the method linked list. |
| RLA rlAAAMethodType2 | 1.3.6.1.4.1.9.6.1.101.79.15.1.3 | RlAAAMethodtype | read-write | second method type that will be used in the method linked list. |
| RLA rlAAAMethodType3 | 1.3.6.1.4.1.9.6.1.101.79.15.1.4 | RlAAAMethodtype | read-write | 3th method type that will be used in the method linked list. |
| RLA rlAAAMethodType4 | 1.3.6.1.4.1.9.6.1.101.79.15.1.5 | RlAAAMethodtype | read-write | 4th method type that will be used in the method linked list. |
| RLA rlAAAMethodType5 | 1.3.6.1.4.1.9.6.1.101.79.15.1.6 | RlAAAMethodtype | read-write | 5th method type that will be used in the method linked list. |
| RLA rlAAAMethodType6 | 1.3.6.1.4.1.9.6.1.101.79.15.1.7 | RlAAAMethodtype | read-write | 6th method type that will be used in the method linked list. |
| RLA rlAAAMethodType7 | 1.3.6.1.4.1.9.6.1.101.79.15.1.8 | RlAAAMethodtype | read-write | 7th method type that will be used in the method linked list. |
| INT rlAAAMibVersion | 1.3.6.1.4.1.9.6.1.101.79.1 | INTEGER | read-only | MIB's version, the current version is 3. The difference in rlAAACreationDateSystemPasswordLevel15 and rlAAALocalUserEntry. |
| INT rlAAAMinPasswordLength | 1.3.6.1.4.1.9.6.1.101.79.42 | INTEGER | read-write | The minimum length of password for local user authentication defined in field rlAAALocalUserPassword in rlAAALocalUserTable. The value applies only to new or updated user passwords. In actual implementation the range may be reduced to (0 | N-64), where N is a platform dependent (for TIC compatibility N=8) |
| INT rlAAAPasswordComplexityCharRepeat | 1.3.6.1.4.1.9.6.1.101.79.64 | INTEGER | read-write | Indicates that no character in new password can't be repeated more than 3 times if password complexity enabled. |
| T/F rlAAAPasswordComplexityEnabled | 1.3.6.1.4.1.9.6.1.101.79.61 | TruthValue | read-write | Specifies whether password complexity rules must be applied. |
| INT rlAAAPasswordComplexityMinCharClasses | 1.3.6.1.4.1.9.6.1.101.79.62 | INTEGER | read-write | Indicates minimal number of character classes from which the password should contain characters if password complexity enabled. charater classes are : lower case, upper case, digits, special characters. |
| T/F rlAAAPasswordComplexityNotManufacturerEnabled | 1.3.6.1.4.1.9.6.1.101.79.66 | TruthValue | read-write | Specifies whether new password can be as same as manufacturer name if password complexity enabled. |
| T/F rlAAAPasswordComplexityNotOldPasswordEnabled | 1.3.6.1.4.1.9.6.1.101.79.63 | TruthValue | read-write | Specifies whether new password can be as same as old password if password complexity enabled. |
| T/F rlAAAPasswordComplexityNotUserNameEnabled | 1.3.6.1.4.1.9.6.1.101.79.65 | TruthValue | read-write | Specifies whether new password can be as same as user name if password complexity enabled. |
| INT rlAAAPasswordGlobalAgingTime | 1.3.6.1.4.1.9.6.1.101.79.67 | INTEGER | read-write | Determines whether password aging should be applied. Tic doesn't have to be enabled. If == 0 then aging is disabled. Note: Actual aging will not be enabled if system doesn't have real time clock until, clock is set either by user or SNTP. |
| U32 rlAAAPasswordHistHoldTime | 1.3.6.1.4.1.9.6.1.101.79.44 | Unsigned32 | read-write | The time in day, which an old password may be used in password history check. Changing the value does not cause the loss of history. |
| U32 rlAAAPasswordHistSize | 1.3.6.1.4.1.9.6.1.101.79.43 | Unsigned32 | read-write | The number of most recent password, previously defined for Local User Table, Line Table, System Password Table for specific entity. This list used for password reusing prevention. Value of 0 means none. Changing the value does not cause the loss of history. History Max size is product specific. |
| T/F rlAAAPasswordRecoveryDisable | 1.3.6.1.4.1.9.6.1.101.79.70 | TruthValue | read-write | if this MIB is set to TRUE then when user will use 'password Recovery' to the device , the configuration will automatically be erased. |
| T/F rlAAARadiusEnabled | 1.3.6.1.4.1.9.6.1.101.79.3 | TruthValue | read-write | Specifies whether AAA will use Radius. When to use Radius exactly depends on its position in the methods list. |
| T/F rlAAARadiusSupported | 1.3.6.1.4.1.9.6.1.101.79.9 | TruthValue | read-only | This mib show whether Radius is supported in AAA. If the value is false Radius will not be used as an authentication and accounting method. If the value is true Radius will be used by AAA for authentication and accounting if the the AAA was configured to do so (by setting the appropriate mibs). |
| INT rlAAARetries | 1.3.6.1.4.1.9.6.1.101.79.2 | INTEGER | read-write | Determines the number of retries for each method (Radius, local passwords, local users table and tacacs). |
| RLA rlAAAServiceType | 1.3.6.1.4.1.9.6.1.101.79.16.1.3 | RlAAAServiceType | read-write | the service type |
| T/F rlAAASuccLoginWriteToFile | 1.3.6.1.4.1.9.6.1.101.79.45 | TruthValue | read-write | Controls whether successful logins are written to login file |
| C32 rlAAASysPassStatConsFailedLogins | 1.3.6.1.4.1.9.6.1.101.79.49.1.3 | Counter32 | read-only | Number of last consecutive failed logins |
| rlAAASysPassStatEntry | 1.3.6.1.4.1.9.6.1.101.79.49.1 | not-accessible | The row definition for this table. | |
| INT rlAAASysPassStatLevel | 1.3.6.1.4.1.9.6.1.101.79.49.1.1 | INTEGER | read-only | System password level |
| INT rlAAASysPassStatLockedState | 1.3.6.1.4.1.9.6.1.101.79.49.1.2 | INTEGER | read-only | System password locked status |
| STR rlAAASysPassStatPasswordExpieryDate | 1.3.6.1.4.1.9.6.1.101.79.49.1.5 | DisplayString | read-only | If System password aging is active, the date, on which the current password will expire. Otherwise zero size string |
| U32 rlAAASysPassStatPasswordValidTime | 1.3.6.1.4.1.9.6.1.101.79.49.1.4 | Unsigned32 | read-write | The period of time in days, during which the password, is considered valid for login. Value of 0 means never expired. The actual range is product specific. After this time the system may allow limited number of logins to change the password. |
| rlAAASysPassStatTable | 1.3.6.1.4.1.9.6.1.101.79.49 | not-accessible | The table specifies all system password and their security properties: is password locked due to wrong password, when and how it was locked or last unsuccessful login information, expiry date of the password. | |
| STR rlAAASystemLoginDateTime | 1.3.6.1.4.1.9.6.1.101.79.48.1.6 | DisplayString | read-only | Date and time in the SysLog Format: DD-MMM-YYYY HH:MM:SS |
| rlAAASystemLoginHistEntry | 1.3.6.1.4.1.9.6.1.101.79.48.1 | not-accessible | The row definition for this table. | |
| U32 rlAAASystemLoginHistIndex | 1.3.6.1.4.1.9.6.1.101.79.48.1.2 | Unsigned32 | not-accessible | Index in History for specific user. Lower number means more recent login. |
| STR rlAAASystemLoginHistInetDateTime | 1.3.6.1.4.1.9.6.1.101.79.60.1.8 | DisplayString | read-only | Date and time in the SysLog Format: DD-MMM-YYYY HH:MM:SS |
| rlAAASystemLoginHistInetEntry | 1.3.6.1.4.1.9.6.1.101.79.60.1 | not-accessible | The row definition for this table. | |
| U32 rlAAASystemLoginHistInetIndex | 1.3.6.1.4.1.9.6.1.101.79.60.1.2 | Unsigned32 | not-accessible | Index in History for specific user. Lower number means more recent login. |
| INT rlAAASystemLoginHistInetLevel | 1.3.6.1.4.1.9.6.1.101.79.60.1.1 | INTEGER | read-only | User Name |
| IP rlAAASystemLoginHistInetLocalInetAddress | 1.3.6.1.4.1.9.6.1.101.79.60.1.7 | InetAddress | read-only | local Ip Address on login. |
| IPt rlAAASystemLoginHistInetLocalInetAddressType | 1.3.6.1.4.1.9.6.1.101.79.60.1.6 | InetAddressType | read-only | local Ip Address Type on login. |
| U32 rlAAASystemLoginHistInetMrid | 1.3.6.1.4.1.9.6.1.101.79.60.1.9 | Unsigned32 | read-only | Mrid - indicates to which instance the connection was established |
| IP rlAAASystemLoginHistInetRemoteInetAddress | 1.3.6.1.4.1.9.6.1.101.79.60.1.5 | InetAddress | read-only | User remote IP address. |
| IPt rlAAASystemLoginHistInetRemoteInetAddressType | 1.3.6.1.4.1.9.6.1.101.79.60.1.4 | InetAddressType | read-only | User remote IP address Type. |
| RLA rlAAASystemLoginHistInetServiceType | 1.3.6.1.4.1.9.6.1.101.79.60.1.3 | RlAAAServiceType | read-only | The service that the user uses. Service don't care is console terminal. |
| rlAAASystemLoginHistInetTable | 1.3.6.1.4.1.9.6.1.101.79.60 | not-accessible | The table holds successful login history for system passwords. This table is read-only. it coexist with rlAAASystemLoginHistTable to support IPv4 and IPv6 | |
| INT rlAAASystemLoginHistLevel | 1.3.6.1.4.1.9.6.1.101.79.48.1.1 | INTEGER | read-only | User Name |
| IP rlAAASystemLoginHistLocalIpAddress | 1.3.6.1.4.1.9.6.1.101.79.48.1.5 | IpAddress | read-only | local Ip Address on login. |
| IP rlAAASystemLoginHistRemoteIpAddress | 1.3.6.1.4.1.9.6.1.101.79.48.1.4 | IpAddress | read-only | User remote IP address. |
| RLA rlAAASystemLoginHistServiceType | 1.3.6.1.4.1.9.6.1.101.79.48.1.3 | RlAAAServiceType | read-only | The service that the user uses. Service don't care is console terminal. |
| rlAAASystemLoginHistTable | 1.3.6.1.4.1.9.6.1.101.79.48 | not-accessible | The table holds successful login history for system passwords. This table is read-only. | |
| U32 rlAAASystemLoginMrid | 1.3.6.1.4.1.9.6.1.101.79.48.1.7 | Unsigned32 | read-only | Mrid - indicates to which instance the connection was established |
| STR rlAAASystemPasswordConfirmNewPassword | 1.3.6.1.4.1.9.6.1.101.79.54.1.4 | DisplayString | read-write | New system password to be confirmed. |
| T/F rlAAASystemPasswordEnabled | 1.3.6.1.4.1.9.6.1.101.79.6 | TruthValue | read-write | Specifies whether AAA will use the system password. When to use the passwords exactly depends on its position in the methods list. |
| STR rlAAASystemPasswordlevel1 | 1.3.6.1.4.1.9.6.1.101.79.18 | DisplayString | read-write | system Password for level 1. allowed formats: a. Display string starting with '$' for clear text b. Encrypted password: starts with # sign followed by 32 octets representing Hex Decimal value(in the 0-9 a-f A-F range) the $ and # as first octet are a directive to indicate what is the type of password and are not not part of it |
| STR rlAAASystemPasswordlevel10 | 1.3.6.1.4.1.9.6.1.101.79.27 | DisplayString | read-write | system Password for level 10 allowed formats: a. Display string starting with '$' for clear text b. Encrypted password: starts with # sign followed by 32 octets representing Hex Decimal value(in the 0-9 a-f A-F range) the $ and # as first octet are a directive to indicate what is the type of password and are not not part of it |
| STR rlAAASystemPasswordlevel11 | 1.3.6.1.4.1.9.6.1.101.79.28 | DisplayString | read-write | system Password for level 11 allowed formats: a. Display string starting with '$' for clear text b. Encrypted password: starts with # sign followed by 32 octets representing Hex Decimal value(in the 0-9 a-f A-F range) the $ and # as first octet are a directive to indicate what is the type of password and are not not part of it |
| STR rlAAASystemPasswordlevel12 | 1.3.6.1.4.1.9.6.1.101.79.29 | DisplayString | read-write | system Password for level 12 allowed formats: a. Display string starting with '$' for clear text b. Encrypted password: starts with # sign followed by 32 octets representing Hex Decimal value(in the 0-9 a-f A-F range) the $ and # as first octet are a directive to indicate what is the type of password and are not not part of it |
| STR rlAAASystemPasswordlevel13 | 1.3.6.1.4.1.9.6.1.101.79.30 | DisplayString | read-write | system Password for level 13 allowed formats: a. Display string starting with '$' for clear text b. Encrypted password: starts with # sign followed by 32 octets representing Hex Decimal value(in the 0-9 a-f A-F range) the $ and # as first octet are a directive to indicate what is the type of password and are not not part of it |
| STR rlAAASystemPasswordlevel14 | 1.3.6.1.4.1.9.6.1.101.79.31 | DisplayString | read-write | system Password for level 14 allowed formats: a. Display string starting with '$' for clear text b. Encrypted password: starts with # sign followed by 32 octets representing Hex Decimal value(in the 0-9 a-f A-F range) the $ and # as first octet are a directive to indicate what is the type of password and are not not part of it |
| STR rlAAASystemPasswordlevel15 | 1.3.6.1.4.1.9.6.1.101.79.32 | DisplayString | read-write | system Password for level 15 allowed formats: a. Display string starting with '$' for clear text b. Encrypted password: starts with # sign followed by 32 octets representing Hex Decimal value(in the 0-9 a-f A-F range) the $ and # as first octet are a directive to indicate what is the type of password and are not part of it |
| STR rlAAASystemPasswordlevel2 | 1.3.6.1.4.1.9.6.1.101.79.19 | DisplayString | read-write | system Password for level 2 allowed formats: a. Display string starting with '$' for clear text b. Encrypted password: starts with # sign followed by 32 octets representing Hex Decimal value(in the 0-9 a-f A-F range) the $ and # as first octet are a directive to indicate what is the type of password and are not not part of it |
| STR rlAAASystemPasswordlevel3 | 1.3.6.1.4.1.9.6.1.101.79.20 | DisplayString | read-write | system Password for level 3 allowed formats: a. Display string starting with '$' for clear text b. Encrypted password: starts with # sign followed by 32 octets representing Hex Decimal value(in the 0-9 a-f A-F range) the $ and # as first octet are a directive to indicate what is the type of password and are not not part of it |
| STR rlAAASystemPasswordlevel4 | 1.3.6.1.4.1.9.6.1.101.79.21 | DisplayString | read-write | system Password for level 4 allowed formats: a. Display string starting with '$' for clear text b. Encrypted password: starts with # sign followed by 32 octets representing Hex Decimal value(in the 0-9 a-f A-F range) the $ and # as first octet are a directive to indicate what is the type of password and are not not part of it |
| STR rlAAASystemPasswordlevel5 | 1.3.6.1.4.1.9.6.1.101.79.22 | DisplayString | read-write | system Password for level 5 allowed formats: a. Display string starting with '$' for clear text b. Encrypted password: starts with # sign followed by 32 octets representing Hex Decimal value(in the 0-9 a-f A-F range) the $ and # as first octet are a directive to indicate what is the type of password and are not not part of it |
| STR rlAAASystemPasswordlevel6 | 1.3.6.1.4.1.9.6.1.101.79.23 | DisplayString | read-write | system Password for level 6 allowed formats: a. Display string starting with '$' for clear text b. Encrypted password: starts with # sign followed by 32 octets representing Hex Decimal value(in the 0-9 a-f A-F range) the $ and # as first octet are a directive to indicate what is the type of password and are not not part of it |
| STR rlAAASystemPasswordlevel7 | 1.3.6.1.4.1.9.6.1.101.79.24 | DisplayString | read-write | system Password for level 7 allowed formats: a. Display string starting with '$' for clear text b. Encrypted password: starts with # sign followed by 32 octets representing Hex Decimal value(in the 0-9 a-f A-F range) the $ and # as first octet are a directive to indicate what is the type of password and are not not part of it |
| STR rlAAASystemPasswordlevel8 | 1.3.6.1.4.1.9.6.1.101.79.25 | DisplayString | read-write | system Password for level 8 allowed formats: a. Display string starting with '$' for clear text b. Encrypted password: starts with # sign followed by 32 octets representing Hex Decimal value(in the 0-9 a-f A-F range) the $ and # as first octet are a directive to indicate what is the type of password and are not not part of it |
| STR rlAAASystemPasswordlevel9 | 1.3.6.1.4.1.9.6.1.101.79.26 | DisplayString | read-write | system Password for level 9 allowed formats: a. Display string starting with '$' for clear text b. Encrypted password: starts with # sign followed by 32 octets representing Hex Decimal value(in the 0-9 a-f A-F range) the $ and # as first octet are a directive to indicate what is the type of password and are not not part of it |
| STR rlAAASystemPasswordSettingNewPassword | 1.3.6.1.4.1.9.6.1.101.79.54.1.3 | DisplayString | read-write | New system password to be set. |
| INT rlAAASystemPasswordSettingPrivilegeLevel | 1.3.6.1.4.1.9.6.1.101.79.54.1.1 | INTEGER | not-accessible | System password Privelege Level to be set. |
| T/F rlAAASystemPasswordSupported | 1.3.6.1.4.1.9.6.1.101.79.12 | TruthValue | read-only | This mib show whether system password is supported in AAA. If the value is false system password will not be used as an authentication and accounting method. If the value is true the system password will be used by AAA for authentication and accounting method if the the AAA was configured to do so (by setting the appropriate mibs). |
| rlAAASystemPasswordVerificationAndSettingEntry | 1.3.6.1.4.1.9.6.1.101.79.54.1 | not-accessible | The row of system password verification and setting table. | |
| rlAAASystemPasswordVerificationAndSettingTable | 1.3.6.1.4.1.9.6.1.101.79.54 | not-accessible | The table specifies per every system level, old and new passwords. Serves for verification the old password and setting a new password. | |
| STR rlAAASystemPasswordVerificationOldPassword | 1.3.6.1.4.1.9.6.1.101.79.54.1.2 | DisplayString | read-write | Old system password to be verified. |
| T/F rlAAATacacsEnabled | 1.3.6.1.4.1.9.6.1.101.79.4 | TruthValue | read-write | Specifies whether AAA will use Tacacs. When to use Tacacs exactly depends on its position in the methods list. |
| T/F rlAAATacacsSupported | 1.3.6.1.4.1.9.6.1.101.79.10 | TruthValue | read-only | This mib show whether Tacacs+ is supported in AAA. If the value is false Tacacs+ will not be used as an authentication and accounting method. If the value is true Tacacs+ will be used by AAA for authentication and accounting if the the AAA was configured to do so (by setting the appropriate mibs). |
| rlAAATest | 1.3.6.1.4.1.9.6.1.101.79.34 | |||
| INT rlAAATestIfIndex | 1.3.6.1.4.1.9.6.1.101.79.34.2.1.3 | INTEGER | read-write | line ifIndex can configue to be zero witch means Don't-care value |
| INT rlAAATestPassword | 1.3.6.1.4.1.9.6.1.101.79.34.1 | INTEGER | read-write | This variable enables the user supplying the correct code to use the AAA test feature. |
| RLA rlAAATestPortType | 1.3.6.1.4.1.9.6.1.101.79.34.2.1.2 | RlAAALinePortType | read-write | the physical port type . |
| RLA rlAAATestServiceType | 1.3.6.1.4.1.9.6.1.101.79.34.2.1.4 | RlAAAServiceType | read-write | the service type |
| INT rlAAATestUserAuthenticationAction | 1.3.6.1.4.1.9.6.1.101.79.34.2.1.6 | INTEGER | read-write | By setting this field the process moves from one state to another. On creation the value must be begin. When the value of rlAAATestUserAuthenticationStatus is needPassword the value can be set to receivePassword or abort. When the value of rlAAATestUserAuthenticationStatus is needUsername the value can be set to receiveUsername or abort. When the value of rlAAATestUserAuthenticationStatus is success or failure the value can be set to delete or abort. When the value of rlAAATestUserAuthenticationStatus is aborted the value can be set to delete. When the value of rlAAATestUserAuthenticationStatus is deleted the value can not be set to any value. When the value of rlAAATestUserAuthenticationStatus is waiting the value can be set or abort. |
| INT rlAAATestUserAuthenticationStatus | 1.3.6.1.4.1.9.6.1.101.79.34.2.1.5 | INTEGER | read-only | Shows the ststus of the operation and what is expected from the 'user'. |
| rlAAATestUserEntry | 1.3.6.1.4.1.9.6.1.101.79.34.2.1 | not-accessible | The row definition for this table. | |
| U32 rlAAATestUserIndex | 1.3.6.1.4.1.9.6.1.101.79.34.2.1.1 | Unsigned32 | read-write | User entry index (the number is used just to identify the user). |
| STR rlAAATestUserInput | 1.3.6.1.4.1.9.6.1.101.79.34.2.1.7 | DisplayString | read-write | If the acion was set to receivePassword than this field should hold the value of the password. If the action was set to receiveUsername than this field should hold the value of the username. |
| ROW rlAAATestUserStatus | 1.3.6.1.4.1.9.6.1.101.79.34.2.1.8 | RowStatus | read-write | Entry status. The entry can not be deleted. It will be deleted if unchanged more than 2 minutes. |
| rlAAATestUserTable | 1.3.6.1.4.1.9.6.1.101.79.34.2 | not-accessible | This table enables a user to perform a simulation of authentiction. | |
| INT rlAAAUnlockSystemPassword | 1.3.6.1.4.1.9.6.1.101.79.52 | INTEGER | read-write | An action MIB variable setting with value of Level will unlock the system password for this level. The value of this variable is not saved to non volatile storage. Read of this variable always returns zero. Zero (0) does no action. |
| STR rlAAAUnlockUserName | 1.3.6.1.4.1.9.6.1.101.79.51 | DisplayString | read-write | An action MIB variable setting with value of Local User Name will unlock this user. The value of this variable is not saved to non volatile storage. Read of this variable always returns zero length display string. |
| rlAAAUserEntry | 1.3.6.1.4.1.9.6.1.101.79.33.1 | not-accessible | The row definition for this table. | |
| U32 rlAAAUserIfIndex | 1.3.6.1.4.1.9.6.1.101.79.33.1.6 | Unsigned32 | read-only | User if index. |
| U32 rlAAAUserIndex | 1.3.6.1.4.1.9.6.1.101.79.33.1.1 | Unsigned32 | not-accessible | User Index |
| rlAAAUserInetEntry | 1.3.6.1.4.1.9.6.1.101.79.57.1 | not-accessible | The row definition for this table. | |
| U32 rlAAAUserInetIfIndex | 1.3.6.1.4.1.9.6.1.101.79.57.1.7 | Unsigned32 | read-only | User if index. |
| U32 rlAAAUserInetIndex | 1.3.6.1.4.1.9.6.1.101.79.57.1.1 | Unsigned32 | not-accessible | User Index |
| U32 rlAAAUserInetLevel | 1.3.6.1.4.1.9.6.1.101.79.57.1.6 | Unsigned32 | read-only | User level |
| DAT rlAAAUserInetLoginDate | 1.3.6.1.4.1.9.6.1.101.79.57.1.8 | DateAndTime | read-only | Date of use creation. |
| U32 rlAAAUserInetLoginDurationMS | 1.3.6.1.4.1.9.6.1.101.79.57.1.9 | Unsigned32 | read-only | Time in MS since user login. |
| STR rlAAAUserInetName | 1.3.6.1.4.1.9.6.1.101.79.57.1.5 | DisplayString | read-only | User Name |
| IP rlAAAUserInetRemoteIpAddress | 1.3.6.1.4.1.9.6.1.101.79.57.1.4 | InetAddress | read-only | User remote INET address. |
| IPt rlAAAUserInetRemoteIpAddressType | 1.3.6.1.4.1.9.6.1.101.79.57.1.3 | InetAddressType | read-only | User remote INET address Type. |
| RLA rlAAAUserInetServiceType | 1.3.6.1.4.1.9.6.1.101.79.57.1.2 | RlAAAServiceType | read-only | The service that the user uses. Service dont care is console terminal. |
| rlAAAUserInetTable | 1.3.6.1.4.1.9.6.1.101.79.57 | not-accessible | The table holds all current users that have been authenticated. it coexist with rlAAAUserTable to support IPv4 and IPv6 | |
| U32 rlAAAUserLevel | 1.3.6.1.4.1.9.6.1.101.79.33.1.5 | Unsigned32 | read-only | User level |
| DAT rlAAAUserLoginDate | 1.3.6.1.4.1.9.6.1.101.79.33.1.7 | DateAndTime | read-only | Date of use creation. |
| U32 rlAAAUserLoginDurationMS | 1.3.6.1.4.1.9.6.1.101.79.33.1.8 | Unsigned32 | read-only | Time in MS since user login. |
| STR rlAAAUserName | 1.3.6.1.4.1.9.6.1.101.79.33.1.4 | DisplayString | read-only | User Name |
| IP rlAAAUserRemoteIpAddress | 1.3.6.1.4.1.9.6.1.101.79.33.1.3 | IpAddress | read-only | User remote IP address. |
| RLA rlAAAUserServiceType | 1.3.6.1.4.1.9.6.1.101.79.33.1.2 | RlAAAServiceType | read-only | The service that the user uses. Service dont care is console terminal. |
| rlAAAUserTable | 1.3.6.1.4.1.9.6.1.101.79.33 | not-accessible | The table holds all current users that have been authenticated. | |
| INT rlRadiusGlobalDefaultDeadtime | 1.3.6.1.4.1.9.6.1.101.80.4 | INTEGER | read-write | Number of minutes that any RADIUS server is ignored after it has failed. This MIB is used if the value of the field rlRadiusServerUseGlobalDefaultDeadtime is false. |
| STR rlRadiusGlobalDefaultKey | 1.3.6.1.4.1.9.6.1.101.80.5 | DisplayString | read-write | Secret key to be shared with this RADIUS server. This MIB is used if the value of the field rlRadiusServerUseGlobalDefaultKey is false. |
| INT rlRadiusGlobalDefaultRetries | 1.3.6.1.4.1.9.6.1.101.80.3 | INTEGER | read-write | The number of times to try contacting this RADIUS server. This MIB is used if the value of the field rlRadiusServerUseGlobalDefaultRetries is false. |
| IP rlRadiusGlobalDefaultSource | 1.3.6.1.4.1.9.6.1.101.80.6 | IpAddress | read-write | IPv4 address of the interface to use with this server. A value of 0.0.0.0 for this object disables source address specification. This MIB is used if the value of the field rlRadiusServerUseGlobalDefaultSource is false. |
| INT rlRadiusGlobalDefaultTimeout | 1.3.6.1.4.1.9.6.1.101.80.2 | INTEGER | read-write | The maximum time (in seconds) to wait for this RADIUS server to reply. This MIB is used if the value of the field rlRadiusServerUseGlobalDefaultTimeout is false. |
| ADR rlRadiusGlobalIPv6DefaultSource | 1.3.6.1.4.1.9.6.1.101.80.9 | InetAddressIPv6 | read-write | IPv6 address of the interface to use with this server. A NULL value for this object disables source address specification. |
| INT rlRadiusMibVersion | 1.3.6.1.4.1.9.6.1.101.80.1 | INTEGER | read-only | MIB's version, the current version is 2. 1 - original version. 2 - field rlRadiusServerUsage was added to rlRadiusServerEntry |
| INT rlRadiusServerAcctPortNumber | 1.3.6.1.4.1.9.6.1.101.80.7.1.3 | INTEGER | read-write | The UDP port the client is using to send accounting requests to this server. |
| IP rlRadiusServerAddress | 1.3.6.1.4.1.9.6.1.101.80.7.1.1 | IpAddress | read-write | The IP address of the RADIUS server referred to in this table entry. |
| INT rlRadiusServerAuthPortNumber | 1.3.6.1.4.1.9.6.1.101.80.7.1.2 | INTEGER | read-write | The UDP port the client is using to send authentication requests to this server. |
| INT rlRadiusServerDeadtime | 1.3.6.1.4.1.9.6.1.101.80.7.1.6 | INTEGER | read-write | Number of minutes that any RADIUS server is ignored after it has failed. Value of 2001 means that rlRadiusGlobalDefaultDeadtime will be used. |
| rlRadiusServerEntry | 1.3.6.1.4.1.9.6.1.101.80.7.1 | not-accessible | An entry (conceptual row) representing a RADIUS server with which the client shares a secret. | |
| INT rlRadiusServerInetAcctPortNumber | 1.3.6.1.4.1.9.6.1.101.80.8.1.4 | INTEGER | read-write | The UDP port the client is using to send accounting requests to this server.The zero value can be used only if rlRadiusServerInetAuthPortNumber value is not zero. |
| IP rlRadiusServerInetAddress | 1.3.6.1.4.1.9.6.1.101.80.8.1.2 | InetAddress | read-write | The Inet address of the RADIUS server referred to in this table entry.Only one instance of specified address can be added at the same time. |
| IPt rlRadiusServerInetAddressType | 1.3.6.1.4.1.9.6.1.101.80.8.1.1 | InetAddressType | read-write | The Inet address type of RADIUS server reffered to in this table entry .IPv6Z type is not supported. |
| INT rlRadiusServerInetAuthPortNumber | 1.3.6.1.4.1.9.6.1.101.80.8.1.3 | INTEGER | read-write | The UDP port the client is using to send authentication requests to this server.The zero value can be used only if rlRadiusServerInetAcctPortNumber value is not zero. |
| INT rlRadiusServerInetDeadtime | 1.3.6.1.4.1.9.6.1.101.80.8.1.7 | INTEGER | read-write | Number of minutes that any RADIUS server is ignored after it has failed. Value of 2001 means that rlRadiusGlobalDefaultDeadtime will be used. |
| rlRadiusServerInetEntry | 1.3.6.1.4.1.9.6.1.101.80.8.1 | not-accessible | An entry (conceptual row) representing a RADIUS server with which the client shares a secret. | |
| STR rlRadiusServerInetKey | 1.3.6.1.4.1.9.6.1.101.80.8.1.9 | DisplayString | read-write | Secret key to be shared with this RADIUS server. |
| TIM rlRadiusServerInetLastResponseTime | 1.3.6.1.4.1.9.6.1.101.80.8.1.15 | TimeStamp | read-only | The value of sysUpTime at the time this server has response. If there is no request to the server, this object contains a zero value. |
| INT rlRadiusServerInetPriority | 1.3.6.1.4.1.9.6.1.101.80.8.1.12 | INTEGER | read-write | Determines the order in which the servers will be used, when 0 is the highest priority. If more than one server share the same priority - they will be used in lexicgoraphic order (the order of entries in this table). |
| INT rlRadiusServerInetRetries | 1.3.6.1.4.1.9.6.1.101.80.8.1.6 | INTEGER | read-write | The number of times to try contacting this RADIUS server. Value of 0 means that rlRadiusGlobalDefaultRetries. |
| IP rlRadiusServerInetSource | 1.3.6.1.4.1.9.6.1.101.80.8.1.11 | InetAddress | read-write | Inet address of the interface to use with this server. To provide backward compatibility the value of 0.0.0.0 for this object will be used to disables source address specification. Default value of 255.255.255.255 means that rlRadiusGlobalDefaultSource will be used for Ipv4 servers and rlRadiusIPv6GlobalDefaultSource will be used for Ipv6 servers.IPv6Z type not supported. Only valid IP address will be used. Application will set default value. |
| IPt rlRadiusServerInetSourceType | 1.3.6.1.4.1.9.6.1.101.80.8.1.10 | InetAddressType | read-write | The rlRadiusServerInetSource address type. IPv6Z type not supported |
| ROW rlRadiusServerInetStatus | 1.3.6.1.4.1.9.6.1.101.80.8.1.13 | RowStatus | read-write | |
| rlRadiusServerInetTable | 1.3.6.1.4.1.9.6.1.101.80.8 | not-accessible | The (conceptual) table listing the RADIUS servers with which the cliient shares a secret. | |
| INT rlRadiusServerInetTimeout | 1.3.6.1.4.1.9.6.1.101.80.8.1.5 | INTEGER | read-write | The maximum time (in seconds) to wait for this RADIUS server to reply. Value of 0 means that rlRadiusGlobalDefaultTimeout. |
| INT rlRadiusServerInetUsage | 1.3.6.1.4.1.9.6.1.101.80.8.1.14 | INTEGER | read-write | Determines actions for which the radius server will be used. WirelessAuthentication will be used if wireless is supported. |
| T/F rlRadiusServerInetUseGlobalDefaultKey | 1.3.6.1.4.1.9.6.1.101.80.8.1.8 | TruthValue | read-write | If this field is set to true the value in field rlRadiusServerKey is ignored and instead the value in the MIB rlRadiusGlobalDefaultKey is used. Otherwise the value in rlRadiusServerKey is used. |
| STR rlRadiusServerKey | 1.3.6.1.4.1.9.6.1.101.80.7.1.8 | DisplayString | read-write | Secret key to be shared with this RADIUS server. |
| INT rlRadiusServerPriority | 1.3.6.1.4.1.9.6.1.101.80.7.1.10 | INTEGER | read-write | Determines the order in which the servers will be used, when 0 is the highest priority. If more than one server share the same priority - they will be used in lexicgoraphic order (the order of entries in this table). |
| INT rlRadiusServerRetries | 1.3.6.1.4.1.9.6.1.101.80.7.1.5 | INTEGER | read-write | The number of times to try contacting this RADIUS server. Value of 0 means that rlRadiusGlobalDefaultRetries. |
| IP rlRadiusServerSource | 1.3.6.1.4.1.9.6.1.101.80.7.1.9 | IpAddress | read-write | IP address of the interface to use with this server. A value of 0.0.0.0 for this object disables source address specification. Default value of 255.255.255.255 means that rlRadiusGlobalDefaultSource will be used. |
| ROW rlRadiusServerStatus | 1.3.6.1.4.1.9.6.1.101.80.7.1.11 | RowStatus | read-write | |
| rlRadiusServerTable | 1.3.6.1.4.1.9.6.1.101.80.7 | not-accessible | The (conceptual) table listing the RADIUS servers with which the cliient shares a secret. | |
| INT rlRadiusServerTimeout | 1.3.6.1.4.1.9.6.1.101.80.7.1.4 | INTEGER | read-write | The maximum time (in seconds) to wait for this RADIUS server to reply. Value of 0 means that rlRadiusGlobalDefaultTimeout. |
| INT rlRadiusServerUsage | 1.3.6.1.4.1.9.6.1.101.80.7.1.12 | INTEGER | read-write | Determines actions for which the radius server will be used. |
| T/F rlRadiusServerUseGlobalDefaultKey | 1.3.6.1.4.1.9.6.1.101.80.7.1.7 | TruthValue | read-write | If this field is set to true the value in field rlRadiusServerKey is ignored and instead the value in the MIB rlRadiusGlobalDefaultKey is used. Otherwise the value in rlRadiusServerKey is used. |
| rlTacacs | 1.3.6.1.4.1.9.6.1.101.79.40 | |||
| STR rlTacacsGlobalDefaultKey | 1.3.6.1.4.1.9.6.1.101.79.40.3 | DisplayString | read-write | Secret key to be shared with TACACS+ server. This MIB is used if the value of the field rlTacacsServerUseGlobalDefaultKey is false. |
| IP rlTacacsGlobalDefaultSourceIpInterface | 1.3.6.1.4.1.9.6.1.101.79.40.6 | IpAddress | read-write | IP address of the interface to use with TACACS+ server. A value of 0.0.0.0 for this object disables source address specification. This MIB is used if the value of the field rlTacacsServerSource is 255.255.255.255. |
| ADR rlTacacsGlobalDefaultSourceIPv6Interface | 1.3.6.1.4.1.9.6.1.101.79.40.8 | InetAddressIPv6 | read-write | IP address of the interface to use with TACACS+ server. A NULL for this object disables source address specification. This MIB is used if the value of the field rlTacacsServerInetSourceInterface is 255.255.255.255. |
| INT rlTacacsGlobalDefaultTimeout | 1.3.6.1.4.1.9.6.1.101.79.40.2 | INTEGER | read-write | The maximum time (in seconds) to wait for TACACS+ server to reply. This MIB is used if the value of the field rlTacacsServerTimeout is 0. |
| INT rlTacacsMibVersion | 1.3.6.1.4.1.9.6.1.101.79.40.1 | INTEGER | read-only | MIB's version, the current version is 1. |
| IP rlTacacsServerAddress | 1.3.6.1.4.1.9.6.1.101.79.40.7.1.1 | IpAddress | read-write | The IP address of the TACACS+ server referred to in this table entry. |
| RLT rlTacacsServerConnectionStatus | 1.3.6.1.4.1.9.6.1.101.79.40.7.1.4 | RlTacacsConnectionStatus | read-only | Specifies status TCP connection type between device and TACACS+ server. |
| RLT rlTacacsServerConnectionType | 1.3.6.1.4.1.9.6.1.101.79.40.7.1.3 | RlTacacsConnectionType | read-write | Specifies TCP connection type between device and TACACS+ server. Either a single open connection between device and server (rlTacacsSingleConnection), or open/close connection per communication session (rlTacacsPerSessionConnection). |
| rlTacacsServerEntry | 1.3.6.1.4.1.9.6.1.101.79.40.7.1 | not-accessible | An entry (conceptual row) representing a TACACS+ server with which the client shares a secret. | |
| IP rlTacacsServerInetAddress | 1.3.6.1.4.1.9.6.1.101.79.40.9.1.2 | InetAddress | read-write | The Inet Address address of the TACACS+ server referred to in this table entry. |
| IPt rlTacacsServerInetAddressType | 1.3.6.1.4.1.9.6.1.101.79.40.9.1.1 | InetAddressType | read-write | The Inet address type of TACACS+ server reffered to in this table entry .IPv6Z type is not supported. |
| RLT rlTacacsServerInetConnectionStatus | 1.3.6.1.4.1.9.6.1.101.79.40.9.1.5 | RlTacacsConnectionStatus | read-only | Specifies status TCP connection type between device and TACACS+ server. |
| RLT rlTacacsServerInetConnectionType | 1.3.6.1.4.1.9.6.1.101.79.40.9.1.4 | RlTacacsConnectionType | read-write | Specifies TCP connection type between device and TACACS+ server. Either a single open connection between device and server (rlTacacsSingleConnection), or open/close connection per communication session (rlTacacsPerSessionConnection). |
| rlTacacsServerInetEntry | 1.3.6.1.4.1.9.6.1.101.79.40.9.1 | not-accessible | An entry (conceptual row) representing a TACACS+ server with which the client shares a secret. | |
| STR rlTacacsServerInetKey | 1.3.6.1.4.1.9.6.1.101.79.40.9.1.8 | DisplayString | read-write | Secret key to be shared with this TACACS+ server. |
| INT rlTacacsServerInetPortNumber | 1.3.6.1.4.1.9.6.1.101.79.40.9.1.3 | INTEGER | read-write | The TCP port the client establishes connections with this server. |
| INT rlTacacsServerInetPriority | 1.3.6.1.4.1.9.6.1.101.79.40.9.1.11 | INTEGER | read-write | Determines the order in which the TACACS+ servers will be used, when 0 is the highest priority. If more than one server share the same priority - they will be used in lexicgoraphic order (the order of entries in this table). |
| ROW rlTacacsServerInetRowStatus | 1.3.6.1.4.1.9.6.1.101.79.40.9.1.12 | RowStatus | read-write | |
| IP rlTacacsServerInetSourceInterface | 1.3.6.1.4.1.9.6.1.101.79.40.9.1.10 | InetAddress | read-write | Inet address of the interface to use with this server. A value of NULL for this object disables source address specification for this server. A value of 255.255.255.255 maens that the global default rlTacacsGlobalDefaultSourceIpInterface or rlTacacsGlobalDefaultSourceIPv6Interface values are used. |
| IPt rlTacacsServerInetSourceInterfaceType | 1.3.6.1.4.1.9.6.1.101.79.40.9.1.9 | InetAddressType | read-write | The Inet address type of the interface to use with this server. |
| rlTacacsServerInetTable | 1.3.6.1.4.1.9.6.1.101.79.40.9 | not-accessible | The (conceptual) table listing the TACACS+ servers with which the cliient shares a secret. | |
| INT rlTacacsServerInetTimeout | 1.3.6.1.4.1.9.6.1.101.79.40.9.1.6 | INTEGER | read-write | The maximum time (in seconds) to wait for this TACACS+ server to reply. Value of 0 means that rlTacacsGlobalDefaultTimeout value is used. |
| T/F rlTacacsServerInetUseGlobalDefaultKey | 1.3.6.1.4.1.9.6.1.101.79.40.9.1.7 | TruthValue | read-write | If this field is set to true the value in field rlTacacsServerKey is ignored and instead the value in the MIB rlTacacsGlobalDefaultKey is used. Otherwise the value in rlTacacsServerKey is used. |
| STR rlTacacsServerKey | 1.3.6.1.4.1.9.6.1.101.79.40.7.1.7 | DisplayString | read-write | Secret key to be shared with this TACACS+ server. |
| INT rlTacacsServerPortNumber | 1.3.6.1.4.1.9.6.1.101.79.40.7.1.2 | INTEGER | read-write | The TCP port the client establishes connections with this server. |
| INT rlTacacsServerPriority | 1.3.6.1.4.1.9.6.1.101.79.40.7.1.9 | INTEGER | read-write | Determines the order in which the TACACS+ servers will be used, when 0 is the highest priority. If more than one server share the same priority - they will be used in lexicgoraphic order (the order of entries in this table). |
| ROW rlTacacsServerRowStatus | 1.3.6.1.4.1.9.6.1.101.79.40.7.1.10 | RowStatus | read-write | |
| IP rlTacacsServerSourceIpInterface | 1.3.6.1.4.1.9.6.1.101.79.40.7.1.8 | IpAddress | read-write | IP address of the interface to use with this server. A value of 0.0.0.0 for this object disables source address specification. Value of 255.255.255.255 means that rlTacacsGlobalDefaultSourceIpInterface will be used. |
| rlTacacsServerTable | 1.3.6.1.4.1.9.6.1.101.79.40.7 | not-accessible | The (conceptual) table listing the TACACS+ servers with which the cliient shares a secret. | |
| INT rlTacacsServerTimeout | 1.3.6.1.4.1.9.6.1.101.79.40.7.1.5 | INTEGER | read-write | The maximum time (in seconds) to wait for this TACACS+ server to reply. Value of 0 means that rlTacacsGlobalDefaultTimeout value is used. |
| T/F rlTacacsServerUseGlobalDefaultKey | 1.3.6.1.4.1.9.6.1.101.79.40.7.1.6 | TruthValue | read-write | If this field is set to true the value in field rlTacacsServerKey is ignored and instead the value in the MIB rlTacacsGlobalDefaultKey is used. Otherwise the value in rlTacacsServerKey is used. |
RFC description
Cisco Small Business (SB) vendor-private MIB for authentication, authorization, and accounting (AAA) configuration and status.
Start monitoring Cisco Small Business (SB) switches with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.