CISCOSB-AAA

MIB Reference — IPNetwork Monitor · Updated September 09, 2026

All MIBsCISCOSB-AAA

Organization: Cisco Small Business

Last Updated: 2010-06-21

Category: RADIUS and AAA, Vendor: RADLAN/Cisco SB

Description: Manages Cisco Small Business switch AAA (Authentication, Authorization, Accounting) configuration.

Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

What Is CISCOSB-AAA?

CISCOSB-AAA is a Cisco Small Business (formerly Linksys, "rl" tree) private MIB for configuring Authentication, Authorization, and Accounting (AAA) on small-business switches. It exposes configuration objects controlling whether RADIUS, TACACS+, local user database, system password, or line password authentication methods are enabled, along with related retry timers and fallback behavior such as an "always succeed" mode. Rather than hardware health, its monitoring value is primarily in security/configuration-state visibility: administrators can verify which authentication backends are active and supported on the device, confirm retry settings, and detect a risky fallback state. It has an implicit dependency on standard RADIUS/TACACS+ protocol concepts and coexists with the device's separate TACACS+-specific subtree. It is deployed on Cisco Small Business (Cisco SB) switches used in SMB network closets where centralized AAA is configured for administrative login control. Engineers can download the CISCOSB-AAA file directly to load it into their MIB browser.

IPNetwork Monitor allows you to monitor SNMP objects defined in CISCOSB-AAA. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • Cisco Small Business (Cisco SB) switches

Monitoring Examples

An administrator would poll rlAAARadiusEnabled and rlAAATacacsEnabled to confirm the intended authentication backend is active, and check rlAAARetries to ensure retry counts match policy. Discovering rlAAAAlwaysSuccessEnabled set to true would be a critical security finding since it means authentication is configured to always pass, and rlAAATest could be used to validate connectivity to a configured AAA server before relying on it in production.

What Can Be Monitored

  • enabled AAA authentication methods (RADIUS/TACACS+/local)
  • authentication retry count
  • always-succeed fallback state
  • system/line password authentication state
Imported Objects

From CISCOSB-MIB

rlAAAEapOBJECT-IDENTITY
rlRadiusOBJECT-IDENTITY
switch001MODULE-IDENTITY

From INET-ADDRESS-MIB

InetAddress
InetAddressIPv6
InetAddressType

From SNMPv2-SMI

Counter32
IpAddress
MODULE-IDENTITY
OBJECT-TYPE
Unsigned32

From SNMPv2-TC

DateAndTime
DisplayString
RowStatus
TEXTUAL-CONVENTION
TimeStamp
TruthValue

How to Use in IPNetwork Monitor

Example using rlAAALineConsFailedLogins OID:

Select a Cisco Small Business (SB) switch as the target host to create a monitor — the SNMP service should be up and running on it. Click New Monitor, then check SNMP Custom on the Favorites tab, click Next, and confirm the host. On the next page, click Select... to open the built-in SNMP MIB Browser and type rlAAALineConsFailedLogins into the Find box to locate it in the OID tree, selecting the specific row/instance you want to monitor since this is a table column, then select it and click OK. It reports the number of last consecutive failed logins. On the monitor's Main parameters page you can set the target's SNMP port (default 161), credentials, polling interval, and other settings — see the SNMP Monitor help for details. On the State conditions and Alerting tabs, configure when the monitor should change state and trigger an alert; since this is a Counter32-type OID, Value bounds is the most useful condition here — trigger an alert if the counter increases between polls, since a rising count of errors, failures, or discards often points to a real underlying problem. Click Finish to create the monitor; you can adjust any parameter later.
OIDs

RFC description

Cisco Small Business (SB) vendor-private MIB for authentication, authorization, and accounting (AAA) configuration and status.

Start monitoring Cisco Small Business (SB) switches with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download CISCOSB-AAA