All MIBs › CISCOSB-SSH-MIB
Organization: Cisco Small Business
Last Updated: 2003--0-1-
Category: VPN and Security, Vendor: RADLAN/Cisco SB
Description: Configures and monitors SSH server settings and active sessions on Cisco Small Business switches.
Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.
What Is CISCOSB-SSH-MIB?
CISCOSB-SSH-MIB is a Cisco Small Business private enterprise MIB that configures and monitors the SSH server on Cisco Small Business switches. It exposes SSH server host public key data, including per-algorithm key tables and key fingerprint tables, along with general SSH server and client configuration objects. Its monitoring role centers on software/service status: verifying the SSH server's host key material and fingerprint is correctly generated and unchanged (which would flag a re-keyed or compromised device) and confirming SSH client/server functionality is active as expected, rather than tracking hardware sensors. As a CISCOSB private MIB it typically sits alongside standard SNMPv3 security MIBs and other CISCOSB management MIBs on the same device rather than depending on a specific IETF SSH standard MIB. It is deployed on Cisco Small Business managed switches where SSH is used for secure remote CLI administration. Engineers can download the CISCOSB-SSH-MIB file directly to load it into their MIB browser.
IPNetwork Monitor allows you to monitor SNMP objects defined in CISCOSB-SSH-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.
Supported Devices
- Cisco Small Business switch
Monitoring Examples
An administrator would query rlSshServerHostPublicKeyTable and its rlSshServerHostPublicKeyFingerprintTable entries to confirm the SSH server's host key algorithm (rlSshServerHostPublicKeyAlgorithm) and fingerprint (rlSshServerHostPublicKeyFingerprint) match the expected, previously recorded value. An unexpected change in the fingerprint returned for a given rlSshServerHostPublicKeyFingerprintAlgorithm would indicate the device's SSH host key was regenerated, possibly after a factory reset or firmware reflash, which should trigger a certificate-pinning alert on management systems. rlSshServer and rlSshClient objects would also be checked to confirm SSH services remain enabled.
What Can Be Monitored
- SSH server enabled/disabled state
- SSH host public key algorithm
- SSH host key fingerprint
- SSH client status
This MIB depends on
Related MIBs
Imported Objects
From CISCOSB-MIB
| switch001 | MODULE-IDENTITY |
From INET-ADDRESS-MIB
| InetAddress | |
| InetAddressType |
From SNMPv2-SMI
| IpAddress | |
| MODULE-IDENTITY | |
| OBJECT-TYPE | |
| Unsigned32 |
From SNMPv2-TC
| DisplayString | |
| RowStatus | |
| TEXTUAL-CONVENTION |
OIDs
| OID symbolic | OID numeric | Type | Access | Description |
|---|---|---|---|---|
| rlSsh | 1.3.6.1.4.1.9.6.1.101.78 | The MIB module describes the private MIB for SSH supported by CISCOSB's software and products. | ||
| rlSshClient | 1.3.6.1.4.1.9.6.1.101.78.3 | |||
| INT rlSshClientAuthenticationMethod | 1.3.6.1.4.1.9.6.1.101.78.3.5 | INTEGER | read-write | Specifies the global authentication method for SSH client. SSH client will apply this authentication method upon connecting to a remote server, if no specific authentication method has been defined for this operation. |
| INT rlSshClientDefaultKeyFlag | 1.3.6.1.4.1.9.6.1.101.78.3.12 | INTEGER | read-only | This scalar indicates which of the SSH client keys are default keys (automatically generated). |
| RLS rlSshClientDeleteSelfKey | 1.3.6.1.4.1.9.6.1.101.78.3.8 | RlSshPublicKeyAlgorithm | read-write | Setting to a value other than 'none' results in deleting the client self key of the chosen type. |
| RLS rlSshClientImportExportSelfKeyAlgorithm | 1.3.6.1.4.1.9.6.1.101.78.3.9.1.1 | RlSshPublicKeyAlgorithm | not-accessible | Identifies the type of key pair. |
| rlSshClientImportExportSelfKeyEntry | 1.3.6.1.4.1.9.6.1.101.78.3.9.1 | not-accessible | The row definition for this table. | |
| INT rlSshClientImportExportSelfKeyFormat | 1.3.6.1.4.1.9.6.1.101.78.3.9.1.2 | INTEGER | not-accessible | Specifies the format of public/key pair. The following formats are supported for import/export: 1) uuencoded_format - in this format both private and public key are in uu-encoded format, and are seperated from one another by header and footer. An example of the concateneation of all fragments in this format is: -----BEGIN ENCRYPTED RSA PRIVATE KEY----- tDaNkZZoCxXfkLLsLDlZ6T9H8U4Gz637eRV7BYBpapkidAxY1UG0/qgfKLPkbId4wzht6ArV9bE4fMtX wSMOxL3q31pOmUdVhjbWYcgZQBDy1DjFSbuIEdP85c96B9bBE2nPv90mSvb/6j8R2NItT/KJeiYMtLtI N3m6/zESKJGIrX0jP1RFDjVZSS5chSAFgB0egsLZEyOQn7jAqpX/x/easD2J6F/OjPXlJ9Hff2tMb3NU QYyBoWH2J9IxhWB6Vo66R9Y04JGR18uL/rV2sMCtpg5ppkVTEpNTp9qE1yXocR2NmzUfNFap+GJ4IHj8 CzkVfmJM/kEWaJsYgHbAgLyRg4QVyelfobv1B71aQ+u1z9KGu/QajkWdR04OQfsGOL1CvU2LGYDcRjfH jv+jl/UkDRRjoD9kt2WvouT+OL6esvKl0OJBqWbGNXg9TWv/VLtJIwgUno+MLaJuOM4Fh44+wpnqUXwQ TFtBFc8pzt5BoOwbv9gXpicTkq4/+GhwXWXxSVFebKhnHAvKSLT+Ba7K7ZeR8EIIxbXdDNFOiS45R2KI jxxXLXK44u6KGl5MygCKXUOFlJ+Zhgrq6ZH17z/RVJQ2CWqb5Ekn9GY3kH9QZ3mb4MDPfriWi2lHGXHY JmJd4SLQhpBdnOS5tu84QmyU3dNbAdzghDsR+dEY/6g7Cn0kcVkeHNZ0H+mCZik5f6XBD8eplkk43bdR FrkwTeAjwurGcKwdiKkR4DlfSq3DKssVBucTqUpqsKqPXLwTIL44rWKhEPXgGPB2XDG0VLvIRKkAgEGI LNTwOm091Ro= -----END RSA PRIVATE KEY----- -----BEGIN RSA PUBLIC KEY----- MIGHAoGBAOeIC9gRg3YaEGGMp3C00qNwLINAEDZV/J4BWM5WnWwCWZyHXDs2XiEmFu0ZONAD4gcT2f2f NNfCBPye39VVuOkKQuSV0MLLX5800LZ4y1BNcPzPZHpnGaCzl7iAjhfj9MolzAh5VRjeiYt0t1um4dm+ q9A4BtfpJqDYxCW9uxd/AgEj -----END RSA PUBLIC KEY----- |
| INT rlSshClientImportExportSelfKeyFragmentId | 1.3.6.1.4.1.9.6.1.101.78.3.9.1.3 | INTEGER | not-accessible | Identifies the index of this fragment in the key pair input/output. |
| OCT rlSshClientImportExportSelfKeyFragmentText | 1.3.6.1.4.1.9.6.1.101.78.3.9.1.4 | OCTET STRING | read-write | A part of the readable text entry for the key pair input/output. |
| rlSshClientImportExportSelfKeyTable | 1.3.6.1.4.1.9.6.1.101.78.3.9 | not-accessible | This table can be used for 2 purposes: 1) Importing public/private key pair to serve as the device key when acting as SSH client. This is done by setting entries to this table, according to the specified format. When the last entry (footer) is set, the whole key pair is checked and if valid, stored in CDB. 2) Exporting the device SSH client public/private key. This can be done by performing GetNext operations on this table. | |
| STR rlSshClientPassword | 1.3.6.1.4.1.9.6.1.101.78.3.6 | DisplayString | read-write | Specifies the global password for SSH client, to be used for 'password' authentication. SSH client will use this password during authentication phase (when connecting remote server), in case no specific password has been specified for this operation. The value of this MIB must not contain charachters ':' or '@' (those are used to indicate parameters seperation in SCP copy). |
| rlSshClientPasswordChangeEntry | 1.3.6.1.4.1.9.6.1.101.78.3.7.1 | not-accessible | The row definition for this table. | |
| STR rlSshClientPasswordChangeFailureReason | 1.3.6.1.4.1.9.6.1.101.78.3.7.1.7 | DisplayString | read-only | In case the value of rlSshClientPasswordChangeStatus is 'failed', this field will contain the failure reason. |
| IP rlSshClientPasswordChangeInetAddr | 1.3.6.1.4.1.9.6.1.101.78.3.7.1.2 | InetAddress | not-accessible | Specifies the inet address of remote SCP server |
| IPt rlSshClientPasswordChangeInetAddrType | 1.3.6.1.4.1.9.6.1.101.78.3.7.1.1 | InetAddressType | not-accessible | Specifies the inet address type of remote SCP server |
| STR rlSshClientPasswordChangeNewPassword | 1.3.6.1.4.1.9.6.1.101.78.3.7.1.5 | DisplayString | read-write | Specifies the new password that should be in use for rlSshClientPasswordChangeUsername from now on. Upon setting a value in this entry, length of this field value must be 6-70. Password of length 0 will always be returned on GET operations. |
| STR rlSshClientPasswordChangeOldPassword | 1.3.6.1.4.1.9.6.1.101.78.3.7.1.4 | DisplayString | read-write | Specifies the old password that was in use for rlSshClientPasswordChangeUsername until now. Upon setting a value in this entry, length of this field value must be 6-70. Password of length 0 will always be returned on GET operations. |
| INT rlSshClientPasswordChangeStatus | 1.3.6.1.4.1.9.6.1.101.78.3.7.1.6 | INTEGER | read-only | Specifies the status of last password change operation on remote server identified by rlSshClientPasswordChangeInetAddress. In case this data was erased (3 or more password change operations have been performed since the operation on this server), the status will be 'noData'. |
| rlSshClientPasswordChangeTable | 1.3.6.1.4.1.9.6.1.101.78.3.7 | not-accessible | This table allows the user to change the password in a remote SSH server. It should be used when working with 'password' authentication with remote server in SCP sessions. Set operation on this table will initiate SCP session with the SSH server whose inet address is specified in the key rlSshClientPasswordChangeInetAddress. During this session the password for username rlSshClientPasswordChangeUsername will be changed in the server from rlSshClientPasswordChangeOldPassword to rlSshClientPasswordChangeNewPassword. The Set operation might fail, in case an SCP session is already being held. In case 'noError' is returned, the user can poll the fields rlSshClientPasswordChangeStatus and rlSshClientPasswordChangeFailureReason in order to get information on operation status and possible failure reason. Note: up to 3 status records can be saved. | |
| STR rlSshClientPasswordChangeUsername | 1.3.6.1.4.1.9.6.1.101.78.3.7.1.3 | DisplayString | read-write | Specifies the username for which the password change is required. |
| RLS rlSshClientRegenerateSelfKey | 1.3.6.1.4.1.9.6.1.101.78.3.2 | RlSshPublicKeyAlgorithm | read-write | Setting to a value other than none results in the client self key being regenerated. The key size is host-specific. |
| OCT rlSshClientRemoteServerFingerprint | 1.3.6.1.4.1.9.6.1.101.78.3.10.1.3 | OCTET STRING | read-create | Remote server fingerprint. |
| IP rlSshClientRemoteServerFingerprintInetAddr | 1.3.6.1.4.1.9.6.1.101.78.3.10.1.2 | InetAddress | not-accessible | Remote server inet address. |
| IPt rlSshClientRemoteServerFingerprintInetAddrType | 1.3.6.1.4.1.9.6.1.101.78.3.10.1.1 | InetAddressType | not-accessible | Remote server inet address type. |
| ROW rlSshClientRemoteServerFingerprintStatus | 1.3.6.1.4.1.9.6.1.101.78.3.10.1.4 | RowStatus | read-create | Row status for this row. |
| rlSshClientRemoteServerPublicKeyFingerprintEntry | 1.3.6.1.4.1.9.6.1.101.78.3.10.1 | not-accessible | The row definition for this table. | |
| rlSshClientRemoteServerPublicKeyFingerprintTable | 1.3.6.1.4.1.9.6.1.101.78.3.10 | not-accessible | Table for storing fingerprints of remote servers public keys. It is used for the purpose of server authentication. An entry can be inserted to this table either explicitly by user configuration, or during copy operation, after user's approval. | |
| INT rlSshClientRemoteServersAuthenticationEnable | 1.3.6.1.4.1.9.6.1.101.78.3.11 | INTEGER | read-write | Setting this field to 'enable' enables remote servers authentication. As a result, while opening a session with a remote server, the fingerprint of the remote server will be computed and looked for in the table rlSshClientRemoteServerPublicKeyFingerprintTable. If an entry with the key (server-inet-address, server-fingerprint) is found, the server is considered authenticated. Otherwise, the server is not authenticated (unless the user specifically approved this server can be trusted). |
| RLS rlSshClientSelfPublicKeyAlgorithm | 1.3.6.1.4.1.9.6.1.101.78.3.3.1.2 | RlSshPublicKeyAlgorithm | read-only | Identifies the type of public key to be displayed. |
| STR rlSshClientSelfPublicKeyFingerprint | 1.3.6.1.4.1.9.6.1.101.78.3.4.1.3 | DisplayString | read-only | SECSH format fingerprint of the client's self key. To prevent man in the middle attacks, users should make sure the ssh Server's fingerprint, as printed in the connection process, is similar to the one printed here. |
| RLS rlSshClientSelfPublicKeyFingerprintAlgorithm | 1.3.6.1.4.1.9.6.1.101.78.3.4.1.1 | RlSshPublicKeyAlgorithm | read-only | Identifies the type of public key to be displayed. |
| RLS rlSshClientSelfPublicKeyFingerprintDigestFormat | 1.3.6.1.4.1.9.6.1.101.78.3.4.1.2 | RlSshPublicKeyDigestFormat | read-only | Format of the digest to be displayed (OpenSSH or SSH.com). |
| rlSshClientSelfPublicKeyFingerprintTable | 1.3.6.1.4.1.9.6.1.101.78.3.4 | not-accessible | This table contains the fingerprint for the client's self key. | |
| rlSshClientSelfPublicKeyFingerprintTableEntry | 1.3.6.1.4.1.9.6.1.101.78.3.4.1 | not-accessible | The row definition for this table. | |
| U32 rlSshClientSelfPublicKeyFragmentId | 1.3.6.1.4.1.9.6.1.101.78.3.3.1.1 | Unsigned32 | read-only | Identifies the index of this fragment in the final key. All segments must be combined to form one big key. |
| STR rlSshClientSelfPublicKeyFragmentText | 1.3.6.1.4.1.9.6.1.101.78.3.3.1.3 | DisplayString | read-write | A part of the readable text entry for the router's client public authorization key. |
| rlSshClientSelfPublicKeyTable | 1.3.6.1.4.1.9.6.1.101.78.3.3 | not-accessible | This table contains the router's client self public key. Each row in this table contains a fragment of the key, in printable binhex format. There may be up to 160 characters in every fragment, and they are all combined to form one key. The key is generated by writing to rlSshClientRegenerateSelfKey. To cause clients to connect to this router without printing warning messages (and also prevent active man-in-the-middle), the router's public key must printed out and inserted into the client's authorized_keys file | |
| rlSshClientSelfPublicKeyTableEntry | 1.3.6.1.4.1.9.6.1.101.78.3.3.1 | not-accessible | The row definition for this table. | |
| STR rlSshClientUserName | 1.3.6.1.4.1.9.6.1.101.78.3.1 | DisplayString | read-write | Specifies the default user name the ssh client will use when authenticating to a remote server. In SCP sessions this global user name will be used unless a specific user name has been specified for the operation. The value of this MIB must not contain charachters ':' or '@' (those are used to indicate parameters seperation in SCP copy). |
| INT rlSshMibVersion | 1.3.6.1.4.1.9.6.1.101.78.1 | INTEGER | read-only | The MIB version. The current version is 2 |
| rlSshServer | 1.3.6.1.4.1.9.6.1.101.78.2 | |||
| STR rlSshServerAuthorizedUserFingerprintName | 1.3.6.1.4.1.9.6.1.101.78.2.5.1.1 | DisplayString | read-write | Name of the user who owns this public key. Both the user name and the key bytes must match before a user is authenticated using this key. |
| STR rlSshServerAuthorizedUserName | 1.3.6.1.4.1.9.6.1.101.78.2.3.1.1 | DisplayString | read-write | Name of the user who owns this public key. Both the user name and the key bytes must match before a user is authenticated using this key. |
| STR rlSshServerAuthorizedUserPublicKeyFingerprint | 1.3.6.1.4.1.9.6.1.101.78.2.5.1.4 | DisplayString | read-only | SECSH format fingerprint of the user's public key. To prevent man in the middle attacks, users should make sure their ssh fingerprint, as printed in the connection process, is similar to the one printed here. |
| RLS rlSshServerAuthorizedUserPublicKeyFingerprintAlgorithm | 1.3.6.1.4.1.9.6.1.101.78.2.5.1.2 | RlSshPublicKeyAlgorithm | read-only | Identifies the type of public key to be displayed. |
| RLS rlSshServerAuthorizedUserPublicKeyFingerprintDigestFormat | 1.3.6.1.4.1.9.6.1.101.78.2.5.1.3 | RlSshPublicKeyDigestFormat | read-only | Format of the digest to be displayed (OpenSSH or SSH.com). |
| U32 rlSshServerAuthorizedUserPublicKeyFragmentId | 1.3.6.1.4.1.9.6.1.101.78.2.3.1.2 | Unsigned32 | read-write | Identifies the index of this fragment in the final key. All segments must be combined to form one big key. |
| ROW rlSshServerAuthorizedUserPublicKeyFragmentStatus | 1.3.6.1.4.1.9.6.1.101.78.2.3.1.4 | RowStatus | read-write | Create or delete a fragment of the user's public key. A user is deleted if it has no remaining fragments. |
| STR rlSshServerAuthorizedUserPublicKeyFragmentText | 1.3.6.1.4.1.9.6.1.101.78.2.3.1.3 | DisplayString | read-write | A part of the readable text entry for the user's public authorzation key. |
| rlSshServerAuthorizedUsersPublicKeyFingerprintTable | 1.3.6.1.4.1.9.6.1.101.78.2.5 | not-accessible | This table contains the fingerprints of the public keys for all users who are authorized to access the router. To prevent man in the middle attacks, users should make sure the user's fingerprint, as printed in the connection process, is similar to the one printed here. | |
| rlSshServerAuthorizedUsersPublicKeyFingerprintTableEntry | 1.3.6.1.4.1.9.6.1.101.78.2.5.1 | not-accessible | The row definition for this table. | |
| rlSshServerAuthorizedUsersPublicKeyTable | 1.3.6.1.4.1.9.6.1.101.78.2.3 | not-accessible | This table contains public keys for all users who are authorized to access the router. For a user to be able to log in using SSH, the user name must appear in this table, and the user's public key must match the one found here. | |
| rlSshServerAuthorizedUsersPublicKeyTableEntry | 1.3.6.1.4.1.9.6.1.101.78.2.3.1 | not-accessible | The row definition for this table. | |
| INT rlSshServerDefaultKeyFlag | 1.3.6.1.4.1.9.6.1.101.78.2.105 | INTEGER | read-only | This scalar indicates which of the SSH server keys are default keys (automatically generated). |
| RLS rlSshServerDeleteSelfKey | 1.3.6.1.4.1.9.6.1.101.78.2.106 | RlSshPublicKeyAlgorithm | read-write | Setting to a value other than 'none' results in deleting the server self key of the chosen type. As a result a default key may be created (according to the MTSC..) |
| INT rlSshServerEnable | 1.3.6.1.4.1.9.6.1.101.78.2.102 | INTEGER | read-write | Enables listening for incoming SSH2 connections on the port defined in rlSshServerPort. |
| INT rlSshServerEnablePasswordAuthentication | 1.3.6.1.4.1.9.6.1.101.78.2.108 | INTEGER | read-write | If password authentication is enabled, incoming SSH connections are authenticated with username/password authentication using the router's standard AAA. |
| INT rlSshServerEnablePublicKeyAuthAutoLogin | 1.3.6.1.4.1.9.6.1.101.78.2.107 | INTEGER | read-write | If PK authentication is succesfull and AAA local DB method is enabled for SSH line, the username is checked with AAA local DB. If present, the user is authenticated automatically without prompting for username or password. |
| INT rlSshServerEnablePublicKeyAuthentication | 1.3.6.1.4.1.9.6.1.101.78.2.103 | INTEGER | read-write | If PK authentication is enabled, incoming SSH connections are authenticated using public key authentication (using rlSshServerAuthorizedUsersPublicKeyTable), before authenticating using the router's standard AAA. |
| RLS rlSshServerHostPublicKeyAlgorithm | 1.3.6.1.4.1.9.6.1.101.78.2.1.1.1 | RlSshPublicKeyAlgorithm | read-only | Identifies the type of public key to be displayed. |
| STR rlSshServerHostPublicKeyFingerprint | 1.3.6.1.4.1.9.6.1.101.78.2.2.1.3 | DisplayString | read-only | SECSH format fingerprint of the server's public key. To prevent man in the middle attacks, users should make sure the ssh Server's fingerprint, as printed in the connection process, is similar to the one printed here. |
| RLS rlSshServerHostPublicKeyFingerprintAlgorithm | 1.3.6.1.4.1.9.6.1.101.78.2.2.1.1 | RlSshPublicKeyAlgorithm | read-only | Identifies the type of public key to be displayed. |
| RLS rlSshServerHostPublicKeyFingerprintDigestFormat | 1.3.6.1.4.1.9.6.1.101.78.2.2.1.2 | RlSshPublicKeyDigestFormat | read-only | Format of the digest to be displayed (OpenSSH or SSH.com). |
| rlSshServerHostPublicKeyFingerprintTable | 1.3.6.1.4.1.9.6.1.101.78.2.2 | not-accessible | This table contains the fingerprint for the router's public key. | |
| rlSshServerHostPublicKeyFingerprintTableEntry | 1.3.6.1.4.1.9.6.1.101.78.2.2.1 | not-accessible | The row definition for this table. | |
| U32 rlSshServerHostPublicKeyFragmentId | 1.3.6.1.4.1.9.6.1.101.78.2.1.1.2 | Unsigned32 | read-only | Identifies the index of this fragment in the final key. All segments must be combined to form one big key. |
| STR rlSshServerHostPublicKeyFragmentText | 1.3.6.1.4.1.9.6.1.101.78.2.1.1.3 | DisplayString | read-only | A part of the readable text entry for the server's public authorzation key. |
| rlSshServerHostPublicKeyTable | 1.3.6.1.4.1.9.6.1.101.78.2.1 | not-accessible | This table contains the router's public key. Each row in this table contains a fragment of the key, in printable binhex format. There may be up to 160 characters in every fragment, and they are all combined to form one key. The key is generated by writing to rlSshServerRegenerateHostKey. To cause clients to connect to this router without printing warning messages (and also prevent active man-in-the-middle), the router's public key must printed out and inserted into the client's authorized_keys file | |
| rlSshServerHostPublicKeyTableEntry | 1.3.6.1.4.1.9.6.1.101.78.2.1.1 | not-accessible | The row definition for this table. | |
| RLS rlSshServerImportExportSelfKeyAlgorithm | 1.3.6.1.4.1.9.6.1.101.78.2.8.1.1 | RlSshPublicKeyAlgorithm | not-accessible | Identifies the type of key pair. |
| rlSshServerImportExportSelfKeyEntry | 1.3.6.1.4.1.9.6.1.101.78.2.8.1 | not-accessible | The row definition for this table. | |
| INT rlSshServerImportExportSelfKeyFormat | 1.3.6.1.4.1.9.6.1.101.78.2.8.1.2 | INTEGER | not-accessible | Specifies the format of public/key pair. The following formats are supported for import/export: 1) uuencoded_format - in this format both private and public key are in uu-encoded format, and are seperated from one another by header and footer. An example of the concateneation of all fragments in this format is: -----BEGIN RSA PRIVATE KEY----- tDaNkZZoCxXfkLLsLDlZ6T9H8U4Gz637eRV7BYBpapkidAxY1UG0/qgfKLPkbId4wzht6ArV9bE4fMtX wSMOxL3q31pOmUdVhjbWYcgZQBDy1DjFSbuIEdP85c96B9bBE2nPv90mSvb/6j8R2NItT/KJeiYMtLtI N3m6/zESKJGIrX0jP1RFDjVZSS5chSAFgB0egsLZEyOQn7jAqpX/x/easD2J6F/OjPXlJ9Hff2tMb3NU QYyBoWH2J9IxhWB6Vo66R9Y04JGR18uL/rV2sMCtpg5ppkVTEpNTp9qE1yXocR2NmzUfNFap+GJ4IHj8 CzkVfmJM/kEWaJsYgHbAgLyRg4QVyelfobv1B71aQ+u1z9KGu/QajkWdR04OQfsGOL1CvU2LGYDcRjfH jv+jl/UkDRRjoD9kt2WvouT+OL6esvKl0OJBqWbGNXg9TWv/VLtJIwgUno+MLaJuOM4Fh44+wpnqUXwQ TFtBFc8pzt5BoOwbv9gXpicTkq4/+GhwXWXxSVFebKhnHAvKSLT+Ba7K7ZeR8EIIxbXdDNFOiS45R2KI jxxXLXK44u6KGl5MygCKXUOFlJ+Zhgrq6ZH17z/RVJQ2CWqb5Ekn9GY3kH9QZ3mb4MDPfriWi2lHGXHY JmJd4SLQhpBdnOS5tu84QmyU3dNbAdzghDsR+dEY/6g7Cn0kcVkeHNZ0H+mCZik5f6XBD8eplkk43bdR FrkwTeAjwurGcKwdiKkR4DlfSq3DKssVBucTqUpqsKqPXLwTIL44rWKhEPXgGPB2XDG0VLvIRKkAgEGI LNTwOm091Ro= -----END RSA PRIVATE KEY----- -----BEGIN RSA PUBLIC KEY----- MIGHAoGBAOeIC9gRg3YaEGGMp3C00qNwLINAEDZV/J4BWM5WnWwCWZyHXDs2XiEmFu0ZONAD4gcT2f2f NNfCBPye39VVuOkKQuSV0MLLX5800LZ4y1BNcPzPZHpnGaCzl7iAjhfj9MolzAh5VRjeiYt0t1um4dm+ q9A4BtfpJqDYxCW9uxd/AgEj -----END RSA PUBLIC KEY----- |
| INT rlSshServerImportExportSelfKeyFragmentId | 1.3.6.1.4.1.9.6.1.101.78.2.8.1.3 | INTEGER | not-accessible | Identifies the index of this fragment in the key pair input/output. |
| OCT rlSshServerImportExportSelfKeyFragmentText | 1.3.6.1.4.1.9.6.1.101.78.2.8.1.4 | OCTET STRING | read-write | A part of the readable text entry for the key pair input/output. |
| rlSshServerImportExportSelfKeyTable | 1.3.6.1.4.1.9.6.1.101.78.2.8 | not-accessible | This table can be used for 2 purposes: 1) Importing public/private key pair to serve as the device key when acting as SSH server. This is done by setting entries to this table, according to the specified format. When the last entry (footer) is set, the whole key pair is checked and if valid, stored in CDB. 2) Exporting the device SSH server public/private key. This can be done by performing GetNext operations on this table. | |
| U32 rlSshServerPort | 1.3.6.1.4.1.9.6.1.101.78.2.101 | Unsigned32 | read-write | Specifies the TCP port used by the SSH 2 Server to listen for incoming connections. |
| RLS rlSshServerRegenerateHostKey | 1.3.6.1.4.1.9.6.1.101.78.2.104 | RlSshPublicKeyAlgorithm | read-write | Setting to a value other than none results in the Server (Host) Key being regenerated. The key size is host-specific. |
| STR rlSshServerSessionCipher | 1.3.6.1.4.1.9.6.1.101.78.2.6.1.6 | DisplayString | read-only | Data encryption cipher used in this connection. |
| STR rlSshServerSessionHMAC | 1.3.6.1.4.1.9.6.1.101.78.2.6.1.7 | DisplayString | read-only | Message authentication code used in this connection. |
| U32 rlSshServerSessionIdentifier | 1.3.6.1.4.1.9.6.1.101.78.2.6.1.1 | Unsigned32 | read-only | Identifies the connection to which this row corresponds. |
| STR rlSshServerSessionInetCipher | 1.3.6.1.4.1.9.6.1.101.78.2.7.1.7 | DisplayString | read-only | Data encryption cipher used in this connection. |
| STR rlSshServerSessionInetHMAC | 1.3.6.1.4.1.9.6.1.101.78.2.7.1.8 | DisplayString | read-only | Message authentication code used in this connection. |
| U32 rlSshServerSessionInetIdentifier | 1.3.6.1.4.1.9.6.1.101.78.2.7.1.1 | Unsigned32 | read-only | Identifies the connection to which this row corresponds. |
| IP rlSshServerSessionInetPeerAddress | 1.3.6.1.4.1.9.6.1.101.78.2.7.1.3 | InetAddress | read-only | The network address of the remote host connected to the server. |
| IPt rlSshServerSessionInetPeerAddressType | 1.3.6.1.4.1.9.6.1.101.78.2.7.1.2 | InetAddressType | read-only | The network address of the remote host connected to the server. |
| U32 rlSshServerSessionInetPeerPort | 1.3.6.1.4.1.9.6.1.101.78.2.7.1.4 | Unsigned32 | read-only | The source network port of the remote host connected to the server. |
| STR rlSshServerSessionInetPeerVersion | 1.3.6.1.4.1.9.6.1.101.78.2.7.1.5 | DisplayString | read-only | The client version of the remote host connected to the server. |
| rlSshServerSessionInetTable | 1.3.6.1.4.1.9.6.1.101.78.2.7 | not-accessible | Each row in this table corresponds to an active SSH session with the server | |
| rlSshServerSessionInetTableEntry | 1.3.6.1.4.1.9.6.1.101.78.2.7.1 | not-accessible | The row definition for this table. | |
| STR rlSshServerSessionInetUsername | 1.3.6.1.4.1.9.6.1.101.78.2.7.1.6 | DisplayString | read-only | SSH authenticated name of user connected to the server. |
| IP rlSshServerSessionPeerAddress | 1.3.6.1.4.1.9.6.1.101.78.2.6.1.2 | IpAddress | read-only | The network address of the remote host connected to the server. |
| U32 rlSshServerSessionPeerPort | 1.3.6.1.4.1.9.6.1.101.78.2.6.1.3 | Unsigned32 | read-only | The source network port of the remote host connected to the server. |
| STR rlSshServerSessionPeerVersion | 1.3.6.1.4.1.9.6.1.101.78.2.6.1.4 | DisplayString | read-only | The client version of the remote host connected to the server. |
| rlSshServerSessionTable | 1.3.6.1.4.1.9.6.1.101.78.2.6 | not-accessible | Each row in this table corresponds to an active SSH session with the server | |
| rlSshServerSessionTableEntry | 1.3.6.1.4.1.9.6.1.101.78.2.6.1 | not-accessible | The row definition for this table. | |
| STR rlSshServerSessionUsername | 1.3.6.1.4.1.9.6.1.101.78.2.6.1.5 | DisplayString | read-only | SSH authenticated name of user connected to the server. |
RFC description
Cisco Small Business SSH private MIB for secure remote access management.
Start monitoring Cisco Small Business managed switch with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.