All MIBs › CM-SECURITY-MIB
Organization: ADVA Optical Networking SE
Last Updated: 2021-01-28
Category: VPN and Security, Vendor: Ceragon
Description: Sets encryption, authentication, and other security parameters for Ceragon microwave radio links.
Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.
What Is CM-SECURITY-MIB?
CM-SECURITY-MIB is an ADVA/Ceragon (FSP150CM/CC, F3 product line) enterprise MIB for configuring security settings on microwave radio and packet transport equipment, governing user authentication for CLI/GUI management sessions. It exposes configuration objects for authentication protocol and type, access order (e.g., local vs. remote first), RADIUS/TACACS+ NAS IP addressing (including IPv6), security policy strength, and TACACS+ privilege-level control and default privilege level, plus trap objects for security events. Its monitoring relevance is centered on software/access-security status: an operator can verify cmAuthType and cmAccessOrder to confirm the intended authentication method chain is active, check f3TacacsPrivLevelControlEnabled and f3TacacsDefaultPrivLevel to confirm privilege enforcement is configured as expected, and watch f3SecurityTrapType/f3SecurityTrapInfo notifications for security-relevant events such as failed logins or configuration changes. It depends on external AAA infrastructure (RADIUS/TACACS+) referenced by its NAS IP and accounting objects. It is typically deployed on Ceragon/ADVA FSP150CM/CC microwave and packet transport nodes in mobile backhaul and metro transport networks where centralized authentication and privilege control of device management sessions is required. Engineers can download the CM-SECURITY-MIB file directly to load it into their MIB browser.
IPNetwork Monitor allows you to monitor SNMP objects defined in CM-SECURITY-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.
Supported Devices
- Ceragon/ADVA FSP150CM/CC microwave radio and packet transport nodes
Monitoring Examples
An operator would check cmAuthProtocol and cmAuthType together with cmAccessOrder to confirm whether local, RADIUS, or TACACS+ authentication is being tried first for CLI/GUI logins, and verify cmRemoteAuthServerAccountingEnabled to confirm accounting records are being sent to cmNASIpAddress (or f3NasIpv6Addr for IPv6 deployments). f3TacacsPrivLevelControlEnabled and f3TacacsDefaultPrivLevel would be checked to ensure users are granted the correct default privilege level, and a f3SecurityTrapType notification carrying f3SecurityTrapInfo would flag an unexpected authentication or privilege event, such as a failed login attempt or unauthorized privilege escalation attempt.
What Can Be Monitored
- authentication protocol/type and access order
- RADIUS/TACACS+ NAS IP configuration (IPv4/IPv6)
- TACACS+ privilege level control and default level
- remote authentication accounting status
- security event trap notifications
This MIB depends on
Related MIBs
Imported Objects
From ADVA-MIB
| fsp150cm | OBJECT-IDENTITY |
From CM-COMMON-MIB
| IpVersion | |
| UserInterfaceType |
From IPV6-TC
| Ipv6Address |
From SNMP-FRAMEWORK-MIB
| SnmpAdminString |
| usmUserEntry | OBJECT-TYPE |
From SNMPv2-CONF
| MODULE-COMPLIANCE | |
| OBJECT-GROUP |
From SNMPv2-SMI
| Integer32 | |
| IpAddress | |
| MODULE-IDENTITY | |
| OBJECT-TYPE | |
| Unsigned32 |
From SNMPv2-TC
| DateAndTime | |
| DisplayString | |
| RowStatus | |
| StorageType | |
| TEXTUAL-CONVENTION | |
| TruthValue | |
| VariablePointer |
OIDs
| OID symbolic | OID numeric | Type | Access | Description |
|---|---|---|---|---|
| CMS cmAccessOrder | 1.3.6.1.4.1.2544.1.12.10.1.2 | CmSecurityAccessOrder | read-write | Order of access for security, i.e. try 'local' first or 'remote' first. |
| I32 cmAnonymizeLogTimeInDays | 1.3.6.1.4.1.2544.1.12.10.1.22 | Integer32 | read-write | This object represents the logging anonymization interval in days. After the configured number of days have passed, the system anonymizes the user names. At midnight of that day, the system anonymizes all the log entries that precede the configured value. 0 means NEVER anonymize. |
| CMR cmAuthProtocol | 1.3.6.1.4.1.2544.1.12.10.1.1 | CmRemoteAuthProtocol | read-write | Remote user authentication protocol. |
| CMS cmAuthType | 1.3.6.1.4.1.2544.1.12.10.1.3 | CmSecurityAuthType | read-write | In case of remote authentication, the chosen protocol. |
| cmIcmpV4Objects | 1.3.6.1.4.1.2544.1.12.10.1.20 | |||
| cmIcmpV6Objects | 1.3.6.1.4.1.2544.1.12.10.1.21 | |||
| IP cmNASIpAddress | 1.3.6.1.4.1.2544.1.12.10.1.4 | IpAddress | read-write | In case of remote authentication RADIUS, the Network Access Server's IP Address. |
| T/F cmRemoteAuthServerAccountingEnabled | 1.3.6.1.4.1.2544.1.12.10.1.8 | TruthValue | read-write | This object allows to enable/disable RADIUS/TACACS+ Accounting on all authentication servers. |
| I32 cmRemoteAuthServerAccountingPort | 1.3.6.1.4.1.2544.1.12.10.1.6.1.9 | Integer32 | read-write | This object allows to specify a Port for RADIUS Accounting. |
| T/F cmRemoteAuthServerEnabled | 1.3.6.1.4.1.2544.1.12.10.1.6.1.2 | TruthValue | read-write | This object allows enabling/disabling a Remote Authentication Server. |
| cmRemoteAuthServerEntry | 1.3.6.1.4.1.2544.1.12.10.1.6.1 | not-accessible | An entry containing information applicable to a particular remote authentication server. | |
| I32 cmRemoteAuthServerIndex | 1.3.6.1.4.1.2544.1.12.10.1.6.1.1 | Integer32 | read-only | Unique index to address/configure a specific Remote Authentication Server. |
| IP cmRemoteAuthServerIpAddress | 1.3.6.1.4.1.2544.1.12.10.1.6.1.4 | IpAddress | read-write | This object allows to specify an IP Address for the Remote Authentication Server. |
| ADR cmRemoteAuthServerIpv6Addr | 1.3.6.1.4.1.2544.1.12.10.1.6.1.11 | Ipv6Address | read-write | This object describe the Ipv6 Address. |
| IPV cmRemoteAuthServerIpVersion | 1.3.6.1.4.1.2544.1.12.10.1.6.1.10 | IpVersion | read-write | This object describe the Ip Version. |
| I32 cmRemoteAuthServerNumRetries | 1.3.6.1.4.1.2544.1.12.10.1.6.1.6 | Integer32 | read-write | This object allows to specify the number of retries the Remote Authentication Server must be tried for security access before giving up. |
| CMR cmRemoteAuthServerOrder | 1.3.6.1.4.1.2544.1.12.10.1.6.1.3 | CmRemoteAuthOrder | read-write | This object determines the order in which the Remote Authentication Servers are accessed for security information. |
| I32 cmRemoteAuthServerPort | 1.3.6.1.4.1.2544.1.12.10.1.6.1.5 | Integer32 | read-write | This object allows to specify a Port for Remote Authentication Server. |
| STR cmRemoteAuthServerSecret | 1.3.6.1.4.1.2544.1.12.10.1.6.1.8 | DisplayString | read-write | This allows configuration of secret password for Remote Authentication Server request. |
| cmRemoteAuthServerTable | 1.3.6.1.4.1.2544.1.12.10.1.6 | not-accessible | A list of entries corresponding to the remote authentication servers. Entries cannot be created in this table by management application action. | |
| I32 cmRemoteAuthServerTimeout | 1.3.6.1.4.1.2544.1.12.10.1.6.1.7 | Integer32 | read-write | This object allows to specify the timeout period for timing out a security access request to the Remote Authentication Server. |
| cmSecurityCompliance | 1.3.6.1.4.1.2544.1.12.10.2.1.1 | Describes the requirements for conformance to the CM Security group. | ||
| cmSecurityCompliances | 1.3.6.1.4.1.2544.1.12.10.2.1 | |||
| cmSecurityConformance | 1.3.6.1.4.1.2544.1.12.10.2 | |||
| STR cmSecurityCryptoPassword | 1.3.6.1.4.1.2544.1.12.10.1.5.1.15 | DisplayString | read-create | Second level password used in connectguard configurations. This applies only to crypto users. Note that this attribute is a SET only attribute. |
| cmSecurityGroups | 1.3.6.1.4.1.2544.1.12.10.2.2 | |||
| cmSecurityMIB | 1.3.6.1.4.1.2544.1.12.10 | This module defines the Security MIB definitions used by the F3 (FSP150CM/CC) product lines. These are used to manage the user/authentication for CLI/GUI sessions. Copyright (C) ADVA. | ||
| cmSecurityNotifGroup | 1.3.6.1.4.1.2544.1.12.10.2.2.2 | A collection of notifications used in the CM Security group. | ||
| cmSecurityNotifications | 1.3.6.1.4.1.2544.1.12.10.3 | |||
| cmSecurityObjectGroup | 1.3.6.1.4.1.2544.1.12.10.2.2.1 | A collection of objects used to manage the CM Security group. | ||
| cmSecurityObjects | 1.3.6.1.4.1.2544.1.12.10.1 | |||
| CMS cmSecurityPolicyStrength | 1.3.6.1.4.1.2544.1.12.10.1.7 | CmSecurityPolicyStrength | read-write | This object represents the security policy strength of the system. Based on this value, the system puts additional restrictions on the user id and password rules. |
| SEC cmSecurityUserAction | 1.3.6.1.4.1.2544.1.12.10.1.5.1.14 | SecurityUserAction | read-write | This object provides ability to perform specific actions on security user. remove-lockout - this removes the locked out condition on the security user . |
| T/F cmSecurityUserCliPagingEnable | 1.3.6.1.4.1.2544.1.12.10.1.5.1.9 | TruthValue | read-create | Whether the security user has CLI paging enabled. |
| STR cmSecurityUserComment | 1.3.6.1.4.1.2544.1.12.10.1.5.1.2 | DisplayString | read-create | Notes on Security User. |
| cmSecurityUserEntry | 1.3.6.1.4.1.2544.1.12.10.1.5.1 | not-accessible | An entry containing information applicable to a particular security user. | |
| DAT cmSecurityUserLastLockedoutTime | 1.3.6.1.4.1.2544.1.12.10.1.5.1.8 | DateAndTime | read-only | Security User Last Locked out Time. |
| DAT cmSecurityUserLastLoginTime | 1.3.6.1.4.1.2544.1.12.10.1.5.1.6 | DateAndTime | read-only | Security User Last Login Time. |
| T/F cmSecurityUserLockedout | 1.3.6.1.4.1.2544.1.12.10.1.5.1.7 | TruthValue | read-only | Whether the security user has been locked out. |
| I32 cmSecurityUserLoginTimeout | 1.3.6.1.4.1.2544.1.12.10.1.5.1.4 | Integer32 | read-create | Security User Login Timeout. |
| STR cmSecurityUserName | 1.3.6.1.4.1.2544.1.12.10.1.5.1.1 | DisplayString | read-create | Security User Name. |
| I32 cmSecurityUserNumFailedLoginAttempts | 1.3.6.1.4.1.2544.1.12.10.1.5.1.5 | Integer32 | read-only | Security User Number of Failed Login Attempts. |
| STR cmSecurityUserPassword | 1.3.6.1.4.1.2544.1.12.10.1.5.1.11 | DisplayString | read-create | Password of the security user. Note that this attribute is a SET only attribute. |
| CMS cmSecurityUserPrivLevel | 1.3.6.1.4.1.2544.1.12.10.1.5.1.3 | CmSecurityPrivLevel | read-create | Security User Privilege Level. |
| T/F cmSecurityUserRemoteCryptoUser | 1.3.6.1.4.1.2544.1.12.10.1.5.1.16 | TruthValue | read-create | Indicates if a security user is a remote crypto user. |
| T/F cmSecurityUserRemoteUser | 1.3.6.1.4.1.2544.1.12.10.1.5.1.10 | TruthValue | read-only | Whether the security user is a remote user. |
| ROW cmSecurityUserRowStatus | 1.3.6.1.4.1.2544.1.12.10.1.5.1.13 | RowStatus | read-create | The status of this row. An entry MUST NOT exist in the active state unless all objects in the entry have an appropriate value, as described in the description clause for each writable object. The values of cmSecurityUserRowStatus supported are createAndGo(4) and destroy(6). All mandatory attributes must be specified in a single SNMP SET request with cmSecurityUserRowStatus value as createAndGo(4). Upon successful row creation, this object has a value of active(1). The cmSecurityUserRowStatus object may be modified if the associated instance of this object is equal to active(1). |
| T/F cmSecurityUserSso2fa | 1.3.6.1.4.1.2544.1.12.10.1.5.1.17 | TruthValue | read-create | If enabled, user can be used to bypass remote authentication if cmSso2faControl is enabled. This parameter can only be set on user creation |
| STO cmSecurityUserStorageType | 1.3.6.1.4.1.2544.1.12.10.1.5.1.12 | StorageType | read-create | The type of storage configured for this entry. |
| cmSecurityUserTable | 1.3.6.1.4.1.2544.1.12.10.1.5 | not-accessible | A list of entries corresponding to the security users. Entries cannot be created in this table by management application action. | |
| CAA f3CaAction | 1.3.6.1.4.1.2544.1.12.10.1.30.1.8 | CaAction | read-write | This object specifies a CA Action. |
| STR f3CaActionChallengePassword | 1.3.6.1.4.1.2544.1.12.10.1.30.1.10 | DisplayString | read-write | This object specifies a challenge password. Applicable to startAutoEnrollment action. |
| STR f3CaActionCsrName | 1.3.6.1.4.1.2544.1.12.10.1.30.1.9 | DisplayString | read-write | This object specifies a CSR Name. Applicable to startAutoEnrollment action. |
| STR f3CaCertList | 1.3.6.1.4.1.2544.1.12.10.1.30.1.5 | DisplayString | read-only | This object provides list of CA certificates sent by the CA as the chain of trust. |
| f3CaEntry | 1.3.6.1.4.1.2544.1.12.10.1.30.1 | not-accessible | The conceptual row in f3CaTable. | |
| STR f3CaLastCsr | 1.3.6.1.4.1.2544.1.12.10.1.30.1.7 | DisplayString | read-only | This object provides last CSR name in an enrollment process. |
| STR f3CaName | 1.3.6.1.4.1.2544.1.12.10.1.30.1.1 | DisplayString | not-accessible | Unique name used to identify this CA. |
| NUM f3CaProfile | 1.3.6.1.4.1.2544.1.12.10.1.30.1.2 | VariablePointer | read-create | This object provides a pointer to CA Profile used for this CA. |
| T/F f3CaProfileAutoRenewalControl | 1.3.6.1.4.1.2544.1.12.10.1.29.1.5 | TruthValue | read-create | This obect allows to specify whether the client certificate is automatically renewed or re-enrolled. |
| CER f3CaProfileEnrollmentProtocol | 1.3.6.1.4.1.2544.1.12.10.1.29.1.3 | CertificateEnrollmentProtocol | read-create | This object allows to specify type of protocol used for automatic certificate enrollment. |
| f3CaProfileEntry | 1.3.6.1.4.1.2544.1.12.10.1.29.1 | not-accessible | A conceptual row in the f3CaProfileTable. | |
| U32 f3CaProfileHttpPort | 1.3.6.1.4.1.2544.1.12.10.1.29.1.4 | Unsigned32 | read-create | This obect allows to specify TCP port number used by enrollment protocol. |
| U32 f3CaProfileIndex | 1.3.6.1.4.1.2544.1.12.10.1.29.1.1 | Unsigned32 | not-accessible | An integer index used to identify this CA Profile. |
| STR f3CaProfileName | 1.3.6.1.4.1.2544.1.12.10.1.29.1.2 | DisplayString | read-create | This object provides name for this CA Profile. |
| T/F f3CaProfileRenewalNewKeyPairGenControl | 1.3.6.1.4.1.2544.1.12.10.1.29.1.7 | TruthValue | read-create | This obect allows to specify if the RSA key pair is regenerated prior to each certificate renewal. |
| U32 f3CaProfileRenewalPercentLifetime | 1.3.6.1.4.1.2544.1.12.10.1.29.1.6 | Unsigned32 | read-create | This obect allows to specify percentage of certificate lifetime at which point the automatic certificate renewal process begins. |
| ROW f3CaProfileRowStatus | 1.3.6.1.4.1.2544.1.12.10.1.29.1.9 | RowStatus | read-create | The status of this row. An entry MUST NOT exist in the active state unless all objects in the entry have an appropriate value, as described in the description clause for each writable object. The values of f3CaProfileRowStatus supported are createAndGo(4) and destroy(6). All mandatory attributes must be specified in a single SNMP SET request with f3CaProfileRowStatus value as createAndGo(4). Upon successful row creation, this object has a value of active(1). The f3CaProfileRowStatus object may be modified if the associated instance of this object is equal to active(1). |
| STO f3CaProfileStorageType | 1.3.6.1.4.1.2544.1.12.10.1.29.1.8 | StorageType | read-create | The type of storage configured for this entry. |
| f3CaProfileTable | 1.3.6.1.4.1.2544.1.12.10.1.29 | not-accessible | A list of Certificate Authority Profiles. | |
| CAR f3CaRootCertStatus | 1.3.6.1.4.1.2544.1.12.10.1.30.1.6 | CaRootCertStatus | read-only | This object provides CA root certificate status. |
| ROW f3CaRowStatus | 1.3.6.1.4.1.2544.1.12.10.1.30.1.12 | RowStatus | read-create | The status of this row. An entry MUST NOT exist in the active state unless all objects in the entry have an appropriate value, as described in the description clause for each writable object. The values of f3CaRowStatus supported are createAndGo(4) and destroy(6). All mandatory attributes must be specified in a single SNMP SET request with f3CaRowStatus value as createAndGo(4). Upon successful row creation, this variable has a value of active(1). The f3CaRowStatus object may be modified if the associated instance of this object is equal to active(1). |
| STR f3CaScepQueryMessage | 1.3.6.1.4.1.2544.1.12.10.1.30.1.4 | DisplayString | read-create | This object provides the SCEP Query Message for certificate enrollment with CA. |
| STO f3CaStorageType | 1.3.6.1.4.1.2544.1.12.10.1.30.1.11 | StorageType | read-create | The type of storage configured for this entry. |
| f3CaTable | 1.3.6.1.4.1.2544.1.12.10.1.30 | not-accessible | A list of Certificate Authority object used for certificate enrollment with CA. | |
| STR f3CaUrl | 1.3.6.1.4.1.2544.1.12.10.1.30.1.3 | DisplayString | read-create | This object provides the URL for certificate enrollment with CA. |
| AUT f3CertSigningRequestAutoEnrollmentStatus | 1.3.6.1.4.1.2544.1.12.10.1.27.13.1.4 | AutoEnrollmentStatus | read-only | This is the auto enrollment status. |
| STR f3CertSigningRequestCsrData | 1.3.6.1.4.1.2544.1.12.10.1.27.13.1.3 | DisplayString | read-only | This is the CSR data. |
| f3CertSigningRequestEntry | 1.3.6.1.4.1.2544.1.12.10.1.27.13.1 | not-accessible | A conceptual row in the f3CertSigningRequestTable. | |
| STR f3CertSigningRequestName | 1.3.6.1.4.1.2544.1.12.10.1.27.13.1.1 | DisplayString | not-accessible | This is a unique name for CSR. |
| f3CertSigningRequestObjects | 1.3.6.1.4.1.2544.1.12.10.1.27 | |||
| STR f3CertSigningRequestRsaKeyPairName | 1.3.6.1.4.1.2544.1.12.10.1.27.13.1.2 | DisplayString | read-only | This is the Key pair name. |
| f3CertSigningRequestTable | 1.3.6.1.4.1.2544.1.12.10.1.27.13 | not-accessible | A list of CSR. | |
| CSR f3CsrAction | 1.3.6.1.4.1.2544.1.12.10.1.27.1 | CsrAction | read-write | This is the action to CSR. |
| STR f3CsrActionAlternativeName | 1.3.6.1.4.1.2544.1.12.10.1.27.12 | DisplayString | read-write | This is the alternative name of CSR action. |
| STR f3CsrActionCommonName | 1.3.6.1.4.1.2544.1.12.10.1.27.9 | DisplayString | read-write | This is the common name of CSR action. |
| STR f3CsrActionCountry | 1.3.6.1.4.1.2544.1.12.10.1.27.4 | DisplayString | read-write | This is the country of CSR action. |
| STR f3CsrActionCsrName | 1.3.6.1.4.1.2544.1.12.10.1.27.2 | DisplayString | read-write | This is the name of CSR action. |
| STR f3CsrActionEmail | 1.3.6.1.4.1.2544.1.12.10.1.27.10 | DisplayString | read-write | This is the email of CSR action. |
| STR f3CsrActionLocality | 1.3.6.1.4.1.2544.1.12.10.1.27.6 | DisplayString | read-write | This is the locality of CSR action. |
| STR f3CsrActionOrganization | 1.3.6.1.4.1.2544.1.12.10.1.27.7 | DisplayString | read-write | This is the organization of CSR action. |
| STR f3CsrActionOrganizationUnit | 1.3.6.1.4.1.2544.1.12.10.1.27.8 | DisplayString | read-write | This is the organization unit of CSR action. |
| STR f3CsrActionRsaKeyName | 1.3.6.1.4.1.2544.1.12.10.1.27.3 | DisplayString | read-write | This is the RSA key name of CSR action. |
| STR f3CsrActionSerialNumber | 1.3.6.1.4.1.2544.1.12.10.1.27.11 | DisplayString | read-write | This is the serial number of CSR action. |
| STR f3CsrActionState | 1.3.6.1.4.1.2544.1.12.10.1.27.5 | DisplayString | read-write | This is the state of CSR action. |
| INT f3FipsAction | 1.3.6.1.4.1.2544.1.12.10.1.23.5 | INTEGER | read-write | Fips Security Self Test Action. |
| f3FipsObjects | 1.3.6.1.4.1.2544.1.12.10.1.23 | |||
| T/F f3FipsOperationMode | 1.3.6.1.4.1.2544.1.12.10.1.23.1 | TruthValue | read-write | Fips Operation Mode. |
| U32 f3FipsSecuritySelfTestFailureCount | 1.3.6.1.4.1.2544.1.12.10.1.23.2 | Unsigned32 | read-only | Fips Security Self Test Failure Count. |
| SEC f3FipsSecuritySelfTestResult | 1.3.6.1.4.1.2544.1.12.10.1.23.3 | SecuritySelfTestResult | read-only | Fips Security Self Test Result. |
| SEC f3FipsSecuritySelfTestStatus | 1.3.6.1.4.1.2544.1.12.10.1.23.4 | SecuritySelfTestStatus | read-only | Fips Security Self Test Status. |
| U32 f3HttpsSslCertExpNotifPeriod | 1.3.6.1.4.1.2544.1.12.10.1.25.1 | Unsigned32 | read-write | Number of days prior to expiration of the HTTPS SSL Certificate that the Expiry Notification Alarm will be raised. |
| STR f3HttpsSslKeyPair | 1.3.6.1.4.1.2544.1.12.10.1.25.2 | DisplayString | read-write | This is the SSL certificate/private key pair used for HTTPS. |
| ADR f3NasIpAddressType | 1.3.6.1.4.1.2544.1.12.10.1.28 | NasIpAddressType | read-write | TThis object describe the ip address type. |
| ADR f3NasIpv6Addr | 1.3.6.1.4.1.2544.1.12.10.1.12 | Ipv6Address | read-write | This object describe the ipv6 address. |
| PRI f3PrivilegeChangeAction | 1.3.6.1.4.1.2544.1.12.10.1.15.1.11 | PrivilegeRequestAction | read-write | Privilege request action. |
| CMS f3PrivilegeChangeCurrentPrivilege | 1.3.6.1.4.1.2544.1.12.10.1.15.1.8 | CmSecurityPrivLevel | read-only | Current privilege level of the user, who is requesting role upgrade. |
| U32 f3PrivilegeChangeDuration | 1.3.6.1.4.1.2544.1.12.10.1.15.1.10 | Unsigned32 | read-only | Requested time period by user (in minutes). |
| f3PrivilegeChangeEntry | 1.3.6.1.4.1.2544.1.12.10.1.15.1 | not-accessible | Column for privilegeChangeTable. | |
| U32 f3PrivilegeChangeId | 1.3.6.1.4.1.2544.1.12.10.1.15.1.1 | Unsigned32 | not-accessible | Unique index identifying a request. |
| NUM f3PrivilegeChangeInterface | 1.3.6.1.4.1.2544.1.12.10.1.15.1.7 | UserInterfaceType | read-only | Interface used by the user |
| IP f3PrivilegeChangeIpv4Address | 1.3.6.1.4.1.2544.1.12.10.1.15.1.3 | IpAddress | read-only | IPv4 address of interface to which user's terminal is connected. |
| ADR f3PrivilegeChangeIpv6Address | 1.3.6.1.4.1.2544.1.12.10.1.15.1.4 | Ipv6Address | read-only | IPv6 address of interface to which user's terminal is connected. |
| U32 f3PrivilegeChangeRemainingTime | 1.3.6.1.4.1.2544.1.12.10.1.15.1.13 | Unsigned32 | read-only | Time remaining in session with upgrade user privilege (in seconds). |
| STR f3PrivilegeChangeRemoteName | 1.3.6.1.4.1.2544.1.12.10.1.15.1.14 | SnmpAdminString | read-only | The name string for Radius/Tacacs authentication purposes. |
| CMS f3PrivilegeChangeRequestedPrivilege | 1.3.6.1.4.1.2544.1.12.10.1.15.1.9 | CmSecurityPrivLevel | read-only | Privilege requested by user for session. |
| PRI f3PrivilegeChangeState | 1.3.6.1.4.1.2544.1.12.10.1.15.1.12 | PrivilegeRequestState | read-only | Privilege request state. |
| f3PrivilegeChangeTable | 1.3.6.1.4.1.2544.1.12.10.1.15 | not-accessible | This table is used for Restricted User Login via NMS. This is for users with lower privileges to elevate them to higher ones for limited amount of time. | |
| IP f3PrivilegeChangeTerminalIpv4Address | 1.3.6.1.4.1.2544.1.12.10.1.15.1.5 | IpAddress | read-only | Source IPv4 address of connected terminal. |
| ADR f3PrivilegeChangeTerminalIpv6Address | 1.3.6.1.4.1.2544.1.12.10.1.15.1.6 | Ipv6Address | read-only | Source IPv6 address of connected terminal. |
| NTF f3PrivilegeChangeTrap | 1.3.6.1.4.1.2544.1.12.10.3.2 | This trap is sent every time a privilege change request is changed (added, modified, removed). | ||
| STR f3PrivilegeChangeUserName | 1.3.6.1.4.1.2544.1.12.10.1.15.1.2 | SnmpAdminString | read-only | The name string for user authentication purposes |
| STR f3RadiusRealm | 1.3.6.1.4.1.2544.1.12.10.1.19 | DisplayString | read-write | When the value of radiusRealm is not a null string, the system shall append an '@' character and the radiusRealm string to the User-Name attribute included in Access-Request Messages. |
| T/F f3RadiusSendVendorAvpEnabled | 1.3.6.1.4.1.2544.1.12.10.1.18 | TruthValue | read-write | If enabled, Vendor-ID AVP is sent in Access-Request Messages. |
| RSA f3RsaKeyPairAction | 1.3.6.1.4.1.2544.1.12.10.1.26.1 | RsaKeyPairAction | read-write | This is the action to RSA key pair. |
| RSA f3RsaKeyPairActionLength | 1.3.6.1.4.1.2544.1.12.10.1.26.3 | RsaKeyLengthType | read-write | This is the length of RSA key pair action. |
| STR f3RsaKeyPairActionName | 1.3.6.1.4.1.2544.1.12.10.1.26.2 | DisplayString | read-write | This is the name of RSA key pair action. |
| f3RsaKeyPairEntry | 1.3.6.1.4.1.2544.1.12.10.1.26.4.1 | not-accessible | A conceptual row in the f3RsaKeyPairTable. | |
| STR f3RsaKeyPairName | 1.3.6.1.4.1.2544.1.12.10.1.26.4.1.1 | DisplayString | not-accessible | This is a unique name for the key pair. |
| f3RsaKeyPairObjects | 1.3.6.1.4.1.2544.1.12.10.1.26 | |||
| STR f3RsaKeyPairPublicKey | 1.3.6.1.4.1.2544.1.12.10.1.26.4.1.2 | DisplayString | read-only | This is a public key. |
| f3RsaKeyPairTable | 1.3.6.1.4.1.2544.1.12.10.1.26.4 | not-accessible | A list of RSA key pairs. | |
| NTF f3SecurityTrap | 1.3.6.1.4.1.2544.1.12.10.3.1 | This is security trap. Security traps are reported according to value of f3SecurityTrapType object. | ||
| STR f3SecurityTrapInfo | 1.3.6.1.4.1.2544.1.12.10.1.14 | DisplayString | read-only | This object is used to describe the security trap info. This object is used only in trap and GET operation on this object will return empty string. |
| SNM f3SecurityTrapType | 1.3.6.1.4.1.2544.1.12.10.1.13 | SnmpSecurityTrapType | read-write | This object provides ability to manage whether report security trap. |
| T/F f3SshCipherStrengthHighControl | 1.3.6.1.4.1.2544.1.12.10.1.31 | TruthValue | read-write | When enabled, high cipher strength is enforced. |
| SSL f3SslCertificateAction | 1.3.6.1.4.1.2544.1.12.10.1.25.3 | SslCertificateAction | read-write | This is the action to take on SSL certificate objects. |
| STR f3SslCertificateActionKeyName | 1.3.6.1.4.1.2544.1.12.10.1.25.6 | DisplayString | read-write | This is the name of the Certificate/Private Key pair to add. |
| STR f3SslCertificateActionPairName | 1.3.6.1.4.1.2544.1.12.10.1.25.4 | DisplayString | read-write | This is the name of the SSL Certificate/Private Key pair to delete or set for HTTPS. |
| f3SslCertificateObjects | 1.3.6.1.4.1.2544.1.12.10.1.25 | |||
| SSL f3SslCertificatePrivateKeyPairAction | 1.3.6.1.4.1.2544.1.12.10.1.25.5.1.7 | SslCertificatePrivateKeyPairAction | read-write | This is the SSL Certificate/Private Key Pair Action. |
| CER f3SslCertificatePrivateKeyPairCertificateStatus | 1.3.6.1.4.1.2544.1.12.10.1.25.5.1.6 | CertificateStatus | read-only | This is the SSL certificate status. |
| CER f3SslCertificatePrivateKeyPairCertificateType | 1.3.6.1.4.1.2544.1.12.10.1.25.5.1.5 | CertificateType | read-only | This is the SSL certificate type. |
| f3SslCertificatePrivateKeyPairEntry | 1.3.6.1.4.1.2544.1.12.10.1.25.5.1 | not-accessible | A conceptual row in the f3SslCertificatePrivateKeyPairTable. | |
| STR f3SslCertificatePrivateKeyPairName | 1.3.6.1.4.1.2544.1.12.10.1.25.5.1.1 | DisplayString | not-accessible | This is a unique name for the key pair. |
| T/F f3SslCertificatePrivateKeyPairPrivateKeyPresent | 1.3.6.1.4.1.2544.1.12.10.1.25.5.1.3 | TruthValue | read-only | This indicates that a private key is present in the key pair. |
| STR f3SslCertificatePrivateKeyPairRsaKeyPairName | 1.3.6.1.4.1.2544.1.12.10.1.25.5.1.4 | DisplayString | read-only | This is the Rsa key of the SSL certificate. |
| STR f3SslCertificatePrivateKeyPairSslCertificate | 1.3.6.1.4.1.2544.1.12.10.1.25.5.1.2 | DisplayString | read-only | This is the contents of the SSL certificate. |
| f3SslCertificatePrivateKeyPairTable | 1.3.6.1.4.1.2544.1.12.10.1.25.5 | not-accessible | A list of entries for the SSL Certificate/Private Key Pairs. | |
| T/F f3Sso2faControl | 1.3.6.1.4.1.2544.1.12.10.1.24 | TruthValue | read-write | When enabled, the f3 device will allow the creation of a cmSecurityUserEntry with the cmSecurityUserSso2fa set to enabled. |
| CMS f3TacacsDefaultPrivLevel | 1.3.6.1.4.1.2544.1.12.10.1.11 | CmSecurityPrivLevel | read-write | This object allows specification of the default privilege level of the TACACS+ user, when the use of ENABLE authorization control is DISABLED, i.e. f3TacacsPrivLevelControlEnabled is set to FALSE. |
| T/F f3TacacsPrivLevelControlEnabled | 1.3.6.1.4.1.2544.1.12.10.1.10 | TruthValue | read-write | This object allows to enable/disable the use of ENABLE authorization control to determine the Privilege Level configured by the remote authentication server. This object is only valid for TACACS+. Default value of this object is TRUE. |
| T/F f3UserPrivMgmtControl | 1.3.6.1.4.1.2544.1.12.10.1.16 | TruthValue | read-write | This object is used to enable/disable User Privilege Management. |
| I32 f3UserPrivRspTimeout | 1.3.6.1.4.1.2544.1.12.10.1.17 | Integer32 | read-write | This object is used to set response timeout for user privilege upgrade request in minutes. |
| USM f3UsmUserAccessType | 1.3.6.1.4.1.2544.1.12.10.1.9.1.1 | UsmUserAccessType | read-only | This indicates the type of USM User, read-only, read-write, trap-only. |
| f3UsmUserEntry | 1.3.6.1.4.1.2544.1.12.10.1.9.1 | not-accessible | An entry in the F3 USM User Table. | |
| f3UsmUserTable | 1.3.6.1.4.1.2544.1.12.10.1.9 | not-accessible | This table is the extension of the F3 USM User Table. | |
| INT icmpV4DropEchoRequests | 1.3.6.1.4.1.2544.1.12.10.1.20.2 | INTEGER | read-write | This object is used to enable/disable Dropping Echo Requests. |
| INT icmpV4Filter | 1.3.6.1.4.1.2544.1.12.10.1.20.1 | INTEGER | read-write | This object is used to enable/disable ICMP Filter. When disabled is set, all IcmpV4 dropping filters are not applied. Only when enabled is set, IcmpV4 dropping filter can be set. |
| INT icmpV6DropEchoRequests | 1.3.6.1.4.1.2544.1.12.10.1.21.2 | INTEGER | read-write | This object is used to enable/disable Dropping Echo Requests. |
| INT icmpV6DropNeighborAdvertisement | 1.3.6.1.4.1.2544.1.12.10.1.21.5 | INTEGER | read-write | This object is used to enable/disable Dropping Neighbor Advertisement. |
| INT icmpV6DropNeighborSolicitation | 1.3.6.1.4.1.2544.1.12.10.1.21.3 | INTEGER | read-write | This object is used to enable/disable Dropping Neighbor Solicitation. |
| INT icmpV6DropRouterAdvertisement | 1.3.6.1.4.1.2544.1.12.10.1.21.4 | INTEGER | read-write | This object is used to enable/disable Dropping Router Advertisement. |
| INT icmpV6DropRouterSolicitation | 1.3.6.1.4.1.2544.1.12.10.1.21.6 | INTEGER | read-write | This object is used to enable/disable Dropping Router Solicitation. |
| INT icmpV6Filter | 1.3.6.1.4.1.2544.1.12.10.1.21.1 | INTEGER | read-write | This object is used to enable/disable ICMP Filter. When disabled is set, all IcmpV6 dropping filters are not applied. Only when enabled is set, IcmpV6 dropping filters can be set individually. |
RFC description
Configures security settings including encryption and authentication for Ceragon microwave radio links.
Start monitoring ADVA/Ceragon FSP150 CM/CC (F3) microwave & Carrier Ethernet transport platform with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.