All MIBs › DLINK-PORT-SECURITY-MIB › swPortSecPortLockAddrMode
swPortSecPortLockAddrMode
Module: DLINK-PORT-SECURITY-MIB
OID (symbolic): DLINK-PORT-SECURITY-MIB::swPortSecPortLockAddrMode
OID (numeric): 1.3.6.1.4.1.171.12.63.3.1.1.1.3
Node type: OBJECT-TYPE
Type: INTEGER
Access: read-write
Description: Indicates the mode of locking address. In deleteOnTimeout(2) mode, the locked addresses can be aged out after the aging timer expires. In this mode, when the locked address is aged out, the number of addresses that can be learned has to be increased by one. In deleteOnReset (3) mode, locked addresses never age out unless the system restarts which will prevent port movement or intrusion.
What is swPortSecPortLockAddrMode?
This read-write enumeration selects how locked MAC addresses on a port age out: permanent(1), deleteOnTimeout(2), or deleteOnReset(3). In deleteOnTimeout mode the port's learning capacity frees up as addresses expire, while deleteOnReset mode keeps addresses locked until the switch reboots, which is stricter against port hopping or spoofing. An admin worried about an attacker unplugging a legitimate device and plugging in a rogue one would set swPortSecPortLockAddrMode to deleteOnReset(3) so the locked MAC can't simply be waited out.
Examples
Walk all instances (SNMPv2c):
snmpwalk -v2c -c public <target> 1.3.6.1.4.1.171.12.63.3.1.1.1.3 snmpwalk -v2c -c public <target> DLINK-PORT-SECURITY-MIB::swPortSecPortLockAddrMode
Get a specific instance (index 1):
snmpget -v2c -c public <target> 1.3.6.1.4.1.171.12.63.3.1.1.1.3.1 snmpget -v2c -c public <target> DLINK-PORT-SECURITY-MIB::swPortSecPortLockAddrMode.1
Set instance 1 (SNMPv2c):
snmpset -v2c -c private <target> 1.3.6.1.4.1.171.12.63.3.1.1.1.3.1 i <value>
Start monitoring D-Link managed switch (MAC-based port security) with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the DLINK-PORT-SECURITY-MIB::swPortSecPortLockAddrMode OID value, configure state conditions and alerts, and monitor any D-Link managed switch (MAC-based port security) from a single console.
OID Breakdown
Upper-level ancestors (8 from the standard OID tree / other modules)
| Numeric OID | Name | Module |
|---|---|---|
| 1 | iso | LANART-AGENT |
| 1.3 | org | AirPair-MIB |
| 1.3.6 | dod | AirPair-MIB |
| 1.3.6.1 | internet | AirPair-MIB |
| 1.3.6.1.4 | private | AirPair-MIB |
| 1.3.6.1.4.1 | enterprises | AirPair-MIB |
| 1.3.6.1.4.1.171 | d_link | DE1500-MIB |
| 1.3.6.1.4.1.171.12 | dlink_common_mgmt | DLINK-ID-REC-MIB |
| Numeric OID | Name | Module |
|---|---|---|
| 1.3.6.1.4.1.171.12.63 | swPortSecMIB | DLINK-PORT-SECURITY-MIB |
| 1.3.6.1.4.1.171.12.63.3 | swPortSecMgmt | DLINK-PORT-SECURITY-MIB |
| 1.3.6.1.4.1.171.12.63.3.1 | swPortSecMgmtByPort | DLINK-PORT-SECURITY-MIB |
| 1.3.6.1.4.1.171.12.63.3.1.1 | swPortSecPortTable | DLINK-PORT-SECURITY-MIB |
| 1.3.6.1.4.1.171.12.63.3.1.1.1 | swPortSecPortEntry | DLINK-PORT-SECURITY-MIB |
| 1.3.6.1.4.1.171.12.63.3.1.1.1.3 | swPortSecPortLockAddrMode | DLINK-PORT-SECURITY-MIB |