Dell-DOT1X-MIB

MIB Reference — IPNetwork Monitor

All MIBsDell-DOT1X-MIB

Organization: Dell

Last Updated: 2007-01-02

Category: Domain: Security, Protocol: 802.1X, Vendor: Dell

Description:

Manages IEEE 802.1X port-based network access control on Dell network switches.

Imported Objects

From BRIDGE-MIB

MacAddress

From Dell-MIB

rndMODULE-IDENTITY

From IEEE8021-PAE-MIB

PaeControlledPortStatus
dot1xAuthSessionStatsEntryOBJECT-TYPE
dot1xPaePortNumberOBJECT-TYPE

From Q-BRIDGE-MIB

PortList
VlanIndex
dot1qFdbIdOBJECT-TYPE

From SNMP-FRAMEWORK-MIB

SnmpAdminString

From SNMPv2-SMI

Counter32
Counter64
MODULE-IDENTITY
OBJECT-TYPE
TimeTicks
Unsigned32

From SNMPv2-TC

RowStatus
TruthValue

What Is Dell-DOT1X-MIB?

Dell-DOT1X-MIB is a Dell private MIB for configuring and monitoring IEEE 802.1X port-based network access control on Dell network switches. It exposes per-session authentication statistics, guest VLAN and unauthenticated VLAN configuration, and user-based VLAN assignment settings for ports running 802.1X. Its monitoring focus is software/protocol status rather than physical hardware: rldot1xExtAuthSessionStatsTable/Entry and rlDot1xAuthSessionAuthenticMethod reveal which authentication method succeeded (or is in use) per session, while the guest-VLAN and unauthenticated-VLAN objects show whether a port has fallen back to a restricted VLAN because 802.1X authentication failed or was never attempted. This MIB depends on and complements the IEEE 802.1X standard and typically coexists with the vendor's core VLAN and port MIBs. It is deployed on Dell access-layer switches in enterprise networks enforcing NAC (network access control) policy at the switch port. Engineers can download the Dell-DOT1X-MIB file directly to load it into their MIB browser.

IPNetwork Monitor allows you to monitor SNMP objects defined in Dell-DOT1X-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

What Can Be Monitored

  • per-session 802.1X authentication method/statistics
  • guest VLAN assignment/ports
  • unauthenticated VLAN status
  • user-based VLAN assignment support

Supported Devices

  • Dell network switch (802.1X access-layer)

Monitoring Examples

An admin would walk rldot1xExtAuthSessionStatsTable/rldot1xExtAuthSessionStatsEntry to see per-session 802.1X authentication statistics and check rlDot1xAuthSessionAuthenticMethod to confirm which method (e.g., EAP type) was used. rldot1xGuestVlanVID and rldot1xGuestVlanPorts show which ports have fallen into the guest VLAN, and rldot1xUnAuthenticatedVlanTable/Entry with rldot1xUnAuthenticatedVlanStatus reveals ports operating in the unauthenticated VLAN. A rising count of ports landing in the guest or unauthenticated VLAN would indicate a wave of 802.1X authentication failures, e.g., from a misconfigured RADIUS server or expired credentials.

OIDs
OID symbolicOID numericTypeAccessDescription
rldot1x1.3.6.1.4.1.89.95This private MIB module defines dot1x private MIBs.
INT rldot1xMibVersion1.3.6.1.4.1.89.95.1INTEGERread-onlyMIB's version, the current version is 1.
rldot1xExtAuthSessionStatsTable1.3.6.1.4.1.89.95.2not-accessibleA table that contains the session statistics objects for the Authenticator PAE associated with each Port. An entry appears in this table for each port that may authenticate access to itself.
rldot1xExtAuthSessionStatsEntry1.3.6.1.4.1.89.95.2.1not-accessibleThe session statistics information for an Authenticator PAE. This shows the current values being collected for each session that is still in progress, or the final values for the last valid session on each port where there is no session currently active.
INT rlDot1xAuthSessionAuthenticMethod1.3.6.1.4.1.89.95.2.1.1INTEGERread-onlyThe authentication method used to establish the session.
T/F rldot1xGuestVlanSupported1.3.6.1.4.1.89.95.3TruthValueread-onlyindicate if guest vlan is supported.
VLA rldot1xGuestVlanVID1.3.6.1.4.1.89.95.4VlanIndexread-writespecify the guest vlan tag , 0 for non exiting.
POR rldot1xGuestVlanPorts1.3.6.1.4.1.89.95.5PortListread-writethe ports that can be members in the guest vlan
T/F rldot1xUnAuthenticatedVlanSupported1.3.6.1.4.1.89.95.6TruthValueread-onlyindicate if unauthenticated Vlan is supported.
rldot1xUnAuthenticatedVlanTable1.3.6.1.4.1.89.95.7not-accessibleport belong to vlan in all port authenticated state except force unauthenticated table
rldot1xUnAuthenticatedVlanEntry1.3.6.1.4.1.89.95.7.1not-accessibleport belong to vlan in all port authenticated state except force unauthenticated entry
ROW rldot1xUnAuthenticatedVlanStatus1.3.6.1.4.1.89.95.7.1.1RowStatusread-createThe row status variable, used according to row installation and removal conventions.
T/F rldot1xUserBasedVlanSupported1.3.6.1.4.1.89.95.8TruthValueread-onlyindicate if user based Vlan is supported.
POR rldot1xUserBasedVlanPorts1.3.6.1.4.1.89.95.9PortListread-writethe ports that can be members in the user based vlan
rldot1xAuthenticationPortTable1.3.6.1.4.1.89.95.10not-accessibleA table of system level information for each port supported by the Port Access Entity. An entry appears in this table for each port of this system.
rldot1xAuthenticationPortEntry1.3.6.1.4.1.89.95.10.1not-accessibleThe Port number and mac method
INT rldot1xAuthenticationPortMethod1.3.6.1.4.1.89.95.10.1.1INTEGERread-writeThe value of the 802.1x-based, mac-based and web-based authentication.
T/F rldot1xRadiusAttrVlanIdEnabled1.3.6.1.4.1.89.95.10.1.2TruthValueread-writeDefines if treat VLAN ID that received from Radius attributes in Radius-Accept message.
T/F rldot1xRadiusAttAclNameEnabled1.3.6.1.4.1.89.95.10.1.3TruthValueread-writeDefines if treat ACL Names that received from Radius attributes in Radius-Accept message.
STR rldot1xTimeBasedName1.3.6.1.4.1.89.95.10.1.4SnmpAdminStringread-writeSpecifies a time range. When the Time Range is not in effect the port state would be Unauthorized.
T/F rldot1xTimeBasedActive1.3.6.1.4.1.89.95.10.1.5TruthValueread-onlySpecifies if time range is active now or not.
VLA rldot1xRadiusAttrVlanIdentifier1.3.6.1.4.1.89.95.10.1.6VlanIndexread-writeIn case that value is not 0, This field will define the VLAN ID in case that it is not received from Radius attributes in Radius-Accept message.
U32 rldot1xMaxHosts1.3.6.1.4.1.89.95.10.1.7Unsigned32read-writeMaximum number of authenticated hosts allowed on the interface. A value of 0 means no limitation.
INT rldot1xMaxLoginAttempts1.3.6.1.4.1.89.95.10.1.8INTEGERread-writeMaximum number of allowedlogin attempts on the interface. A value of 0 means the infinite number of attemtps. The configuration is applied only to Web-Based authentication.
INT rldot1xTimeoutSilencePeriod1.3.6.1.4.1.89.95.10.1.9INTEGERread-writeSet the number of seconds that if an authorized client did not send traffic during this period, then the client is changed to unauthrized. The configuration is applied only to Web-Based authentication.
INT rldot1xNumOfAuthorizedHosts1.3.6.1.4.1.89.95.10.1.10INTEGERread-onlyNumber of authorized host in multi-sessions mode.
T/F rldot1xAuthenticationOpenEnabled1.3.6.1.4.1.89.95.10.1.11TruthValueread-writeOpen access allows clients or devices to gain network access before authentication is performed. In the mode the switch performs failure replies received from a Radius server as success.
rldot1xAuthMultiStatsTable1.3.6.1.4.1.89.95.11not-accessibleA table that contains the statistics objects for the Authenticator PAE associated with each Port and MAC for multisession 802.1x mode of operation. An entry appears in this table for each port and MAC that have an authentication session currently running under way for them.
rldot1xAuthMultiStatsEntry1.3.6.1.4.1.89.95.11.1not-accessibleThe statistics information for an Authenticator PAE.
INT rldot1xAuthMultiStatsPortNumber1.3.6.1.4.1.89.95.11.1.1INTEGERread-onlyPort Number.
MAC rldot1xAuthMultiStatsSourceMac1.3.6.1.4.1.89.95.11.1.2MacAddressread-onlyMac of the authentication session.
C32 rldot1xAuthMultiEapolFramesRx1.3.6.1.4.1.89.95.11.1.3Counter32read-onlyThe number of valid EAPOL frames of any type that have been received by this Authenticator.
C32 rldot1xAuthMultiEapolFramesTx1.3.6.1.4.1.89.95.11.1.4Counter32read-onlyThe number of EAPOL frames of any type that have been transmitted by this Authenticator.
C32 rldot1xAuthMultiEapolStartFramesRx1.3.6.1.4.1.89.95.11.1.5Counter32read-onlyThe number of EAPOL Start frames that have been received by this Authenticator.
C32 rldot1xAuthMultiEapolLogoffFramesRx1.3.6.1.4.1.89.95.11.1.6Counter32read-onlyThe number of EAPOL Logoff frames that have been received by this Authenticator.
C32 rldot1xAuthMultiEapolRespIdFramesRx1.3.6.1.4.1.89.95.11.1.7Counter32read-onlyThe number of EAP Resp/Id frames that have been received by this Authenticator.
C32 rldot1xAuthMultiEapolRespFramesRx1.3.6.1.4.1.89.95.11.1.8Counter32read-onlyThe number of valid EAP Response frames (other than Resp/Id frames) that have been received by this Authenticator.
C32 rldot1xAuthMultiEapolReqIdFramesTx1.3.6.1.4.1.89.95.11.1.9Counter32read-onlyThe number of EAP Req/Id frames that have been transmitted by this Authenticator.
C32 rldot1xAuthMultiEapolReqFramesTx1.3.6.1.4.1.89.95.11.1.10Counter32read-onlyThe number of EAP Request frames (other than Rq/Id frames) that have been transmitted by this Authenticator.
C32 rldot1xAuthMultiInvalidEapolFramesRx1.3.6.1.4.1.89.95.11.1.11Counter32read-onlyThe number of EAPOL frames that have been received by this Authenticator in which the frame type is not recognized.
C32 rldot1xAuthMultiEapLengthErrorFramesRx1.3.6.1.4.1.89.95.11.1.12Counter32read-onlyThe number of EAPOL frames that have been received by this Authenticator in which the Packet Body Length field is invalid.
rldot1xAuthMultiDiagTable1.3.6.1.4.1.89.95.12not-accessibleA table that contains the diagnostics objects for the Authenticator PAE associated with each Port and MAC. An entry appears in this table for each port and MAC that have an authentication session currently running under way for them.
rldot1xAuthMultiDiagEntry1.3.6.1.4.1.89.95.12.1not-accessibleThe diagnostics information for an Authenticator PAE.
INT rldot1xAuthMultiDiagPortNumber1.3.6.1.4.1.89.95.12.1.1INTEGERread-onlyPort Number.
MAC rldot1xAuthMultiDiagSourceMac1.3.6.1.4.1.89.95.12.1.2MacAddressread-onlyMac of the authentication session.
C32 rldot1xAuthMultiEntersConnecting1.3.6.1.4.1.89.95.12.1.3Counter32read-onlyCounts the number of times that the state machine transitions to the CONNECTING state from any other state.
C32 rldot1xAuthMultiEntersAuthenticating1.3.6.1.4.1.89.95.12.1.4Counter32read-onlyCounts the number of times that the state machine transitions from CONNECTING to AUTHENTICATING, as a result of an EAP-Response/Identity message being received from the Supplicant.
C32 rldot1xAuthMultiAuthSuccessWhileAuthenticating1.3.6.1.4.1.89.95.12.1.5Counter32read-onlyCounts the number of times that the state machine transitions from AUTHENTICATING to AUTHENTICATED, as a result of the Backend Authentication state machine indicating successful authentication of the Supplicant (authSuccess = TRUE).
C32 rldot1xAuthMultiAuthFailWhileAuthenticating1.3.6.1.4.1.89.95.12.1.6Counter32read-onlyCounts the number of times that the state machine transitions from AUTHENTICATING to HELD, as a result of the Backend Authentication state machine indicating authentication failure (authFail = TRUE).
C32 rldot1xAuthMultiAuthReauthsWhileAuthenticating1.3.6.1.4.1.89.95.12.1.7Counter32read-onlyCounts the number of times that the state machine transitions from AUTHENTICATING to ABORTING, as a result of a reauthentication request (reAuthenticate = TRUE).
C32 rldot1xAuthMultiAuthEapStartsWhileAuthenticating1.3.6.1.4.1.89.95.12.1.8Counter32read-onlyCounts the number of times that the state machine transitions from AUTHENTICATING to ABORTING, as a result of an EAPOL-Start message being received from the Supplicant.
C32 rldot1xAuthMultiAuthReauthsWhileAuthenticated1.3.6.1.4.1.89.95.12.1.9Counter32read-onlyCounts the number of times that the state machine transitions from AUTHENTICATED to CONNECTING, as a result of a reauthentication request (reAuthenticate = TRUE).
C32 rldot1xAuthMultiAuthEapStartsWhileAuthenticated1.3.6.1.4.1.89.95.12.1.10Counter32read-onlyCounts the number of times that the state machine transitions from AUTHENTICATED to CONNECTING, as a result of an EAPOL-Start message being received from the Supplicant.
C32 rldot1xAuthMultiBackendResponses1.3.6.1.4.1.89.95.12.1.11Counter32read-onlyCounts the number of times that the state machine sends an initial Access-Request packet to the Authentication server (i.e., executes sendRespToServer on entry to the RESPONSE state). Indicates that the Authenticator attempted communication with the Authentication Server.
C32 rldot1xAuthMultiBackendAccessChallenges1.3.6.1.4.1.89.95.12.1.12Counter32read-onlyCounts the number of times that the state machine receives an initial Access-Challenge packet from the Authentication server (i.e., aReq becomes TRUE, causing exit from the RESPONSE state). Indicates that the Authentication Server has communication with the Authenticator.
C32 rldot1xAuthMultiBackendOtherRequestsToSupplicant1.3.6.1.4.1.89.95.12.1.13Counter32read-onlyCounts the number of times that the state machine sends an EAP-Request packet (other than an Identity, Notification, Failure or Success message) to the Supplicant (i.e., executes txReq on entry to the REQUEST state). Indicates that the Authenticator chose an EAP-method.
C32 rldot1xAuthMultiBackendNonNakResponsesFromSupplicant1.3.6.1.4.1.89.95.12.1.14Counter32read-onlyCounts the number of times that the state machine receives a response from the Supplicant to an initial EAP-Request, and the response is something other than EAP-NAK (i.e., rxResp becomes TRUE, causing the state machine to transition from REQUEST to RESPONSE, and the response is not an EAP-NAK). Indicates that the Supplicant can respond to the Authenticators chosen EAP-method.
C32 rldot1xAuthMultiBackendAuthSuccesses1.3.6.1.4.1.89.95.12.1.15Counter32read-onlyCounts the number of times that the state machine receives an EAP-Success message from the Authentication Server (i.e., aSuccess becomes TRUE, causing a transition from RESPONSE to SUCCESS). Indicates that the Supplicant has successfully authenticated to the Authentication Server.
rldot1xAuthMultiSessionStatsTable1.3.6.1.4.1.89.95.13not-accessibleA table that contains the session statistics objects for the Authenticator PAE associated with each Port. An entry appears in this table for each port that may authenticate access to itself.
rldot1xAuthMultiSessionStatsEntry1.3.6.1.4.1.89.95.13.1not-accessibleThe session statistics information for an Authenticator PAE. This shows the current values being collected for each session that is still in progress, or the final values for the last valid session on each port where there is no session currently active.
INT rldot1xAuthMultiSessionStatsPortNumber1.3.6.1.4.1.89.95.13.1.1INTEGERread-onlyPort Number.
MAC rldot1xAuthMultiSessionStatsSourceMac1.3.6.1.4.1.89.95.13.1.2MacAddressread-onlyMac of the authentication session.
C64 rldot1xAuthMultiSessionOctetsRx1.3.6.1.4.1.89.95.13.1.3Counter64read-onlyThe number of octets received in user data frames on this Port during the session.
C64 rldot1xAuthMultiSessionOctetsTx1.3.6.1.4.1.89.95.13.1.4Counter64read-onlyThe number of octets transmitted in user data frames on this Port during the session.
C32 rldot1xAuthMultiSessionFramesRx1.3.6.1.4.1.89.95.13.1.5Counter32read-onlyThe number of user data frames received on this Port during the session.
C32 rldot1xAuthMultiSessionFramesTx1.3.6.1.4.1.89.95.13.1.6Counter32read-onlyThe number of user data frames transmitted on this Port during the session.
STR rldot1xAuthMultiSessionId1.3.6.1.4.1.89.95.13.1.7SnmpAdminStringread-onlyA unique identifier for the session, in the form of a printable ASCII string of at least three characters.
TIK rldot1xAuthMultiSessionTime1.3.6.1.4.1.89.95.13.1.8TimeTicksread-onlyThe duration of the session in seconds.
STR rldot1xAuthMultiSessionUserName1.3.6.1.4.1.89.95.13.1.9SnmpAdminStringread-onlyThe User-Name representing the identity of the Supplicant PAE.
INT rldot1xAuthMultiSessionRadiusAttrVlan1.3.6.1.4.1.89.95.13.1.10INTEGERread-onlyVLAN ID that received from Radius attributes.
STR rldot1xAuthMultiSessionRadiusAttrFilterId1.3.6.1.4.1.89.95.13.1.11SnmpAdminStringread-onlyFirst filter ID that received from Radius attributes.
STR rldot1xAuthMultiSessionRadiusAttrSecondFilterId1.3.6.1.4.1.89.95.13.1.12SnmpAdminStringread-onlySecond filter ID that received from Radius attributes.
INT rlDot1xAuthMultiSessionMonitorResultsReason1.3.6.1.4.1.89.95.13.1.13INTEGERread-onlyThe monitor result reason of the session.
INT rlDot1xAuthMultiSessionMethodType1.3.6.1.4.1.89.95.13.1.14INTEGERread-onlyThe current session method type.
rldot1xAuthMultiConfigTable1.3.6.1.4.1.89.95.14not-accessibleA table that contains the configuration objects for the Authenticator PAE associated with each port and MAC. An entry appears in this table for each port and MAC that may authenticate access to itself.
rldot1xAuthMultiConfigEntry1.3.6.1.4.1.89.95.14.1not-accessibleThe configuration information for an Authenticator PAE.
INT rldot1xAuthMultiPortNumber1.3.6.1.4.1.89.95.14.1.1INTEGERread-onlyPort Number.
MAC rldot1xAuthMultiSourceMac1.3.6.1.4.1.89.95.14.1.2MacAddressread-onlyMac of the authentication session.
INT rldot1xAuthMultiPaeState1.3.6.1.4.1.89.95.14.1.3INTEGERread-onlyThe current value of the Authenticator PAE state machine.
INT rldot1xAuthMultiBackendAuthState1.3.6.1.4.1.89.95.14.1.4INTEGERread-onlyThe current state of the Backend Authentication state machine.
PAE rldot1xAuthMultiControlledPortStatus1.3.6.1.4.1.89.95.14.1.5PaeControlledPortStatusread-onlyThe current value of the controlled Port status parameter for the Port.
T/F rldot1xBpduFilteringEnabled1.3.6.1.4.1.89.95.15TruthValueread-writeSpecify that when 802.1x is globally disabled, 802.1x BPDU packets would be filtered or bridged.
T/F rldot1xRadiusAttributesErrorsAclReject1.3.6.1.4.1.89.95.18TruthValueread-writeSpecify ACL error handling for the Radius attributes feature.
INT rldot1xGuestVlanTimeInterval1.3.6.1.4.1.89.95.19INTEGERread-writeindicate the guest vlan timeout interval.
T/F rldot1xMacAuthSuccessTrapEnabled1.3.6.1.4.1.89.95.20TruthValueread-writeSpecify if sending traps when a MAC address is successfully authenticated by the 802.1X mac-authentication access control.
T/F rldot1xMacAuthFailureTrapEnabled1.3.6.1.4.1.89.95.21TruthValueread-writeSpecify if sending traps when MAC address was failed in authentication of the 802.1X MAC authentication access control.
rldot1xLegacyPortTable1.3.6.1.4.1.89.95.22not-accessibleA table of system level information for each port supported by the Port Access Entity. An entry appears in this table for each port of this system.
rldot1xLegacyPortEntry1.3.6.1.4.1.89.95.22.1not-accessibleThe Port number and leagcy mode
T/F rldot1xLegacyPortModeEnabled1.3.6.1.4.1.89.95.22.1.1TruthValueread-writeIndicates whether in multiple sessions mode work according to legacy devices mode or not.
INT rldot1xSystemAuthControlMonitorVlan1.3.6.1.4.1.89.95.23INTEGERread-writeVLAN Tag of 802.1x monitoring VLAN in the System. value of 0 means that the monitoring mode is disabled.
POR rldot1xClearPortMibCounters1.3.6.1.4.1.89.95.24PortListread-writeEach bit that is set in this portList represent a port that its mib counters should be reset.
T/F rldot1xWebQuietFailureTrapEnabled1.3.6.1.4.1.89.95.25TruthValueread-writeSpecify if sending traps when a client is set in quiet state after the maximum sequential attempts of login.
INT rldot1xMacWebAuthSuccessTrapEnabled1.3.6.1.4.1.89.95.26INTEGERread-writeSpecify if sending traps per authentication method when a session is successfully authenticated.
INT rldot1xMacWebAuthFailureTrapEnabled1.3.6.1.4.1.89.95.27INTEGERread-writeSpecify if sending traps per authentication method when a session was failed.
rldot1xLockedCientsTable1.3.6.1.4.1.89.95.28not-accessibleA table that contains the locked clients information for Web-based authentication.
rldot1xLockedCientsEntry1.3.6.1.4.1.89.95.28.1not-accessibleThe locked clients entry that entered silence period timeout for Web-based authentication.
INT rldot1xLockedCientsPortNumber1.3.6.1.4.1.89.95.28.1.1INTEGERread-onlyPort Number.
MAC rldot1xLockedCientsSourceMac1.3.6.1.4.1.89.95.28.1.2MacAddressread-onlyMac of the locked client.
INT rldot1xLockedCientsRemainedTime1.3.6.1.4.1.89.95.28.1.3INTEGERread-onlyThe time that is remained till the expiry of silence period.
ROW rldot1xLockedCientsRowStatus1.3.6.1.4.1.89.95.28.1.4RowStatusread-writeRow status.

RFC description

Dell IEEE 802.1X port-based network access control for authentication and session management.

Start monitoring Dell PowerConnect/Networking managed switch (802.1X port access control) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download Dell-DOT1X-MIB