All MIBs › FASTPATH-QOS-ACL-MIB
Organization: Netgear
Last Updated: 2007-05-23
Category: Quality of Service, Technology: QoS, Vendor: Dell/DNOS
Description: Broadcom FastPath MIB for Quality of Service Access Control Lists, defining traffic classification and policy rules.
Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.
What Is FASTPATH-QOS-ACL-MIB?
FASTPATH-QOS-ACL-MIB is a Broadcom FastPath MIB, part of the QoS Flex package, that defines Access Control List (ACL)-based traffic classification and Quality of Service policy objects for FastPath-based switches. It exposes configuration for ACL rules used to classify traffic (by criteria such as source/destination address, port, or protocol) and the QoS actions or policies applied to matched traffic, such as marking, rate-limiting, or queue assignment. Its monitoring relevance is mainly on the configuration/software side — confirming which ACL rules and QoS policies are active and, where counters are present, how much traffic each rule has matched — which helps diagnose whether traffic is being classified, prioritized, or filtered as intended. It works in conjunction with FastPath's core QoS and ACL infrastructure and general FastPath switching MIBs, since ACL/QoS policies apply to interfaces and traffic classes defined elsewhere in the MIB family. It is deployed on FastPath-based switches wherever traffic prioritization or access filtering policies need to be enforced, such as at the network edge or in QoS-sensitive environments. Engineers can download the FASTPATH-QOS-ACL-MIB file directly to load it into their MIB browser.
IPNetwork Monitor allows you to monitor SNMP objects defined in FASTPATH-QOS-ACL-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.
Supported Devices
- Broadcom FastPath-based switches
Monitoring Examples
Specific object and table names were not available in the sampled data for this module, but based on its stated purpose an operator would poll ACL rule match counters and QoS policy assignment objects to confirm that a given traffic class is being classified and prioritized (or filtered) as configured. An unexpectedly low or zero match count on an ACL rule expected to be actively matching traffic would indicate a misconfigured classification criterion.
What Can Be Monitored
- ACL rule configuration/match activity
- QoS policy assignment
- traffic classification results
This MIB depends on
Related MIBs
Imported Objects
From FASTPATH-QOS-MIB
| fastPathQOS | MODULE-IDENTITY |
From IF-MIB
| InterfaceIndexOrZero |
From RFC1213-MIB
| DisplayString |
From SNMPv2-SMI
| Counter64 | |
| Integer32 | |
| IpAddress | |
| MODULE-IDENTITY | |
| NOTIFICATION-TYPE | |
| OBJECT-TYPE | |
| Unsigned32 |
From SNMPv2-TC
| MacAddress | |
| RowStatus | |
| TEXTUAL-CONVENTION | |
| TruthValue |
OIDs
| OID symbolic | OID numeric | Type | Access | Description |
|---|---|---|---|---|
| aclEntry | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.1.1 | not-accessible | ||
| I32 aclIfAclId | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.2.1.5 | Integer32 | not-accessible | The ACL identifier value, which is interpreted based on the aclIfType object. For the IP ACLs, the actual ACL number is its identifier as follows: IP standard ranges from 1-99, while IP extended ranges from 100-199. Here, aclIfAclId represents aclIndex. The MAC ACLs use an internally-generated index value that is assigned when the ACL is created.Here, aclIfAclId represents aclMacIndex. The IPv6 ACLs use an internally-generated index value that is assigned when the ACL is created.Here, aclVlanAclId represents aclIpv6Index. The aclIfType object must be specified along with this object. |
| INT aclIfAclType | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.2.1.4 | INTEGER | not-accessible | The type of this ACL, which is used to interpret the aclIfId object value. Each type of ACL uses its own numbering scheme for identification (see aclIfAclId object for details). The aclIfAclId object must be specified along with this object. |
| INT aclIfDirection | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.2.1.2 | INTEGER | not-accessible | The interface direction to which this ACL instance applies. |
| aclIfEntry | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.2.1 | not-accessible | ||
| I32 aclIfIndex | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.2.1.1 | Integer32 | not-accessible | The interface to which this ACL instance applies. |
| U32 aclIfSequence | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.2.1.3 | Unsigned32 | not-accessible | The relative evaluation sequence of this ACL for this interface and direction. When multiple ACLs are allowed for a given interface and direction, the sequence number determines the order in which the list of ACLs are evaluated, with lower sequence numbers given higher precedence. The sequence number value is arbitrary, but must be a unique non-zero value for a given interface and direction. Setting this object to an existing sequence number value for a given interface and direction causes the ACL corresponding to that value to be replaced with this ACL. |
| ROW aclIfStatus | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.2.1.6 | RowStatus | read-create | Status of this instance. active(1) - this ACL interface instance is active createAndGo(4) - set to this value to assign an ACL to an interface and direction destroy(6) - set to this value to remove an ACL from an interface and direction |
| aclIfTable | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.2 | not-accessible | A table of ACL interface instances per direction. | |
| I32 aclIndex | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.1.1.1 | Integer32 | not-accessible | The IP ACL table index this instance is associated with. |
| aclIpv6Entry | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.11.1 | not-accessible | ||
| I32 aclIpv6Index | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.11.1.1 | Integer32 | not-accessible | The IPv6 ACL table index this instance is associated with. When creating a new IPv6 ACL, refer to the aclIPv6IndexNextFree object to determine the next available aclIpv6Index to use. |
| I32 aclIpv6IndexNextFree | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.10 | Integer32 | read-only | This object contains an unused value for the aclIPv6Index to be used when creating a new IPv6 ACL. A value of zero zero indicates the ACL table is full. |
| STR aclIpv6Name | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.11.1.2 | DisplayString | read-create | The name of this IPv6 ACL entry, which must consist of 1 to 31 alphanumeric characters and uniquely identify this IPv6 ACL. An existing IPv6 ACL can be renamed by setting this object to a new name. This object must be set to complete a new IPv6 ACL row instance. |
| INT aclIpv6RuleAction | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.12.1.2 | INTEGER | read-create | The type of action this IPv6 ACL rule should perform. |
| U32 aclIpv6RuleAssignQueueId | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.12.1.4 | Unsigned32 | read-create | Queue identifier to which all inbound packets matching this ACL rule are directed. This object defaults to the standard queue assignment for user priority 0 traffic per the IEEE 802.1D specification based on the number of assignable queues in the system: 1-3 queues: 0 4-7 queues: 1 8 queues: 2 This default assignment is static and is not influenced by other system configuration changes. |
| I32 aclIpv6RuleDestL4Port | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.12.1.12 | Integer32 | read-create | The Destination Port (Layer 4) used in ACl classification. |
| I32 aclIpv6RuleDestL4PortRangeEnd | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.12.1.14 | Integer32 | read-create | The Destination Port (Layer 4) ending range used in ACL classification. |
| I32 aclIpv6RuleDestL4PortRangeStart | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.12.1.13 | Integer32 | read-create | The Destination Port (Layer 4) starting range used in ACL classification. |
| aclIpv6RuleEntry | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.12.1 | not-accessible | A table of IPv6 ACL Classification Rules | |
| I32 aclIpv6RuleFlowLabel | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.12.1.16 | Integer32 | read-create | Flow label is 20-bit number that is unique to an IPv6 packet, used by end stations to signify quality-of-service handling in routers. |
| I32 aclIpv6RuleIndex | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.12.1.1 | Integer32 | not-accessible | The index of this rule instance within an IPv6 ACL. |
| I32 aclIpv6RuleIPDSCP | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.12.1.17 | Integer32 | read-create | The Differentiated Services Code Point value. |
| T/F aclIpv6RuleLogging | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.12.1.3 | TruthValue | read-create | Flag to indicate that the ACL rule is being logged. A hardware count of the number of times this rule is hit is reported via the aclTrapRuleLogEvent notification. This object may be supported for an aclIPv6RuleAction setting of permit(1) and/or deny(2), depending on the ACL feature capabilities of the device. |
| T/F aclIpv6RuleMatchEvery | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.12.1.7 | TruthValue | read-create | Flag to indicate that the ACL rule is defined to match on every IP packet, regardless of content. |
| NUM aclIpv6RuleMirrorIntf | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.12.1.6 | InterfaceIndexOrZero | read-create | A non-zero value indicates the external ifIndex to which all inbound packets matching this IPv6 ACL rule are copied. A value of zero means packet mirroring is not in effect, which is the default value of this object. Note that packet mirroring and redirection (aclIpv6RuleRedirectIntf object) are mutually-exclusive rule attributes. |
| I32 aclIpv6RuleProtocol | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.12.1.8 | Integer32 | read-create | icmp - 1 igmp - 2 ip - 4 tcp - 6 udp - 17 All values from 1 to 255 are valid. |
| NUM aclIpv6RuleRedirectIntf | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.12.1.5 | InterfaceIndexOrZero | read-create | A non-zero value indicates the external ifIndex to which all inbound packets matching this Ipv6 ACL rule are directed. A value of zero means packet redirection is not in effect, which is the default value of this object. Note that packet redirection and mirroring (aclIpv6RuleMirrorIntf object) are mutually-exclusive rule attributes. |
| I32 aclIpv6RuleSrcL4Port | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.12.1.9 | Integer32 | read-create | The Source Port Number (Layer 4) used in the ACL Classification. |
| I32 aclIpv6RuleSrcL4PortRangeEnd | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.12.1.11 | Integer32 | read-create | The Source Port Number(Layer 4) range end. |
| I32 aclIpv6RuleSrcL4PortRangeStart | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.12.1.10 | Integer32 | read-create | The Source Port Number(Layer 4) range start. |
| ROW aclIpv6RuleStatus | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.12.1.15 | RowStatus | read-create | Status of this instance. active(1) - this ACL Rule is active createAndGo(4) - set to this value to create an instance destroy(6) - set to this value to delete an instance |
| aclIpv6RuleTable | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.12 | not-accessible | A table of IPv6 ACL Rule instances. | |
| ROW aclIpv6Status | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.11.1.3 | RowStatus | read-create | Status of this instance. active(1) - this ACL instance is active createAndGo(4) - set to this value to create an instance destroy(6) - set to this value to delete an instance The aclMacName object must be set to complete this row instance. |
| aclIpv6Table | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.11 | not-accessible | A table of Ipv6 ACL instances. | |
| aclLoggingGroup | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.9 | |||
| aclMacEntry | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.5.2.1 | not-accessible | ||
| aclMacGroup | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.5 | |||
| I32 aclMacIndex | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.5.2.1.1 | Integer32 | not-accessible | The MAC ACL table index this instance is associated with. When creating a new MAC ACL, refer to the aclMacIndexNextFree object to determine the next available aclMacIndex to use. |
| I32 aclMacIndexNextFree | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.5.1 | Integer32 | read-only | This object contains an unused value for the aclMacIndex to be used when creating a new MAC ACL. A value of zero zero indicates the ACL table is full. |
| STR aclMacName | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.5.2.1.2 | DisplayString | read-create | The name of this MAC ACL entry, which must consist of 1 to 31 alphanumeric characters and uniquely identify this MAC ACL. An existing MAC ACL can be renamed by setting this object to a new name. This object must be set to complete a new MAC ACL row instance. |
| INT aclMacRuleAction | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.5.3.1.2 | INTEGER | read-create | The type of action this MAC ACL rule should perform. |
| U32 aclMacRuleAssignQueueId | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.5.3.1.18 | Unsigned32 | read-create | Queue identifier to which all inbound packets matching this MAC ACL rule are directed. This object defaults to the standard queue assignment for user priority 0 traffic per the IEEE 802.1D specification based on the number of assignable queues in the system: 1-3 queues: 0 4-7 queues: 1 8 queues: 2 This default assignment is static and is not influenced by other system configuration changes. |
| U32 aclMacRuleCos | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.5.3.1.3 | Unsigned32 | read-create | The Class of Service (COS) used in the MAC ACL Classification. This is the three-bit user priority field in the 802.1Q tag header of a tagged Ethernet frame. For frames containing a double VLAN tag, this field is located in the first/outer tag. |
| U32 aclMacRuleCos2 | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.5.3.1.4 | Unsigned32 | read-create | The Secondary Class of Service (COS2) used in the MAC ACL Classification. This is the three-bit user priority field in the second/inner 802.1Q tag header of a double VLAN tagged Ethernet frame. |
| MAC aclMacRuleDestMacAddr | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.5.3.1.5 | MacAddress | read-create | The Destination MAC address used in the MAC ACL Classification. |
| MAC aclMacRuleDestMacMask | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.5.3.1.6 | MacAddress | read-create | The Destination MAC address mask used in the MAC ACL Classification. This mask value identifies the portion of the aclMacRuleDestMacAddr that is compared against a packet. A non-contiguous mask value is permitted. |
| aclMacRuleEntry | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.5.3.1 | not-accessible | A table of layer 2 MAC ACL Classification Rules | |
| INT aclMacRuleEtypeKey | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.5.3.1.7 | INTEGER | read-create | The Ethertype keyword used in the MAC ACL Classification. A keyword of custom(1) requires that the aclMacRuleEtypeValue object also be set. |
| ETY aclMacRuleEtypeValue | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.5.3.1.8 | EtypeValue | read-create | The Ethertype custom value used in the MAC ACL Classification. This object is only valid if the aclMacRuleEtypeKey is set to custom(1). The allowed value for this object is 0x0600 to 0xFFFF (1536 to 65535). |
| I32 aclMacRuleIndex | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.5.3.1.1 | Integer32 | not-accessible | The index of this rule instance within an MAC ACL. |
| T/F aclMacRuleLogging | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.5.3.1.22 | TruthValue | read-create | Flag to indicate that the ACL rule is being logged. A hardware count of the number of times this rule is hit is reported via the aclTrapRuleLogEvent notification. This object may be supported for an aclMacRuleAction setting of permit(1) and/or deny(2), depending on the ACL feature capabilities of the device. |
| T/F aclMacRuleMatchEvery | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.5.3.1.20 | TruthValue | read-create | Flag to indicate that the MAC ACL rule is defined to match all packets, regardless of Ethertype. |
| NUM aclMacRuleMirrorIntf | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.5.3.1.21 | InterfaceIndexOrZero | read-create | A non-zero value indicates the external ifIndex to which all inbound packets matching this MAC ACL rule are copied. A value of zero means packet mirroring is not in effect, which is the default value of this object. Note that packet mirroring and redirection (aclMacRuleRedirectIntf object) are mutually-exclusive rule attributes. |
| NUM aclMacRuleRedirectIntf | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.5.3.1.19 | InterfaceIndexOrZero | read-create | A non-zero value indicates the external ifIndex to which all inbound packets matching this MAC ACL rule are directed. A value of zero means packet redirection is not in effect, which is the default value of this object. Note that packet redirection and mirroring (aclMacRuleMirrorIntf object) are mutually-exclusive rule attributes. |
| MAC aclMacRuleSrcMacAddr | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.5.3.1.9 | MacAddress | read-create | The Source MAC address used in the MAC ACL Classification. |
| MAC aclMacRuleSrcMacMask | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.5.3.1.10 | MacAddress | read-create | The Source MAC address mask used in the MAC ACL Classification. This mask value identifies the portion of the aclMacRuleSrcMacAddr that is compared against a packet. A non-contiguous mask value is permitted. |
| ROW aclMacRuleStatus | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.5.3.1.17 | RowStatus | read-create | Status of this instance. active(1) - this ACL Rule is active createAndGo(4) - set to this value to create an instance destroy(6) - set to this value to delete an instance |
| aclMacRuleTable | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.5.3 | not-accessible | A table of layer 2 MAC ACL Rule instances. | |
| U32 aclMacRuleVlanId | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.5.3.1.11 | Unsigned32 | read-create | The VLAN ID value used in the MAC ACL Classification. The VLAN ID field is defined as the 12-bit VLAN identifier in the 802.1Q tag header of a tagged Ethernet frame. This is contained in the first/outer tag of a double VLAN tagged frame. |
| U32 aclMacRuleVlanId2 | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.5.3.1.14 | Unsigned32 | read-create | The Secondary VLAN ID value used in the MAC ACL Classification. The Secondary VLAN ID field is defined as the 12-bit VLAN identifier in the second/inner 802.1Q tag header of a double VLAN tagged Ethernet frame. |
| U32 aclMacRuleVlanId2RangeEnd | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.5.3.1.16 | Unsigned32 | read-create | The Secondary VLAN ID range end value used in the MAC ACL Classification. Setting this value less than the current aclMacRuleVlanId2RangeStart changes the Secondary VLAN ID range start to the same value as the range end. The Secondary VLAN ID field is defined as the 12-bit VLAN identifier in the second/inner 802.1Q tag header of a double VLAN tagged Ethernet frame. |
| U32 aclMacRuleVlanId2RangeStart | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.5.3.1.15 | Unsigned32 | read-create | The Secondary VLAN ID range start value used in the MAC ACL Classification. Setting this value greater than the current aclMacRuleVlanId2RangeEnd changes the Secondary VLAN ID range end to the same value as the range start. The Secondary VLAN ID field is defined as the 12-bit VLAN identifier in the second/inner 802.1Q tag header of a double VLAN tagged Ethernet frame. |
| U32 aclMacRuleVlanIdRangeEnd | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.5.3.1.13 | Unsigned32 | read-create | The VLAN ID range end value used in the MAC ACL Classification. Setting this value less than the current aclMacRuleVlanIdRangeStart changes the VLAN ID range start to the same value as the range end. The VLAN ID field is defined as the 12-bit VLAN identifier in the 802.1Q tag header of a tagged Ethernet frame. This is contained in the first/outer tag of a double VLAN tagged frame. |
| U32 aclMacRuleVlanIdRangeStart | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.5.3.1.12 | Unsigned32 | read-create | The VLAN ID range start value used in the MAC ACL Classification. Setting this value greater than the current aclMacRuleVlanIdRangeEnd changes the VLAN ID range end to the same value as the range start. The VLAN ID field is defined as the 12-bit VLAN identifier in the 802.1Q tag header of a tagged Ethernet frame. This is contained in the first/outer tag of a double VLAN tagged frame. |
| ROW aclMacStatus | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.5.2.1.3 | RowStatus | read-create | Status of this instance. ACL MAC entries can not be deleted until all rows in the aclIfTable and aclRuleTable with corresponding values of aclMacIndex have been deleted. active(1) - this ACL instance is active createAndGo(4) - set to this value to create an instance destroy(6) - set to this value to delete an instance The aclMacName object must be set to complete this row instance. |
| aclMacTable | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.5.2 | not-accessible | A table of MAC ACL instances. | |
| STR aclName | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.1.1.2 | DisplayString | read-create | The name of this IPv4 ACL entry, which must consist of 1 to 31 alphanumeric characters and uniquely identify this IPv4 ACL. An existing IPv4 ACL can be renamed by setting this object to a new name. This object must be set to complete a new IPv4 ACL row instance. |
| I32 aclNamedIpv4IndexNextFree | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.14 | Integer32 | read-only | This object contains an unused value for the aclIndex to be used when creating a new named IPv4 ACL. A value of zero zero indicates the ACL table is full. |
| aclNotifications | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.0 | |||
| INT aclRuleAction | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.4.1.2 | INTEGER | read-create | The type of action this rule should perform. |
| U32 aclRuleAssignQueueId | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.4.1.19 | Unsigned32 | read-create | Queue identifier to which all inbound packets matching this ACL rule are directed. This object defaults to the standard queue assignment for user priority 0 traffic per the IEEE 802.1D specification based on the number of assignable queues in the system: 1-3 queues: 0 4-7 queues: 1 8 queues: 2 This default assignment is static and is not influenced by other system configuration changes. |
| IP aclRuleDestIpAddress | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.4.1.9 | IpAddress | read-create | The Destination IP Address used in the ACL Classification. |
| IP aclRuleDestIpMask | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.4.1.10 | IpAddress | read-create | The Destination IP Mask used in the ACL Classification. This mask is expressed using wild-card notation,which is the 1's compliment of traditional Subnet Masks. Here, the 'Don't care bits' are represented by binary 1's and 'Do care bits' are represented by binary 0's. |
| I32 aclRuleDestL4Port | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.4.1.11 | Integer32 | read-create | The Destination Port (Layer 4) used in ACl classification. |
| I32 aclRuleDestL4PortRangeEnd | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.4.1.13 | Integer32 | read-create | The Destination Port (Layer 4) ending range used in ACL classification. |
| I32 aclRuleDestL4PortRangeStart | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.4.1.12 | Integer32 | read-create | The Destination Port (Layer 4) starting range used in ACL classification. |
| ADR aclRuleDstIpv6Prefix | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.12.1.20 | Ipv6AddressPrefix | read-write | The Ipv6 Prefix Address configured on the Service Port. |
| I32 aclRuleDstIpv6PrefixLength | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.12.1.21 | Integer32 | read-create | The Prefix Length. |
| aclRuleEntry | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.4.1 | not-accessible | A table of IP ACL Classification Rules | |
| I32 aclRuleIndex | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.4.1.1 | Integer32 | not-accessible | The index of this rule instance within an IP ACL. |
| I32 aclRuleIPDSCP | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.4.1.14 | Integer32 | read-create | The Differentiated Services Code Point value. |
| I32 aclRuleIpPrecedence | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.4.1.15 | Integer32 | read-create | The Type of Service (TOS) IP Precedence value. |
| I32 aclRuleIpTosBits | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.4.1.16 | Integer32 | read-create | The Type of Service (TOS) Bits value. |
| I32 aclRuleIpTosMask | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.4.1.17 | Integer32 | read-create | The Type of Service (TOS) Mask value. |
| T/F aclRuleLogging | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.4.1.23 | TruthValue | read-create | Flag to indicate that the ACL rule is being logged. A hardware count of the number of times this rule is hit is reported via the aclTrapRuleLogEvent notification. This object may be supported for an aclRuleAction setting of permit(1) and/or deny(2), depending on the ACL feature capabilities of the device. |
| T/F aclRuleMatchEvery | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.4.1.21 | TruthValue | read-create | Flag to indicate that the ACL rule is defined to match on every IP packet, regardless of content. |
| NUM aclRuleMirrorIntf | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.4.1.22 | InterfaceIndexOrZero | read-create | A non-zero value indicates the external ifIndex to which all inbound packets matching this ACL rule are copied. A value of zero means packet mirroring is not in effect, which is the default value of this object. Note that packet mirroring and redirection (aclRuleRedirectIntf object) are mutually-exclusive rule attributes. |
| I32 aclRuleProtocol | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.4.1.3 | Integer32 | read-create | icmp - 1 igmp - 2 ip - 4 tcp - 6 udp - 17 All values from 1 to 255 are valid. |
| NUM aclRuleRedirectIntf | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.4.1.20 | InterfaceIndexOrZero | read-create | A non-zero value indicates the external ifIndex to which all inbound packets matching this ACL rule are directed. A value of zero means packet redirection is not in effect, which is the default value of this object. Note that packet redirection and mirroring (aclRuleMirrorIntf object) are mutually-exclusive rule attributes. |
| IP aclRuleSrcIpAddress | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.4.1.4 | IpAddress | read-create | The Source IP Address used in the ACL Classification. |
| IP aclRuleSrcIpMask | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.4.1.5 | IpAddress | read-create | The Source IP Mask used in the ACL Classification. This mask is expressed using wild-card notation,which is the 1's compliment of traditional Subnet Masks. Here, the 'Don't care bits' are represented by binary 1's and 'Do care bits' are represented by binary 0's. |
| ADR aclRuleSrcIpv6Prefix | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.12.1.18 | Ipv6AddressPrefix | read-write | The Ipv6 Prefix Address configured on the Service Port. |
| I32 aclRuleSrcIpv6PrefixLength | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.12.1.19 | Integer32 | read-create | The Prefix Length. |
| I32 aclRuleSrcL4Port | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.4.1.6 | Integer32 | read-create | The Source Port Number (Layer 4) used in the ACL Classification. |
| I32 aclRuleSrcL4PortRangeEnd | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.4.1.8 | Integer32 | read-create | The Source Port Number(Layer 4) range end. |
| I32 aclRuleSrcL4PortRangeStart | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.4.1.7 | Integer32 | read-create | The Source Port Number(Layer 4) range start. |
| ROW aclRuleStatus | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.4.1.18 | RowStatus | read-create | Status of this instance. active(1) - this ACL Rule is active createAndGo(4) - set to this value to create an instance destroy(6) - set to this value to delete an instance |
| aclRuleTable | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.4 | not-accessible | A table of IP ACL Rule instances. | |
| ROW aclStatus | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.1.1.3 | RowStatus | read-create | Status of this instance. Entries can not be deleted until all rows in the aclIfTable and aclRuleTable with corresponding values of aclIndex have been deleted. active(1) - this ACL instance is active createAndGo(4) - set to this value to create an instance destroy(6) - set to this value to delete an instance |
| aclTable | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.1 | not-accessible | A table of ACL instances. | |
| INT aclTrapFlag | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.9.5 | INTEGER | read-write | ACL Trap Flag - Enables or disables ACL trap generation. When this value is set to enable(1), ACL traps are sent from the switch when they occur. |
| INT aclTrapRuleAction | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.9.3 | INTEGER | accessible-for-notify | The type of action this rule should perform, either permit(1) or deny(2). Used by aclTrapRuleLogEvent trap. |
| C64 aclTrapRuleHitCount | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.9.4 | Counter64 | accessible-for-notify | Number of times the ACL rule was hit during the most recent logging interval. Used by aclTrapRuleLogEvent trap. |
| I32 aclTrapRuleIndex | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.9.2 | Integer32 | accessible-for-notify | The index of an ACL rule instance. Used by aclTrapRuleLogEvent trap. |
| NTF aclTrapRuleLogEvent | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.0.1 | This trap is generated on a periodic basis to indicate that an ACL rule configured for logging was actively used by hardware to take action on one or more packets. The aclTrapRuleHitCount denotes the number of times this rule was hit during the most recent logging interval. ACL Trap generation requires that the aclTrapFlag object be set to enable(1). | ||
| I32 aclVlanAclId | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.13.1.5 | Integer32 | not-accessible | The ACL identifier value, which is interpreted based on the aclVlanType object. For the IP ACLs, the actual ACL number is its identifier as follows: IP standard ranges from 1-99, while IP extended ranges from 100-199. Here, aclVlanAclId represents aclIndex. The MAC ACLs use an internally-generated index value that is assigned when the ACL is created. Here, aclVlanAclId represents aclMacIndex. The IPv6 ACLs use an internally-generated index value that is assigned when the ACL is created.Here, aclVlanAclId represents aclIpv6Index. The aclVlanType object must be specified along with this object. |
| INT aclVlanAclType | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.13.1.4 | INTEGER | not-accessible | The type of this ACL, which is used to interpret the aclVlanId object value. Each type of ACL uses its own numbering scheme for identification (see aclVlanAclId object for details). The aclVlanAclId object must be specified along with this object. |
| INT aclVlanDirection | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.13.1.2 | INTEGER | not-accessible | The Vlan direction to which this ACL instance applies. |
| aclVlanEntry | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.13.1 | not-accessible | ||
| I32 aclVlanIndex | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.13.1.1 | Integer32 | not-accessible | The Vlan to which this ACL instance applies. |
| U32 aclVlanSequence | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.13.1.3 | Unsigned32 | not-accessible | The relative evaluation sequence of this ACL for this Vlan and direction. When multiple ACLs are allowed for a given Vlan and direction, the sequence number determines the order in which the list of ACLs are evaluated, with lower sequence numbers given higher precedence. The sequence number value is arbitrary, but must be a unique non-zero value for a given Vlan and direction. Setting this object to an existing sequence number value for a given Vlan and direction causes the ACL corresponding to that value to be replaced with this ACL. |
| ROW aclVlanStatus | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.13.1.6 | RowStatus | read-create | Status of this instance. active(1) - this ACL Vlan instance is active createAndGo(4) - set to this value to assign an ACL to a Vlan and direction destroy(6) - set to this value to remove an ACL from a Vlan and direction |
| aclVlanTable | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2.13 | not-accessible | A table of ACL VLAN instances per direction. | |
| fastPathQOSACL | 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.3.2 | The MIB definitions for Quality of Service - ACL Flex package. |
RFC description
Manages Quality of Service ACL configuration including IPv4, IPv6, and MAC-based access controls.
Start monitoring Broadcom FastPath-based Ethernet switch (multi-vendor OEM) (ACL-based QoS classification) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.