NETSCREEN-SET-AUTH-MIB

MIB Reference — IPNetwork Monitor

All MIBsNETSCREEN-SET-AUTH-MIB

Organization: Juniper Networks, Inc.

Last Updated: 2004-11-10

Category: Firewall, RADIUS/AAA

Description:

Configures authentication server settings including RADIUS and LDAP parameters on Juniper NetScreen firewalls.

Imported Objects

From NETSCREEN-SMI

netscreenSettingOBJECT-IDENTITY
netscreenSettingMibModuleOBJECT-IDENTITY

From SNMPv2-SMI

Integer32
MODULE-IDENTITY
OBJECT-TYPE

From SNMPv2-TC

DisplayString

What Is NETSCREEN-SET-AUTH-MIB?

NETSCREEN-SET-AUTH-MIB is a Juniper NetScreen (legacy ScreenOS) firewall MIB used to configure and monitor authentication server settings for VPN and remote-access services, including RADIUS, LDAP, and local account backends per virtual system (vsys). It exposes configuration-style data such as primary and backup authentication server assignments, connection idle timeouts, and dedicated accounts for IKE and L2TP sessions rather than traffic counters. Its monitoring relevance is chiefly configuration-status: an administrator can verify which authentication servers are actively assigned to each vsys and confirm failover backup servers are correctly populated, which indirectly signals whether remote-access authentication would succeed or fail. It depends on the broader NetScreen/ScreenOS enterprise MIB tree for vsys indexing and general device identification. It is typically deployed on Juniper NetScreen firewall/VPN gateway appliances in multi-tenant or branch-office security deployments. Engineers can download the NETSCREEN-SET-AUTH-MIB file directly to load it into their MIB browser.

IPNetwork Monitor allows you to monitor SNMP objects defined in NETSCREEN-SET-AUTH-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

What Can Be Monitored

  • primary/backup authentication server assignment per vsys
  • connection idle timeout
  • IKE account binding
  • L2TP account binding
  • authentication account configuration

Supported Devices

  • Juniper NetScreen firewall/VPN appliance

Monitoring Examples

An administrator would poll the nsSetAuthCfgTable/nsSetAuthCfgEntry indexed by nsSetAuthCfgIdx and nsSetAuthCfgVsys to confirm nsSetAuthCfgPrimary and nsSetAuthCfgBackup1/nsSetAuthCfgBackup2 point to reachable RADIUS or LDAP servers for each virtual system. If nsSetAuthCfgConnIdleTimeout is set too low, VPN users could be prematurely logged out, which this table would reveal. Separate account fields like nsSetAuthCfgIkeAccount and nsSetAuthCfgL2tpAccount let an operator confirm the correct authentication account is bound to each VPN tunnel type.

OIDs
OID symbolicOID numericTypeAccessDescription
netscreenSetAuthMibModule1.3.6.1.4.1.3224.7.0.2This module defines the object that are used to monitor all the configuration info
nsSetAuth1.3.6.1.4.1.3224.7.2
nsSetAuthCfgTable1.3.6.1.4.1.3224.7.2.1not-accessibleThe authentication configuration of NetScreen device.
nsSetAuthCfgEntry1.3.6.1.4.1.3224.7.2.1.1not-accessibleNetScreen admin user authentication setting table.
I32 nsSetAuthCfgIdx1.3.6.1.4.1.3224.7.2.1.1.1Integer32read-onlyAuthentication server config index.
I32 nsSetAuthCfgVsys1.3.6.1.4.1.3224.7.2.1.1.2Integer32read-onlyVirtural system the setting belongs to.
STR nsSetAuthCfgName1.3.6.1.4.1.3224.7.2.1.1.3DisplayStringread-onlyAuthentication server setting entry name.
STR nsSetAuthCfgPrimary1.3.6.1.4.1.3224.7.2.1.1.4DisplayStringread-onlyPrimary authentication server IP or domain name.
STR nsSetAuthCfgBackup11.3.6.1.4.1.3224.7.2.1.1.5DisplayStringread-onlyFirst backup authentication server IP or domain name.It's optional.
STR nsSetAuthCfgBackup21.3.6.1.4.1.3224.7.2.1.1.6DisplayStringread-onlySecondary backup authentication server IP or domain name.It's optional.
I32 nsSetAuthCfgConnIdleTimeout1.3.6.1.4.1.3224.7.2.1.1.7Integer32read-onlyconnection timeout threshold setting. 0 means no timeout setting.
INT nsSetAuthCfgAuthAccount1.3.6.1.4.1.3224.7.2.1.1.8INTEGERread-onlyAllow authentication account.
INT nsSetAuthCfgIkeAccount1.3.6.1.4.1.3224.7.2.1.1.9INTEGERread-onlyAllow IKE account.
INT nsSetAuthCfgL2tpAccount1.3.6.1.4.1.3224.7.2.1.1.10INTEGERread-onlyAllow L2tp account.
INT nsSetAuthCfgAdminAccount1.3.6.1.4.1.3224.7.2.1.1.11INTEGERread-onlyAllow administration account.
INT nsSetAuthCfgXauthAccount1.3.6.1.4.1.3224.7.2.1.1.12INTEGERread-onlyAllow Xauth account.
INT nsSetAuthCfgMethod1.3.6.1.4.1.3224.7.2.1.1.13INTEGERread-onlyNetScreen device admin user authentication method.
I32 nsSetAuthCfgPort1.3.6.1.4.1.3224.7.2.1.1.14Integer32read-onlyServer listening port number.
I32 nsSetAuthCfgSecCliRetry1.3.6.1.4.1.3224.7.2.1.1.15Integer32read-onlySecureID client client retry times
I32 nsSetAuthCfgSecCliTimeout1.3.6.1.4.1.3224.7.2.1.1.16Integer32read-onlySecureID client timeout threshold.
INT nsSetAuthCfgSecEncType1.3.6.1.4.1.3224.7.2.1.1.17INTEGERread-onlySecureID traffic encryption type.
INT nsSetAuthCfgSecUseDuress1.3.6.1.4.1.3224.7.2.1.1.18INTEGERread-onlyUse duress in SecureID authentication.
STR nsSetAuthCfgLDAPCni1.3.6.1.4.1.3224.7.2.1.1.19DisplayStringread-onlyLDAP server common name identifier
STR nsSetAuthCfgLDAPDn1.3.6.1.4.1.3224.7.2.1.1.20DisplayStringread-onlyLDAP server distinguished name
STR nsSetAuthCfgSepChar1.3.6.1.4.1.3224.7.2.1.1.21DisplayStringread-onlySeperator character for this entry
I32 nsSetAuthCfgSepNumber1.3.6.1.4.1.3224.7.2.1.1.22Integer32read-onlySeperator number for this entry
I32 nsSetAuthCfgRevInterval1.3.6.1.4.1.3224.7.2.1.1.23Integer32read-onlyRevert interval for this entry
I32 nsSetAuthCfgRadRetries1.3.6.1.4.1.3224.7.2.1.1.24Integer32read-onlyRadius retries for this entries
INT nsSetAuthCfgEnableStnID1.3.6.1.4.1.3224.7.2.1.1.25INTEGERread-onlyEnable/Disable call station ID for this entry.
STR nsSetAuthCfgDomainName1.3.6.1.4.1.3224.7.2.1.1.26DisplayStringread-onlyDomain name for this entry
I32 nsSetAuthCfgAcctSessIdLen1.3.6.1.4.1.3224.7.2.1.1.27Integer32read-onlyAcct session identifier length for this entry
INT nsSetAuthCfgRFC2138Compatibility1.3.6.1.4.1.3224.7.2.1.1.28INTEGERread-onlyIs RFC2138 compatible for this entry
STR nsSetAuthCfgSourceIfName1.3.6.1.4.1.3224.7.2.1.1.29DisplayStringread-onlySource interface name for this entry
I32 nsSetAuthCfgAcctPort1.3.6.1.4.1.3224.7.2.1.1.30Integer32read-onlyRadius accounting port for this entry
INT nsSetAuthCfgAcctListActn1.3.6.1.4.1.3224.7.2.1.1.31INTEGERread-onlyRadius accounting action for this entry
I32 nsSetAuthCfgSourceIfInfo1.3.6.1.4.1.3224.7.2.1.1.32Integer32read-onlySource interface info for this entry. Returns -1 if no interface is selected

RFC description

Monitors authentication configuration including RADIUS/LDAP servers, authentication methods, and security settings.

Start monitoring Juniper NetScreen firewall/VPN appliance (VPN/remote-access auth servers) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download NETSCREEN-SET-AUTH-MIB