All MIBs › NETSCREEN-SET-AUTH-MIB
Organization: Juniper Networks, Inc.
Last Updated: 2004-11-10
Category: Firewall, RADIUS/AAA
Description: Configures authentication server settings including RADIUS and LDAP parameters on Juniper NetScreen firewalls.
Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.
What Is NETSCREEN-SET-AUTH-MIB?
NETSCREEN-SET-AUTH-MIB is a Juniper NetScreen (legacy ScreenOS) firewall MIB used to configure and monitor authentication server settings for VPN and remote-access services, including RADIUS, LDAP, and local account backends per virtual system (vsys). It exposes configuration-style data such as primary and backup authentication server assignments, connection idle timeouts, and dedicated accounts for IKE and L2TP sessions rather than traffic counters. Its monitoring relevance is chiefly configuration-status: an administrator can verify which authentication servers are actively assigned to each vsys and confirm failover backup servers are correctly populated, which indirectly signals whether remote-access authentication would succeed or fail. It depends on the broader NetScreen/ScreenOS enterprise MIB tree for vsys indexing and general device identification. It is typically deployed on Juniper NetScreen firewall/VPN gateway appliances in multi-tenant or branch-office security deployments. Engineers can download the NETSCREEN-SET-AUTH-MIB file directly to load it into their MIB browser.
IPNetwork Monitor allows you to monitor SNMP objects defined in NETSCREEN-SET-AUTH-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.
Supported Devices
- Juniper NetScreen firewall/VPN appliance
Monitoring Examples
An administrator would poll the nsSetAuthCfgTable/nsSetAuthCfgEntry indexed by nsSetAuthCfgIdx and nsSetAuthCfgVsys to confirm nsSetAuthCfgPrimary and nsSetAuthCfgBackup1/nsSetAuthCfgBackup2 point to reachable RADIUS or LDAP servers for each virtual system. If nsSetAuthCfgConnIdleTimeout is set too low, VPN users could be prematurely logged out, which this table would reveal. Separate account fields like nsSetAuthCfgIkeAccount and nsSetAuthCfgL2tpAccount let an operator confirm the correct authentication account is bound to each VPN tunnel type.
What Can Be Monitored
- primary/backup authentication server assignment per vsys
- connection idle timeout
- IKE account binding
- L2TP account binding
- authentication account configuration
Imported Objects
From SNMPv2-SMI
| Integer32 | |
| MODULE-IDENTITY | |
| OBJECT-TYPE |
From SNMPv2-TC
| DisplayString |
OIDs
RFC description
Monitors authentication configuration including RADIUS/LDAP servers, authentication methods, and security settings.
Start monitoring Juniper NetScreen firewall/VPN appliance (VPN/remote-access auth servers) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.