RADIUS-AUTH-CLIENT-MIB

MIB Reference — IPNetwork Monitor · Updated September 09, 2026

All MIBsRADIUS-AUTH-CLIENT-MIB

Organization: IETF RADIUS Extensions Working Group.

Last Updated: 2006-08-21

Category: RADIUS and AAA

Description: Monitors RADIUS authentication client (NAS) operations, tracking outgoing Access-Requests and incoming responses per configured server.

IPNetwork Monitor uses several OIDs from this MIB in network discovery and polling the applicable devices. Start monitoring RADIUS-AUTH-CLIENT-MIB with a free 30-day trial of IPNetwork Monitor.

What Is RADIUS-AUTH-CLIENT-MIB?

RADIUS-AUTH-CLIENT-MIB, standardized in RFC 4668, is a vendor-neutral MIB for entities implementing the client side (NAS) of the RADIUS authentication protocol, tracking outgoing Access-Request messages and incoming responses per configured RADIUS server. It exposes a per-server table of round-trip time, retransmission counts, accept/reject counts, and invalid-server-address tracking, giving a detailed operational view of authentication traffic health. Its monitoring value is centered on software/protocol-level status—detecting slow or unresponsive RADIUS servers via radiusAuthClientRoundTripTime, spotting authentication failures via rising radiusAuthClientAccessRejects, and identifying network/config issues via radiusAuthClientAccessRetransmissions or radiusAuthClientInvalidServerAddresses—rather than physical hardware sensors. It is part of the IETF RADIUS MIB family and commonly deployed alongside RADIUS-AUTH-SERVER-MIB and RADIUS accounting MIBs on the same NAS device. It is deployed on any vendor-neutral, standards-based network access server (NAS), VPN gateway, or wireless controller performing RADIUS authentication. The RADIUS-AUTH-CLIENT-MIB RFC (4668) itself obsoleted the earlier RFC 2618 definition, so implementations should be checked against the newer specification for correct object naming and semantics.

IPNetwork Monitor allows you to monitor SNMP objects defined in RADIUS-AUTH-CLIENT-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • vendor-neutral, standards-based MIB, not tied to a specific manufacturer
  • network access server (NAS), VPN gateway, or wireless controller

Monitoring Examples

An admin would poll radiusAuthServerTable's radiusAuthClientRoundTripTime for each radiusAuthServerIndex/radiusAuthServerAddress to detect a RADIUS server responding slowly or not at all, and watch radiusAuthClientAccessRetransmissions rising as a sign of packet loss or an unresponsive server. A spike in radiusAuthClientAccessRejects relative to radiusAuthClientAccessAccepts would indicate a wave of authentication failures, while radiusAuthClientInvalidServerAddresses climbing would reveal spoofed or misconfigured response packets arriving from unexpected sources.

What Can Be Monitored

  • RADIUS server round-trip time
  • access-request retransmissions
  • access-accept count
  • access-reject count
  • invalid server address count
  • configured RADIUS server port
Imported Objects

From INET-ADDRESS-MIB

InetAddress
InetAddressType
InetPortNumber

From SNMP-FRAMEWORK-MIB

SnmpAdminString

From SNMPv2-CONF

MODULE-COMPLIANCE
OBJECT-GROUP

From SNMPv2-SMI

Counter32
Gauge32
Integer32
IpAddress
MODULE-IDENTITY
OBJECT-IDENTITY
OBJECT-TYPE
TimeTicks
mib-2

How to Use in IPNetwork Monitor

Example using radiusAuthClientCounterDiscontinuity OID:

Select a device implementing RADIUS-AUTH-CLIENT-MIB as the target host to create a monitor — the SNMP service should be up and running on it. Click New Monitor, then check SNMP Custom on the Favorites tab, click Next, and confirm the host. On the next page, click Select... to open the built-in SNMP MIB Browser and type radiusAuthClientCounterDiscontinuity into the Find box to locate it in the OID tree, then select it and click OK. It reports how long, in centiseconds, since the RADIUS Client's counters last had a discontinuity (typically caused by a reinitialization). On the monitor's Main parameters page you can set the target's SNMP port (default 161), credentials, polling interval, and other settings — see the SNMP Monitor help for details. On the State conditions and Alerting tabs, configure when the monitor should change state and trigger an alert; since this is a TimeTicks-type OID, Value bounds is the most useful condition here — trigger an alert if the value is unexpectedly low, since that indicates the RADIUS authentication counters were recently reset — often the result of an unplanned restart. Click Finish to create the monitor; you can adjust any parameter later.
OIDs

RFC description

Manages RADIUS authentication clients per RFC 2618, providing monitoring of RADIUS server statistics and authentication client operations.

Start monitoring vendor-neutral, standards-based MIB, network access server/VPN gateway/wireless controller (RADIUS auth client, RFC 4668) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download RADIUS-AUTH-CLIENT-MIB