RADLAN-ARPSPOOFING-MIB

MIB Reference — IPNetwork Monitor

All MIBsRADLAN-ARPSPOOFING-MIB

Organization: Radlan - a MARVELL company. Marvell Semiconductor, Inc.

Last Updated: 2007-01-02

Category: Security, Vendor: RADLAN/Cisco SB

Description:

Configures dynamic ARP inspection to prevent ARP spoofing attacks on Marvell switch ports.

Imported Objects

From IF-MIB

InterfaceIndex
InterfaceIndexOrZero

From RADLAN-MIB

rndOBJECT-IDENTITY

From SNMPv2-SMI

IpAddress
MODULE-IDENTITY
OBJECT-TYPE

From SNMPv2-TC

PhysAddress
RowStatus

What Is RADLAN-ARPSPOOFING-MIB?

RADLAN-ARPSPOOFING-MIB is a private MIB module from Radlan (now part of Marvell) implemented on Marvell-based switching platforms, including many rebranded Cisco Small Business and other OEM switch lines. It exposes configuration and per-port status data for Dynamic ARP Inspection, a Layer 2 security feature that validates ARP packets against trusted IP-to-MAC bindings to block ARP spoofing and man-in-the-middle attacks. The data is mostly configuration and security state rather than classic hardware health metrics, covering which interfaces have ARP inspection enabled and the trusted binding entries in force. Monitoring this MIB is valuable for tracking whether the anti-spoofing feature is actually active and functioning correctly on each port, since a disabled or errored per-port status reveals that spoofing protection has silently failed rather than reporting CPU or temperature data. It implicitly relies on standard IF-MIB ifIndex values for interface references and is typically deployed on enterprise access-layer switches where ARP spoofing/man-in-the-middle mitigation is required. Engineers can download the RADLAN-ARPSPOOFING-MIB file directly to load it into their MIB browser.

IPNetwork Monitor allows you to monitor SNMP objects defined in RADLAN-ARPSPOOFING-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

What Can Be Monitored

  • ARP inspection enable status per interface
  • trusted IP-to-MAC bindings
  • local vs remote IP address bindings
  • outbound physical interface mapping
  • per-port spoofing protection state

Supported Devices

  • Marvell/Radlan-based managed switch
  • Cisco Small Business switch (Marvell OEM)

Monitoring Examples

An administrator can poll rlArpSpoofingTable/rlArpSpoofingEntry, indexed by rlArpSpoofingIfIndex, to see configured trusted bindings (rlArpSpoofingLocalIpAddr, rlArpSpoofingRemoteIpAddr, rlArpSpoofingMacAddr) alongside rlArpSpoofingStatus for each protected port. A change in rlArpSpoofingStatus to a disabled or error state on a port that should be protected would indicate the anti-spoofing feature has failed or been turned off, exposing that segment to ARP spoofing. rlArpSpoofingOutPhysIfIndex can also be checked to confirm inspected traffic is being redirected to the correct outbound physical interface.

OIDs
OID symbolicOID numericTypeAccessDescription
rlArpSpoofing1.3.6.1.4.1.89.60This private MIB module defines ARP spoofing private MIBs.
INT rlArpSpoofingMibVersion1.3.6.1.4.1.89.60.1INTEGERread-onlyMIB's version, the current version is 1.
rlArpSpoofingTable1.3.6.1.4.1.89.60.2not-accessibleA list of the ifIndexes, IP addresses and corresponding MAC addresses.
rlArpSpoofingEntry1.3.6.1.4.1.89.60.2.1not-accessibleAn entry of this table specifis ifIndex,IP Address and MAC address.
NUM rlArpSpoofingIfIndex1.3.6.1.4.1.89.60.2.1.1InterfaceIndexread-createThe physical interface for which this entry contains information.
IP rlArpSpoofingLocalIpAddr1.3.6.1.4.1.89.60.2.1.2IpAddressread-createIp addres for which the device will send ARP reply (ARP spoofing).
PHY rlArpSpoofingMacAddr1.3.6.1.4.1.89.60.2.1.3PhysAddressread-createMAC addres with which the device will send ARP reply. If the field is ommited or its value 0.0.0.0 the device will send with the interface's MAC address.
IP rlArpSpoofingRemoteIpAddr1.3.6.1.4.1.89.60.2.1.4IpAddressread-createIp addres for which the device will send periodically ARP requests if its value differs from 0.0.0.0.
NUM rlArpSpoofingOutPhysIfIndex1.3.6.1.4.1.89.60.2.1.5InterfaceIndexOrZeroread-createThe physical interface to which the device will send periodically ARP requests if its value differs from 0. If its value is 0 then ARP requests will send to all the VLAN's ports.
ROW rlArpSpoofingStatus1.3.6.1.4.1.89.60.2.1.6RowStatusread-createIt is used to insert, update or delete an entry

RFC description

ARP spoofing detection and prevention feature for Marvell Radlan network devices.

Start monitoring Marvell/Radlan-based managed switch, Cisco Small Business switch OEM (Dynamic ARP Inspection) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download RADLAN-ARPSPOOFING-MIB