All MIBs › RADLAN-ARPSPOOFING-MIB
Organization: Radlan - a MARVELL company. Marvell Semiconductor, Inc.
Last Updated: 2007-01-02
Category: Security, Vendor: RADLAN/Cisco SB
Description:
Configures dynamic ARP inspection to prevent ARP spoofing attacks on Marvell switch ports.
Imported Objects
From IF-MIB
| InterfaceIndex | |
| InterfaceIndexOrZero |
From RADLAN-MIB
| rnd | OBJECT-IDENTITY |
From SNMPv2-SMI
| IpAddress | |
| MODULE-IDENTITY | |
| OBJECT-TYPE |
From SNMPv2-TC
| PhysAddress | |
| RowStatus |
What Is RADLAN-ARPSPOOFING-MIB?
RADLAN-ARPSPOOFING-MIB is a private MIB module from Radlan (now part of Marvell) implemented on Marvell-based switching platforms, including many rebranded Cisco Small Business and other OEM switch lines. It exposes configuration and per-port status data for Dynamic ARP Inspection, a Layer 2 security feature that validates ARP packets against trusted IP-to-MAC bindings to block ARP spoofing and man-in-the-middle attacks. The data is mostly configuration and security state rather than classic hardware health metrics, covering which interfaces have ARP inspection enabled and the trusted binding entries in force. Monitoring this MIB is valuable for tracking whether the anti-spoofing feature is actually active and functioning correctly on each port, since a disabled or errored per-port status reveals that spoofing protection has silently failed rather than reporting CPU or temperature data. It implicitly relies on standard IF-MIB ifIndex values for interface references and is typically deployed on enterprise access-layer switches where ARP spoofing/man-in-the-middle mitigation is required. Engineers can download the RADLAN-ARPSPOOFING-MIB file directly to load it into their MIB browser.
IPNetwork Monitor allows you to monitor SNMP objects defined in RADLAN-ARPSPOOFING-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.
What Can Be Monitored
- ARP inspection enable status per interface
- trusted IP-to-MAC bindings
- local vs remote IP address bindings
- outbound physical interface mapping
- per-port spoofing protection state
Supported Devices
- Marvell/Radlan-based managed switch
- Cisco Small Business switch (Marvell OEM)
Monitoring Examples
An administrator can poll rlArpSpoofingTable/rlArpSpoofingEntry, indexed by rlArpSpoofingIfIndex, to see configured trusted bindings (rlArpSpoofingLocalIpAddr, rlArpSpoofingRemoteIpAddr, rlArpSpoofingMacAddr) alongside rlArpSpoofingStatus for each protected port. A change in rlArpSpoofingStatus to a disabled or error state on a port that should be protected would indicate the anti-spoofing feature has failed or been turned off, exposing that segment to ARP spoofing. rlArpSpoofingOutPhysIfIndex can also be checked to confirm inspected traffic is being redirected to the correct outbound physical interface.
OIDs
| OID symbolic | OID numeric | Type | Access | Description |
|---|---|---|---|---|
| rlArpSpoofing | 1.3.6.1.4.1.89.60 | This private MIB module defines ARP spoofing private MIBs. | ||
| INT rlArpSpoofingMibVersion | 1.3.6.1.4.1.89.60.1 | INTEGER | read-only | MIB's version, the current version is 1. |
| rlArpSpoofingTable | 1.3.6.1.4.1.89.60.2 | not-accessible | A list of the ifIndexes, IP addresses and corresponding MAC addresses. | |
| rlArpSpoofingEntry | 1.3.6.1.4.1.89.60.2.1 | not-accessible | An entry of this table specifis ifIndex,IP Address and MAC address. | |
| NUM rlArpSpoofingIfIndex | 1.3.6.1.4.1.89.60.2.1.1 | InterfaceIndex | read-create | The physical interface for which this entry contains information. |
| IP rlArpSpoofingLocalIpAddr | 1.3.6.1.4.1.89.60.2.1.2 | IpAddress | read-create | Ip addres for which the device will send ARP reply (ARP spoofing). |
| PHY rlArpSpoofingMacAddr | 1.3.6.1.4.1.89.60.2.1.3 | PhysAddress | read-create | MAC addres with which the device will send ARP reply. If the field is ommited or its value 0.0.0.0 the device will send with the interface's MAC address. |
| IP rlArpSpoofingRemoteIpAddr | 1.3.6.1.4.1.89.60.2.1.4 | IpAddress | read-create | Ip addres for which the device will send periodically ARP requests if its value differs from 0.0.0.0. |
| NUM rlArpSpoofingOutPhysIfIndex | 1.3.6.1.4.1.89.60.2.1.5 | InterfaceIndexOrZero | read-create | The physical interface to which the device will send periodically ARP requests if its value differs from 0. If its value is 0 then ARP requests will send to all the VLAN's ports. |
| ROW rlArpSpoofingStatus | 1.3.6.1.4.1.89.60.2.1.6 | RowStatus | read-create | It is used to insert, update or delete an entry |
RFC description
ARP spoofing detection and prevention feature for Marvell Radlan network devices.
Start monitoring Marvell/Radlan-based managed switch, Cisco Small Business switch OEM (Dynamic ARP Inspection) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.