RADLAN-IPV6FHS-MIB

MIB Reference — IPNetwork Monitor · Updated September 09, 2026

All MIBsRADLAN-IPV6FHS-MIB

Organization: Marvell Semiconductor, Inc.

Last Updated: 2012-12-12

Category: Security, Vendor: RADLAN/Cisco SB

Description: Configures IPv6 First Hop Security features including RA guard and ND inspection.

Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

What Is RADLAN-IPV6FHS-MIB?

RADLAN-IPV6FHS-MIB is a private Marvell/Radlan switch MIB configuring IPv6 First Hop Security features such as RA Guard and Neighbor Discovery (ND) Inspection, which protect IPv6 hosts from rogue router advertisements and spoofed ND traffic. It exposes per-VLAN-range enable bitmaps for these features along with hardware-fault-style error counters. Notably, rlFirstHopSecErrorCountersTcamOverflow is a hardware capacity/fault indicator: an incrementing value shows the switch's TCAM (ternary content-addressable memory) resources used to enforce these security rules have been exhausted, meaning some traffic may go uninspected. It builds on IPv6 Neighbor Discovery concepts from RFC 4861 and coexists with standard IF-MIB/VLAN indexing used elsewhere in the switch's MIB set. It is deployed on IPv6-enabled access/edge switches that need to block rogue RA and ND messages from compromised or misconfigured hosts, and administrators often use a RADLAN-IPV6FHS-MIB MIB Browser to inspect the per-VLAN enable bitmaps before scripting automated polling.

IPNetwork Monitor allows you to monitor SNMP objects defined in RADLAN-IPV6FHS-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • Marvell/Radlan-based managed switch (IPv6 access/edge deployment)

Monitoring Examples

rlFirstHopSecEnableVlanTable's segmented objects (rlFirstHopSecEnableVlan1to1024, rlFirstHopSecEnableVlan1025to2048, etc.) expose which VLAN ranges have first-hop security enabled as bitmaps. rlFirstHopSecErrorCountersTcamOverflow is a critical object to poll: a nonzero or climbing value indicates the switch has run out of TCAM hardware capacity to enforce IPv6 FHS filtering rules. rlNdInspectionEnableVlanTable/rlNdInspectionEnableVlanIndex with its corresponding bitmask objects lets an admin confirm ND Inspection is active on the VLANs serving IPv6 hosts.

What Can Be Monitored

  • RA Guard enable status per VLAN
  • ND Inspection enable status per VLAN
  • TCAM overflow error counter
  • per-VLAN-range security feature bitmaps
Imported Objects

From IF-MIB

InterfaceIndex
InterfaceIndexOrZero

From INET-ADDRESS-MIB

InetAddress
InetAddressPrefixLength
InetAddressType

From Q-BRIDGE-MIB

PortList
VlanId
VlanIndex

From RADLAN-BRIDGEMIBOBJECTS-MIB

VlanList1
VlanList2
VlanList3
VlanList4

From RADLAN-DEVICEPARAMS-MIB

rndErrorDescOBJECT-TYPE
rndErrorSeverityOBJECT-TYPE

From RADLAN-MIB

rlMacMulticastOBJECT-IDENTITY
rndOBJECT-IDENTITY
rndNotificationsOBJECT-IDENTITY

From SNMPv2-SMI

Counter32
Integer32
IpAddress
NOTIFICATION-TYPE
OBJECT-TYPE
Unsigned32

From SNMPv2-TC

DisplayString
MacAddress
RowStatus
TEXTUAL-CONVENTION
TruthValue

How to Use in IPNetwork Monitor

Example using rlFirstHopSecCountersRxNdpRA OID:

Select a Marvell/Radlan-based managed switch, IPv6 access/edge deployment (First Hop Security) as the target host to create a monitor — the SNMP service should be up and running on it. Click New Monitor, then check SNMP Custom on the Favorites tab, click Next, and confirm the host. On the next page, click Select... to open the built-in SNMP MIB Browser and type rlFirstHopSecCountersRxNdpRA into the Find box to locate it in the OID tree, selecting the specific row/instance you want to monitor since this is a table column, then select it and click OK. It reports the number of NDP Router Advertisement messages received on the interface. On the monitor's Main parameters page you can set the target's SNMP port (default 161), credentials, polling interval, and other settings — see the SNMP Monitor help for details. On the State conditions and Alerting tabs, configure when the monitor should change state and trigger an alert; since this is a Counter32-type OID, Value bounds is the most useful condition here — trigger an alert if the counter increases sharply between polls relative to its normal baseline, since an unexpected spike often reflects a real change in traffic or activity. Click Finish to create the monitor; you can adjust any parameter later.
OIDs

RFC description

Marvell Semiconductor (Radlan) vendor-private MIB for IPv6 First Hop Security configuration and management.

Start monitoring Marvell/Radlan-based managed switch, IPv6 access/edge deployment (First Hop Security) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download RADLAN-IPV6FHS-MIB