All MIBs › RAPID-CITY › rcMacViolation
rcMacViolation
Module: RAPID-CITY
OID (symbolic): RAPID-CITY::rcMacViolation
OID (numeric): 1.3.6.1.4.1.2272.1.21.9
Node type: NOTIFICATION-TYPE
Description:
A rcMacViolation trap signifies that the SNMPv2 entity, acting in an agent role, has received a PDU with an invalid source MAC address.
What is rcMacViolation?
This is a trap notification that fires when the device receives a protocol data unit (PDU) with an invalid source MAC address, indicating a potential security violation or configuration error. It alerts network administrators to examine the suspicious packet and the port where it arrived. Operators use this to detect MAC address spoofing, misconfigured devices, or unauthorized access attempts.
Examples
Send this trap to an SNMP manager — replace <manager> with the IP or hostname of your monitoring server (SNMPv2c):
snmptrap -v2c -c public <manager> '' RAPID-CITY::rcMacViolation snmptrap -v2c -c public <manager> '' 1.3.6.1.4.1.2272.1.21.9
Listen for incoming traps on the manager host (-f keeps it in the foreground, -Lo prints to stdout — useful for testing):
snmptrapd -f -Lo -c /dev/null authCommunity log public
Example snmptrapd log entry:
zoo11-linux.zoo [UDP: [192.168.30.111]:61562->[192.168.30.10]:162]: DISMAN-EVENT-MIB::sysUpTimeInstance = Timeticks: (509820538) 59 days, 0:10:05.38 SNMPv2-MIB::snmpTrapOID.0 = OID: RAPID-CITY::rcMacViolation
OID Breakdown
| Numeric OID | Name | Module |
|---|---|---|
| 1 | iso | LANART-AGENT |
| 1.3 | org | BIANCA-BRICK-PPP-MIB |
| 1.3.6 | dod | BIANCA-BRICK-PPP-MIB |
| 1.3.6.1 | internet | BIANCA-BRICK-PPP-MIB |
| 1.3.6.1.4 | private | BIANCA-BRICK-PPP-MIB |
| 1.3.6.1.4.1 | enterprises | ANIROOT-MIB |
| 1.3.6.1.4.1.2272 | rapidCity | RAPID-CITY |
| 1.3.6.1.4.1.2272.1 | rcMgmt | RAPID-CITY |
| 1.3.6.1.4.1.2272.1.21 | rcTraps | RAPID-CITY |
| 1.3.6.1.4.1.2272.1.21.9 | rcMacViolation | RAPID-CITY |