RAPID-CITY :: rcMacViolation

MIB Reference — IPNetwork Monitor

All MIBsRAPID-CITYrcMacViolation

rcMacViolation

Module: RAPID-CITY

OID (symbolic): RAPID-CITY::rcMacViolation

OID (numeric): 1.3.6.1.4.1.2272.1.21.9

Node type: NOTIFICATION-TYPE

Description:

A rcMacViolation trap signifies that the SNMPv2 entity, acting in an agent role, has received a PDU with an invalid source MAC address.

What is rcMacViolation?

This is a trap notification that fires when the device receives a protocol data unit (PDU) with an invalid source MAC address, indicating a potential security violation or configuration error. It alerts network administrators to examine the suspicious packet and the port where it arrived. Operators use this to detect MAC address spoofing, misconfigured devices, or unauthorized access attempts.

Examples

Send this trap to an SNMP manager — replace <manager> with the IP or hostname of your monitoring server (SNMPv2c):

snmptrap -v2c -c public <manager> '' RAPID-CITY::rcMacViolation
snmptrap -v2c -c public <manager> '' 1.3.6.1.4.1.2272.1.21.9

Listen for incoming traps on the manager host (-f keeps it in the foreground, -Lo prints to stdout — useful for testing):

snmptrapd -f -Lo -c /dev/null authCommunity log public

Example snmptrapd log entry:

zoo11-linux.zoo [UDP: [192.168.30.111]:61562->[192.168.30.10]:162]:
  DISMAN-EVENT-MIB::sysUpTimeInstance = Timeticks: (509820538) 59 days, 0:10:05.38
  SNMPv2-MIB::snmpTrapOID.0 = OID: RAPID-CITY::rcMacViolation

OID Breakdown

Numeric OIDNameModule
1isoLANART-AGENT
1.3orgBIANCA-BRICK-PPP-MIB
1.3.6dodBIANCA-BRICK-PPP-MIB
1.3.6.1internetBIANCA-BRICK-PPP-MIB
1.3.6.1.4privateBIANCA-BRICK-PPP-MIB
1.3.6.1.4.1enterprisesANIROOT-MIB
1.3.6.1.4.1.2272rapidCityRAPID-CITY
1.3.6.1.4.1.2272.1rcMgmtRAPID-CITY
1.3.6.1.4.1.2272.1.21rcTrapsRAPID-CITY
1.3.6.1.4.1.2272.1.21.9rcMacViolationRAPID-CITY