VIPTELA-DOT1X

MIB Reference — IPNetwork Monitor

All MIBsVIPTELA-DOT1X

Organization: Viptela, Inc.

Last Updated: 2020-07-01

Category: Viptela SD-WAN

Description:

Manages Viptela SD-WAN 802.1X port authentication and supplicant configuration on edge devices.

Imported Objects

From SNMPv2-SMI

Counter32
Counter64
Gauge32
Integer32
IpAddress
MODULE-IDENTITY
OBJECT-TYPE
Unsigned32

From SNMPv2-TC

DateAndTime
RowStatus
TEXTUAL-CONVENTION
TruthValue

From VIPTELA-GLOBAL

viptelaOBJECT-IDENTITY

What Is VIPTELA-DOT1X?

VIPTELA-DOT1X is a vendor MIB from Viptela (Cisco SD-WAN) that models IEEE 802.1X network access control configuration and operational state on SD-WAN edge device interfaces. It exposes per-interface 802.1X operational state, host mode, control direction, MAC Authentication Bypass (MAB) settings, Wake-on-LAN, timers, and guest VLAN assignment. Its monitoring relevance is chiefly configuration/software-status oriented — tracking dot1xInterfacesOperState to confirm whether 802.1X enforcement is active on a port and verifying reauthentication/inactivity timeout settings, which is more of an access-control status check than a hardware health check. It models the IEEE 802.1X standard as its underlying reference framework. It is typically deployed on Viptela/Cisco SD-WAN edge routers/switches providing port-based network access control at branch sites. Network engineers evaluating or troubleshooting this functionality can download the VIPTELA-DOT1X file directly to load it into their MIB browser.

IPNetwork Monitor allows you to monitor SNMP objects defined in VIPTELA-DOT1X. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

What Can Be Monitored

  • 802.1X operational state per interface
  • host mode and control direction
  • MAB server/local settings
  • reauthentication/inactivity timeouts
  • guest VLAN assignment

Supported Devices

  • Viptela/Cisco SD-WAN edge routers/switches

Monitoring Examples

An admin polls dot1xInterfacesTable/dot1xInterfacesEntry keyed by dot1xInterfacesIfName to check dot1xInterfacesOperState and dot1xInterfacesHostMode on a branch access port. If dot1xInterfacesOperState shows disabled when it should be enforcing 802.1X, or dot1xInterfacesGuestVlan is unexpectedly active, that flags a misconfigured port allowing unauthenticated access.

OIDs
OID symbolicOID numericTypeAccessDescription
viptela_dot1x1.3.6.1.4.1.41916.19This module defines the data model for 802.1x Network Access Control
dot1x1.3.6.1.4.1.41916.19.1
dot1xInterfacesTable1.3.6.1.4.1.41916.19.1.1not-accessibleDisplay 802.1x interface information
dot1xInterfacesEntry1.3.6.1.4.1.41916.19.1.1.1not-accessible
STR dot1xInterfacesIfName1.3.6.1.4.1.41916.19.1.1.1.1Stringnot-accessibleInterface name
INT dot1xInterfacesOperState1.3.6.1.4.1.41916.19.1.1.1.2INTEGERread-onlyOperational state
INT dot1xInterfacesHostMode1.3.6.1.4.1.41916.19.1.1.1.3INTEGERread-onlyHost mode
INT dot1xInterfacesCtrlDir1.3.6.1.4.1.41916.19.1.1.1.4INTEGERread-only802.1x port access control direction
T/F dot1xInterfacesMabServer1.3.6.1.4.1.41916.19.1.1.1.5TruthValueread-onlyMAC authentication bypass configured to use RADIUS server
T/F dot1xInterfacesMabLocal1.3.6.1.4.1.41916.19.1.1.1.6TruthValueread-onlyMAC authentication bypass configured locally on the interface
T/F dot1xInterfacesWakeOnLan1.3.6.1.4.1.41916.19.1.1.1.7TruthValueread-onlyAllow wake-on-lan packets to egress the port
UNS dot1xInterfacesReauthTimeout1.3.6.1.4.1.41916.19.1.1.1.8UnsignedShortread-onlyTimeout for reauthentication, in minutes
UNS dot1xInterfacesInactivityTimeout1.3.6.1.4.1.41916.19.1.1.1.9UnsignedShortread-onlyTimeout for inactivity, in minutes
I32 dot1xInterfacesGuestVlan1.3.6.1.4.1.41916.19.1.1.1.10Integer32read-onlyVLAN to drop non-802.1x enabled clients into if client is not in MAB list
I32 dot1xInterfacesAuthFailVlan1.3.6.1.4.1.41916.19.1.1.1.11Integer32read-onlyVLAN to drop 802.1x enabled clients into if authentication server is unreachable
I32 dot1xInterfacesAuthRejectVlan1.3.6.1.4.1.41916.19.1.1.1.12Integer32read-onlyVLAN to drop 802.1x enabled clients into if authentication is rejected
I32 dot1xInterfacesDefaultVlan1.3.6.1.4.1.41916.19.1.1.1.13Integer32read-onlyVLAN to drop clients into when VLAN not specified by RADIUS
ADR dot1xInterfacesPrimaryRadiusServer1.3.6.1.4.1.41916.19.1.1.1.14InetAddressIPread-onlyPrimary RADIUS server IP address
ADR dot1xInterfacesSecondaryRadiusServer1.3.6.1.4.1.41916.19.1.1.1.15InetAddressIPread-onlySecondary RADIUS server IP address
UNS dot1xInterfacesAccountingInterval1.3.6.1.4.1.41916.19.1.1.1.16UnsignedShortread-onlyInterim accounting interval, in minutes
STR dot1xInterfacesNasIdentifier1.3.6.1.4.1.41916.19.1.1.1.17Stringread-onlyNAS Identifier sent to RADIUS server
ADR dot1xInterfacesNasIPAddr1.3.6.1.4.1.41916.19.1.1.1.18InetAddressIPread-onlyNAS IP address sent to RADIUS server
U32 dot1xInterfacesNumClients1.3.6.1.4.1.41916.19.1.1.1.19Unsigned32read-onlyNumber of connected clients
dot1xClientsTable1.3.6.1.4.1.41916.19.1.2not-accessibleDisplay 802.1x client information
dot1xClientsEntry1.3.6.1.4.1.41916.19.1.2.1not-accessible
STR dot1xClientsIfName1.3.6.1.4.1.41916.19.1.2.1.1Stringnot-accessible802.1x interface name
STR dot1xClientsMacAddress1.3.6.1.4.1.41916.19.1.2.1.2Stringnot-accessibleMAC address of the client
DOT dot1xClientsAuthState1.3.6.1.4.1.41916.19.1.2.1.3Dot1xAuthStateread-only802.1x authentication state of the client
DOT dot1xClientsAuthMethod1.3.6.1.4.1.41916.19.1.2.1.4Dot1xAuthMethodread-only802.1x authentication method of the client
I32 dot1xClientsVlan1.3.6.1.4.1.41916.19.1.2.1.5Integer32read-onlyOperational VLAN of the client
I32 dot1xClientsVpn1.3.6.1.4.1.41916.19.1.2.1.6Integer32read-onlyOperational VPN of the client
STR dot1xClientsEapMethod1.3.6.1.4.1.41916.19.1.2.1.7Stringread-onlyAuthenticated EAP method
STR dot1xClientsUsername1.3.6.1.4.1.41916.19.1.2.1.8Stringread-onlyUsername for client session
U32 dot1xClientsSessionTime1.3.6.1.4.1.41916.19.1.2.1.9Unsigned32read-onlySession time, in seconds
U32 dot1xClientsConnectedTime1.3.6.1.4.1.41916.19.1.2.1.10Unsigned32read-onlyConnected time, in seconds
U32 dot1xClientsInactiveTime1.3.6.1.4.1.41916.19.1.2.1.11Unsigned32read-onlyTime client has been inactive, in seconds
STR dot1xClientsSessionId1.3.6.1.4.1.41916.19.1.2.1.12Stringread-onlyClient Session ID
U32 dot1xClientsEapolFramesRx1.3.6.1.4.1.41916.19.1.2.1.13Unsigned32read-onlyEAPoL frames received
U32 dot1xClientsEapolFramesTx1.3.6.1.4.1.41916.19.1.2.1.14Unsigned32read-onlyEAPoL frames sent
U32 dot1xClientsEapolStartFramesRx1.3.6.1.4.1.41916.19.1.2.1.15Unsigned32read-onlyEAPoL start frames received
U32 dot1xClientsEapolLogoffFramesRx1.3.6.1.4.1.41916.19.1.2.1.16Unsigned32read-onlyEAPoL logoff frames received
U32 dot1xClientsEapolRequestIdFramesTx1.3.6.1.4.1.41916.19.1.2.1.17Unsigned32read-onlyEAPoL identity request frames sent
U32 dot1xClientsEapolResponseIdFramesRx1.3.6.1.4.1.41916.19.1.2.1.18Unsigned32read-onlyEAPoL identity response frames received
U32 dot1xClientsEapolRequestFramesTx1.3.6.1.4.1.41916.19.1.2.1.19Unsigned32read-onlyEAPoL request frames sent
U32 dot1xClientsEapolResponseFramesRx1.3.6.1.4.1.41916.19.1.2.1.20Unsigned32read-onlyEAPoL response frames received
dot1xRadiusTable1.3.6.1.4.1.41916.19.1.3not-accessibleDisplay 802.1x radius server information
dot1xRadiusEntry1.3.6.1.4.1.41916.19.1.3.1not-accessible
STR dot1xRadiusIfName1.3.6.1.4.1.41916.19.1.3.1.1Stringnot-accessible802.1x interface name
ADR dot1xRadiusIpAddress1.3.6.1.4.1.41916.19.1.3.1.2InetAddressIPnot-accessibleRADIUS server IP address
U32 dot1xRadiusVpn1.3.6.1.4.1.41916.19.1.3.1.3Unsigned32read-onlyRADIUS server VPN
T/F dot1xRadiusIsPrimary1.3.6.1.4.1.41916.19.1.3.1.4TruthValueread-onlyRADIUS server is configured to be the primary one
U32 dot1xRadiusAuthPort1.3.6.1.4.1.41916.19.1.3.1.5Unsigned32read-onlyRADIUS server authentication port number
T/F dot1xRadiusAuthIsCurrent1.3.6.1.4.1.41916.19.1.3.1.6TruthValueread-onlyRADIUS server is the currently active one for authentication
U32 dot1xRadiusAuthRoundTripTime1.3.6.1.4.1.41916.19.1.3.1.7Unsigned32read-onlyAuthentication server round trip time for last message, in seconds
U32 dot1xRadiusAuthAccessRequests1.3.6.1.4.1.41916.19.1.3.1.8Unsigned32read-onlyNumber of access requests sent
U32 dot1xRadiusAuthAccessRetransmissions1.3.6.1.4.1.41916.19.1.3.1.9Unsigned32read-onlyNumber of access request retransmissions
U32 dot1xRadiusAuthAccessAccepts1.3.6.1.4.1.41916.19.1.3.1.10Unsigned32read-onlyNumber of access accepts received
U32 dot1xRadiusAuthAccessRejects1.3.6.1.4.1.41916.19.1.3.1.11Unsigned32read-onlyNumber of access rejects received
U32 dot1xRadiusAuthAccessChallenges1.3.6.1.4.1.41916.19.1.3.1.12Unsigned32read-onlyNumber of access challenges received
U32 dot1xRadiusAuthMalformedAccessResponses1.3.6.1.4.1.41916.19.1.3.1.13Unsigned32read-onlyNumber of malformed access responses received
U32 dot1xRadiusAuthBadAuthenticators1.3.6.1.4.1.41916.19.1.3.1.14Unsigned32read-onlyNumber of authentication requests with bad authentication
U32 dot1xRadiusAuthPendingRequests1.3.6.1.4.1.41916.19.1.3.1.15Unsigned32read-onlyNumber of un-acknowledged access requests
U32 dot1xRadiusAuthTimeouts1.3.6.1.4.1.41916.19.1.3.1.16Unsigned32read-onlyNumber of authentication request timeouts
U32 dot1xRadiusAuthUnknownTypes1.3.6.1.4.1.41916.19.1.3.1.17Unsigned32read-onlyNumber of authentication messages of unknown type
U32 dot1xRadiusAuthPacketsDropped1.3.6.1.4.1.41916.19.1.3.1.18Unsigned32read-onlyNumber of dropped authentication packets
U32 dot1xRadiusAcctPort1.3.6.1.4.1.41916.19.1.3.1.19Unsigned32read-onlyRADIUS server accounting port number
T/F dot1xRadiusAcctIsCurrent1.3.6.1.4.1.41916.19.1.3.1.20TruthValueread-onlyRADIUS server is the currently active one for accounting
U32 dot1xRadiusAcctRoundTripTime1.3.6.1.4.1.41916.19.1.3.1.21Unsigned32read-onlyAccounting server round trip time for last message, in seconds
U32 dot1xRadiusAcctRequests1.3.6.1.4.1.41916.19.1.3.1.22Unsigned32read-onlyNumber of accounting requests sent
U32 dot1xRadiusAcctRetransmissions1.3.6.1.4.1.41916.19.1.3.1.23Unsigned32read-onlyNumber of accounting request restransmissions
U32 dot1xRadiusAcctResponses1.3.6.1.4.1.41916.19.1.3.1.24Unsigned32read-onlyNumber of accounting responses received
U32 dot1xRadiusAcctMalformedResponses1.3.6.1.4.1.41916.19.1.3.1.25Unsigned32read-onlyNumber of malformed accounting responses received
U32 dot1xRadiusAcctBadAuthenticators1.3.6.1.4.1.41916.19.1.3.1.26Unsigned32read-onlyNumber of accounting requests with bad authentication
U32 dot1xRadiusAcctPendingRequests1.3.6.1.4.1.41916.19.1.3.1.27Unsigned32read-onlyNumber of un-acknowledged accounting requests
U32 dot1xRadiusAcctTimeouts1.3.6.1.4.1.41916.19.1.3.1.28Unsigned32read-onlyNumber of accounting request timeouts
U32 dot1xRadiusAcctUnknownTypes1.3.6.1.4.1.41916.19.1.3.1.29Unsigned32read-onlyNumber of accounting responses of unknown type
U32 dot1xRadiusAcctPacketsDropped1.3.6.1.4.1.41916.19.1.3.1.30Unsigned32read-onlyNumber of dropped accounting packets

RFC description

Defines data model for 802.1x Network Access Control on Viptela SD-WAN devices.

Start monitoring Viptela/Cisco SD-WAN edge routers/switches (802.1X port-authentication operational state status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download VIPTELA-DOT1X