Home/Catalog/BAYSTACK-IPV6-FIRST-HOP-SEC-MIB

BAYSTACK-IPV6-FIRST-HOP-SEC-MIB

AI MIB Summary

The BAYSTACK-IPV6-FIRST-HOP-SEC-MIB monitors and configures IPv6 First Hop Security policies on Brocade (formerly Foundry) BayStack switches to enforce neighbor discovery validation, router advertisement filtering, and duplicate address detection between directly connected nodes. This module provides visibility into security binding tables and counters for dropped packets resulting from violations of RA guard, ND inspection, and DHCPv6 guard rules.

This MIB module is used for IPv6 First Hop Security configuration. The purpose of First Hop Security feature is to take care of the treats caused by the immediate node to another immediate node attached to the same First Hop Security device.
Main OID:
bayStackIpv6FirstHopSecMib.bayStackMibs.45
85
Objects
Active
Status
5
Dependencies

Imported Objects

Objects

85 total
Object Name
bayStackIpv6FirstHopSecMibThis MIB module is used for IPv6 First Hop Security configuration. The purpose of First Hop Security feature is to take care of the treats caused by the immediate node to another immediate node attached to the same First Hop Security device.
MODULE-IDENTITY
.bayStackMibs.45
bsIpv6FirstHopSecNotifications
OBJECT IDENTIFIER
.bayStackMibs.45.0
bsIpv6NDSBTTableFullThis notification is generated when an attempt is made to add a new SBT entry when the Secure Binding Table is full. The value of bsIpv6NDInspectionNotificationClientMACAddr represents the MAC address that could not be added to the SBT table. This notification also indicates that additional packets will not be added to the SBT and will be dropped.
NOTIFICATION-TYPE
.bayStackMibs.45.0.1
bsIpv6NDNotificationsUntrustedPortThis notification is generated when an ND message is suspected to be generated by the untrusted system/host.
NOTIFICATION-TYPE
.bayStackMibs.45.0.2
bsIpv6FirstHopSecObjects
OBJECT IDENTIFIER
.bayStackMibs.45.1
bsIpv6FHSScalVar
OBJECT IDENTIFIER
.bayStackMibs.45.1.1
bsIpv6FHSAdminFirst Hop Security Global Admin statusrw
TruthValue (SNMPv2-TC)
.bayStackMibs.45.1.1.1
bsIpv6FHSRagAdminRA guard Global Admin statusrw
TruthValue (SNMPv2-TC)
.bayStackMibs.45.1.1.2
bsIpv6FHSDhcpv6gAdminDHCPv6 guard Global Admin statusrw
TruthValue (SNMPv2-TC)
.bayStackMibs.45.1.1.3
bsIpv6FHSNdInspectAdminND Inspection Global Admin statusrw
TruthValue (SNMPv2-TC)
.bayStackMibs.45.1.1.4
bsIpv6FHSMaxDynSbtEntriesMaximum Dynamic SBT entries allowedrw
INTEGER
.bayStackMibs.45.1.1.5
bsIpv6FHSSbtReachLifeTimeSBT Reachable state life time in seconds starts from 30 till 86400. Configure timer as 0 will not expire this timerrw
INTEGER
.bayStackMibs.45.1.1.6
bsIpv6FHSSbtStaleLifeTimeSBT Stale state life time in seconds starts from 30 till 86400. Configure timer as 0 will not expire this timerrw
INTEGER
.bayStackMibs.45.1.1.7
bsIpv6FHSSbtDownLifeTimeSBT Down state life time in seconds starts from 30 till 86400. Configure timer as 0 will not expire this timerrw
INTEGER
.bayStackMibs.45.1.1.8
bsIpv6FHSSbtTblOverFlowSBT Table Overflow due to the maximum SBT entry restrictionro
Counter32
.bayStackMibs.45.1.1.9
bsIpv6FHSIpv6AccessListTableTable contains the list of IPv6 Access List used for Frist Hop Security Feature.
SEQUENCE OF BsIpv6FHSIpv6AccessEntry
.bayStackMibs.45.1.2
bsIpv6FHSIpv6AccessListEntryEntry contains the list of IPv6 Access List used for Frist Hop Security Feature.
BsIpv6FHSIpv6AccessEntry
.bayStackMibs.45.1.2.1
bsIpv6FHSIpv6AccessListNameIPv6 Access List Name
FhsListName
.bayStackMibs.45.1.2.1.1
bsIpv6FHSIpv6AccessListPrefixIPv6 Prefix attached to this IPv6 access list Id
Ipv6Address (IPV6-TC)
.bayStackMibs.45.1.2.1.2
bsIpv6FHSIpv6AccessListPrefixMaskLenIPv6 Prefix mask length attached to this IPv6 access list Id
INTEGER
.bayStackMibs.45.1.2.1.3
bsIpv6FHSIpv6AccessListMaskLenFromIPv6 Prefix mask length range fromrw
INTEGER
.bayStackMibs.45.1.2.1.4
bsIpv6FHSIpv6AccessListMaskLenToIPv6 Prefix mask length range torw
INTEGER
.bayStackMibs.45.1.2.1.5
bsIpv6FHSIpv6AccessListAccessTypeIPv6 IP Access Type Allow or Denyrw
FhsAccessType
.bayStackMibs.45.1.2.1.6
bsIpv6FHSIpv6AccessListRowStatusIPv6 IP Access List row statusrw
RowStatus (SNMPv2-TC)
.bayStackMibs.45.1.2.1.7
bsIpv6FHSMacAccessListTableTable contains the list of MAC Access List used for Frist Hop Security Feature.
SEQUENCE OF BsIpv6FHSMacAccessEntry
.bayStackMibs.45.1.3
bsIpv6FHSMacAccessListEntryEntry contains the list of MAC Access List used for Frist Hop Security Feature.
BsIpv6FHSMacAccessEntry
.bayStackMibs.45.1.3.3
bsIpv6FHSMacAccessListNameMAC Access List Name
FhsListName
.bayStackMibs.45.1.3.3.1
bsIpv6FHSMacAccessListMacMAC address attached to this MAC access list Id
MacAddress (SNMPv2-TC)
.bayStackMibs.45.1.3.3.2
bsIpv6FHSMacAccessListAccessTypeMAC Access Type Allow or Denyrw
FhsAccessType
.bayStackMibs.45.1.3.3.3
bsIpv6FHSMacAccessListRowStatusMAC Access List row statusrw
RowStatus (SNMPv2-TC)
.bayStackMibs.45.1.3.3.4
bsIpv6FHSPolicyPortMapTableTable contains the list of First Hop security Policies attached to the interface.
SEQUENCE OF BsIpv6FHSPolicyPortMapEntry
.bayStackMibs.45.1.4
bsIpv6FHSPolicyPortMapEntryEntry contains the list of First Hop security Policies attached to the interface.
BsIpv6FHSPolicyPortMapEntry
.bayStackMibs.45.1.4.1
bsIpv6FHSPolicyPortMapIfIndexInterface index number
InterfaceIndex (IF-MIB)
.bayStackMibs.45.1.4.1.1
bsIpv6FHSPolicyPortMapDhcpv6gPolicyNameDHCPv6 guard policy namerw
FhsListName
.bayStackMibs.45.1.4.1.2
bsIpv6FHSPolicyPortMapRagPolicyNameRA guard policy namerw
FhsListName
.bayStackMibs.45.1.4.1.3
bsIpv6FHSPolicyPortMapNDAdminEnable/Disable ND-inspectionrw
TruthValue (SNMPv2-TC)
.bayStackMibs.45.1.4.1.4
bsIpv6FHSPolicyPortMapSbtDynLearnAdminEnable/Disable learning dynamic SBT entryrw
TruthValue (SNMPv2-TC)
.bayStackMibs.45.1.4.1.5
bsIpv6FHSPolicyPortMapTotDhcpv6PktRcvTotal Number of Dhcpv6 packets Receivedro
Counter32
.bayStackMibs.45.1.4.1.6
bsIpv6FHSPolicyPortMapTotDhcpv6PktDroppedTotal Number of Dhcpv6 packets droppedro
Counter32
.bayStackMibs.45.1.4.1.7
bsIpv6FHSPolicyPortMapTotRaPktRcvTotal Number of RA packets Receivedro
Counter32
.bayStackMibs.45.1.4.1.8
bsIpv6FHSPolicyPortMapTotRaPktDroppedTotal Number of RA packets droppedro
Counter32
.bayStackMibs.45.1.4.1.9
bsIpv6FHSPolicyPortMapTotNdPktRcvTotal Number of ND Packets Receivedro
Counter32
.bayStackMibs.45.1.4.1.10
bsIpv6FHSPolicyPortMapTotNdPktDroppedTotal Number of ND Packets Droppedro
Counter32
.bayStackMibs.45.1.4.1.11
bsIpv6FHSPolicyPortMapClearDhcpGuardStatsFirst Hop security clear stats: bsIpv6FHSPolicyPortMapTotDhcpv6PktRcv and bsIpv6FHSPolicyPortMapTotDhcpv6PktDroppedrw
TruthValue (SNMPv2-TC)
.bayStackMibs.45.1.4.1.12
bsIpv6FHSPolicyPortMapClearRaGuardStatsFirst Hop security clear stats: bsIpv6FHSPolicyPortMapTotRaPktRcv and bsIpv6FHSPolicyPortMapTotRaPktDroppedrw
TruthValue (SNMPv2-TC)
.bayStackMibs.45.1.4.1.13
bsIpv6FHSPolicyPortMapClearNDInspectStatsFirst Hop security clear stats: bsIpv6FHSPolicyPortMapTotNdPktRcv, bsIpv6FHSPolicyPortMapTotNdPktDropped and bsIpv6FHSPolicyPortMapTotSbtEntDroppedrw
TruthValue (SNMPv2-TC)
.bayStackMibs.45.1.4.1.14
bsIpv6FHSPolicyPortMapRowStatusFirst Hop security row statusrw
RowStatus (SNMPv2-TC)
.bayStackMibs.45.1.4.1.15
bsIpv6FHSDhcpv6gPolicyListTableTable contains the list of DHCPv6 guard Policies used for Hop Security Feature.
SEQUENCE OF BsIpv6FHSDhcpv6gPolicyEntry
.bayStackMibs.45.1.5
bsIpv6FHSDhcpv6gPolicyListEntryEntry contains the list of DHCPv6 guard Policies used for Hop Security Feature.
BsIpv6FHSDhcpv6gPolicyEntry
.bayStackMibs.45.1.5.1
bsIpv6FHSDhcpv6gPolicyNameThis is the DHCPv6 guard Policy Name
FhsListName
.bayStackMibs.45.1.5.1.1
bsIpv6FHSDhcpv6gDeviceRoleThis is the device role of the received port. If the device role is client and if it receives DHCPv6 reply then those packets should be droppedrw
FhsDhcpv6GuardDeviceRole
.bayStackMibs.45.1.5.1.2
bsIpv6FHSDhcpv6gServerAccessListNameThis is the IPv6 access list which will be validating source IPv6 address of the DHCPv6 Reply packet from the serverrw
FhsListName
.bayStackMibs.45.1.5.1.3
bsIpv6FHSDhcpv6gReplyPrefixListNameValidate the prefix information in the DHCPv6 reply against the configured reply prefix list.rw
FhsListName
.bayStackMibs.45.1.5.1.4
bsIpv6FHSDhcpv6gPrefLimitMinThis is check against the DHCPv6 server / relay router preference. If the received router preference is less than the configured router preference than drop the packetrw
INTEGER
.bayStackMibs.45.1.5.1.5
bsIpv6FHSDhcpv6gPrefLimitMaxThis is check against the DHCPv6 server / relay router preference. If the received router preference is greater than the configured router preference than drop the packetrw
INTEGER
.bayStackMibs.45.1.5.1.6
bsIpv6FHSDhcpv6gPolicyListRowStatusDHCPv6 guard policy row statusrw
RowStatus (SNMPv2-TC)
.bayStackMibs.45.1.5.1.7
bsIpv6FHSRagPolicyListTableTable contains the list of RA guard Policies used for Hop Security Feature.
SEQUENCE OF BsIpv6FHSRagPolicyEntry
.bayStackMibs.45.1.6
bsIpv6FHSRagPolicyListEntryEntry contains the list of RA guard Policies used for Hop Security Feature.
BsIpv6FHSRagPolicyEntry
.bayStackMibs.45.1.6.1
bsIpv6FHSRagPolicyNameRA guard policy Name
FhsListName
.bayStackMibs.45.1.6.1.1
bsIpv6FHSRagDeviceRoleThis is the device role to be checked againstrw
FhsRaGuardDeviceRole
.bayStackMibs.45.1.6.1.2
bsIpv6FHSRagIpv6AccessListNameThis is the IPv6 access list which will be validating the source IPv6 address of the RA packetrw
FhsListName
.bayStackMibs.45.1.6.1.3
bsIpv6FHSRagIpv6PrefixListNameThis is the IPv6 access list which will be validating the Prefix present in the RA packetrw
FhsListName
.bayStackMibs.45.1.6.1.4
bsIpv6FHSRagMacListNameThis is the MAC access list which will be validating the source MAC of the received RA packetrw
FhsListName
.bayStackMibs.45.1.6.1.5
bsIpv6FHSRagManagedConfigFlagIn the RA packets, there is an M flag (Managed Address configuration Flag) which is set indicating that the address assignments are available via DHCPv6. This means that DHCPv6 would take care of the interface address assignment in that LAN segment. If filtering policy is enabled then all the RA packets with M flag not set will be dropped. By default this check will be ignoredrw
FhsRaManagedConfigFlag
.bayStackMibs.45.1.6.1.6
bsIpv6FHSRagRouterPrefMaxIn the RA packet there is router preference information is available in the Flags. This could be HIGH or LOW or MEDIUM. This filtering policy option would verify that the advertised default router preference parameter value is lower than or equal to a specified limitrw
FhsRaRouterPrefMax
.bayStackMibs.45.1.6.1.7
bsIpv6FHSRagHopLimitMinThis is the minimum value check for the hop limit value present in the RA packet. If the value is less than configured minimum value then drop the RA packetrw
INTEGER
.bayStackMibs.45.1.6.1.8
bsIpv6FHSRagHopLimitMaxThis is the maximum value check for the hop limit value present in the RA packet. If the value is greater than configured maximum value then drop the RA packetrw
INTEGER
.bayStackMibs.45.1.6.1.9
bsIpv6FHSRagPolicyListRowStatusRA guard policy row statusrw
RowStatus (SNMPv2-TC)
.bayStackMibs.45.1.6.1.10
bsIpv6FHSSbtTableTable contains the list of SBT entries learnt Dynamically and statically configure.
SEQUENCE OF BsIpv6FHSSbtEntry
.bayStackMibs.45.1.7
bsIpv6FHSSbtListEntryEntry contains the list of SBT entries.
BsIpv6FHSSbtEntry
.bayStackMibs.45.1.7.1
bsIpv6FHSSbtInterfaceIndexDerive unit and port number from this ifindex
InterfaceIndex (IF-MIB)
.bayStackMibs.45.1.7.1.1
bsIpv6FHSSbtVlanVLAN
INTEGER
.bayStackMibs.45.1.7.1.2
bsIpv6FHSSbtSrcIpSource IPv6 Address
Ipv6Address (IPV6-TC)
.bayStackMibs.45.1.7.1.3
bsIpv6FHSSbtLinkLayerAddressLink Layer MAC addressrw
MacAddress (SNMPv2-TC)
.bayStackMibs.45.1.7.1.4
bsIpv6FHSSbtLearnTypeSBT Entry Typero
FhsSbtType
.bayStackMibs.45.1.7.1.5
bsIpv6FHSSbtLearnPrioritySBT Entry priorityro
Integer32
.bayStackMibs.45.1.7.1.6
bsIpv6FHSSbtLearnStateSBT Entry statero
FhsSbtState
.bayStackMibs.45.1.7.1.7
bsIpv6FHSSbtLearnAgeTime Elapsed after being in this statero
Integer32
.bayStackMibs.45.1.7.1.8
bsIpv6FHSSbtRowStatusSBT entry row statusrw
RowStatus (SNMPv2-TC)
.bayStackMibs.45.1.7.1.9
bsIpv6NDTrapNotificationObjects
OBJECT IDENTIFIER
.bayStackMibs.45.1.8
bsIpv6NDInspectionNotificationClientMACAddrThis value indicates the source MAC Address of a dropped ND inspection packet.ro
MacAddress (SNMPv2-TC)
.bayStackMibs.45.1.8.1
bsIpv6NDInspectionNotificationMsgTypeThis value indicates the message type of a dropped ND packet.ro
Enumeration
.bayStackMibs.45.1.8.2
bsIpv6FHSNDInterfaceIndexThis value indicates the unit and port number of a dropped ND inspection packet.ro
InterfaceIndex (IF-MIB)
.bayStackMibs.45.1.8.3
bsIpv6FHSNDIpv6AddressThis value indicates the Ipv6 source address of a dropped ND inspection packet.ro
Ipv6Address (IPV6-TC)
.bayStackMibs.45.1.8.4
bsIpv6FHSNDVlanIDThis value indicates the Vlan ID of a dropped ND inspection packet.ro
INTEGER
.bayStackMibs.45.1.8.5
BAYSTACK-IPV6-FIRST-HOP-SEC-MIB - SNMP MIB Reference | MIBs Explorer