BAYSTACK-IPV6-FIRST-HOP-SEC-MIB
AI MIB Summary
The BAYSTACK-IPV6-FIRST-HOP-SEC-MIB monitors and configures IPv6 First Hop Security policies on Brocade (formerly Foundry) BayStack switches to enforce neighbor discovery validation, router advertisement filtering, and duplicate address detection between directly connected nodes. This module provides visibility into security binding tables and counters for dropped packets resulting from violations of RA guard, ND inspection, and DHCPv6 guard rules.
This MIB module is used for IPv6 First Hop Security configuration. The purpose of First Hop Security feature is to take care of the treats caused by the immediate node to another immediate node attached to the same First Hop Security device.
Main OID:
bayStackIpv6FirstHopSecMib.bayStackMibs.45
85
Objects
Active
Status
5
Dependencies
Imported Objects
Objects
85 total| Object Name |
|---|
bayStackIpv6FirstHopSecMibThis MIB module is used for IPv6 First Hop Security configuration.
The purpose of First Hop Security feature is to take care of the treats
caused by the immediate node to another immediate node attached to the same
First Hop Security device. MODULE-IDENTITY .bayStackMibs.45 |
bsIpv6FirstHopSecNotifications OBJECT IDENTIFIER .bayStackMibs.45.0 |
bsIpv6NDSBTTableFullThis notification is generated when an attempt is made to add a new
SBT entry when the Secure Binding Table is full. The value of
bsIpv6NDInspectionNotificationClientMACAddr represents the MAC address that
could not be added to the SBT table. This notification also
indicates that additional packets will not be added to
the SBT and will be dropped. NOTIFICATION-TYPE .bayStackMibs.45.0.1 |
bsIpv6NDNotificationsUntrustedPortThis notification is generated when an ND message is suspected
to be generated by the untrusted system/host. NOTIFICATION-TYPE .bayStackMibs.45.0.2 |
bsIpv6FirstHopSecObjects OBJECT IDENTIFIER .bayStackMibs.45.1 |
bsIpv6FHSScalVar OBJECT IDENTIFIER .bayStackMibs.45.1.1 |
bsIpv6FHSAdminFirst Hop Security Global Admin statusrw TruthValue (SNMPv2-TC) .bayStackMibs.45.1.1.1 |
bsIpv6FHSRagAdminRA guard Global Admin statusrw TruthValue (SNMPv2-TC) .bayStackMibs.45.1.1.2 |
bsIpv6FHSDhcpv6gAdminDHCPv6 guard Global Admin statusrw TruthValue (SNMPv2-TC) .bayStackMibs.45.1.1.3 |
bsIpv6FHSNdInspectAdminND Inspection Global Admin statusrw TruthValue (SNMPv2-TC) .bayStackMibs.45.1.1.4 |
bsIpv6FHSMaxDynSbtEntriesMaximum Dynamic SBT entries allowedrw INTEGER .bayStackMibs.45.1.1.5 |
bsIpv6FHSSbtReachLifeTimeSBT Reachable state life time in seconds starts from 30 till 86400. Configure timer as 0 will not expire this timerrw INTEGER .bayStackMibs.45.1.1.6 |
bsIpv6FHSSbtStaleLifeTimeSBT Stale state life time in seconds starts from 30 till 86400. Configure timer as 0 will not expire this timerrw INTEGER .bayStackMibs.45.1.1.7 |
bsIpv6FHSSbtDownLifeTimeSBT Down state life time in seconds starts from 30 till 86400. Configure timer as 0 will not expire this timerrw INTEGER .bayStackMibs.45.1.1.8 |
bsIpv6FHSSbtTblOverFlowSBT Table Overflow due to the maximum SBT entry restrictionro Counter32 .bayStackMibs.45.1.1.9 |
bsIpv6FHSIpv6AccessListTableTable contains the list of
IPv6 Access List used for Frist
Hop Security Feature. SEQUENCE OF BsIpv6FHSIpv6AccessEntry .bayStackMibs.45.1.2 |
bsIpv6FHSIpv6AccessListEntryEntry contains the list of
IPv6 Access List used for Frist
Hop Security Feature. BsIpv6FHSIpv6AccessEntry .bayStackMibs.45.1.2.1 |
bsIpv6FHSIpv6AccessListNameIPv6 Access List Name FhsListName .bayStackMibs.45.1.2.1.1 |
bsIpv6FHSIpv6AccessListPrefixIPv6 Prefix attached to this IPv6 access list Id Ipv6Address (IPV6-TC) .bayStackMibs.45.1.2.1.2 |
bsIpv6FHSIpv6AccessListPrefixMaskLenIPv6 Prefix mask length attached to this IPv6 access list Id INTEGER .bayStackMibs.45.1.2.1.3 |
bsIpv6FHSIpv6AccessListMaskLenFromIPv6 Prefix mask length range fromrw INTEGER .bayStackMibs.45.1.2.1.4 |
bsIpv6FHSIpv6AccessListMaskLenToIPv6 Prefix mask length range torw INTEGER .bayStackMibs.45.1.2.1.5 |
bsIpv6FHSIpv6AccessListAccessTypeIPv6 IP Access Type
Allow or Denyrw FhsAccessType .bayStackMibs.45.1.2.1.6 |
bsIpv6FHSIpv6AccessListRowStatusIPv6 IP Access List row statusrw RowStatus (SNMPv2-TC) .bayStackMibs.45.1.2.1.7 |
bsIpv6FHSMacAccessListTableTable contains the list of
MAC Access List used for Frist
Hop Security Feature. SEQUENCE OF BsIpv6FHSMacAccessEntry .bayStackMibs.45.1.3 |
bsIpv6FHSMacAccessListEntryEntry contains the list of
MAC Access List used for Frist
Hop Security Feature. BsIpv6FHSMacAccessEntry .bayStackMibs.45.1.3.3 |
bsIpv6FHSMacAccessListNameMAC Access List Name FhsListName .bayStackMibs.45.1.3.3.1 |
bsIpv6FHSMacAccessListMacMAC address attached to this MAC access list Id MacAddress (SNMPv2-TC) .bayStackMibs.45.1.3.3.2 |
bsIpv6FHSMacAccessListAccessTypeMAC Access Type
Allow or Denyrw FhsAccessType .bayStackMibs.45.1.3.3.3 |
bsIpv6FHSMacAccessListRowStatusMAC Access List row statusrw RowStatus (SNMPv2-TC) .bayStackMibs.45.1.3.3.4 |
bsIpv6FHSPolicyPortMapTableTable contains the list of
First Hop security Policies
attached to the interface. SEQUENCE OF BsIpv6FHSPolicyPortMapEntry .bayStackMibs.45.1.4 |
bsIpv6FHSPolicyPortMapEntryEntry contains the list of
First Hop security Policies
attached to the interface. BsIpv6FHSPolicyPortMapEntry .bayStackMibs.45.1.4.1 |
bsIpv6FHSPolicyPortMapIfIndexInterface index number InterfaceIndex (IF-MIB) .bayStackMibs.45.1.4.1.1 |
bsIpv6FHSPolicyPortMapDhcpv6gPolicyNameDHCPv6 guard policy namerw FhsListName .bayStackMibs.45.1.4.1.2 |
bsIpv6FHSPolicyPortMapRagPolicyNameRA guard policy namerw FhsListName .bayStackMibs.45.1.4.1.3 |
bsIpv6FHSPolicyPortMapNDAdminEnable/Disable ND-inspectionrw TruthValue (SNMPv2-TC) .bayStackMibs.45.1.4.1.4 |
bsIpv6FHSPolicyPortMapSbtDynLearnAdminEnable/Disable learning dynamic SBT entryrw TruthValue (SNMPv2-TC) .bayStackMibs.45.1.4.1.5 |
bsIpv6FHSPolicyPortMapTotDhcpv6PktRcvTotal Number of Dhcpv6
packets Receivedro Counter32 .bayStackMibs.45.1.4.1.6 |
bsIpv6FHSPolicyPortMapTotDhcpv6PktDroppedTotal Number of Dhcpv6
packets droppedro Counter32 .bayStackMibs.45.1.4.1.7 |
bsIpv6FHSPolicyPortMapTotRaPktRcvTotal Number of RA
packets Receivedro Counter32 .bayStackMibs.45.1.4.1.8 |
bsIpv6FHSPolicyPortMapTotRaPktDroppedTotal Number of RA
packets droppedro Counter32 .bayStackMibs.45.1.4.1.9 |
bsIpv6FHSPolicyPortMapTotNdPktRcvTotal Number of ND Packets Receivedro Counter32 .bayStackMibs.45.1.4.1.10 |
bsIpv6FHSPolicyPortMapTotNdPktDroppedTotal Number of ND Packets Droppedro Counter32 .bayStackMibs.45.1.4.1.11 |
bsIpv6FHSPolicyPortMapClearDhcpGuardStatsFirst Hop security clear stats:
bsIpv6FHSPolicyPortMapTotDhcpv6PktRcv and
bsIpv6FHSPolicyPortMapTotDhcpv6PktDroppedrw TruthValue (SNMPv2-TC) .bayStackMibs.45.1.4.1.12 |
bsIpv6FHSPolicyPortMapClearRaGuardStatsFirst Hop security clear stats:
bsIpv6FHSPolicyPortMapTotRaPktRcv and
bsIpv6FHSPolicyPortMapTotRaPktDroppedrw TruthValue (SNMPv2-TC) .bayStackMibs.45.1.4.1.13 |
bsIpv6FHSPolicyPortMapClearNDInspectStatsFirst Hop security clear stats:
bsIpv6FHSPolicyPortMapTotNdPktRcv,
bsIpv6FHSPolicyPortMapTotNdPktDropped and
bsIpv6FHSPolicyPortMapTotSbtEntDroppedrw TruthValue (SNMPv2-TC) .bayStackMibs.45.1.4.1.14 |
bsIpv6FHSPolicyPortMapRowStatusFirst Hop security row statusrw RowStatus (SNMPv2-TC) .bayStackMibs.45.1.4.1.15 |
bsIpv6FHSDhcpv6gPolicyListTableTable contains the list of
DHCPv6 guard Policies used for
Hop Security Feature. SEQUENCE OF BsIpv6FHSDhcpv6gPolicyEntry .bayStackMibs.45.1.5 |
bsIpv6FHSDhcpv6gPolicyListEntryEntry contains the list of
DHCPv6 guard Policies used for
Hop Security Feature. BsIpv6FHSDhcpv6gPolicyEntry .bayStackMibs.45.1.5.1 |
bsIpv6FHSDhcpv6gPolicyNameThis is the DHCPv6
guard Policy Name FhsListName .bayStackMibs.45.1.5.1.1 |
bsIpv6FHSDhcpv6gDeviceRoleThis is the device role of
the received port. If the
device role is client and if
it receives DHCPv6 reply then
those packets should be
droppedrw FhsDhcpv6GuardDeviceRole .bayStackMibs.45.1.5.1.2 |
bsIpv6FHSDhcpv6gServerAccessListNameThis is the IPv6 access list which
will be validating source
IPv6 address of the DHCPv6 Reply
packet from the serverrw FhsListName .bayStackMibs.45.1.5.1.3 |
bsIpv6FHSDhcpv6gReplyPrefixListNameValidate the prefix
information in the DHCPv6
reply against the configured
reply prefix list.rw FhsListName .bayStackMibs.45.1.5.1.4 |
bsIpv6FHSDhcpv6gPrefLimitMinThis is check against the
DHCPv6 server / relay
router preference. If
the received router
preference is less
than the configured
router preference than
drop the packetrw INTEGER .bayStackMibs.45.1.5.1.5 |
bsIpv6FHSDhcpv6gPrefLimitMaxThis is check against the
DHCPv6 server / relay
router preference. If
the received router
preference is greater
than the configured
router preference than
drop the packetrw INTEGER .bayStackMibs.45.1.5.1.6 |
bsIpv6FHSDhcpv6gPolicyListRowStatusDHCPv6 guard policy row statusrw RowStatus (SNMPv2-TC) .bayStackMibs.45.1.5.1.7 |
bsIpv6FHSRagPolicyListTableTable contains the list of
RA guard Policies used for
Hop Security Feature. SEQUENCE OF BsIpv6FHSRagPolicyEntry .bayStackMibs.45.1.6 |
bsIpv6FHSRagPolicyListEntryEntry contains the list of
RA guard Policies used for
Hop Security Feature. BsIpv6FHSRagPolicyEntry .bayStackMibs.45.1.6.1 |
bsIpv6FHSRagPolicyNameRA guard policy Name FhsListName .bayStackMibs.45.1.6.1.1 |
bsIpv6FHSRagDeviceRoleThis is the device role to
be checked againstrw FhsRaGuardDeviceRole .bayStackMibs.45.1.6.1.2 |
bsIpv6FHSRagIpv6AccessListNameThis is the IPv6 access list which
will be validating the source
IPv6 address of the RA packetrw FhsListName .bayStackMibs.45.1.6.1.3 |
bsIpv6FHSRagIpv6PrefixListNameThis is the IPv6 access list which
will be validating the Prefix
present in the RA packetrw FhsListName .bayStackMibs.45.1.6.1.4 |
bsIpv6FHSRagMacListNameThis is the MAC access list which
will be validating the source
MAC of the received RA packetrw FhsListName .bayStackMibs.45.1.6.1.5 |
bsIpv6FHSRagManagedConfigFlagIn the RA packets, there is an M flag
(Managed Address configuration Flag)
which is set indicating that the address
assignments are available via DHCPv6.
This means that DHCPv6 would take care
of the interface address assignment
in that LAN segment. If filtering policy
is enabled then all the RA packets with
M flag not set will be dropped.
By default this check will be ignoredrw FhsRaManagedConfigFlag .bayStackMibs.45.1.6.1.6 |
bsIpv6FHSRagRouterPrefMaxIn the RA packet there is router
preference information is available
in the Flags. This could be HIGH
or LOW or MEDIUM. This filtering
policy option would verify that
the advertised default router
preference parameter value is lower
than or equal to a specified limitrw FhsRaRouterPrefMax .bayStackMibs.45.1.6.1.7 |
bsIpv6FHSRagHopLimitMinThis is the minimum value check for
the hop limit value present in the
RA packet. If the value is less
than configured minimum value then drop
the RA packetrw INTEGER .bayStackMibs.45.1.6.1.8 |
bsIpv6FHSRagHopLimitMaxThis is the maximum value check for
the hop limit value present in the
RA packet. If the value is greater
than configured maximum value then drop
the RA packetrw INTEGER .bayStackMibs.45.1.6.1.9 |
bsIpv6FHSRagPolicyListRowStatusRA guard policy row statusrw RowStatus (SNMPv2-TC) .bayStackMibs.45.1.6.1.10 |
bsIpv6FHSSbtTableTable contains the list of
SBT entries learnt
Dynamically and statically
configure. SEQUENCE OF BsIpv6FHSSbtEntry .bayStackMibs.45.1.7 |
bsIpv6FHSSbtListEntryEntry contains the list of
SBT entries. BsIpv6FHSSbtEntry .bayStackMibs.45.1.7.1 |
bsIpv6FHSSbtInterfaceIndexDerive unit and port number from this ifindex InterfaceIndex (IF-MIB) .bayStackMibs.45.1.7.1.1 |
bsIpv6FHSSbtVlanVLAN INTEGER .bayStackMibs.45.1.7.1.2 |
bsIpv6FHSSbtSrcIpSource IPv6 Address Ipv6Address (IPV6-TC) .bayStackMibs.45.1.7.1.3 |
bsIpv6FHSSbtLinkLayerAddressLink Layer MAC addressrw MacAddress (SNMPv2-TC) .bayStackMibs.45.1.7.1.4 |
bsIpv6FHSSbtLearnTypeSBT Entry Typero FhsSbtType .bayStackMibs.45.1.7.1.5 |
bsIpv6FHSSbtLearnPrioritySBT Entry priorityro Integer32 .bayStackMibs.45.1.7.1.6 |
bsIpv6FHSSbtLearnStateSBT Entry statero FhsSbtState .bayStackMibs.45.1.7.1.7 |
bsIpv6FHSSbtLearnAgeTime Elapsed after being in this statero Integer32 .bayStackMibs.45.1.7.1.8 |
bsIpv6FHSSbtRowStatusSBT entry row statusrw RowStatus (SNMPv2-TC) .bayStackMibs.45.1.7.1.9 |
bsIpv6NDTrapNotificationObjects OBJECT IDENTIFIER .bayStackMibs.45.1.8 |
bsIpv6NDInspectionNotificationClientMACAddrThis value indicates the source MAC Address of a dropped ND inspection packet.ro MacAddress (SNMPv2-TC) .bayStackMibs.45.1.8.1 |
bsIpv6NDInspectionNotificationMsgTypeThis value indicates the message type of a dropped ND packet.ro Enumeration .bayStackMibs.45.1.8.2 |
bsIpv6FHSNDInterfaceIndexThis value indicates the unit and port number of a dropped ND inspection packet.ro InterfaceIndex (IF-MIB) .bayStackMibs.45.1.8.3 |
bsIpv6FHSNDIpv6AddressThis value indicates the Ipv6 source address of a dropped ND inspection packet.ro Ipv6Address (IPV6-TC) .bayStackMibs.45.1.8.4 |
bsIpv6FHSNDVlanIDThis value indicates the Vlan ID of a dropped ND inspection packet.ro INTEGER .bayStackMibs.45.1.8.5 |