CABH-IETF-SEC-MIB
AI MIB Summary
The CABH-IETF-SEC-MIB defines management objects for monitoring Security Portal Services, specifically tracking authentication sessions, access control states, and security event logs within CABH-compliant network infrastructure. It enables the collection of security metrics such as active user counts, login failure rates, and portal service availability for policy enforcement and audit compliance.
This MIB module supplies the basic management objects for the Security Portal Services.
Copyright (C) The Internet Society (2003). This version of this MIB module is part of RFC xxxx; see the RFC itself for full legal notices.
Main OID:
cabhSecMib.1.3.6.1.4.1.3727.20.20.3.1.1
73
Objects
Active
Status
8
Dependencies
Imported Objects
Objects
73 total| Object Name |
|---|
cabhSecMibThis MIB module supplies the basic management
objects for the Security Portal Services.
Copyright (C) The Internet Society (2003). This version
of this MIB module is part of RFC xxxx; see the RFC
itself
for full legal notices. MODULE-IDENTITY .1.3.6.1.4.1.3727.20.20.3.1.1 |
cabhSecMibObjects OBJECT IDENTIFIER .1.3.6.1.4.1.3727.20.20.3.1.1.1 |
cabhSecFwObjects OBJECT IDENTIFIER .1.3.6.1.4.1.3727.20.20.3.1.1.1.1 |
cabhSecFwBase OBJECT IDENTIFIER .1.3.6.1.4.1.3727.20.20.3.1.1.1.1.1 |
cabhSecFwPolicyFileEnableThis parameter indicates whether or not to enable the
firewall functionality.rw Enumeration .1.3.6.1.4.1.3727.20.20.3.1.1.1.1.1.1 |
cabhSecFwPolicyFileURLContains the location of the last successfull downloaded
policy rule set file in the format pointed in the
reference. A policy rule set file download is triggered
when the value used to SET this MIB is different than the
value in the cabhSecFwPolicySuccessfulFileURL object.rw SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.4.1.3727.20.20.3.1.1.1.1.1.2 |
cabhSecFwPolicyFileHashHash of the contents of the rules set file, calculated
and sent to the PS prior to sending the rules set file.
For the SHA-1 authentication algorithm the length of the
hash is 160 bits. This hash value is encoded in binary
format.rw OCTET STRING .1.3.6.1.4.1.3727.20.20.3.1.1.1.1.1.3 |
cabhSecFwPolicyFileOperStatusinProgress(1) indicates a firewall configuration file
download is underway.
complete (2) indicates the firewall configuration file
downloaded and configured successfully.
completeFromMgt(3) This state is deprecated.
failed(4) indicates the last attempted firewall
configuration file download or processing failed
ordinarily due to TFTP timeout.ro Enumeration .1.3.6.1.4.1.3727.20.20.3.1.1.1.1.1.4 |
cabhSecFwPolicyFileCurrentVersionThe rule set version currently operating in the PS
device. This object should be in the syntax used by the
individual vendor to identify software versions. Any PS
element MUST return a string descriptive of the current
rule set file load. If this is not applicable, this
object MUST contain an empty string.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.4.1.3727.20.20.3.1.1.1.1.1.5 |
cabhSecFwPolicySuccessfulFileURLContains the location of the last successfull downloaded
policy rule set file in the format pointed in the
reference. If a successful download has not yet occurred,
this MIB object should report empty string.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.4.1.3727.20.20.3.1.1.1.1.1.6 |
cabhSecFwLogCtl OBJECT IDENTIFIER .1.3.6.1.4.1.3727.20.20.3.1.1.1.1.2 |
cabhSecFwEventType1EnableThis object enables or disables logging of type 1
firewall event messages. Type 1 event messages report
attempts from both private and public clients to traverse
the firewall that violate the Security Policy.rw Enumeration .1.3.6.1.4.1.3727.20.20.3.1.1.1.1.2.1 |
cabhSecFwEventType2EnableThis object enables or disables logging of type 2
firewall event messages. Type 2 event messages report
identified Denial of Service attack attempts.rw Enumeration .1.3.6.1.4.1.3727.20.20.3.1.1.1.1.2.2 |
cabhSecFwEventType3EnableEnables or disables logging of type 3 firewall event
messages.
Type 3 event messages report changes made to the
following firewall management parameters:
cabhSecFwPolicyFileURL,
cabhSecFwPolicyFileCurrentVersion,
cabhSecFwPolicyFileEnablerw Enumeration .1.3.6.1.4.1.3727.20.20.3.1.1.1.1.2.3 |
cabhSecFwEventAttackAlertThresholdIf the number of type 1 or 2 hacker attacks exceeds
this threshold in the period define by
cabhSecFwEventAttackAlertPeriod, a firewall message
event MUST be logged with priority level 4.rw INTEGER .1.3.6.1.4.1.3727.20.20.3.1.1.1.1.2.4 |
cabhSecFwEventAttackAlertPeriodIndicates the period to be used (in hours) for the
cabhSecFwEventAttackAlertThreshold. This MIB variable
should always keep track of the last x hours of events
meaning that if the variable is set to track events for
10 hours then when the 11th hour is reached, the 1st hour
of events is deleted from the tracking log. A default
value is set to zero, meaning zero time, so that this MIB
variable will not track any events unless configured.rw INTEGER .1.3.6.1.4.1.3727.20.20.3.1.1.1.1.2.5 |
cabhSecCertObjects OBJECT IDENTIFIER .1.3.6.1.4.1.3727.20.20.3.1.1.1.2 |
cabhSecCertPsCertThe X509 DER-encoded PS certificate.ro DocsX509ASN1DEREncodedCertificate (DOCS-IETF-BPI2-MIB) .1.3.6.1.4.1.3727.20.20.3.1.1.1.2.1 |
cabhSecKerbObjects OBJECT IDENTIFIER .1.3.6.1.4.1.3727.20.20.3.1.1.1.3 |
cabhSecKerbBase OBJECT IDENTIFIER .1.3.6.1.4.1.3727.20.20.3.1.1.1.3.1 |
cabhSecKerbPKINITGracePeriodThe PKINIT Grace Period is needed by the PS to know when
it should start retrying to get a new ticket. The PS MUST
obtain a new Kerberos ticket (with a PKINIT exchange);
this may be many minutes before the old ticket expires.rw Unsigned32 .1.3.6.1.4.1.3727.20.20.3.1.1.1.3.1.1 |
cabhSecKerbTGSGracePeriodThe TGS Grace Period is needed by the PS to know when it
should start retrying to get a new ticket. The PS MUST
obtain a new Kerberos ticket (with a TGS Request); this
may be many minutes before the old ticket expires.rw Unsigned32 .1.3.6.1.4.1.3727.20.20.3.1.1.1.3.1.2 |
cabhSecKerbUnsolicitedKeyMaxTimeoutThis timeout applies to PS initiated AP-REQ/REP key
management exchange with NMS. The maximum timeout is the
value which may not be exceeded in the exponential
backoff algorithm.rw Unsigned32 .1.3.6.1.4.1.3727.20.20.3.1.1.1.3.1.3 |
cabhSecKerbUnsolicitedKeyMaxRetriesThe number of retries the PS is allowed for AP-REQ/REP
key management exchange initiation with the NMS. This is
the maximum number of retries before the PS gives up
attempting to establish an SNMPv3 security association
with NMS.rw Unsigned32 .1.3.6.1.4.1.3727.20.20.3.1.1.1.3.1.4 |
cabhSec2FwObjects OBJECT IDENTIFIER .1.3.6.1.4.1.3727.20.20.3.1.1.1.4 |
cabhSec2FwBase OBJECT IDENTIFIER .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.1 |
cabhSec2FwEnableThis parameter indicates whether to enable or disable
the firewall.rw Enumeration .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.1.1 |
cabhSec2FwPolicyFileURLContains the location of the last successfull downloaded
policy rule set file in the format pointed in the
reference. A policy rule set file download is triggered
when the value used to SET this MIB is different than the
value in the cabhSec2FwPolicySuccessfulFileURL object.rw SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.1.2 |
cabhSec2FwPolicyFileHashHash of the contents of the firewall configuration file.
For the SHA-1 authentication algorithm the length of the
hash is 160 bits. This hash value is encoded in binary
format.rw OCTET STRING .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.1.3 |
cabhSec2FwPolicyFileOperStatusInProgress(1) indicates a firewall configuration file
download is underway. Complete(2) indicates the firewall
configuration file was downloaded and processed
successfully. Failed(3) indicates that the last attempted
firewall configuration file download or processing
failed.ro Enumeration .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.1.4 |
cabhSec2FwPolicyFileCurrentVersionA label set by the cable operator that can be used to
track various versions of configured rulesets. Once the
label is set it and configured rules are changed, it may
not accurately reflect the version of configured rules
running on the box.
This object MUST contain the string 'null' if has never
been configured.rw SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.1.5 |
cabhSec2FwClearPreviousRulesetAllows PS or firewall configuration files to contain
either a complete firewall configured ruleset or an
incremental to the already established configured ruleset
depending up on its existence in the configuration file.
If the PS receives a configuration file with firewall
settings which includes a cabhSec2FwClearPreviousRuleset
object setting marked as increment(1) or if this object
setting is not included in a configuration file which
contains filter settings for the firewall, then the PS
MUST treat the firewall filter settings in the
configuration file as an increment to the configured
ruleset. If the PS receives a configuration file with
firewall settings which includes a
cabhSec2FwClearPreviousRuleset object setting marked as
incrementDefault(3) then the PS MUST remove all
previously configured rules from the configured ruleset,
including any rules in the filter schedule table and
increment the newly downloaded rules on top of (i.e.
subsequent to) the factory default policy. If the PS
receives a configuration file with firewall settings
which includes a cabhSec2FwClearPreviousRuleset object
setting marked as complete(2), then the PS MUST remove
all previously configured rules from the configured
ruleset, including any rules in
cabhSec2FwFilterScheduleTable table before applying
the firewall filter settings contained in the
configuration file.
If cabhSec2FwClearPreviousRuleset is set to increment(1)
using SNMP, the PS MUST treat all of the following
firewall filter settings using SNMP as an increment to
the configured ruleset.
If cabhSec2FwClearPreviousRuleset is set to
incrementDefault(3) using SNMP, the PS MUST remove all
previously configured rules from the configured ruleset,
including any rules in the filter schedule table and
treat all of the following firewall filter settings using
SNMP as an increment on top of the factory default
policy. If cabhSec2FwClearPreviousRuleset is set to
complete(2), then the PS MUST remove all rules from the
configured ruleset, including any rules in the filter
schedule table. In this scenario the PS will operate
without any configured rules, (e.g. there will be no
defined filtering rules, but the firewall will still
provide the minimum set of capabilities and
architecture).rw Enumeration .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.1.6 |
cabhSec2FwPolicySelectionThis parameter indicates which policy should currently
be running in the firewall, either the factoryDefault
policy or the configuredRuleset.rw Enumeration .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.1.7 |
cabhSec2FwEventSetToFactoryIf set to 'true', entries in cabhSec2FwEventControlEntry
are set to their default values. Reading this value
always returns false.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.1.8 |
cabhSec2FwEventLastSetToFactoryThe value of sysUpTime when cabhSec2FwEventSetToFactory
was last set to true. Zero if never reset.ro TimeStamp (SNMPv2-TC) .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.1.9 |
cabhSec2FwPolicySuccessfulFileURLContains the location of the last successfull downloaded
policy rule set file in the format pointed in the
reference. If a successful download has not yet occurred,
this MIB object should report empty string.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.1.10 |
cabhSec2FwEvent OBJECT IDENTIFIER .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.2 |
cabhSec2FwEventControlTableThis table controls the reporting of the Firewall
Attacks events SEQUENCE OF CabhSec2FwEventControlEntry .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.2.1 |
cabhSec2FwEventControlEntryAllows configuration of the reporting mechanisms for a
particular type of attack. CabhSec2FwEventControlEntry .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.2.1.1 |
cabhSec2FwEventTypeClassification of the different types of attacks.
Type 1 logs all attempts from both LAN and WAN clients to
traverse the Firewall that violate the Security Policy.
Type 2 logs identified Denial of Service attack attempts.
Type 3 logs all changes made to the cabhSec2FwPolicyFileURL,
cabhSec2FwPolicyFileCurrentVersion or
cabhSec2FwPolicyFileEnable objects.
Type 4 logs all failed attempts to modify
cabhSec2FwPolicyFileURL and cabhSec2FwPolicyFileEnable
objects. Type 5 logs allowed inbound packets from the WAN.
Type 6 logs allowed outbound packets from the LAN. Enumeration .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.2.1.1.1 |
cabhSec2FwEventEnableEnables or disables counting and logging of firewall
events by type as assigned by cabhSec2FwEventType.rw Enumeration .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.2.1.1.2 |
cabhSec2FwEventThresholdNumber of attacks to count before sending the
appropriate event by type as assigned by
cabhSec2FwEventType.rw Unsigned32 .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.2.1.1.3 |
cabhSec2FwEventIntervalIndicates the time interval in hours to count and log
occurrences of a firewall event type as assigned in
cabhSec2FwEventType. If this MIB has a value of zero then
there is no interval assigned and the PS will not count
or log events.rw Unsigned32 .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.2.1.1.4 |
cabhSec2FwEventCountIndicates the current count up to the
cabhSec2FwEventThreshold value by type as assigned by
cabhSec2FwEventType.ro ZeroBasedCounter32 (RMON2-MIB) .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.2.1.1.5 |
cabhSec2FwEventLogResetSetting this object to true clears the log table for the
specified event type. Reading this object always returns
false.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.2.1.1.6 |
cabhSec2FwEventLogLastResetThe value of sysUpTime when cabhSec2FwEventLogReset was
last set to true. Zero if never reset.ro TimeStamp (SNMPv2-TC) .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.2.1.1.7 |
cabhSec2FwLog OBJECT IDENTIFIER .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.3 |
cabhSec2FwLogTableContains a log of packet information as related to
events enabled by the cable operator. The types are
defined in the CableHome 1.1 specification and require
various objects to be included in the log.
The following is a description for what is expected in
the log for each type Type 1, Type 2, Type 5 and Type 6
table MUST include cabhSec2FwEventType,
cabhSec2FwEventPriority, cabhSec2FwEventId,
cabhSec2FwLogTime, cabhSec2FwIpProtocol,
cabhSec2FwIpSourceAddr, cabhSec2FwIpDestAddr,
cabhSec2FwIpSourcePort, cabhSec2FwIpDestPort,
cabhSec2Fw, cabhSec2FwReplayCount. The other values not
used by types 1, 2, 5 and 6 are default values. Type 3
and Type 4 MUST include cabhSec2FwEventType,
cabhSec2FwEventPriority,
cabhSec2FwEventId, cabhSec2FwLogTime,
cabhSec2FwIpSourceAddr, cabhSec2FwLogMIBPointer.
The other values not used by type 3 and 4 are default
values. SEQUENCE OF CabhSec2FwLogEntry .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.3.1 |
cabhSec2FwLogEntryEach entry contains the log of firewall events CabhSec2FwLogEntry .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.3.1.1 |
cabhSec2FwLogIndexA sequence number for the specific events under a
cabhSec2FwEventType. Unsigned32 .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.3.1.1.1 |
cabhSec2FwLogEventTypeClassification of the different types of attacks.
Type 1 logs all attempts from both LAN and WAN clients to
traverse the Firewall that violate the Security Policy.
Type 2 logs identified Denial of Service attack attempts.
Type 3 logs all changes made to the
cabhSec2FwPolicyFileURL,
cabhSec2FwPolicyFileCurrentVersion or
cabhSec2FwPolicyFileEnable objects.
Type 4 logs all failed attempts to modify
cabhSec2FwPolicyFileURL and cabhSec2FwPolicyFileEnable
objects.
Type 5 logs allowed inbound packets from the WAN.
Type 6 logs allowed outbound packets from the LAN.ro Enumeration .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.3.1.1.2 |
cabhSec2FwLogEventPriorityThe priority level of this event as defined by CableHome
Specification. If a priority is not assigned in the
CableHome specification for a particular event then the
vendor or cable operator may assign priorities. These are
ordered from most serious (emergency) to least serious
(debug).ro Enumeration .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.3.1.1.3 |
cabhSec2FwLogEventIdThe assigned event ID.ro Unsigned32 .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.3.1.1.4 |
cabhSec2FwLogTimeThe time that this entry was created by the PS.ro DateAndTime (SNMPv2-TC) .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.3.1.1.5 |
cabhSec2FwLogIpProtocolThe IP Protocolro Unsigned32 .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.3.1.1.6 |
cabhSec2FwLogIpAddrTypeThe type of IP addresses in the packetro InetAddressType (INET-ADDRESS-MIB) .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.3.1.1.7 |
cabhSec2FwLogIpSourceAddrThe Source IP Address of the packet logged.
The address type of this object is specified by
cabhSec2FwLogIpAddrType.ro InetAddress (INET-ADDRESS-MIB) .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.3.1.1.8 |
cabhSec2FwLogIpDestAddrThe Destination IP Address of the packet logged.
The address type of this object is specified by
cabhSec2FwLogIpAddrType.ro InetAddress (INET-ADDRESS-MIB) .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.3.1.1.9 |
cabhSec2FwLogIpSourcePortThe Source IP Port of the packet loggedro InetPortNumber (INET-ADDRESS-MIB) .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.3.1.1.10 |
cabhSec2FwLogIpDestPortThe Source IP Port of the packet loggedro InetPortNumber (INET-ADDRESS-MIB) .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.3.1.1.11 |
cabhSec2FwLogMessageTypeThe ICMP defined types.ro Unsigned32 .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.3.1.1.12 |
cabhSec2FwLogReplayCountThe number of identical attack packets that were seen by
the firewall based on cabhSec2FwLogIpProtocol,
cabhSec2FwLogIpSourceAddr, cabhSec2FwLogIpDestAddr,
cabhSec2FwLogIpSourcePort, cabhSec2FwLogIpDestPort and
cabhSec2FwLogMessageTypero Unsigned32 .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.3.1.1.13 |
cabhSec2FwLogMIBPointerIdentifies if the cabhSec2FwPolicyFileURL or the
cabhSec2FwEnable MIB object changed or an attempt was
made to change it.ro VariablePointer (SNMPv2-TC) .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.3.1.1.14 |
cabhSec2FwFilter OBJECT IDENTIFIER .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.4 |
cabhSec2FwFilterScheduleTableExtends the filtering matching parameters of
docsDevFilterIpTable defined in RFC 2669 for CableHome
Residential Gateways to include time day intervals and
days of the week. SEQUENCE OF CabhSec2FwFilterScheduleEntry .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.4.1 |
cabhSec2FwFilterScheduleEntryExtended values for entries of docsDevFilterIpTable.
If the PS has not acquired ToD the entire
docsDevFilterIpEntry rule set is ignored. CabhSec2FwFilterScheduleEntry .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.4.1.1 |
cabhSec2FwFilterScheduleStartTimeThe start time, with optional time zone, for a firewall
filter ruleset. Only the time portion of the DateAndTime
TEXTUAL-CONVENTION have a meaning.rw DateAndTime (SNMPv2-TC) .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.4.1.1.1 |
cabhSec2FwFilterScheduleEndTimeThe end time, with optional time zone, for a firewall
filter ruleset. Only the time portion of the DateAndTime
TEXTUAL-CONVENTION have a meaning.rw DateAndTime (SNMPv2-TC) .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.4.1.1.2 |
cabhSec2FwFilterScheduleDOWIf the day of week bit associated with the PS given day
is '1', this object criteria matches.rw Bits .1.3.6.1.4.1.3727.20.20.3.1.1.1.4.4.1.1.3 |
cabhSecNotification OBJECT IDENTIFIER .1.3.6.1.4.1.3727.20.20.3.1.1.2 |
cabhSecConformance OBJECT IDENTIFIER .1.3.6.1.4.1.3727.20.20.3.1.1.3 |
cabhSecCompliances OBJECT IDENTIFIER .1.3.6.1.4.1.3727.20.20.3.1.1.3.1 |
cabhSecGroups OBJECT IDENTIFIER .1.3.6.1.4.1.3727.20.20.3.1.1.3.2 |