Home/Catalog/CISCO-AUTH-FRAMEWORK-MIB

CISCO-AUTH-FRAMEWORK-MIB

AI MIB Summary

The CISCO-AUTH-FRAMEWORK-MIB monitors and configures AAA authentication methods and their failover sequences on Cisco IOS and IOS-XE platforms. It exposes metrics for authentication method lists, server group states, and the operational status of fallback mechanisms to ensure continuous access control availability.

MIB module for Authentication Framework in the system. Authentication Framework provides generic configurations for authentication methods in the system and manage the failover sequence of these methods in a flexible manner.
Main OID:
ciscoAuthFrameworkMIB.1.3.6.1.4.1.9.9.656
90
Objects
Active
Status
9
Dependencies

Imported Objects

Objects

90 total
Object Name
ciscoAuthFrameworkMIBMIB module for Authentication Framework in the system. Authentication Framework provides generic configurations for authentication methods in the system and manage the failover sequence of these methods in a flexible manner.
MODULE-IDENTITY
.1.3.6.1.4.1.9.9.656
ciscoAuthFrameworkMIBNotifs
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.656.0
cafSecurityViolationNotifA cafSecurityViolationNotif is sent if a security violation is detected on a port, and the instance value of cafSecurityViolationNotifEnable is 'true'.
NOTIFICATION-TYPE
.1.3.6.1.4.1.9.9.656.0.1
cafAuthFailNotifA cafAuthFailNotif is sent if an authentication failure is detected on a port, and the instance value of cafAuthFailNotifEnable is 'true'. ifName contains the name of the interface where the authentication failure happened. cafAuthFailClient contains the mac address of the client which failed to authenticate.
NOTIFICATION-TYPE
.1.3.6.1.4.1.9.9.656.0.2
ciscoAuthFrameworkMIBObjects
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.656.1
ciscoAuthFrameworkSystem
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.656.1.1
cafAaaNoRespRecoveryDelaySpecifies the AAA recovery delay for authentication methods registered in Authentication Framework when AAA server becomes active again after being inactive. A value of zero indicates that AAA recovery delay is disabled in the system.rw
Unsigned32 UNITS "milliseconds"
.1.3.6.1.4.1.9.9.656.1.1.1
cafAuthMethodRegTableA list of authentication methods which are currrently registered with Authentication Framework. An entry is created by the agent when an authentication method has successfully registered with Authentication Framework. An entry is deleted by the agent upon de-registration of the authentication method.
SEQUENCE OF CafAuthMethodRegEntry
.1.3.6.1.4.1.9.9.656.1.1.2
cafAuthMethodRegEntryAn entry containing registration information of a particular authentication method with Authentication Framework.
CafAuthMethodRegEntry
.1.3.6.1.4.1.9.9.656.1.1.2.1
cafAuthMethodThe authentication method registered with Authentication Framework.
CiscoAuthMethod
.1.3.6.1.4.1.9.9.656.1.1.2.1.1
cafAuthMethodDefaultPriorityA unique number which indicates the default priority of a authentication method. The default priority is assigned by Authentication Framework during method registration. The method with smallest value has highest priority.ro
Unsigned32
.1.3.6.1.4.1.9.9.656.1.1.2.1.2
cafAuthMethodDefaultExecOrderA unique number which indicates the default execution order of a authentication method. The default execution order is assigned by Authentication Framework during method registration. The method with smallest value will be execute first.ro
Unsigned32
.1.3.6.1.4.1.9.9.656.1.1.2.1.3
cafMacMoveModeThis object specifies the MAC Move configuration for Authentication Framework. deny : When a host is authenticated on one port, that address is not allowed on another authenticated manager-enabled port of the device. permit: Authenticated hosts are allowed to move from one port to another on the same device. When a host moves to a new port, the authenticated session on the original port is deleted, and the host is reauthenticated on the new port.rw
Enumeration
.1.3.6.1.4.1.9.9.656.1.1.3
cafCoABouncePortCommandIgnoreEnabledThis object specifies whether the device ignores the bounce port command that sent from RADIUS via Change-of-Authorization (CoA) packets.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.9.9.656.1.1.4
cafCoADisablePortCommandIgnoreEnabledThis object specifies whether the device ingores the disable port command that sent from RADIUS via Change-of-Authorization (CoA) packets.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.9.9.656.1.1.5
ciscoAuthFrwkAuthenticator
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.656.1.2
cafPortConfigTableA list of port entries. An entry will exist for each interface which support Authentication Framework feature.
SEQUENCE OF CafPortConfigEntry
.1.3.6.1.4.1.9.9.656.1.2.1
cafPortConfigEntryAn entry containing management information of Authentication Framework applicable to a particular port.
CafPortConfigEntry
.1.3.6.1.4.1.9.9.656.1.2.1.1
cafPortControlledDirectionSpecifies the controlled direction of this port.rw
CiscoAuthControlledDirections
.1.3.6.1.4.1.9.9.656.1.2.1.1.1
cafPortFallBackProfileSpecifies the name of the fallback profile to be used when failing over to Web Proxy Authentication. A zero length string indicates that fallback mechanism to Web Proxy Authentication is disabled in Authentication Framework.rw
SnmpAdminString (SNMP-FRAMEWORK-MIB)
.1.3.6.1.4.1.9.9.656.1.2.1.1.2
cafPortAuthHostModeSpecifies the authentication host mode for this port.rw
CiscoAuthHostMode
.1.3.6.1.4.1.9.9.656.1.2.1.1.3
cafPortPreAuthOpenAccessSpecifies if the Pre-Authentication Open Access feature allows clients/devices to gain network access before authentication is performed. A value of 'true' for this object indicates that client/device is able to gain network access before authentication is performed.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.9.9.656.1.2.1.1.4
cafPortAuthorizeControlSpecifies the authorization control for this port.rw
CiscoAuthControlledPortControl
.1.3.6.1.4.1.9.9.656.1.2.1.1.5
cafPortReauthEnabledSpecifies if reauthentication is enabled for this port.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.9.9.656.1.2.1.1.6
cafPortReauthIntervalSpecifies the reauthentication interval, after which the port will be reauthenticated if value of the corresponding instance of cafPortReauthEnabled is 'true'. A value of zero indicates that the reauthentication interval is downloaded from AAA server when this port is authenticated.rw
Unsigned32 UNITS "seconds"
.1.3.6.1.4.1.9.9.656.1.2.1.1.7
cafPortRestartIntervalSpecifies the interval after which a further authentication attempt should be made to this port if it is not authorized. A value of zero indicates that no further authentication attempt will be made if this port is unauthorized.rw
Unsigned32 UNITS "seconds"
.1.3.6.1.4.1.9.9.656.1.2.1.1.8
cafPortInactivityTimeoutSpecifies the period of time that a client associating with this port is allowed to be inactive before being terminated. A value of zero indicates that inactivity timeout is disabled on this port. A value of -1 indicates that inactivity timeout is downloaded from the AAA server when this port is authenticated.rw
Integer32 (-1 | 0 | 1..65535) UNITS "seconds"
.1.3.6.1.4.1.9.9.656.1.2.1.1.9
cafPortViolationActionSpecifies the action to be taken due to a security violation occurs on this port. restrict: This port will be moved to restricted state. shutdown: This port will be shutdown from Authentication Framework perspective. protect : This port will be moved to protected state. replace : The current authentication session on this port will be terminated and replaced by a new authentication session, upon the detection of security violation on the current authentication session on the port.rw
Enumeration
.1.3.6.1.4.1.9.9.656.1.2.1.1.10
cafPortMethodTableThe table contains a list of port entries. An entry will exist for each port which supports Authentication Framework feature.
SEQUENCE OF CafPortMethodEntry
.1.3.6.1.4.1.9.9.656.1.2.2
cafPortMethodEntryEntry containing configuration and information of authentication methods for a particular port.
CafPortMethodEntry
.1.3.6.1.4.1.9.9.656.1.2.2.1
cafPortMethodAdminExecOrderThis object specifies the administrative execution order of authentication methods on the port. Methods are executed in the order as specified in the method list. Method which is at the beginning of the method list will be executed first. Method which is at the end of method list will be executed last. A zero length string of this object indicates that no per port execution order configuration has been specified on this port. The actual execution order is based on the value of cafAuthMethodDefaultExecOrder in cafAuthMethodRegTable.rw
CiscoAuthMethodList
.1.3.6.1.4.1.9.9.656.1.2.2.1.1
cafPortMethodAdminPriorityThis object specifies the administrative priority of authentication methods on the port. The priority of each method is assigned based on the method list. Method which is at the beginning of the method list has highest priority. Method which is at the end of method list has lowest priority. A zero length string of this object indicates that no per port method priority configuration has been specified on this port. The actual execution order is based on the value of cafAuthMethodDefaultExecOrder in cafAuthMethodRegTable.rw
CiscoAuthMethodList
.1.3.6.1.4.1.9.9.656.1.2.2.1.2
cafPortMethodAvailableThis object indicates the authentication methods currently available on this port.ro
CiscoAuthMethodList
.1.3.6.1.4.1.9.9.656.1.2.2.1.3
cafPortMethodOperExecOrderThis object indicates the operational execution order of authentication methods on this port. Methods are executed in the order as specified in the method list. Method which is at the beginning of the method list will be executed first. Method which is at the end of method list will be executed last.ro
CiscoAuthMethodList
.1.3.6.1.4.1.9.9.656.1.2.2.1.4
cafPortMethodOperPriorityThis object indicates the operational priority of authentication methods on this port. Methods have the priority as specified in the method list. Method which is at the beginning of the method list has highest priority. Method which is at the end of method list has lowest priority.ro
CiscoAuthMethodList
.1.3.6.1.4.1.9.9.656.1.2.2.1.5
ciscoAuthFrameworkEvent
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.656.1.3
cafAuthFailedEventPortTableThe table contains a list of port entries. An entry will exist for each port which supports Authentication Fail event within the Authentication Framework.
SEQUENCE OF CafAuthFailedEventPortEntry
.1.3.6.1.4.1.9.9.656.1.3.1
cafAuthFailedEventPortEntryEntry containing management information of Authentication Fail event for a particular port.
CafAuthFailedEventPortEntry
.1.3.6.1.4.1.9.9.656.1.3.1.1
cafAuthFailedMaxRetryThis object specifies the maximum number of retry should be performed before generating Authentication Fail event. A value of zero indicates that Authentication Fail event will be generated upon authentication fail without any retry.rw
Unsigned32
.1.3.6.1.4.1.9.9.656.1.3.1.1.1
cafAuthFailedNoActionEnabledThis object specifies whether no action will be performed when an Authentication Fail event occurs. Setting 'true' on this object indicates that no action will be performed when Authentication Fail event occurs. The read-only value 'false' indicates that an action will be performed when an Authentication Fail event occurs.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.9.9.656.1.3.1.1.2
cafAuthFailedAuthorizedVlanThis object specifies the Authentication Failed VLAN number. The read-only value of -1 indicates that this object is not applicable on this port. The read-only value of zero indicates that this port will not be authorized to any VLAN when Authentication Failed event occurs. Setting a non-zero value on this object indicates that this port will be authorized to the VLAN as specified by this object value, when Authentication Fail event occurs.rw
Integer32 (-1 | 0 | 1..2147483647)
.1.3.6.1.4.1.9.9.656.1.3.1.1.3
cafAuthFailedNextMethodEnabledThis object specifies whether the next authentication method will be used if an Authentication Fail event is generated by the current authentication method. Setting this object to 'true' indicates that the next available authentication method will be used when Authentication Fail event occurs. The read-only value 'false' indicates that the next available authentication method will not be used when Authentication Fail event occurs.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.9.9.656.1.3.1.1.4
cafClientNoRespEventPortTableThe table contains a list of port entries. An entry exists for each port which supports No Response event within the Authentication Framework.
SEQUENCE OF CafClientNoRespEventPortEntry
.1.3.6.1.4.1.9.9.656.1.3.2
cafClientNoRespEventPortEntryEntry containing management information of No Response event for a particular port.
CafClientNoRespEventPortEntry
.1.3.6.1.4.1.9.9.656.1.3.2.1
cafClientNoRespNoActionEnabledThis object specifies whether an action is performed when No Response event occurs. Setting 'true' on this object indicates that no action will be performed when No Response event occurs. The read-only value 'false' of this object indicates that an action will be performed when No Response event occurs.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.9.9.656.1.3.2.1.1
cafClientNoRespAuthorizedVlanThis object specifies the No Response Authorized VLAN number. The read-only value of -1 indicates that this object is not applicable on this port. The read-only value of zero indicates that this port will not be authorized to any VLAN when No Response event occurs. Setting a non-zero value on this object indicates that this port will be authorized to the VLAN as specified by this object value, when No Response event occurs.rw
Integer32 (-1 | 0 | 1..2147483647)
.1.3.6.1.4.1.9.9.656.1.3.2.1.2
cafServerEventPortTableThe table contains a list of port entries. An entry exists for each port which supports AAA Server Reachability event within the Authentication Framework.
SEQUENCE OF CafServerEventPortEntry
.1.3.6.1.4.1.9.9.656.1.3.3
cafServerEventPortEntryEntry containing management information of AAA Server Reachability event for a particular port.
CafServerEventPortEntry
.1.3.6.1.4.1.9.9.656.1.3.3.1
cafServerDeadNoActionEnabledThis object indicates whether an action is performed if an AAA Server Reachability event occurs. Setting 'true' on this object indicates that no action will be performed when AAA Server Reachability event occurs. The read-only value 'false' indicates that an action will be performed when AAA Server Reachability event occurs.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.9.9.656.1.3.3.1.1
cafServerDeadRemainAuthorizedThis object specifies if current authorization will remain unchanged for the port when AAA Server Reachability event occurs. Setting 'true' on this object indicates that current authorization will remain unchanged for the port when AAA Server Reachability event occurs. The read-only value 'false' indicates that the current authorization will not be retained for the port when AAA Server Reachability event occurs.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.9.9.656.1.3.3.1.2
cafServerDeadAuthorizedVlanThis object specifies the AAA Server Reachability Authorized VLAN number. The read-only value of -1 indicates that this object is not applicable on this port. The read-only value of zero indicates that this port will not be authorized to any VLAN when AAA Server Reachability event occurs. Setting a non-zero value on this object indicates that this port will be authorized to the VLAN as specified by this object value, when AAA Server Reachability event occurs.rw
Integer32 (-1 | 0 | 1..2147483647)
.1.3.6.1.4.1.9.9.656.1.3.3.1.3
cafServerAliveActionThis object specifies the action applied to the port upon AAA recovery. none : no action will be applied. reinitialize: the port will be reinitialized with the current authentication method.rw
Enumeration
.1.3.6.1.4.1.9.9.656.1.3.3.1.4
ciscoAuthFrameworkSession
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.656.1.4
cafSessionTableThe table contains a list of authentication session. An entry is created when an authentication session has successfully created within Authentication Framework. An entry is deleted when an authentication session has been removed.
SEQUENCE OF CafSessionEntry
.1.3.6.1.4.1.9.9.656.1.4.1
cafSessionEntryEntry containing management information for a particular authentication session.
CafSessionEntry
.1.3.6.1.4.1.9.9.656.1.4.1.1
cafSessionIdA unique identifier of the authentication session.
OCTET STRING
.1.3.6.1.4.1.9.9.656.1.4.1.1.1
cafSessionClientMacAddressIndicates the MAC address of the device associates with the authentication session.ro
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.9.9.656.1.4.1.1.2
cafSessionClientAddrTypeIndicates the type of Internet address of the client associates with the authentication session.ro
InetAddressType (INET-ADDRESS-MIB)
.1.3.6.1.4.1.9.9.656.1.4.1.1.3
cafSessionClientAddressIndicates the Internet address of the client associates with the authentication session. The type of this address is determined by the value of cafSessionClientAddrType object.ro
InetAddress (INET-ADDRESS-MIB)
.1.3.6.1.4.1.9.9.656.1.4.1.1.4
cafSessionStatusIndicates the current status of the authentication session. idle : the session has been initialized and no method has run yet. running : an authentication method is running for this session. noMethod : no authentication method has provided a result for this session. authenticationSuccess: an authentication method has resulted in authentication success for this session. authenticationFailed: an authentication method has resulted in authentication failed for this session. authorizationSuccess: authorization is successful for this session. authorizationFailed : authorization is failed for this session.ro
Enumeration
.1.3.6.1.4.1.9.9.656.1.4.1.1.5
cafSessionDomainIndicates the type of domain that the authentication session belongs to. other : none of the below. data : indicates the data domain. voice: indicates the voice domain.ro
Enumeration
.1.3.6.1.4.1.9.9.656.1.4.1.1.6
cafSessionAuthHostModeIndicates the authentication host mode of the port in the authentication session.ro
CiscoAuthHostMode
.1.3.6.1.4.1.9.9.656.1.4.1.1.7
cafSessionControlledDirectionIndicates the operational controlled directions parameter for this port in the authentication session.ro
CiscoAuthControlledDirections
.1.3.6.1.4.1.9.9.656.1.4.1.1.8
cafSessionPostureTokenIndicates the posture token associates with the authentication session.ro
CnnEouPostureTokenString (CISCO-NAC-TC-MIB)
.1.3.6.1.4.1.9.9.656.1.4.1.1.9
cafSessionAuthUserNameIndicates the name of the authenticated user for the authentication session.ro
SnmpAdminString (SNMP-FRAMEWORK-MIB)
.1.3.6.1.4.1.9.9.656.1.4.1.1.10
cafSessionClientFramedIpPoolIndicates the name of the address pool from which the session's client IP address is assigned.ro
SnmpAdminString (SNMP-FRAMEWORK-MIB)
.1.3.6.1.4.1.9.9.656.1.4.1.1.11
cafSessionAuthorizedByIndicates the name of the feature which authorizes the authentication session.ro
SnmpAdminString (SNMP-FRAMEWORK-MIB)
.1.3.6.1.4.1.9.9.656.1.4.1.1.12
cafSessionCriticalTimeLeftIndicates the leftover time before the next authentication attempt for the authentication session after Server Reachability event occurred. Value zero indicates that this session is currently being authenticated or it is not applicable.ro
Unsigned32 UNITS "seconds"
.1.3.6.1.4.1.9.9.656.1.4.1.1.13
cafSessionAuthVlanIndicates the authorized VLAN applied to the authentication session. Value zero indicates that no authorized VLAN has been applied, or it is not applicable.ro
VlanIndexOrZero
.1.3.6.1.4.1.9.9.656.1.4.1.1.14
cafSessionTimeoutIndicates the session timeout used by Authentication Framework in the authentication session.ro
Unsigned32 UNITS "seconds"
.1.3.6.1.4.1.9.9.656.1.4.1.1.15
cafSessionTimeLeftIndicates the leftover time of the current authentication session.ro
Unsigned32 UNITS "seconds"
.1.3.6.1.4.1.9.9.656.1.4.1.1.16
cafSessionTimeoutActionIndicates the timeout action on the authentication session, when value of the corresponding instance of cafSessionTimeLeft reaches zero. unknown : None of the below. terminate : Session will be terminated. reauthenticate: Session will be reauthenticated.ro
Enumeration
.1.3.6.1.4.1.9.9.656.1.4.1.1.17
cafSessionInactivityTimeoutIndicates the inactivity timeout used by Authentication Framework in the authentication session.ro
Unsigned32 UNITS "seconds"
.1.3.6.1.4.1.9.9.656.1.4.1.1.18
cafSessionInactivityTimeLeftIndicates the leftover time of the inactivity timer of the authentication session.ro
Unsigned32 UNITS "seconds"
.1.3.6.1.4.1.9.9.656.1.4.1.1.19
cafSessionReauthThe reauthentication control for the authentication session. Setting this object to 'true' cause the current authenticated session to reauthenticate the authenticated client. Setting this object to 'false' has no effect. This object always returns 'false' when being read.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.9.9.656.1.4.1.1.20
cafSessionTerminateThe termination request control for the authentication session. Setting this object to 'true' terminates the current session. Setting this object to 'false' has no effect. This object always returns 'false' when being read.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.9.9.656.1.4.1.1.21
cafSessionVlanGroupNameThe name of the VLAN group that has been used during VLAN assignment for this session. A zero length string indicates that there is no VLAN group been used during VLAN assignment.ro
SnmpAdminString (SNMP-FRAMEWORK-MIB)
.1.3.6.1.4.1.9.9.656.1.4.1.1.22
cafSessionMethodsInfoTableThe table contains a list of authentication method for every authentication session. An entry exists for each authentication method that can authenticate an authentication session within Authentication Framework.
SEQUENCE OF CafSessionMethodsInfoEntry
.1.3.6.1.4.1.9.9.656.1.4.2
cafSessionMethodsInfoEntryEntry containing method information for a particular runnable authentication methods which is associated with a session for an Authentication Framework managed port.
CafSessionMethodsInfoEntry
.1.3.6.1.4.1.9.9.656.1.4.2.1
cafSessionMethodIndicates this authentication method.
CiscoAuthMethod
.1.3.6.1.4.1.9.9.656.1.4.2.1.1
cafSessionMethodStateIndicates the state of this authentication method. notRun : The method has not run for this session. running : The method is running for this session. failedOver : The method has failed and the next method is expected to provide a result. authcSuccess: The method has provided a successful authentication result for this session. authcFailed : The method has provided a failed authentication result for this session.ro
Enumeration
.1.3.6.1.4.1.9.9.656.1.4.2.1.2
ciscoAuthFrwkNotifControl
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.656.1.5
cafSecurityViolationNotifEnableThis variable indicates whether the system produces the cafSecurityViolationNotif. A 'false' value will prevent cafSecurityViolationNotif from being generated by this system.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.9.9.656.1.5.1
cafAuthFailNotifEnableThis object specifies whether the system produces the cafAuthFailNotif. A 'true' value will cause cafAuthFailNotif to be generated by this system when an authentication failure happens. A 'false' value will prevent cafAuthFailNotif from being generated by this system.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.9.9.656.1.5.2
ciscoAuthFrwkNotifInfo
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.656.1.6
cafSecurityViolationClientThe MAC address included in the notification currently being sent, indicating the client who triggered the security violation notification.ro
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.9.9.656.1.6.1
cafAuthFailClientThe MAC address included in the cafAuthFailNotif being sent, indicating the client which failed to authenticate.ro
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.9.9.656.1.6.2
ciscoAuthFrameworkMIBConform
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.656.2
ciscoAuthFrameworkMIBCompliances
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.656.2.1
ciscoAuthFrameworkMIBGroups
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.656.2.2
CISCO-AUTH-FRAMEWORK-MIB - SNMP MIB Reference | MIBs Explorer