CISCO-CASA-FA-MIB
AI MIB Summary
The CISCO-CASA-FA-MIB provides SNMP management objects for Cisco CASA Forwarding Agents to monitor and configure packet flow affinity tables, specifically tracking Wildcard and Fixed Affinities, Interest Packet counters, and Tickle Packet events. This module enables the observation of how network hardware devices (such as switches or routers) offload traffic processing to Service Managers like load balancers or firewalls based on source/destination IP, port, and protocol fields.
This MIB module in conjunction with the CISCO-CASA-MIB, defines the SNMP management information base for managing the Cisco Appliance Services Architecture (CASA) Forwarding Agent.
The following is a set of definitions used in the rest of the MIB.
CASA is a protocol allowing software entities (called Appliances, examples are web caches, firewalls, load balancers) to control the behavior of network hardware devices (called Forwarding Agents, examples are switches or routers) by providing a set of rules used to handle network traffic.
A Network Appliance (referred to as an Appliance) is any subsystem whose purpose is to provide a specific additional value-added service to the network device, and could be implemented as a standalone box, a line card or processor card, or a software subsystem. Examples of Network Appliances would include Load Balancers, WebCaches, and Firewalls.
An Appliance tells Fowarding Agents how to handle packets based on their source and destination IP addresses and ports, and IP protocol fields. This set of information is called an Affinity.
A Service Manager is an Appliance that requests packet flows from Forwarding Agents through CASA.
A Real Server is a physical computing engine or part of that physical computing engine that offers one or more application services to a set of clients in the network.
A packet flow is a TCP connection or a sequence of UDP packets between a client and a specific Real Server, pertaining to a specific application. Flows are represented by entries in the affinity cache tables.
The Service Manager requests packet flows from Forwarding Agents by sending Affinities which contains wildcards on some of the Affinity fields. Affinities that contain wildcards in some of the fields are called Wildcard Affinities. The Service Manager may send the Forwarding Agent an Affinity containing explicit values for each of the fields. These Affinities are called Fixed Affinities.
Typically Wildcard Affinities are used to instruct the Forwarding Agent to send packets received by the Forwarding Agent, which match the Wildcard Affinity, to the Service Manager. When the Service Manager receives the matching packet, the Service Manager typically will send the Forwarding Agent a Fixed Affinity. The Forwarding Agent uses Fixed Affinities to match packets coming from the network, execute any processing required on that packet, and forward that packet to a destination IP address (designated in the Fixed Affinity) called the Dispatch Address.
When an IP packet arrives at the Forwarding Agent, the Forwarding Agent attempts to match the packet with the Fixed Affinities in the Fixed Affinity cache. If there is no match, an attempt is made to match the packet with the list of Wildcard Affinities. If there is no match the packet is routed normally. If there is a match with a Wildcard Affinity, the Forwarding Agent sends the packet to the Service Manager who will send the Forwarding Manager a Fixed Affinity which provides information on how to process IP packets similar to the one received by the Forwarding Agent. Processing of such packets may include sending the packet to the Service Manager. Such packets are called Interest Packets. Alternatively a Tickle Packet may be sent to the Service Manager which is an indication that a matched packet has been received by the Forwarding Agent.
Reference: [1] Cisco Appliance Services Architecture
(CASA) document.
[2] CISCO-CASA-MIB.
Diagram showing Forwarding Agents, Service Manager, Real Server and clients.
______ ______ ______ (Real ) (Real ) (Real ) (Server) (Server) (Server) (______) (______) (______) | | |
+---------------+ | | |
|Service Manager|-+----------+--------------+ |
+---------------+ | | | | |
++---------+ ++---------+ ++---------+
| F. Agent | | F. Agent | | F. Agent |
+----------+ +----------+ +----------+
| | | ___|_________________|______________|__ ( ) ( N E T W O R K ) (_______________________________________)
71
Objects
Active
Status
6
Dependencies
Imported Objects
Objects
71 total| Object Name |
|---|
ciscoCasaFaMIB OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.115 |
RFC1155-SMI Unknown .1.3.6.1.4.1.9.9.115 |
ciscoCasaFaMIBObjects OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.115.1 |
ccfaGlobal OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.115.1.1 |
ccfaStats OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.115.1.2 |
ccfaWildcardAff OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.115.1.3 |
ccfaWildcardAffTotalBytesNumber of bytes of data for all the packets
which matched any Wildcard Affinity.ro Counter -- Units -- bytes .1.3.6.1.4.1.9.9.115.1.3.1 |
ccfaWildcardAffHCTotalBytesNumber of bytes of data for all the packets which
matched any Wildcard Affinity. This object is a 64-bit
version of ccfaWildcardAffTotalBytes.ro --?? syntax is not convertable to SMIv1 Counter -- Units -- bytes .1.3.6.1.4.1.9.9.115.1.3.2 |
ccfaWildcardAffTotalPacketsNumber of packets that matched any Wildcard Affinity.ro Counter -- Units -- packets .1.3.6.1.4.1.9.9.115.1.3.3 |
ccfaWildcardAffNumOfThis is the number of Wildcard Affinities for which
this Forwarding Agent is actively using for handling
TCP and UDP packets. This is the number of entries in
ccfaWildcardAffTable.ro Gauge -- Units -- affinities .1.3.6.1.4.1.9.9.115.1.3.4 |
ccfaWildcardAffNotifEnabledtrue indicates that
ciscoCasaFaWildcardAffCreated and
ciscoCasaFaWildcardAffDeleted
notification generation is enabled.
false indicates that
ciscoCasaFaWildcardAffCreated and
ciscoCasaFaWildcardAffDeleted
notification generation is disabled.rw TruthValue -- Rsyntax INTEGER { -- true(1), -- false(2) -- } .1.3.6.1.4.1.9.9.115.1.3.5 |
ccfaWildcardAffTableList of Wildcard Affinity entries, which contain stats
on each Wildcard Affinity supported by the Forwarding
Agent.
This is a dynamic table. Entries are created when the
Service Manager sends Wildcard Affinities to this
Forwarding Agent, and deleted upon instruction from
the Service Manager. SEQUENCE OF CcfaWildcardAffEntry .1.3.6.1.4.1.9.9.115.1.3.6 |
ccfaWildcardAffEntryA list of Wildcard Affinity entities.
Entries are added to this table dynamically by the
subagent when Wildcard Affinities are received on the
multicast IP address (see cCasaMulticastAddress in the
CISCO-CASA-MIB) for which this Forwarding Agent is
listening. CcfaWildcardAffEntry .1.3.6.1.4.1.9.9.115.1.3.6.1 |
ccfaWildcardAffIndexThe value of this index uniquely identifies
this Wildcard Affinity from others in the table. CasaWildcardAffIndex -- Rsyntax OCTET STRING .1.3.6.1.4.1.9.9.115.1.3.6.1.1 |
ccfaWildcardAffSourceAddrThe value used to compare the source IP address
of the TCP and UDP packets. When the comparison is
done, ccfaWildcardAffSourceMask is used as the
mask on this object.ro IpAddress .1.3.6.1.4.1.9.9.115.1.3.6.1.2 |
ccfaWildcardAffDestinationAddrThe value used to compare the destination IP address
of the TCP and UDP packets. When the comparison is
done, ccfaWildcardAffDestinationMask is used as
the mask on this object.ro IpAddress .1.3.6.1.4.1.9.9.115.1.3.6.1.3 |
ccfaWildcardAffSourcePortThe value used to compare the source port of the TCP
and UDP packets. A value of 0 means all port numbers
will match.ro CiscoPort -- Rsyntax INTEGER .1.3.6.1.4.1.9.9.115.1.3.6.1.4 |
ccfaWildcardAffDestinationPortThe value used to compare the destination port of the
TCP and UDP packets. A value of 0 means all port
numbers will match.ro CiscoPort -- Rsyntax INTEGER .1.3.6.1.4.1.9.9.115.1.3.6.1.5 |
ccfaWildcardAffProtocolThe value used to compare the IP Protocol field of
the TCP and UDP packets. A value of 0 means all
protocol numbers will match.ro CiscoIpProtocol -- Rsyntax INTEGER .1.3.6.1.4.1.9.9.115.1.3.6.1.6 |
ccfaWildcardAffFragmentTrue indicates that fragments are to be sent to the
Service Manager,
false indicates that fragments are compared against
fields in this Wildcard Affinity for a possible
match in which case the fragment is sent to the
Service Manager.ro TruthValue -- Rsyntax INTEGER { -- true(1), -- false(2) -- } .1.3.6.1.4.1.9.9.115.1.3.6.1.7 |
ccfaWildcardAffSourceMaskThe IP mask indicating which bits in the
ccfaWildcardAffSourceAddr are relevant. For each
set bit in this mask, the corresponding bits in
ccfaWildcardAffSourceAddr and the source IP
address of the received packet must be equal in order
to match this Wildcard Affinity.ro IpAddress .1.3.6.1.4.1.9.9.115.1.3.6.1.8 |
ccfaWildcardAffDestinationMaskThe IP mask indicating which bits in the
ccfaWildcardAffDestinationAddr are relevant. For each
set bit in this mask, the corresponding bits in
ccfaWildcardAffDestinationAddr and the destination IP
address of the received packet must be equal in order
to match this Wildcard Affinity.ro IpAddress .1.3.6.1.4.1.9.9.115.1.3.6.1.9 |
ccfaWildcardAffSvcManagerAddrCASA Service Manager IP address to which packets
matching this Wildcard Affinity are forwarded.ro IpAddress .1.3.6.1.4.1.9.9.115.1.3.6.1.10 |
ccfaWildcardAffSvcManagerPortThe Service Manager port to which packets matching this
Wildcard Affinity are fowarded.ro CiscoPort -- Rsyntax INTEGER .1.3.6.1.4.1.9.9.115.1.3.6.1.11 |
ccfaWildcardAffBytesNumber of bytes in packets which matched this
Wildcard Affinity or any Fixed Affinity associated
with this Wildcard Affinity, that were forwarded to
the destination IP address.ro Counter -- Units -- bytes .1.3.6.1.4.1.9.9.115.1.3.6.1.12 |
ccfaWildcardAffHCBytesNumber of bytes in packets which matched this
Wildcard Affinity or any Fixed Affinity associated
with this Wildcard Affinity, that were forwarded to
the destination IP address. This object is a 64-bit
version of ccfaWildcardAffBytes.ro --?? syntax is not convertable to SMIv1 Counter -- Units -- bytes .1.3.6.1.4.1.9.9.115.1.3.6.1.13 |
ccfaWildcardAffPacketsNumber of packets which matched this Wildcard
Affinity or any Fixed Affinity associated with this
Wildcard Affinity, that were forwarded to the
destination IP address.ro Counter -- Units -- packets .1.3.6.1.4.1.9.9.115.1.3.6.1.14 |
ccfaWildcardAffHCPacketsNumber of packets which matched this Wildcard
Affinity or any Fixed Affinity associated with this
Wildcard Affinity, that were forwarded to the
destination IP address. This object is a 64-bit
version of ccfaWildcardAffPackets.ro --?? syntax is not convertable to SMIv1 Counter -- Units -- packets .1.3.6.1.4.1.9.9.115.1.3.6.1.15 |
ccfaWildcardAffFlowsFrom a logical point of view, this is the number of
TCP/UDP flows resulting from packets received which
matched this Wildcard Affinity.
A flow is a sequence of IP packets from a specific
client to a specific real server going through this
Forwarding Agent.
Literally this is the current number of Fixed Affinity
entries in the Fixed Affinity cache, that were put
there as a result of packets matching this Wildcard
Affinity.ro Gauge -- Units -- affinities .1.3.6.1.4.1.9.9.115.1.3.6.1.16 |
ccfaWildcardAffInsertTimeDate and time when this Wildcard Affinity was
inserted into this table.ro DateAndTime -- Rsyntax OCTET STRING .1.3.6.1.4.1.9.9.115.1.3.6.1.17 |
ccfaWildcardAffInterestTimeoutsNumber of expected Fixed Affinities that were not
received from the Service Manager within a period of
time from when a Fixed Affinity was requested by this
Forwarding Agent.ro Counter .1.3.6.1.4.1.9.9.115.1.3.6.1.18 |
ccfaWildcardAffAdvertiseDestAddrtrue indicates that the IP address defined by
ccfaWildcardAffDestinationAddr is to be
advertised by the routing protocol in this
Forwarding Agent.
false indicates that the IP address is not to be
advertised.ro TruthValue -- Rsyntax INTEGER { -- true(1), -- false(2) -- } .1.3.6.1.4.1.9.9.115.1.3.6.1.19 |
ccfaWildcardAffInterestAddrThe IP address of the CASA entity to which Interest
Packets should be forwarded by this Forwarding Agent.ro IpAddress .1.3.6.1.4.1.9.9.115.1.3.6.1.20 |
ccfaWildcardAffInterestPortThe UDP port of the CASA entity to which Interest
Packets should be forwarded by this Forwarding Agent.ro CiscoPort -- Rsyntax INTEGER .1.3.6.1.4.1.9.9.115.1.3.6.1.21 |
ccfaWildAffInterestPacketSpecThe criteria used to identify an Interest Packet.
When such a packet is identified, that packet is sent
to the entity described by
ccfaWildcardAffInterestAddr and
ccfaWildcardAffInterestPort.ro CasaInterestPacketSpecification -- Rsyntax OCTET STRING .1.3.6.1.4.1.9.9.115.1.3.6.1.22 |
ccfaWildAffInterestTickelSpecThe criteria used to identify an Interest Packet
resulting in a Tickle Packet being sent to the entity
described by ccfaWildcardAffInterestAddr and
ccfaWildcardAffInterestPort.ro CasaInterestPacketSpecification -- Rsyntax OCTET STRING .1.3.6.1.4.1.9.9.115.1.3.6.1.23 |
ccfaWildcardAffDispatchtrue indicates that the MAC address of the IP packet
should be modified to that of the dispatch
entity who's IP address is given by
ccfaWildcardAffDispatchAddr, prior to
transmitting the packet on the interface. If
ccfaWildcardAffDispatchAddr has value
0.0.0.0 then the Forwarding Agent will discard
the packet.
false indicates that the MAC address is not to be
translated.ro TruthValue -- Rsyntax INTEGER { -- true(1), -- false(2) -- } .1.3.6.1.4.1.9.9.115.1.3.6.1.24 |
ccfaWildcardAffDispatchAddrThe IP address of the dispatch entity for packets
matching Fixed Affinities derived from this Wildcard
Affinity.ro IpAddress .1.3.6.1.4.1.9.9.115.1.3.6.1.25 |
ccfaWildcardAffHiWtrMarkThis is the maximum number of Wildcard Affinities
(high water mark) concurrently held in the Wildcard
Affinity cache since last time cCasaState transitioned
to cCasaEnabled or since this object was reset.
Resetting this object is achieved by setting this
object to 0. Attempting to set this object to any
other value will result in a wrongValue error.rw Gauge -- Units -- affinities .1.3.6.1.4.1.9.9.115.1.3.7 |
ccfaWildAffCacheHiWtrMarkResetThis indicates when ccfaWildcardAffHiWtrMark
was set to 0.ro TimeStamp -- Rsyntax TimeTicks .1.3.6.1.4.1.9.9.115.1.3.8 |
ccfaWildcardAffDeniesThis is the number of Wildcard Affinities for which
this Forwarding Agent was not able to accept
(i.e. denied) because a mandatory action item included
with the Wildcard Affinity was not supported by this
Forwarding Agent.ro Counter -- Units -- affinities .1.3.6.1.4.1.9.9.115.1.3.9 |
ccfaWildcardAffDropsThis is the number of Wildcard Affinities for which
this Forwarding Agent did not process (i.e. dropped).
This can happen because of low resource conditions
prevailing in the Forwarding Agent, such as low
memory.ro Counter -- Units -- affinities .1.3.6.1.4.1.9.9.115.1.3.10 |
ccfaDispatchStats OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.115.1.4 |
ccfaDispatchStatsTableTable of traffic statistics between this Forwarding
Agent and the dispatch IP address. The statistics are
gathered by the Forwarding agent and are relative to
the Forwarding Agent. SEQUENCE OF CcfaDispatchStatsEntry .1.3.6.1.4.1.9.9.115.1.4.1 |
ccfaDispatchStatsEntryA list of traffic statistics.
Entries are added to this table dynamically by the
subagent when Fixed Affinities are received from the
Appliance indicating a dispatch IP address which is
not currently in the table. When there are no Fixed
Affinities left which contain ccfaDispatchAddress in
the Dispatch Address field, a timer is invoked. The
entry is deleted when this timer expires if no new
Fixed Affinities are received with the Dispatch
Address field equal to ccfaDispatchAddress. CcfaDispatchStatsEntry .1.3.6.1.4.1.9.9.115.1.4.1.1 |
ccfaDispatchAddressDispatch Address of the remote entity for which
these statistics are related to. IpAddress .1.3.6.1.4.1.9.9.115.1.4.1.1.1 |
ccfaDispatchBytesInNumber of bytes received by this Fowarding Agent from
the Dispatch Address.ro Counter -- Units -- bytes .1.3.6.1.4.1.9.9.115.1.4.1.1.2 |
ccfaDispatchHCBytesInNumber of bytes received by this Fowarding Agent from
the Dispatch Address. This object is a 64-bit version
of ccfaDispatchBytesIn.ro --?? syntax is not convertable to SMIv1 Counter -- Units -- bytes .1.3.6.1.4.1.9.9.115.1.4.1.1.3 |
ccfaDispatchBytesOutNumber of bytes sent by this Fowarding Agent to the
Dispatch Address.ro Counter -- Units -- bytes .1.3.6.1.4.1.9.9.115.1.4.1.1.4 |
ccfaDispatchHCBytesOutNumber of bytes sent by this Fowarding Agent to the
Dispatch Address. This object is a 64-bit version of
ccfaDispatchBytesOut.ro --?? syntax is not convertable to SMIv1 Counter -- Units -- bytes .1.3.6.1.4.1.9.9.115.1.4.1.1.5 |
ccfaDispatchPacketsInPackets received by this Fowarding Agent from the
Dispatch Address.ro Counter -- Units -- packets .1.3.6.1.4.1.9.9.115.1.4.1.1.6 |
ccfaDispatchHCPacketsInPackets received by this Fowarding Agent from the
Dispatch Address. This object is a 64-bit version of
ccfaDispatchPacketsIn.ro --?? syntax is not convertable to SMIv1 Counter -- Units -- packets .1.3.6.1.4.1.9.9.115.1.4.1.1.7 |
ccfaDispatchPacketsOutPackets sent by this Fowarding Agent to the Dispatch
Address.ro Counter -- Units -- packets .1.3.6.1.4.1.9.9.115.1.4.1.1.8 |
ccfaDispatchHCPacketsOutPackets sent by this Fowarding Agent to the Dispatch
Address.
This object is a 64-bit version of
ccfaDispatchPacketsOut.ro --?? syntax is not convertable to SMIv1 Counter -- Units -- packets .1.3.6.1.4.1.9.9.115.1.4.1.1.9 |
ccfaDispatchFlowsFrom a logical point of view, this is the number of
TCP/UDP flows resulting from packets received which
matched any Wildcard Affinity active in this
Forwarding Agent. This is current number of Fixed
Affinity entries whose destination IP address is equal
to ccfaDispatchAddress.ro Gauge -- Units -- affinities .1.3.6.1.4.1.9.9.115.1.4.1.1.10 |
ccfaAdvertisedDispatchTableThis table correlates dispatch addresses with their
corresponding advertised address. SEQUENCE OF CcfaAdvertisedDispatchEntry .1.3.6.1.4.1.9.9.115.1.4.2 |
ccfaAdvertisedDispatchEntryA list of dispatch addresses for each advertised
address.
An entry is added to this table by the subagent when
the Wildcard Affinity associated with a received Fixed
Affinity has ccfaWildcardAffDispatch set to true
and the entry is not already in the table. An entry is
deleted from this table when all fixed affinities
containing the dispatch address for the associated
advertised address, time out. CcfaAdvertisedDispatchEntry .1.3.6.1.4.1.9.9.115.1.4.2.1 |
ccfaAdvertisedAddressThe advertised IP Address. This corresponds to
ccfaWildcardAffDestinationAddr with
ccfaWildcardAffAdvertiseDestAddr set to true. IpAddress .1.3.6.1.4.1.9.9.115.1.4.2.1.1 |
ccfaAdvertisedDispatchAddressDispatch Address of the remote entity for which
these statistics are related to.ro IpAddress .1.3.6.1.4.1.9.9.115.1.4.2.1.2 |
ciscoCasaFaMIBNotificationPrefix OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.115.2 |
ciscoCasaFaMIBNotifications OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.115.2.0 |
ciscoCasaFaWildcardAffCreatedThis notification indicates that this CASA Forwarding
Agent has created a Wildcard Affinity entry. This is
gated on ccfaWildcardAffNotifEnabled. TRAP-TYPE .1.3.6.1.4.1.9.9.115.2.0.1 |
ciscoCasaFaWildcardAffDeletedThis notification indicates that this CASA Forwarding
Agent has deleted this Wildcard Affinity entry. This
is gated on ccfaWildcardAffNotifEnabled. TRAP-TYPE .1.3.6.1.4.1.9.9.115.2.0.2 |
ciscoCasaFaMIBConformance OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.115.3 |
ciscoCasaFaMIBCompliances OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.115.3.1 |
ciscoCasaFaMIBCompliance OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.115.3.1.1 |
ciscoCasaFaMIBGroups OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.115.3.2 |
ciscoCasaFaWildcardAffGroup OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.115.3.2.3 |
ciscoCasaFaDispatchGroup OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.115.3.2.5 |
ciscoCasaFaADGroup OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.115.3.2.6 |
ciscoCasaFaNotifGroup OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.115.3.2.7 |