CISCO-LWAPP-LOCAL-AUTH-MIB
AI MIB Summary
The CISCO-LWAPP-LOCAL-AUTH-MIB enables the monitoring and management of local authentication parameters for Cisco Lightweight Access Point Protocol (LWAPP) Central Controllers, specifically tracking the authentication state and configuration of associated LWAPP Access Points. This module facilitates the retrieval of Local Authentication data to verify the secure establishment of LWAPP tunnels between the controller and lightweight APs during the bootup and join processes.
This MIB is intended to be implemented on all those devices operating as Central controllers, that terminate the Light Weight Access Point Protocol tunnel from Cisco Light-weight LWAPP Access Points.
Information provided by this MIB is used to manage Local authentication information on the controller.
The relationship between CC and the LWAPP APs can be depicted as follows:
+......+ +......+ +......+
+ + + + + +
+ CC + + CC + + CC +
+ + + + + +
+......+ +......+ +......+
.. . . .. . . . . . . . . . . . . . . . . . .
+......+ +......+ +......+ +......+
+ + + + + + + +
+ AP + + AP + + AP + + AP +
+ + + + + + + +
+......+ +......+ +......+ +......+
. . . . . . . . . . . . . . . . . . .
+......+ +......+ +......+ +......+
+ + + + + + + +
+ MN + + MN + + MN + + MN +
+ + + + + + + +
+......+ +......+ +......+ +......+
The LWAPP tunnel exists between the controller and the APs. The MNs communicate with the APs through the protocol defined by the 802.11 standard.
LWAPP APs, upon bootup, discover and join one of the controllers and the controller pushes the configuration, that includes the WLAN parameters, to the LWAPP APs. The APs then encapsulate all the 802.11 frames from wireless clients inside LWAPP frames and forward the LWAPP frames to the controller.
GLOSSARY
Access Point ( AP )
An entity that contains an 802.11 medium access control ( MAC ) and physical layer ( PHY ) interface and provides access to the distribution services via the wireless medium for associated clients.
LWAPP APs encapsulate all the 802.11 frames in LWAPP frames and sends them to the controller to which it is logically connected.
Gratuitous Probe Response (GPR)
The Gratuitous Probe Response feature aids in conserving battery power of WLAN-enabled cell phones by providing a high rate packet on the order of tens of milliseconds such that these kind of phones can wake up and wait at predefined intervals, to reduce battery power. The GPR packet is transmitted from the AP at a predefined time interval.
Light Weight Access Point Protocol ( LWAPP )
This is a generic protocol that defines the communication between the Access Points and the Central Controller.
Mobile Node ( MN )
A roaming 802.11 wireless device in a wireless network associated with an access point. Mobile Node and client are used interchangeably.
Extensible Authentication Protocol ( EAP )
EAP is a universal authentication protocol used in wireless and PPP networks. It is defined by RFC 3748.
EAP-Flexible Authentication ( EAP-FAST )
This protocol is used via secure tunneling for 802.1X EAP.
Transport Layer Security ( TLS )
This is a cryptographic protocol which provides secure communication over the network.
Protected Extensible Authentication Protocol ( PEAP )
PEAP is a method to securely transmit authentication information, including passwords, over wired or wireless networks.
Lightweight Directory Access Protocol ( LDAP )
LDAP is a protocol used for obtaining directory services and runs over TCP/IP.
REFERENCE
[1] Wireless LAN Medium Access Control ( MAC ) and Physical Layer ( PHY ) Specifications
[2] Draft-obara-capwap-lwapp-00.txt, IETF Light Weight Access Point Protocol
Main OID:
ciscoLwappLocalAuthMIB.1.3.6.1.4.1.9.9.619
43
Objects
Active
Status
5
Dependencies
Imported Objects
Objects
43 total| Object Name |
|---|
ciscoLwappLocalAuthMIBThis MIB is intended to be implemented on all those
devices operating as Central controllers, that
terminate the Light Weight Access Point Protocol
tunnel from Cisco Light-weight LWAPP Access Points.
Information provided by this MIB is used to manage
Local authentication information on the controller.
The relationship between CC and the LWAPP APs
can be depicted as follows:
+......+ +......+ +......+
+ + + + + +
+ CC + + CC + + CC +
+ + + + + +
+......+ +......+ +......+
.. . .
.. . .
. . . .
. . . .
. . . .
. . . .
+......+ +......+ +......+ +......+
+ + + + + + + +
+ AP + + AP + + AP + + AP +
+ + + + + + + +
+......+ +......+ +......+ +......+
. . .
. . . .
. . . .
. . . .
. . . .
+......+ +......+ +......+ +......+
+ + + + + + + +
+ MN + + MN + + MN + + MN +
+ + + + + + + +
+......+ +......+ +......+ +......+
The LWAPP tunnel exists between the controller and
the APs. The MNs communicate with the APs through
the protocol defined by the 802.11 standard.
LWAPP APs, upon bootup, discover and join one of the
controllers and the controller pushes the configuration,
that includes the WLAN parameters, to the LWAPP APs.
The APs then encapsulate all the 802.11 frames from
wireless clients inside LWAPP frames and forward
the LWAPP frames to the controller.
GLOSSARY
Access Point ( AP )
An entity that contains an 802.11 medium access
control ( MAC ) and physical layer ( PHY ) interface
and provides access to the distribution services via
the wireless medium for associated clients.
LWAPP APs encapsulate all the 802.11 frames in
LWAPP frames and sends them to the controller to which
it is logically connected.
Gratuitous Probe Response (GPR)
The Gratuitous Probe Response feature aids in conserving
battery power of WLAN-enabled cell phones by providing
a high rate packet on the order of tens of milliseconds
such that these kind of phones can wake up and wait at
predefined intervals, to reduce battery power. The
GPR packet is transmitted from the AP at a predefined
time interval.
Light Weight Access Point Protocol ( LWAPP )
This is a generic protocol that defines the
communication between the Access Points and the
Central Controller.
Mobile Node ( MN )
A roaming 802.11 wireless device in a wireless
network associated with an access point. Mobile Node
and client are used interchangeably.
Extensible Authentication Protocol ( EAP )
EAP is a universal authentication protocol used in
wireless and PPP networks. It is defined by RFC 3748.
EAP-Flexible Authentication ( EAP-FAST )
This protocol is used via secure tunneling for 802.1X EAP.
Transport Layer Security ( TLS )
This is a cryptographic protocol which provides secure
communication over the network.
Protected Extensible Authentication Protocol ( PEAP )
PEAP is a method to securely transmit authentication
information, including passwords, over wired or wireless
networks.
Lightweight Directory Access Protocol ( LDAP )
LDAP is a protocol used for obtaining directory services
and runs over TCP/IP.
REFERENCE
[1] Wireless LAN Medium Access Control ( MAC ) and
Physical Layer ( PHY ) Specifications
[2] Draft-obara-capwap-lwapp-00.txt, IETF Light
Weight Access Point Protocol MODULE-IDENTITY .1.3.6.1.4.1.9.9.619 |
ciscoLwappLocalAuthMIBNotifs OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.619.0 |
ciscoLwappLocalAuthMIBObjects OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.619.1 |
cllaConfig OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.619.1.1 |
cllaLocalAuth OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.619.1.1.1 |
cllaActiveTimeoutThis object represents timeout period for the Local EAP
to remain active.rw Unsigned32 UNITS "seconds" .1.3.6.1.4.1.9.9.619.1.1.1.1 |
cllaEapIdentityReqTimeoutThis object represents timeout period for the EAP
Identity request within which response should be sent.rw Unsigned32 UNITS "seconds" .1.3.6.1.4.1.9.9.619.1.1.1.2 |
cllaEapIdentityReqMaxRetriesThis object represents maximum number of retransmissions
for EAP Identity request.rw Unsigned32 .1.3.6.1.4.1.9.9.619.1.1.1.3 |
cllaEapDynamicWepKeyIndexThis object represents key index for the EAP dynamic
Wired Equivalent Privacy security policy.
It applies to Static WEP key index of WLAN which has layer 2
security of type Static WEP. According to 802.11 standard 4
keys
are supported for informing Mobile Station (clients) which key
it
should use for Static WEP Authentication
The default value of 0 works for all devices, but for some old
devices/clients which uses the unicast key as 3, the key index
has to be configured to 3 to match the client side setting.rw Unsigned32 .1.3.6.1.4.1.9.9.619.1.1.1.4 |
cllaEapReqTimeoutThis object represents timeout period for the EAP request
within which response should be sent.rw Unsigned32 UNITS "seconds" .1.3.6.1.4.1.9.9.619.1.1.1.5 |
cllaEapReqMaxRetriesThis object represents maximum number of retransmissions
for EAP request.rw Unsigned32 .1.3.6.1.4.1.9.9.619.1.1.1.6 |
cllaEapMaxLoginIgnIdRespThis object enables the checking of the number of devices that
can be connected to the controller with the same username.
You can login up to eight times from different devices
(PDA, laptop, IP phone, and so on) on the same controller.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.9.9.619.1.1.1.7 |
cllaEapKeyTimeoutThis object represents the amount of time in which the
controller attempts to send an EAP key over the LAN to
wireless clients using local EAP.rw Unsigned32 .1.3.6.1.4.1.9.9.619.1.1.1.8 |
cllaEapKeyMaxRetriesThis object represents the maximum number of times
that the controller attempts to send an EAP key over
the LAN to wireless clients using local EAP.rw Unsigned32 .1.3.6.1.4.1.9.9.619.1.1.1.9 |
cllaEapProfileTableThis table represents the local EAP authentication
information on the controller.
Rows are added or deleted by explicit
management actions initiated by the user from a
network management station through the
cllaEapProfileRowStatus object. SEQUENCE OF CllaEapProfileEntry .1.3.6.1.4.1.9.9.619.1.1.2 |
cllaEapProfileEntryA conceptual row in cllaEapProfileTable. Each
entry in this table represents the local EAP
authentication information, identified by
the cllEapProfileName. CllaEapProfileEntry .1.3.6.1.4.1.9.9.619.1.1.2.1 |
cllaEapProfileNameThis object represent the profile name used to identify
the Local EAP information. DisplayString .1.3.6.1.4.1.9.9.619.1.1.2.1.1 |
cllaEapProfileMethodsThis object represents the method type for this
entry.
none - No method is in use
leap - LEAP is used as one of the methods
eapFast - EAP-FAST is used as one of the methods
tls - TLS is being used as one of the methods
peap - PEAP is being used as one of the methods.rw Bits .1.3.6.1.4.1.9.9.619.1.1.2.1.2 |
cllaEapProfileCertIssuerThis object represents the name of the certificate issuer
cisco - Cisco is the certificate issuer.
vendor - The issuer is an outside vendor.rw Enumeration .1.3.6.1.4.1.9.9.619.1.1.2.1.3 |
cllaEapProfileCaCertificationCheckThis parameter indicates whether to check peer certificate
against installed CA certificates.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.9.9.619.1.1.2.1.4 |
cllaEapProfileCnCertificationIdVerifyThis parameter indicates whether to verify certificate
CN against peer identity and user database.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.9.9.619.1.1.2.1.5 |
cllaEapProfileDateValidityEnabledThis parameter indicates whether to verify certificate
date is valid and is within validity period.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.9.9.619.1.1.2.1.6 |
cllaEapProfileLocalCertificateRequiredThis is applicable when cllaEapProfileMethods is
EAP-FAST parameter. This parameter indicates
whether local certificate is required.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.9.9.619.1.1.2.1.7 |
cllaEapProfileClientCertificateRequiredThis is applicable when cllaEapProfileMethods is
EAP-FAST parameter. This parameter indicates
whether client certificate is required.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.9.9.619.1.1.2.1.8 |
cllaEapProfileRowStatusUsed to add or delete an entry in this table.rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.9.9.619.1.1.2.1.9 |
cllaWlanProfileTableThis table represents the information about configuring
the EAP profiles for a WLAN. The creation of a new row
occurs when a WLAN entry is added through an explicit
network management action to the cLWlanConfigTable in
CISCO-LWAPP-WLAN-MIB.
Similarly, deletion of a row in cLWlanConfigTable
through user action, causes the deletion of corresponding
row in this table. SEQUENCE OF CllaWlanProfileEntry .1.3.6.1.4.1.9.9.619.1.1.3 |
cllaWlanProfileEntryEach entry in this table provides information about
the Local EAP profile configured for this WLAN. CllaWlanProfileEntry .1.3.6.1.4.1.9.9.619.1.1.3.1 |
cllaWlanProfileNameThe profile name configured for this WLAN.rw DisplayString .1.3.6.1.4.1.9.9.619.1.1.3.1.1 |
cllaWlanProfileStateThis object indicates whether Local Authentication
is enabled or disables for this WLAN.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.9.9.619.1.1.3.1.2 |
cllaUserPriorityTableThis table contains entries for 802.11 user credential
methods configured in the controller. At startup,
all the entries in this table are set up by the central
controller. A management application can later change
the priority order using the cllaUserPriorityNumber. SEQUENCE OF CllaUserPriorityEntry .1.3.6.1.4.1.9.9.619.1.1.4 |
cllaUserPriorityEntryA conceptual row in cllaUserPriorityTable. There is an
entry in this table for each 802.11 user authentication
available at the agent, as identified by a value of
cllaUserCredential. CllaUserPriorityEntry .1.3.6.1.4.1.9.9.619.1.1.4.1 |
cllaUserCredentialThis object represents the user crediantial information.
local - indicates that local credential is used
for authentication
ldap - indicates that LDAP credential is used
for authentication. Enumeration .1.3.6.1.4.1.9.9.619.1.1.4.1.1 |
cllaUserPriorityNumberThis object represents the order in which the user credentials
are validated by the controller. At start up,
the agent assigns the value of this object. Later this can
be changed by the management station.
This object reflects the priority in which the user credential
information is applied. A lower value indicates an higher
priority. For example, an entry set to value '1' has a higher
priority over an entry set to value '2'.
The zero value indicates that the priority is not set.
No two instances of this object will have the same priority.rw Integer32 .1.3.6.1.4.1.9.9.619.1.1.4.1.2 |
cllaEapParams OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.619.1.1.5 |
cllaEapMethodPacTtlThis is EAP Fast parameter. This parameter represents
time to live for the protected access credentials.rw Unsigned32 .1.3.6.1.4.1.9.9.619.1.1.5.1 |
cllaEapAnonymousProvEnabledThis is EAP Fast parameter. This parameter represents
whether anonymous provisioning is enabled. A value of
'true' indicates the controller will accept anonymous
requests. A value of 'false' indicates that the controller
will reject anonymous requests.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.9.9.619.1.1.5.2 |
cllaEapAuthorityIdThis is EAP Fast parameter. This parameter configures
the authority ID. The maximum length per platform is
specified by the cllaEapAuthorityIdLength object.rw OCTET STRING .1.3.6.1.4.1.9.9.619.1.1.5.3 |
cllaEapAuthorityInfoThis is EAP Fast parameter. This parameter configures
the authority information.rw OCTET STRING .1.3.6.1.4.1.9.9.619.1.1.5.4 |
cllaEapServerKeyThis is EAP Fast parameter. This parameter configures
the server key ID.rw OCTET STRING .1.3.6.1.4.1.9.9.619.1.1.5.5 |
cllaEapAuthorityIdLengthThis object represents the length of the cllaEapAuthorityId
object, supported by this agent implementation.ro Unsigned32 .1.3.6.1.4.1.9.9.619.1.1.5.6 |
ciscoLwappLocalAuthMIBConform OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.619.2 |
ciscoLwappLocalAuthMIBCompliances OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.619.2.1 |
ciscoLwappLocalAuthMIBGroups OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.619.2.2 |