CISCO-LWAPP-TRUSTSEC-MIB
AI MIB Summary
The CISCO-LWAPP-TRUSTSEC-MIB manages Cisco TrustSec fabric devices by configuring and monitoring SGT Exchange Protocol over TCP (SXPoTCP) parameters, including Protected Access Credential (PAC) states and Security Group Tag (SGT) policy enforcement. This module provides granular visibility into hop-by-hop authentication, authorization, and encryption status for traffic traversing the network fabric.
This MIB module is for the configuration of a network device on the Cisco Trusted Security (TrustSec) system.
TrustSec secures a network fabric by authenticating and authorizing each device connecting to the network, allowing for the encryption, authentication and replay protection of data traffic on a hop by hop basis.
Glossary :
TrustSec - Cisco Trusted Security
EAP-FAST - Extensible Authentication Protocol-Flexible Authentication via Secure Tunneling (RFC 4851)
PAC - Protected Access Credential A credential dynamically downloaded from the Access Control Server. ACS - Access Control Server SGT - Security Group Tag SXP - SGT Exchange Protocol. A tag identifying its source, assigned to a packet on ingress to a TrustSec cloud, and used to determine security and other policy to be applied to it along its path through the cloud. This MIB module is for the configuration and status query of SGT Exchange Protocol over TCP (SXPoTCP) feature of the device on the Cisco's Trusted Security (TrustSec) system.
Security Group Tag (SGT) identifying its source, assigned to a packet on ingress to a TrustSec cloud, and used to determine security and other policy to be applied to it along its path through the cloud.
Main OID:
ciscoLwappTrustSecMIB.1.3.6.1.4.1.9.9.836
19
Objects
Active
Status
8
Dependencies
Imported Objects
Objects
19 total| Object Name |
|---|
ciscoLwappTrustSecMIBThis MIB module is for the configuration of a network
device on the Cisco Trusted Security (TrustSec) system.
TrustSec secures a network fabric by authenticating and
authorizing each device connecting to the network, allowing for
the encryption, authentication and replay protection of data
traffic on a hop by hop basis.
Glossary :
TrustSec - Cisco Trusted Security
EAP-FAST - Extensible Authentication Protocol-Flexible
Authentication via Secure Tunneling (RFC 4851)
PAC - Protected Access Credential
A credential dynamically downloaded from the
Access Control Server.
ACS - Access Control Server
SGT - Security Group Tag
SXP - SGT Exchange Protocol.
A tag identifying its source, assigned to a packet on
ingress to a TrustSec cloud, and used to determine
security and other policy to be applied to it along
its path through the cloud.
This MIB module is for the configuration and status query
of SGT Exchange Protocol over TCP (SXPoTCP) feature of the
device on the Cisco's Trusted Security (TrustSec) system.
Security Group Tag (SGT) identifying its source, assigned to a
packet on ingress to a TrustSec cloud, and used to determine
security and other policy to be applied to it along its path
through the cloud. MODULE-IDENTITY .1.3.6.1.4.1.9.9.836 |
clCtsMIBNotifs OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.836.0 |
clCtsTableMIBObjects OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.836.1 |
clCtsApSxpPeerTableA list of SXP peers configured on this device.
It is a list of IP addresses of respective
SXP connection peers configured for this device.
SXP peers exchange security group tags information
of clients through SxpV4 protocol. SEQUENCE OF CLCtsApSxpPeerEntry .1.3.6.1.4.1.9.9.836.1.1 |
cLCtsApSxpPeerEntryAn entry containing management information of a
particular SXP peers. CLCtsApSxpPeerEntry .1.3.6.1.4.1.9.9.836.1.1.1 |
clCtsApSxpPeerIpTypeThe type of Internet address of the peer SXP device. InetAddressType (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.836.1.1.1.1 |
clCtsApSxpPeerIpThe Internet address of the SXP peer device. The type of this
address is determined by the value of cLCtsApSxpPeerIpType
object. InetAddress (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.836.1.1.1.2 |
clCtsApSxpModeThis object specifies the device mode of this SXP connection.
A value of 'speaker' indicates that device will acts as
the speaker in this SXP connection.
A value of 'listener' indicates that device will acts as
the listener in this SXP connection.
A value of 'both' indicates that device will acts as
both speaker and listener making it a Bi-directional SXP
connection.rw Enumeration .1.3.6.1.4.1.9.9.836.1.1.1.3 |
clCtsApSxpPeerPasswordThis object specifies to configure the
password of the sxp peer device.rw Enumeration .1.3.6.1.4.1.9.9.836.1.1.1.4 |
clCtsApSxpPeerRowStatusThis object specifies the conceptual status of the
row.rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.9.9.836.1.1.1.5 |
clCtsMIBConform OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.836.2 |
clCtsMIBCompliances OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.836.2.1 |
clCtsMIBGroups OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.836.2.2 |
clCtsGlobalMIBObjects OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.836.3 |
clCtsSecurityGroupTagIdThis object specifies user to specify the SGT for the packets
originating from this device.
A value of zero for this object indicates that no SGT has been
configured.rw CtsSecurityGroupTag (CISCO-TRUSTSEC-TC-MIB) .1.3.6.1.4.1.9.9.836.3.1 |
clCtsDeviceIdThis object specifies the identifier for the device.
This identifier and the device password (specified by
clCtsDevicePassword) are used together by the Cisco Trusted
Security feature for authenticating the device.
The object may not be set to a zero length string.
The system will return a zero length string for this object
either when there is no value configured for this object or
TrustSec credentials for the device have been cleared by
setting clCtsCredentialsClearAll to 'true'.rw SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.4.1.9.9.836.3.2 |
clCtsDevicePasswordThis object specifies user to specify the password for
the device.
This password and the device identifier (specified by
clCtsDeviceId) are used together by the Cisco Trusted Security
feature for authenticating the device.
The object may not be set to a zero length string.
When read, this object always returns the value of a
zero-length octet string.rw SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.4.1.9.9.836.3.3 |
clCtsInlineTagEnableStatusThis object specifies whether the inline tagging option is
Enabled or disabled.
A 'true' value indicates that inline tagging option is enabled.
A 'false' value indicates that inline tagging option is disabled.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.9.9.836.3.4 |
clCtsEnableStatusThis object specifies whether the CTS option is
Enabled or disabled.
A value of 'true' indicates that CTS is enabled.
A value of 'false' indicates that CTS is disabled.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.9.9.836.3.6 |