Home/Catalog/CISCO-LWAPP-TRUSTSEC-MIB

CISCO-LWAPP-TRUSTSEC-MIB

AI MIB Summary

The CISCO-LWAPP-TRUSTSEC-MIB manages Cisco TrustSec fabric devices by configuring and monitoring SGT Exchange Protocol over TCP (SXPoTCP) parameters, including Protected Access Credential (PAC) states and Security Group Tag (SGT) policy enforcement. This module provides granular visibility into hop-by-hop authentication, authorization, and encryption status for traffic traversing the network fabric.

This MIB module is for the configuration of a network device on the Cisco Trusted Security (TrustSec) system. TrustSec secures a network fabric by authenticating and authorizing each device connecting to the network, allowing for the encryption, authentication and replay protection of data traffic on a hop by hop basis. Glossary : TrustSec - Cisco Trusted Security EAP-FAST - Extensible Authentication Protocol-Flexible Authentication via Secure Tunneling (RFC 4851) PAC - Protected Access Credential A credential dynamically downloaded from the Access Control Server. ACS - Access Control Server SGT - Security Group Tag SXP - SGT Exchange Protocol. A tag identifying its source, assigned to a packet on ingress to a TrustSec cloud, and used to determine security and other policy to be applied to it along its path through the cloud. This MIB module is for the configuration and status query of SGT Exchange Protocol over TCP (SXPoTCP) feature of the device on the Cisco's Trusted Security (TrustSec) system. Security Group Tag (SGT) identifying its source, assigned to a packet on ingress to a TrustSec cloud, and used to determine security and other policy to be applied to it along its path through the cloud.
Main OID:
ciscoLwappTrustSecMIB.1.3.6.1.4.1.9.9.836
19
Objects
Active
Status
8
Dependencies

Imported Objects

Objects

19 total
Object Name
ciscoLwappTrustSecMIBThis MIB module is for the configuration of a network device on the Cisco Trusted Security (TrustSec) system. TrustSec secures a network fabric by authenticating and authorizing each device connecting to the network, allowing for the encryption, authentication and replay protection of data traffic on a hop by hop basis. Glossary : TrustSec - Cisco Trusted Security EAP-FAST - Extensible Authentication Protocol-Flexible Authentication via Secure Tunneling (RFC 4851) PAC - Protected Access Credential A credential dynamically downloaded from the Access Control Server. ACS - Access Control Server SGT - Security Group Tag SXP - SGT Exchange Protocol. A tag identifying its source, assigned to a packet on ingress to a TrustSec cloud, and used to determine security and other policy to be applied to it along its path through the cloud. This MIB module is for the configuration and status query of SGT Exchange Protocol over TCP (SXPoTCP) feature of the device on the Cisco's Trusted Security (TrustSec) system. Security Group Tag (SGT) identifying its source, assigned to a packet on ingress to a TrustSec cloud, and used to determine security and other policy to be applied to it along its path through the cloud.
MODULE-IDENTITY
.1.3.6.1.4.1.9.9.836
clCtsMIBNotifs
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.836.0
clCtsTableMIBObjects
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.836.1
clCtsApSxpPeerTableA list of SXP peers configured on this device. It is a list of IP addresses of respective SXP connection peers configured for this device. SXP peers exchange security group tags information of clients through SxpV4 protocol.
SEQUENCE OF CLCtsApSxpPeerEntry
.1.3.6.1.4.1.9.9.836.1.1
cLCtsApSxpPeerEntryAn entry containing management information of a particular SXP peers.
CLCtsApSxpPeerEntry
.1.3.6.1.4.1.9.9.836.1.1.1
clCtsApSxpPeerIpTypeThe type of Internet address of the peer SXP device.
InetAddressType (INET-ADDRESS-MIB)
.1.3.6.1.4.1.9.9.836.1.1.1.1
clCtsApSxpPeerIpThe Internet address of the SXP peer device. The type of this address is determined by the value of cLCtsApSxpPeerIpType object.
InetAddress (INET-ADDRESS-MIB)
.1.3.6.1.4.1.9.9.836.1.1.1.2
clCtsApSxpModeThis object specifies the device mode of this SXP connection. A value of 'speaker' indicates that device will acts as the speaker in this SXP connection. A value of 'listener' indicates that device will acts as the listener in this SXP connection. A value of 'both' indicates that device will acts as both speaker and listener making it a Bi-directional SXP connection.rw
Enumeration
.1.3.6.1.4.1.9.9.836.1.1.1.3
clCtsApSxpPeerPasswordThis object specifies to configure the password of the sxp peer device.rw
Enumeration
.1.3.6.1.4.1.9.9.836.1.1.1.4
clCtsApSxpPeerRowStatusThis object specifies the conceptual status of the row.rw
RowStatus (SNMPv2-TC)
.1.3.6.1.4.1.9.9.836.1.1.1.5
clCtsMIBConform
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.836.2
clCtsMIBCompliances
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.836.2.1
clCtsMIBGroups
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.836.2.2
clCtsGlobalMIBObjects
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.836.3
clCtsSecurityGroupTagIdThis object specifies user to specify the SGT for the packets originating from this device. A value of zero for this object indicates that no SGT has been configured.rw
CtsSecurityGroupTag (CISCO-TRUSTSEC-TC-MIB)
.1.3.6.1.4.1.9.9.836.3.1
clCtsDeviceIdThis object specifies the identifier for the device. This identifier and the device password (specified by clCtsDevicePassword) are used together by the Cisco Trusted Security feature for authenticating the device. The object may not be set to a zero length string. The system will return a zero length string for this object either when there is no value configured for this object or TrustSec credentials for the device have been cleared by setting clCtsCredentialsClearAll to 'true'.rw
SnmpAdminString (SNMP-FRAMEWORK-MIB)
.1.3.6.1.4.1.9.9.836.3.2
clCtsDevicePasswordThis object specifies user to specify the password for the device. This password and the device identifier (specified by clCtsDeviceId) are used together by the Cisco Trusted Security feature for authenticating the device. The object may not be set to a zero length string. When read, this object always returns the value of a zero-length octet string.rw
SnmpAdminString (SNMP-FRAMEWORK-MIB)
.1.3.6.1.4.1.9.9.836.3.3
clCtsInlineTagEnableStatusThis object specifies whether the inline tagging option is Enabled or disabled. A 'true' value indicates that inline tagging option is enabled. A 'false' value indicates that inline tagging option is disabled.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.9.9.836.3.4
clCtsEnableStatusThis object specifies whether the CTS option is Enabled or disabled. A value of 'true' indicates that CTS is enabled. A value of 'false' indicates that CTS is disabled.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.9.9.836.3.6
CISCO-LWAPP-TRUSTSEC-MIB - SNMP MIB Reference | MIBs Explorer