Home/Catalog/CISCO-LWAPP-WAPI-MIB

CISCO-LWAPP-WAPI-MIB

AI MIB Summary

The CISCO-LWAPP-WAPI-MIB enables SNMP monitoring and management of WAPI-compliant Wireless LAN authentication and privacy interfaces on Cisco Lightweight Access Point Protocol (LWAPP) controllers. It exposes specific metrics for the WAI and WPI subsystems, including authentication and key management (AKM) states, multicast session keys (MSK), and base key identification (BKID) to enforce the Chinese National Standard GB 15629.11-2003.

cisco WiFi Controller Snmp agent support for Wapi. WAPI is a Chinese National Standard for Wireless LAN (GB 15629.11-2003) GLOSSARY: WAPI - WLAN Authentication and Privacy Infrastructures WAI - WLAN Authentication Interface WLAN - Wireless Local Area Network WPI - Wireless Privacy Interface MSK - multicast session key AKM - authentication and key management BKID - Base Key IDentification
Main OID:
ciscoLwappWapiMIB.1.3.6.1.4.1.9.9.9997
94
Objects
Active
Status
7
Dependencies

Imported Objects

Objects

94 total
Object Name
ciscoLwappWapiMIBcisco WiFi Controller Snmp agent support for Wapi. WAPI is a Chinese National Standard for Wireless LAN (GB 15629.11-2003) GLOSSARY: WAPI - WLAN Authentication and Privacy Infrastructures WAI - WLAN Authentication Interface WLAN - Wireless Local Area Network WPI - Wireless Privacy Interface MSK - multicast session key AKM - authentication and key management BKID - Base Key IDentification
MODULE-IDENTITY
.1.3.6.1.4.1.9.9.9997
ciscoLwappWapiMIBObjects
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.9997.1
cLWapiWlanStatsThis table maintains the WAPI statistics for each WLAN on which WAPI is configured as the security protocol.
SEQUENCE OF CiscoWapiWlanStatsEntry
.1.3.6.1.4.1.9.9.9997.1.1
cLWapiWlanStatsEntryAn entry in the cLWWSW Table
CiscoWapiWlanStatsEntry
.1.3.6.1.4.1.9.9.9997.1.1.1
cLWWSWAISignatureErrorsThis counter shall increment when the signature in the received WAI message is incorrectro
Counter32
.1.3.6.1.4.1.9.9.9997.1.1.1.1
cLWWSWAIHMACErrorsThis counter shall increment when the message authentication code in the received WAI message is incorrectro
Counter32
.1.3.6.1.4.1.9.9.9997.1.1.1.2
cLWWSWAIAuthResultFailuresThis counter shall increment when the WAI authentication is unsuccessfulro
Counter32
.1.3.6.1.4.1.9.9.9997.1.1.1.3
cLWWSWAIDiscardCountersThis counter shall increment when the received WAI message is discardedro
Counter32
.1.3.6.1.4.1.9.9.9997.1.1.1.4
cLWWSWAITimeoutCountersThis counter shall increment when the WAI message is timeoutro
Counter32
.1.3.6.1.4.1.9.9.9997.1.1.1.5
cLWWSWAIFormatErrorsThis counter shall increment when there exists format error in the WAI messagero
Counter32
.1.3.6.1.4.1.9.9.9997.1.1.1.6
cLWWSWAICertHandshakeFailuresThis counter shall increment when the WAI Certificate Authentication is unsuccessfulro
Counter32
.1.3.6.1.4.1.9.9.9997.1.1.1.7
cLWWSWAIUnicastHandshakeFailuresThis counter shall increment when the WAI Unicast Key Negotiation is unsuccessfulro
Counter32
.1.3.6.1.4.1.9.9.9997.1.1.1.8
cLWWSWAIMulticastHandshakeFailuresThis counter shall increment when the WAI Multicast Key Negotiation is unsuccessfulro
Counter32
.1.3.6.1.4.1.9.9.9997.1.1.1.9
cLWWSWPIRXReplayCountersThis counter shall increment when the WPI RX replay check is unsuccessfulro
Counter32
.1.3.6.1.4.1.9.9.9997.1.1.1.10
cLWWSWPIRXMicErrorCountersThis counter shall increment when the WPI MIC is errorro
Counter64
.1.3.6.1.4.1.9.9.9997.1.1.1.11
cLWWSWPIRXDecryptErrorCountersThis counter shall increment when the WPI Decryption is errorro
Counter64
.1.3.6.1.4.1.9.9.9997.1.1.1.12
cLWapiClientStatsThis table maintains the WAPI statistics for each client connected to a WLAN on which WAPI is configured as the security protocol.
SEQUENCE OF CiscoWapiClientStatsEntry
.1.3.6.1.4.1.9.9.9997.1.2
cLWapiClientStatsEntryAn entry in the cLWapiClientStats Table
CiscoWapiClientStatsEntry
.1.3.6.1.4.1.9.9.9997.1.2.1
cLWCSWapiClientVersionThis object represents the WAPI draft version used by the WAPI clientro
Integer32
.1.3.6.1.4.1.9.9.9997.1.2.1.1
cLWCSWAISignatureErrorsThis counter shall increment when the signature in the received WAI message is incorrectro
Counter32
.1.3.6.1.4.1.9.9.9997.1.2.1.2
cLWCSWAIHMACErrorsThis counter shall increment when the message authentication code in the received WAI message is incorrectro
Counter32
.1.3.6.1.4.1.9.9.9997.1.2.1.3
cLWCSWAIAuthResultFailuresThis counter shall increment when the WAI authentication is unsuccessfulro
Counter32
.1.3.6.1.4.1.9.9.9997.1.2.1.4
cLWCSWAIDiscardCountersThis counter shall increment when the received WAI message is discardedro
Counter32
.1.3.6.1.4.1.9.9.9997.1.2.1.5
cLWCSWAITimeoutCountersThis counter shall increment when the WAI message is timeoutro
Counter32
.1.3.6.1.4.1.9.9.9997.1.2.1.6
cLWCSWAIFormatErrorsThis counter shall increment when there exists format error in the WAI messagero
Counter32
.1.3.6.1.4.1.9.9.9997.1.2.1.7
cLWCSWAICertHandshakeFailuresThis counter shall increment when the WAI Certificate Authentication is unsuccessfulro
Counter32
.1.3.6.1.4.1.9.9.9997.1.2.1.8
cLWCSWAIUnicastHandshakeFailuresThis counter shall increment when the WAI Unicast Key Negotiation is unsuccessfulro
Counter32
.1.3.6.1.4.1.9.9.9997.1.2.1.9
cLWCSWAIMulticastHandshakeFailuresThis counter shall increment when the WAI Multicast Key Negotiation is unsuccessfulro
Counter32
.1.3.6.1.4.1.9.9.9997.1.2.1.10
cLWCSWAIUnicastCipherSuiteThis value represents the Client Unicast Cipher Suite in use, of which obtained from Assoc req framero
OCTET STRING
.1.3.6.1.4.1.9.9.9997.1.2.1.11
cLWCSWAIMcastCipherSuiteThis value represents the Client Multicast Cipher Suite in use, of which obtained from Assoc req framero
OCTET STRING
.1.3.6.1.4.1.9.9.9997.1.2.1.12
cLWCSWAIAuthenticationSuiteRequestedThis object specificies the last AKM suite requested from client. 0x 00 14 72 01 : cert 0x 00 14 72 02 : pskro
OCTET STRING
.1.3.6.1.4.1.9.9.9997.1.2.1.13
cLWCSWAIBKIDUsedThis value represents the selector of the last BKID used in the last Unicast Key Negotiation Handshakero
OCTET STRING
.1.3.6.1.4.1.9.9.9997.1.2.1.14
cLWCSWAICtrPortStateThis value represents the state of client controlled port entity, true means authenticated, false means not authenticatedro
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.9.9.9997.1.2.1.15
cLWapiWlanConfigThis table maintains the WAPI config entry for the WLAN.
SEQUENCE OF CiscoWapiWlanConfigEntry
.1.3.6.1.4.1.9.9.9997.1.3
cLWapiWlanConfigEntrtyAn entry in the cLWapiWlanConfig Table
CiscoWapiWlanConfigEntry
.1.3.6.1.4.1.9.9.9997.1.3.1
cLWCSWlanWapiEnableThis object is used to enable the WAPI security on the WLAN.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.9.9.9997.1.3.1.1
cLWCSWlanWapiAkmKeyMgmtModeThis object is used to enable the AKM type to be used for the WAPI WLAN.rw
Enumeration
.1.3.6.1.4.1.9.9.9997.1.3.1.2
cLWCSWlanWapiEncryptTypeThis object is used to enable the encryption type for WAPI WLAN.rw
Bits
.1.3.6.1.4.1.9.9.9997.1.3.1.3
cLWCSWlanWapiPskFmtThis object indicates the type of the authentication preshared key configured through the object cLWCSWlanWapiPskSetkey. Note that the key configuration is applicable only when psk is configured as the key management mechanism through the cLWCSWlanWapiAkmKeyMgmtMode object.rw
CLSecKeyFormat (CISCO-LWAPP-TC-MIB)
.1.3.6.1.4.1.9.9.9997.1.3.1.4
cLWCSWlanWapiPskThis object is used to configure the Pre-Shared Key for WAI PSK authentication for the WLAN. The key can be in ASCII or HEX format. 'ascii' 8-40 characters 'hex' 4-40 octets.rw
OCTET STRING
.1.3.6.1.4.1.9.9.9997.1.3.1.5
cLWCSWlanWapiConfigUnicasCiphersEntryThe selector of a supported unicast cipher suite. It consists of an OUI (the first 3 octets) and a cipher suite identifier (the last octet).ro
OCTET STRING
.1.3.6.1.4.1.9.9.9997.1.3.1.6
cLWCSWlanWapiConfigUnicastCipherSizeThis object indicates the length in bit of the USK. This should be 256 for SMS4. The first 128bits is the UEK and the last 128bits is the UCK.ro
Unsigned32
.1.3.6.1.4.1.9.9.9997.1.3.1.7
cLWCSWlanWapiMcastCipherSizeThis object indicates the length in bit of the MSK. This should be 256 for in SMS4. The first 128bits is the MEK and the last 128bits is the MCK.ro
Unsigned32
.1.3.6.1.4.1.9.9.9997.1.3.1.8
cLWCSWlanBKLifeTimeThis object is used to configure the maximum lifetime of a BK in the BK cache.rw
Unsigned32 UNITS "seconds"
.1.3.6.1.4.1.9.9.9997.1.3.1.9
cLWCSWlanBKReauthThresholdThis object is used to configure the percentage of the BK lifetime that should expire before a WAI reauthentication occurs.rw
Unsigned32 UNITS "percentage"
.1.3.6.1.4.1.9.9.9997.1.3.1.10
cLWCSWlanWapiConfigMulticastCipherThis object indicates the multicast cipher suite that this entity must adopt. The WAPI Parameter Set information element shall adopt the value of this variable, which contains a 3-octet OUI and a one-octet cipher suite identifier.rw
OCTET STRING
.1.3.6.1.4.1.9.9.9997.1.3.1.11
cLWCSWlanWapiAuthenticationSuiteSelectedThis object represents the selector of the last AKM suite negotiated.ro
OCTET STRING
.1.3.6.1.4.1.9.9.9997.1.3.1.12
cLWCSWlanWapiUnicastCipherSelectedThis object indicates the selector of the last unicast cipher suite negotiated.ro
OCTET STRING
.1.3.6.1.4.1.9.9.9997.1.3.1.13
cLWCSWlanWapiMulticastCipherSelectedThis object indicates the selector of the last multicast cipher suite negotiated.ro
OCTET STRING
.1.3.6.1.4.1.9.9.9997.1.3.1.14
cLWCSWlanWapiPreauthenticationStateThis object represents the state of Preauthentication in WAPI and currently it is not supported.ro
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.9.9.9997.1.3.1.15
cLWapiAPTableThis table maintains the WAPI details and configurations for each AP connected.
SEQUENCE OF CiscoWapiAPEntry
.1.3.6.1.4.1.9.9.9997.1.4
cLWapiAPEntryAn entry in the cLWapiAPTable Table.
CiscoWapiAPEntry
.1.3.6.1.4.1.9.9.9997.1.4.1
cLWCSWapiAPMaxUnicastKeysSupportThis object represents the maximum number of USK's that an AP can support.ro
Integer32
.1.3.6.1.4.1.9.9.9997.1.4.1.1
cLWapiWlanAKMSuitesConfigTableThis table maintains the WAPI config entry for the WLAN.
SEQUENCE OF CiscoWapiAuthenticationConfigEntry
.1.3.6.1.4.1.9.9.9997.1.5
cLWapiWlanAKMSuitesConfigEntryAn entry in the cLWapiWlanAKMSuitesConfig Table
CiscoWapiAuthenticationConfigEntry
.1.3.6.1.4.1.9.9.9997.1.5.1
cLWCSWlanWapiAuthenticationSuiteIndexThis object is used to a index for AKM suites on the WLAN.
Enumeration
.1.3.6.1.4.1.9.9.9997.1.5.1.1
cLWCSWlanWapiAuthenticationSuiteThis object is used to indicate the AKM suite octects on the WLAN.ro
OCTET STRING
.1.3.6.1.4.1.9.9.9997.1.5.1.2
cLWCSWlanWapiAuthenticationSuiteEnableThis object is used to enable the AKM suites on the WLAN.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.9.9.9997.1.5.1.3
cLWapiCiphersThis table maintains the unicast cipher suites supported by this entity. It allows enabling and disabling of each unicast cipher suite by network management. The unicast cipher suite list in the WAPI Parameter Set information element is formed using the information in this table.
SEQUENCE OF CiscoWapiCiphersEntry
.1.3.6.1.4.1.9.9.9997.1.6
cLWapiCiphersEntryAn entry in the cLWapiCiphers Table.
CiscoWapiCiphersEntry
.1.3.6.1.4.1.9.9.9997.1.6.1
cLWCSWlanCipherIndexThis object represents auxiliary index of the CiscoWapiCiphersEntry.
Unsigned32
.1.3.6.1.4.1.9.9.9997.1.6.1.1
cLWCSWlanCipherEnabledThis object represents enables or disables the unicast cipher.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.9.9.9997.1.6.1.2
ciscoLwappWapiConfig
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.9997.2
clWapiASIpAddressThis object represents the IP address of the WAPI authentication server.rw
IpAddress
.1.3.6.1.4.1.9.9.9997.2.1
clWapiASPortNumberThis object represents the UDP port number for WAPI authentication server.rw
Integer32
.1.3.6.1.4.1.9.9.9997.2.2
clWapiASRequestTimeoutThis object represents timeout value for the packets sent to Auth Server.rw
Integer32
.1.3.6.1.4.1.9.9.9997.2.3
clWapiMulticastRekeyMethodThis object selects a mechanism for rekeying the WAPI MSK. The default is time-based, once per day. Rekeying the MSK is only applicable to an entry acting in the AE role.rw
Enumeration
.1.3.6.1.4.1.9.9.9997.2.4
clWapiMulticastRekeyTimeThis object represents the time in seconds after which the WAPI MSK will be refreshed. The timer will start the moment the MSK was set using the MLME-SETWPIKEYS request primitive.rw
Unsigned32 UNITS "seconds"
.1.3.6.1.4.1.9.9.9997.2.5
clWapiMulticastRekeyMessagesThis object represents the message count in thousands after which the WAPI MSK will be refreshed. The message counter will start the moment the MSK was set using the MLME-SETWPIKEYS request primitive.rw
Unsigned32
.1.3.6.1.4.1.9.9.9997.2.6
clWapiMulticastRekeyStrictThis object signals that the MSK shall be refreshed whenever a STA leaves the BSS that possesses the MSK.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.9.9.9997.2.7
clWapiConfigCertificateUpdateCountThis object represents the number of times messages in the WAPI hhandshake protocol will be retried per certificate handshake attempt.rw
Unsigned32
.1.3.6.1.4.1.9.9.9997.2.8
clWapiConfigMulticastUpdateCountThis object represents the number of times message 1 in the WAPI muticast key announcement handshake will be retried per MSK handshake attempt.rw
Unsigned32
.1.3.6.1.4.1.9.9.9997.2.9
clWapiConfigUnicastUpdateCountThis object represents the number of times message 1 and message 3 in the WAPI unicast key announcement handshake will be retried per USK handshake attempt.rw
Unsigned32
.1.3.6.1.4.1.9.9.9997.2.10
cLWCSWapiConfigureVersionThis object represents the WAPI configuration versionro
Integer32
.1.3.6.1.4.1.9.9.9997.2.11
clWapiConfigControlledPortControlThis object indicates the value of the Controlled port. If the value is 0 which means automatic, the current behaviour. The state of the controlled port shall be based on the result of authentication.ro
Enumeration
.1.3.6.1.4.1.9.9.9997.2.12
clWapiUserInvalidCertificationInbreakNetworkThis object represents the WAPI user with invalid certification.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.9997.2.13
cLApWAPISecurityLowAttackThis object represents the WAPI security low attack notification information.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.9997.2.14
clWapiUnicastRekeyMethodThis object selects a mechanism for rekeying the WAPI USK. The default is time-based, once per day. Rekeying the USK is only applicable to an entry acting in the AE role. Method 1 (disabled) will temporarily stop the unicast rekeyingrw
Enumeration
.1.3.6.1.4.1.9.9.9997.2.15
clWapiUnicastRekeyTimeThis object represents the time in seconds after which the WAPI USK will be refreshed. The timer will start the moment the USK was set using the MLME-SETWPIKEYS request primitive.rw
Unsigned32 UNITS "seconds"
.1.3.6.1.4.1.9.9.9997.2.16
clWapiUnicastRekeyMessageThis object represents the message count in thousands after which the WAPI USK will be refreshed. The message counter will start the moment the USK was set using the MLME-SETWPIKEYS request primitive. This MIB will be configurable od of TIME or TIME&PACKETrw
Unsigned32 UNITS "1000 messages"
.1.3.6.1.4.1.9.9.9997.2.17
clWapiConfigSATimeoutThis object represents the maximum time a security association shall take to set up.rw
Unsigned32 UNITS "seconds"
.1.3.6.1.4.1.9.9.9997.2.18
cLApWAPIReplayAttackThis object represents the WAPI replay attack notification information.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.9997.2.19
cLApWAPITamperAttackThis object represents the WAPI tamper attack notification information.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.9997.2.20
clWapiAddressRedirectAttackThis object represents the WAPI redirect attack notification information.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.9.9.9997.2.21
ciscoLwappWapiCertificateObjects
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.9997.3
clWapiWLCCertificateStatusThis object represents the installation state of WLC Certificate. True means the WLC certificate is installed. False means it is uninstalled.ro
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.9.9.9997.3.1
clWapiCACertificateStatusThis object represents the installation state of Certificate Authority Certificate. True means the CA certificate is installed. False means it is uninstalledro
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.9.9.9997.3.2
clWapiASCertificateStatusThis object represents the installation state of Auth Server Certificate. True means the AS certificate is installed. False means it is uninstalled.ro
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.9.9.9997.3.3
ciscoLwappWapiMIBNotifObjects
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.9997.4
ciscoLwappWapiUserInvalidCertificateNetworkTrapThis notification will be sent when the WAPI Client is installed with invalid certificates.
NOTIFICATION-TYPE
.1.3.6.1.4.1.9.9.9997.4.1
ciscoLwappWapiSecurityLowAttackTrapThis notification will be sent when AP received a fake Unicast Key Negotiation Response frame of which the WIE_AUSE is different with that of AP sent before.
NOTIFICATION-TYPE
.1.3.6.1.4.1.9.9.9997.4.2
ciscoLwappWapiReplayAttackTrapThis notification will be sent when AP received an AE challenge is different with that of AP received before.
NOTIFICATION-TYPE
.1.3.6.1.4.1.9.9.9997.4.3
ciscoLwappWapiTamperAttackTrapThis notification will be sent when AP received an invaild Message Authentication Code.
NOTIFICATION-TYPE
.1.3.6.1.4.1.9.9.9997.4.4
ciscoLwappWapiAddressRedirectAttackTrapThis notification will be sent when AP received an address redirect attack trap. Radio interface information (MAC), BSSID, SSID, Mac of station
NOTIFICATION-TYPE
.1.3.6.1.4.1.9.9.9997.4.5