CISCO-REMOTE-ACCESS-MONITOR-MIB
AI MIB Summary
The CISCO-REMOTE-ACCESS-MONITOR-MIB provides vendor-specific instrumentation for Cisco devices to aggregate and monitor performance counters, resource utilization, session states, and security violations across Layer 2 (PPTP, L2TP), Layer 3 (IPSec), and Layer 4 (SSL/SSL VPN) remote access services. It enables fault and capacity management by exposing metrics for connection limits, current active sessions, failure rates, and configurable high-water mark thresholds for both individual sessions and user groups.
Acronyms and Definitions The following acronyms and terms are used in this
document:
IPSec: Secure IP Protocol
VPN: Virtual Private Network
RAS: Remote Access Service
ISP: Internet Service Provider.
LAN: Local Area Network
Group: A collection of remote access users grouped
and managed together as a single entity for administrative convenience.
Session: A Remote Access Session.
SVC: SSL VPN Client
Webvpn: VPN connection established using web browser.
Overview of the MIB
This is a MIB Module for monitoring the structures in Virtual Private Networks based remote access networks. The MIB seeks to create a common model of Remote Access across implementations of the service on layer 2 (PPTP, L2TP, L2F), layer 3 (IPsec) and layer 4 (SSL) virtual private networks. The MIB defines counters and objects of interest to performance/fault monitoring in a way which is independent of the technology of the remote access implementation.
MIB contains eight major groups of objects which are used to manage Remote Access connections: a) Remote Access capacity group This section defines metrics to gauge the limits of resources on this device which are critical to RAS service.
b) Remote Access resource usage group This section defines metrics to gauge the usage of resources on this device which are critical to RAS service service.
c) Current activity and performance of RAS service This section defines metrics to gauge the current remote access activity.
d) Remote Access Service failures This section defines metrics to monitor session failures and failures of the service itself, measured at aggregate level, session level and group level.
e) Security violations in the Remote Access service This section defines metrics which reflect the state of remote access service of interest to Security Operations staff in an enterprise.
f) Threshold group (allows definition of high water marks) This section allows the management entity to define thresholds to set high water marks on critical metrics.
g) Notifications This section defines notifications to signal significant events pertaining to the Remote Access Service.
Main OID:
ciscoRemoteAccessMonitorMIB.1.3.6.1.4.1.9.9.392
139
Objects
Active
Status
6
Dependencies
Imported Objects
Objects
139 total| Object Name |
|---|
ciscoRemoteAccessMonitorMIBAcronyms and Definitions
The following acronyms and terms are used in this
document:
IPSec: Secure IP Protocol
VPN: Virtual Private Network
RAS: Remote Access Service
ISP: Internet Service Provider.
LAN: Local Area Network
Group: A collection of remote access users grouped
and managed together as a single entity for
administrative convenience.
Session: A Remote Access Session.
SVC: SSL VPN Client
Webvpn: VPN connection established using web browser.
Overview of the MIB
This is a MIB Module for monitoring the structures in Virtual
Private Networks based remote access networks. The MIB seeks
to create a common model of Remote Access across implementations
of the service on layer 2 (PPTP, L2TP, L2F), layer 3 (IPsec) and
layer 4 (SSL) virtual private networks. The MIB defines counters
and objects of interest to performance/fault monitoring in a
way which is independent of the technology of the remote access
implementation.
MIB contains eight major groups of objects which are used
to manage Remote Access connections:
a) Remote Access capacity group
This section defines metrics to gauge the limits of
resources on this device which are critical to RAS
service.
b) Remote Access resource usage group
This section defines metrics to gauge the usage of
resources on this device which are critical to RAS
service service.
c) Current activity and performance of RAS service
This section defines metrics to gauge the current
remote access activity.
d) Remote Access Service failures
This section defines metrics to monitor session
failures and failures of the service itself, measured
at aggregate level, session level and group level.
e) Security violations in the Remote Access service
This section defines metrics which reflect the state
of remote access service of interest to Security
Operations staff in an enterprise.
f) Threshold group (allows definition of high water marks)
This section allows the management entity to define
thresholds to set high water marks on critical metrics.
g) Notifications
This section defines notifications to signal
significant events pertaining to the Remote Access
Service. MODULE-IDENTITY .1.3.6.1.4.1.9.9.392 |
ciscoRasMonitorMIBNotifs OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.392.0 |
ciscoRasTooManySessionsThis notification is generated when the managed entity
detects that the number of sessions established exceeds
the set threshold crasThrMaxSessions.
Once the notification has been issued, further
notifications are suppressed till the value returns
below the specified threshold. NOTIFICATION-TYPE .1.3.6.1.4.1.9.9.392.0.1 |
ciscoRasTooManyFailedAuthsThis notification is generated when the managed entity
detects that the number of login attempts (over all
users) exceeds the set threshold for throughput
(crasThrMaxFailedAuths).
Once the notification has been issued, further
notifications are suppressed till the value returns
below the specified threshold. NOTIFICATION-TYPE .1.3.6.1.4.1.9.9.392.0.2 |
ciscoRasTooHighThroughputThis notification is generated when the managed entity
detects that the current throughput of the device exceeds
the set threshold for throughput (crasThrMaxThroughput).
Once the notification has been issued, further
notiifcations are suppressed till the value returns
below the specified threshold. NOTIFICATION-TYPE .1.3.6.1.4.1.9.9.392.0.3 |
ciscoRasMonitorMIBObjects OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.392.1 |
crasCapacity OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.392.1.1 |
crasMaxSessionsSupportableThe maximum number of remote access sessions
that may be supported on this device.
If the device imposes no arbitrary limit on the
maximum number of sessions, it should return a
value of 0.ro Integer32 .1.3.6.1.4.1.9.9.392.1.1.1 |
crasMaxUsersSupportableThe maximum number of remote access users
for whom Remote Access sessions may be supported on
this device.
If the device imposes no arbitrary limit on the
maximum number of users, it should return a
value of 0.ro Integer32 .1.3.6.1.4.1.9.9.392.1.1.2 |
crasMaxGroupsSupportableThe maximum number of remote access groups
that may be defined on this device. 'Group'
refers to a collection of users grouped together
for administrative convenience.
If the device imposes no arbitrary limit on
the maximum number of groups, it should return
a value of 0.ro Integer32 .1.3.6.1.4.1.9.9.392.1.1.3 |
crasNumCryptoAcceleratorsThe maximum number of hardware crypto accelerators
which can be installed on this device to support
remote access sessions. 'cryptoaccelerator' denotes
a hardware/software entity which the managed entity
uses to offload some or all computations pertaining
to cryptographic operations.
If the device imposes no arbitrary limit on the
number of crypto accelerators to support Remote Access
function, it should return a value of 0.ro Integer32 .1.3.6.1.4.1.9.9.392.1.1.4 |
crasResourceUsage OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.392.1.2 |
crasGlobalBwUsageThe average bandwidth used by all the active
remote access sessions.ro Gauge32 UNITS "MBytes/second" .1.3.6.1.4.1.9.9.392.1.2.1 |
crasActivity OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.392.1.3 |
crasNumSessionsThe number of currently active sessions.
A session is a connection terminating on the managed
entity which has been established to provide remote
access connectivity to a user. A session is said to be
'active' if it is ready to carry application traffic
between the user and the managed entity. A session which
is not active is defined to be 'dormant'.ro Gauge32 UNITS "Sessions" .1.3.6.1.4.1.9.9.392.1.3.1 |
crasNumPrevSessionsThe number of remote access sessions which were
previously active but which where since terminated.
Measured since the last reboot of the device.ro Counter32 UNITS "Sessions" .1.3.6.1.4.1.9.9.392.1.3.2 |
crasNumUsersThe number of users who have active sessions.ro Gauge32 UNITS "Users" .1.3.6.1.4.1.9.9.392.1.3.3 |
crasNumGroupsThe number of user groups whose members have
active sessions.ro Gauge32 UNITS "Groups" .1.3.6.1.4.1.9.9.392.1.3.4 |
crasGlobalInPktsThe total number of packets received by all
currently and previously active remote access
sessions.ro Counter64 UNITS "Packets" .1.3.6.1.4.1.9.9.392.1.3.5 |
crasGlobalOutPktsThe total number of packets transmitted by all
currently and previously active remote access
sessions.ro Counter64 UNITS "Packets" .1.3.6.1.4.1.9.9.392.1.3.6 |
crasGlobalInOctetsThe total number of octets received by all currently
and previously active remote access sessions.
This value is accumulated BEFORE determining whether
or not the packet should be decompressed.ro Counter64 UNITS "Octets" .1.3.6.1.4.1.9.9.392.1.3.7 |
crasGlobalInDecompOctetsThe total number of decompressed octets received
by all current and previous remote access sessions.
This value is accumulated AFTER the packet is
decompressed. If compression is not being used,
this value will match the value of crasGlobalInOctets.ro Counter64 UNITS "Octets" .1.3.6.1.4.1.9.9.392.1.3.8 |
crasGlobalOutOctetsThe total number of octets transmitted by all
currently and previously active remote access
sessions.
This value is accumulated AFTER determining
whether or not the packet should be compressed.ro Counter64 UNITS "Octets" .1.3.6.1.4.1.9.9.392.1.3.9 |
crasGlobalOutUncompOctetsThe total number of uncompressed octets sent
by all current and previous remote access sessions.
This value is accumulated BEFORE the packet is
compressed. If compression is not being used, this
value will match the value of crasGlobalOutOctets.ro Counter64 UNITS "Octets" .1.3.6.1.4.1.9.9.392.1.3.10 |
crasGlobalInDropPktsThe total number of packets which were dropped
during receive processing by all currently and
previously active remote access sessions.ro Counter64 UNITS "Packets" .1.3.6.1.4.1.9.9.392.1.3.11 |
crasGlobalOutDropPktsThe total number of packets which were
dropped during receive processing by all
currently and previously active remote access
sessions.ro Counter64 UNITS "Packets" .1.3.6.1.4.1.9.9.392.1.3.12 |
crasSessionTableThis table lists all the currently active sessions.
For each session, it lists the attributes (user,
group, protocol, security), statistics (packet and
octets) and status. SEQUENCE OF CrasSessionEntry .1.3.6.1.4.1.9.9.392.1.3.21 |
crasSessionEntryEach entry contains the attributes, statistics and
status of an active session. CrasSessionEntry .1.3.6.1.4.1.9.9.392.1.3.21.1 |
crasUsernameThe name of the user associated with this remote
access session. SnmpAdminString .1.3.6.1.4.1.9.9.392.1.3.21.1.1 |
crasGroupThe name of the user group to which this remote
access session belongs.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.4.1.9.9.392.1.3.21.1.2 |
crasSessionIndexUnique index to distinguish between multiple
Remote Access Sessions associated with the same
user.
The value of crasSessionIndex must increase monotonically
till it wraps. An implementation may choose to wrap this
index before the value of 2147483647. SessionIndex .1.3.6.1.4.1.9.9.392.1.3.21.1.3 |
crasAuthenMethodThe method used to authenticate the user prior to
establishing the session.ro UserAuthenMethod .1.3.6.1.4.1.9.9.392.1.3.21.1.4 |
crasAuthorMethodThe method used to authorize the user prior to
establishing the session.ro UserAuthorMethod .1.3.6.1.4.1.9.9.392.1.3.21.1.5 |
crasSessionDurationThe number of seconds elapsed since this session
was established.ro Counter32 .1.3.6.1.4.1.9.9.392.1.3.21.1.6 |
crasLocalAddressTypeThe type of the address returned in 'crasLocalAddress'.ro InetAddressType (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.392.1.3.21.1.7 |
crasLocalAddressThe IP address assigned to the client of this session
in the private network assigned by the managed entity.ro InetAddress (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.392.1.3.21.1.8 |
crasISPAddressTypeThe type of the address returned in 'crasISPAddress'.ro InetAddressType (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.392.1.3.21.1.9 |
crasISPAddressThe IP address of the peer (client) assigned by the ISP.
This is the address of the client device in the public
network.ro InetAddress (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.392.1.3.21.1.10 |
crasSessionProtocolThe protocol underlying this remote access session.ro RasProtocol .1.3.6.1.4.1.9.9.392.1.3.21.1.11 |
crasProtocolElementA reference to MIB definitions specific to the protocol
underlying corresponding to the session or tunnel
used to realized the remote access session corresponding
to this conceptual row.
For instance, if this remote access session is based on
IPsec, then this object must contain the complete
instance identifier of the IPsec tunnel corresponding
to this remote access session.
If no MIB definitions specific to the underlying
protocol are available, the value should be set to the
OBJECT IDENTIFIER { 0 0 }.ro OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.392.1.3.21.1.12 |
crasSessionEncryptionAlgoThe algorithm used by this remote access session to
encrypt its payload.ro SessionEncrAlgo .1.3.6.1.4.1.9.9.392.1.3.21.1.13 |
crasSessionPktAuthenAlgoThe algorithm used by this remote access session to
to validate packets.ro SessionAuthAlgo .1.3.6.1.4.1.9.9.392.1.3.21.1.14 |
crasSessionCompressionAlgoThe algorithm used by this remote access session to
compress packets.ro SessionCompressionAlgo .1.3.6.1.4.1.9.9.392.1.3.21.1.15 |
crasHeartbeatIntervalThe interval in seconds between two successive heartbeats
employed by this session. Value of 0 denotes that no
heartbeat is used.ro Unsigned32 .1.3.6.1.4.1.9.9.392.1.3.21.1.16 |
crasClientVendorStringThe string identifying the vendor of the client
application initiating this Remote Access session.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.4.1.9.9.392.1.3.21.1.17 |
crasClientVersionStringThe string identifying the version of the of the client
application initiating the Remote Access session.
This can be used by the administrator to identify which
users are running unsupported client versions.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.4.1.9.9.392.1.3.21.1.18 |
crasClientOSVendorStringThe string identifying the vendor of the operating system
on which the client application initiating the Remote Access
Session is running.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.4.1.9.9.392.1.3.21.1.19 |
crasClientOSVersionStringThe string identifying the version of the operating
system of the entity which initiated this Remote Access
session.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.4.1.9.9.392.1.3.21.1.20 |
crasPrimWINSServerAddrTypeThe type of the address returned in
'crasPrimWINSServer'.ro InetAddressType (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.392.1.3.21.1.21 |
crasPrimWINSServerThe IP address of the primary WINS server assigned
managed entity to this client session.ro InetAddress (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.392.1.3.21.1.22 |
crasSecWINSServerAddrTypeThe type of the address returned in
'crasSecWINSServer'.ro InetAddressType (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.392.1.3.21.1.23 |
crasSecWINSServerThe IP address of the secondary WINS server assigned
by the managed entity to this client session.ro InetAddress (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.392.1.3.21.1.24 |
crasPrimDNSServerAddrTypeThe type of the address returned in
'crasPrimDNSServer'.ro InetAddressType (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.392.1.3.21.1.25 |
crasPrimDNSServerThe IP address of the primary DNS server assigned by
the managed entity to this client session.ro InetAddress (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.392.1.3.21.1.26 |
crasSecDNSServerAddrTypeThe type of the address returned in
'crasSecDNSServer'.ro InetAddressType (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.392.1.3.21.1.27 |
crasSecDNSServerThe IP address of the secondary DNS server assigned
by the managed entity to this client session.ro InetAddress (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.392.1.3.21.1.28 |
crasDHCPServerAddrTypeThe type of the address returned in
'crasDHCPServer'.ro InetAddressType (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.392.1.3.21.1.29 |
crasDHCPServerThe IP address of the DHCP server assigned by the
managed entity to this client session.ro InetAddress (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.392.1.3.21.1.30 |
crasSessionInPktsThe total number of packets received by this Remote
Access session.ro Counter64 UNITS "Packets" .1.3.6.1.4.1.9.9.392.1.3.21.1.31 |
crasSessionOutPktsThe total number of packets transmitted by this
Remote Access Session.ro Counter64 UNITS "Packets" .1.3.6.1.4.1.9.9.392.1.3.21.1.32 |
crasSessionInDropPktsThe total number of packets received for processing
on this session which were dropped by the managed entity.ro Counter64 UNITS "Packets" .1.3.6.1.4.1.9.9.392.1.3.21.1.33 |
crasSessionOutDropPktsThe total number of outgoing packets on this session
which were dropped during transmit processing by the
managed entity.ro Counter64 UNITS "Packets" .1.3.6.1.4.1.9.9.392.1.3.21.1.34 |
crasSessionInOctetsThe total number of octets received by this Remote
Access Session.
This value is accumulated BEFORE determining whether
or not the packet should be decompressed.ro Counter64 UNITS "Octets" .1.3.6.1.4.1.9.9.392.1.3.21.1.35 |
crasSessionOutOctetsThe total number of octets transmitted by this Remote
Access Session.
This value is accumulated AFTER determining whether
or not the packet should be compressed.ro Counter64 UNITS "Octets" .1.3.6.1.4.1.9.9.392.1.3.21.1.36 |
crasSessionStateThe state of the remote access session corresponding
to this conceptual row.
The management entity may use this object to terminate
an established session by setting value of the object
to 'terminating'.rw SessionStatus .1.3.6.1.4.1.9.9.392.1.3.21.1.37 |
crasActGroupTableThis table lists all the currently active remote
access user groups. For each group, it lists the
attributes (group, aggregate activity, aggregate
traffic), and status. SEQUENCE OF CrasActGroupEntry .1.3.6.1.4.1.9.9.392.1.3.22 |
crasActGroupEntryEach entry contains the attributes, statistics and
status of an active session. CrasActGroupEntry .1.3.6.1.4.1.9.9.392.1.3.22.1 |
crasActGrpNameThe name of the active user group corresponding to
this entry. SnmpAdminString .1.3.6.1.4.1.9.9.392.1.3.22.1.1 |
crasActGrNumUsersThe number of users in this group currently connected
to the managed device.ro Integer32 .1.3.6.1.4.1.9.9.392.1.3.22.1.2 |
crasActGrpInPktsThe total number of packets received by this session.ro Counter64 UNITS "Packets" .1.3.6.1.4.1.9.9.392.1.3.22.1.3 |
crasActGrpOutPktsThe total number of packets transmitted by this session.ro Counter64 UNITS "Packets" .1.3.6.1.4.1.9.9.392.1.3.22.1.4 |
crasActGrpInDropPktsThe total number of packets dropped by this session
which were received for processing.ro Counter64 UNITS "Packets" .1.3.6.1.4.1.9.9.392.1.3.22.1.5 |
crasActGrpOutDropPktsThe total number of outgoing packets which were
dropped during transmit processing by this session.ro Counter64 UNITS "Packets" .1.3.6.1.4.1.9.9.392.1.3.22.1.6 |
crasActGrpInOctetsThe total number of octets received by this session.ro Counter64 UNITS "Octets" .1.3.6.1.4.1.9.9.392.1.3.22.1.7 |
crasActGrpOutOctetsThe total number of octets transmitted by this session.ro Counter64 UNITS "Octets" .1.3.6.1.4.1.9.9.392.1.3.22.1.8 |
crasEmailNumSessionsThe number of currently active Email proxy sessions.ro Gauge32 UNITS "Sessions" .1.3.6.1.4.1.9.9.392.1.3.23 |
crasEmailCumulateSessionsThe number of cumulative Email proxy sessions since system up.ro Counter32 UNITS "Sessions" .1.3.6.1.4.1.9.9.392.1.3.24 |
crasEmailPeakConcurrentSessionsThe number of peak concurrent Email proxy sessions since system up.ro Unsigned32 UNITS "Sessions" .1.3.6.1.4.1.9.9.392.1.3.25 |
crasIPSecNumSessionsThe number of currently active IPSec sessions.ro Gauge32 UNITS "Sessions" .1.3.6.1.4.1.9.9.392.1.3.26 |
crasIPSecCumulateSessionsThe number of cumulative IPSec sessions since system up.ro Counter32 UNITS "Sessions" .1.3.6.1.4.1.9.9.392.1.3.27 |
crasIPSecPeakConcurrentSessionsThe number of peak concurrent Email proxy sessions since system up.ro Unsigned32 UNITS "Sessions" .1.3.6.1.4.1.9.9.392.1.3.28 |
crasL2LNumSessionsThe number of currently active LAN to LAN sessions.ro Gauge32 UNITS "Sessions" .1.3.6.1.4.1.9.9.392.1.3.29 |
crasL2LCumulateSessionsThe number of cumulative LAN to LAN sessions since system up.ro Counter32 UNITS "Sessions" .1.3.6.1.4.1.9.9.392.1.3.30 |
crasL2LPeakConcurrentSessionsThe number of peak concurrent LAN to LAN sessions since system up.ro Unsigned32 UNITS "Sessions" .1.3.6.1.4.1.9.9.392.1.3.31 |
crasLBNumSessionsThe number of currently active Load Balancing sessions.ro Gauge32 UNITS "Sessions" .1.3.6.1.4.1.9.9.392.1.3.32 |
crasLBCumulateSessionsThe number of cumulative Load Balancing sessions since system up.ro Counter32 UNITS "Sessions" .1.3.6.1.4.1.9.9.392.1.3.33 |
crasLBPeakConcurrentSessionsThe number of peak concurrent Load Balancing sessions since system up.ro Unsigned32 UNITS "Sessions" .1.3.6.1.4.1.9.9.392.1.3.34 |
crasSVCNumSessionsThe number of currently active SVC sessions.ro Gauge32 UNITS "Sessions" .1.3.6.1.4.1.9.9.392.1.3.35 |
crasSVCCumulateSessionsThe number of cumulative SVC sessions since system up.ro Counter32 UNITS "Sessions" .1.3.6.1.4.1.9.9.392.1.3.36 |
crasSVCPeakConcurrentSessionsThe number of peak concurrent SVC sessions since system up.ro Unsigned32 UNITS "Sessions" .1.3.6.1.4.1.9.9.392.1.3.37 |
crasWebvpnNumSessionsThe number of currently active Webvpn sessions.ro Gauge32 UNITS "Sessions" .1.3.6.1.4.1.9.9.392.1.3.38 |
crasWebvpnCumulateSessionsThe number of cumulative Webvpn sessions since system up.ro Counter32 UNITS "Sessions" .1.3.6.1.4.1.9.9.392.1.3.39 |
crasWebvpnPeakConcurrentSessionsThe number of peak concurrent Webvpn sessions since system up.ro Unsigned32 UNITS "Sessions" .1.3.6.1.4.1.9.9.392.1.3.40 |
crasFailures OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.392.1.4 |
crasFailuresGlobals OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.392.1.4.1 |
crasNumTotalFailuresThe number of attempts to establish sessions which
failed, since the last reboot of the managed device.ro Counter64 .1.3.6.1.4.1.9.9.392.1.4.1.1 |
crasNumDeclinedSessionsThe number of session setup attempts, counted since
the last time the notification
'ciscoRasTooManyFailedAuths' was issued, which were
declined due to authentication or authorization
failure.ro Unsigned32 .1.3.6.1.4.1.9.9.392.1.4.1.2 |
crasNumSetupFailInsufResourcesThe number of session setup attempts that failed
due to insufficient resources.ro Counter64 UNITS "Sessions" .1.3.6.1.4.1.9.9.392.1.4.1.3 |
crasNumAbortedSessionsThe number of sessions which were successfully
setup but were since terminated abnormally.ro Counter64 UNITS "Sessions" .1.3.6.1.4.1.9.9.392.1.4.1.4 |
crasFailGlobalCntl OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.392.1.4.2 |
crasFailTableSizeThe window size of the Remote Access Failure tables.
The failure tables for session and group failures
maintain only the last crasFailTableSize number of
failure records. A value of 0 for this MIB variable
indicates that archiving of the failures is disabled.
An implementation may choose suitable minimum and
maximum values for this element based on the local
policy and available resources. If an SNMP SET request
specifies a value outside this window for this element,
a BAD VALUE may be returned.rw Unsigned32 .1.3.6.1.4.1.9.9.392.1.4.2.1 |
crasSessFailures OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.392.1.4.3 |
crasSessFailTableThis table records the last 'N' session failures,
where 'N' is the value of the MIB element
'crasFailTableSize' defined earlier.
A failure could be a failure to establish a session
('setup' failure) or a failure of a session after it
was established ('operational' failure). SEQUENCE OF CrasSessFailEntry .1.3.6.1.4.1.9.9.392.1.4.3.1 |
crasSessFailEntryEach entry contains the attributes associated with
a remote access session failure. CrasSessFailEntry .1.3.6.1.4.1.9.9.392.1.4.3.1.1 |
crasSessFailIndexThe index of the session failure table.
The value of the index is a number which
begins at one and is incremented with each
session failure. The value of this object will
wrap at 4,294,967,295. FailureRecordIndex .1.3.6.1.4.1.9.9.392.1.4.3.1.1.1 |
crasSessFailUsernameThe name of the user associated with this failed
remote access session.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.4.1.9.9.392.1.4.3.1.1.2 |
crasSessFailGroupnameThe name of the user group to which this failed
remote access session belongs.ro SnmpAdminString (SNMP-FRAMEWORK-MIB) .1.3.6.1.4.1.9.9.392.1.4.3.1.1.3 |
crasSessFailTypeThe type of the failure:
1 = failure occurred during session setup
2 = failed occurred after the session was setup
successfully.ro Enumeration .1.3.6.1.4.1.9.9.392.1.4.3.1.1.4 |
crasSessFailReasonThe reason for the failure. Possible reasons
include:
1 = other (error which cannot be classified in
any of the types listed below).
2 = internal error occurred
3 = failed to authenticate the peer/user
4 = failed to authorize the peer/user
5 = system capacity exceeded (memory, cpu, max
users etc)
6 = peer requested to abort the session or the
setup
7 = lost peer's heartbeat
8 = local management request.ro Enumeration .1.3.6.1.4.1.9.9.392.1.4.3.1.1.5 |
crasSessFailTimeThe value of the MIB element 'sysUpTime'
at the time of the failure.ro TimeStamp (SNMPv2-TC) .1.3.6.1.4.1.9.9.392.1.4.3.1.1.6 |
crasSessFailSessionIndexThe index of the session which failed (in case
this was an operational failure). In case of setup
failures (where the value of 'crasSessFailType' of
this conceptual row is 'operationalFailure'), the
value of this object is undefined and should not be
processed.ro SessionIndex .1.3.6.1.4.1.9.9.392.1.4.3.1.1.7 |
crasSessFailISPAddrTypeThe type of the address returned in
'crasSessFailISPAddr'.ro InetAddressType (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.392.1.4.3.1.1.8 |
crasSessFailISPAddrThe public address of the peer.ro InetAddress (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.392.1.4.3.1.1.9 |
crasSessFailLocalAddrTypeThe type of the address returned in
'crasSessFailLocalAddr'.ro InetAddressType (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.392.1.4.3.1.1.10 |
crasSessFailLocalAddrThe address assigned to the peer by the local
address management mechanism. In case no address
was assigned to the peer when the failure occurred,
this MIB variable would contain the IPv4 address
value 0.0.0.0ro InetAddress (INET-ADDRESS-MIB) .1.3.6.1.4.1.9.9.392.1.4.3.1.1.11 |
crasFailLastFailIndexThe value of column 'crasSessFailIndex'
corresponding to the last row added to the
crasSessFailTable.
The value of this object is undefined and should
not be processed by the management entity if the
value of the object 'crasFailTableSize' is 0.ro FailureRecordIndex .1.3.6.1.4.1.9.9.392.1.4.3.2 |
crasGroupFailures OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.392.1.4.4 |
crasGrpFailTableThis table records the last 'N' occurrences of
failures (setup or operational) per user group,
where 'N' is the value of the MIB element
'crasFailTableSize' defined earlier.
When 'N' entries have been created, the failure
information about a new user group must be created by
deleting the oldest entry in this table. SEQUENCE OF CrasGrpFailEntry .1.3.6.1.4.1.9.9.392.1.4.4.1 |
crasGrpFailEntryEach entry contains the summary of failures for a
specific user group. CrasGrpFailEntry .1.3.6.1.4.1.9.9.392.1.4.4.1.1 |
crasGrpFailGroupnameThe name of the user group to which this failure
record corresponds.
This is the index of the group failure table. SnmpAdminString .1.3.6.1.4.1.9.9.392.1.4.4.1.1.1 |
crasGrpFailNumFailAuthsThe number of sessions belonging to this group which
failed authentication; counted since last reboot.ro Counter64 .1.3.6.1.4.1.9.9.392.1.4.4.1.1.2 |
crasGrpFailNumResourceFailuresThe number of session setup attempts which failed due
to insufficient resources.ro Counter64 .1.3.6.1.4.1.9.9.392.1.4.4.1.1.3 |
crasGrpFailNumDeclinedThe number of session setup attempts which were declined
by the managed entity due to local policy. These would
include sessions which were denied due to rate control
settings.ro Counter64 .1.3.6.1.4.1.9.9.392.1.4.4.1.1.4 |
crasGrpFailNumTerminatedMgmtThe number of established sessions which were terminated
by explicit management action. The termination may have
been triggered locally or based on a request from the peer.ro Counter64 .1.3.6.1.4.1.9.9.392.1.4.4.1.1.5 |
crasGrpFailNumTerminatedOtherThe number of established sessions which were
terminated due to insufficient reasons, internal error
or other reasons not caused by management action.ro Counter64 .1.3.6.1.4.1.9.9.392.1.4.4.1.1.6 |
crasSecurity OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.392.1.5 |
crasSecurityGlobals OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.392.1.5.1 |
crasNumDisabledAccountsThe total number of user accounts which were
disabled due to repeated login failures.ro Counter64 UNITS "Users" .1.3.6.1.4.1.9.9.392.1.5.1.1 |
crasThresholds OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.392.1.6 |
crasThrMaxSessionsThe maximum number of sessions which are successfully
setup after which the managed entity should alert the
network management entity using the notification
'ciscoRasTooManySessions', if the notification has been
enabled.
A value of 0 indicates that the threshold has not been
set.ro Integer32 .1.3.6.1.4.1.9.9.392.1.6.1 |
crasThrMaxFailedAuthsThe value of object 'crasNumDeclinedSessions' at
which the managed entity should alert the network
management entity using the notification
'ciscoRasTooManyFailedAuths', if the notification
has been enabled.
A value of 0 indicates that the threshold has not been
set.ro Unsigned32 .1.3.6.1.4.1.9.9.392.1.6.2 |
crasThrMaxThroughputThe highest throughput of the Remote Access Service at
which the managed entity should alert the network management
entity using the notification 'ciscoRasTooHighThroughput',
if the notification has been enabled.
The notification is disabled till the value of the
aggregate throughput of the managed entity drops below
the value of this object.
A value of 0 indicates that the threshold has not been
set.ro Integer32 .1.3.6.1.4.1.9.9.392.1.6.3 |
crasNotifCntl OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.392.1.7 |
crasCntlTooManySessionsThis object defines the administrative state of
sending the trap to signal the violation of the
Max session threshold.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.9.9.392.1.7.1 |
crasCntlTooManyFailedAuthsThis object defines the administrative state of
sending the trap to signal the violation of the
Max authentication failure count threshold.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.9.9.392.1.7.2 |
crasCntlTooHighThroughputThis object defines the administrative state of
sending the trap to signal the violation of the
Max throughput threshold.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.9.9.392.1.7.3 |
ciscoRasMonitorMIBConform OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.392.2 |
ciscoRasMonitorMIBCompliances OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.392.2.1 |
ciscoRasMonitorMIBGroups OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.392.2.2 |