Home/Catalog/CISCO-SNMP-HANDSHAKE-MIB

CISCO-SNMP-HANDSHAKE-MIB

AI MIB Summary

The CISCO-SNMP-HANDSHAKE-MIB implements an application-layer authentication handshake on Cisco devices to dynamically provision View-based Access Control Model (VACM) entries, restricting SNMPv2c community string or SNMPv3 user access to specific MIB views until a verified session is established. This mechanism enforces strict, pre-access authorization for known SNMP managers, preventing unauthorized third-party browsers from retrieving data via standard SNMP protocol queries.

This MIB is intended for those devices where SNMP access is given to be given to known SNMP Manager only. All the SNMP MIBs are published, any thrid party SNMP browser can retrieve data using SNMP protocol. By implementing this MIB, a application layer handshake has to be done before any MIB view access is granted to SNMPV2c community string or SNMPV3 user. Once the handshake is successfully over then SNMP agent can create VACM entry to provide access to any MIB view. GLOSSARY View-based Access Control Model ( VACM ) The VACM determines whether access to a managed object in a local MIB by a remote SNMP manager should be allowed.
Main OID:
ciscoSnmpHandshakeMIB.1.3.6.1.4.1.14179.2.40
13
Objects
Active
Status
4
Dependencies

Imported Objects

Objects

13 total
Object Name
ciscoSnmpHandshakeMIBThis MIB is intended for those devices where SNMP access is given to be given to known SNMP Manager only. All the SNMP MIBs are published, any thrid party SNMP browser can retrieve data using SNMP protocol. By implementing this MIB, a application layer handshake has to be done before any MIB view access is granted to SNMPV2c community string or SNMPV3 user. Once the handshake is successfully over then SNMP agent can create VACM entry to provide access to any MIB view. GLOSSARY View-based Access Control Model ( VACM ) The VACM determines whether access to a managed object in a local MIB by a remote SNMP manager should be allowed.
MODULE-IDENTITY
.1.3.6.1.4.1.14179.2.40
ciscoSnmpHandshakeMIBNotifs
OBJECT IDENTIFIER
.1.3.6.1.4.1.14179.2.40.0
ciscoSnmpHandshakeMIBObjects
OBJECT IDENTIFIER
.1.3.6.1.4.1.14179.2.40.1
ciscoSnmpHandshakeProcess
OBJECT IDENTIFIER
.1.3.6.1.4.1.14179.2.40.1.1
csHandshakeInitGet on this object will return random 16 bytes octet-string. Device will cache this string against IP-Address of sender. This string will be later used to comeplete the handshake.ro
OCTET STRING
.1.3.6.1.4.1.14179.2.40.1.1.1
csHandshakeUpdateSet on this object will make snmp agent to run the secret algorithm to give access or deny access to SNMP manager. Access will be given to the community string used and to the sender's IP-Address only.rw
OCTET STRING
.1.3.6.1.4.1.14179.2.40.1.1.2
ciscoSnmpHandshakeTest
OBJECT IDENTIFIER
.1.3.6.1.4.1.14179.2.40.1.2
csHandshakeCheckThis object can be use to perform test of MIB view access. Once the handshake is successfully completed. The MIB-view access will be granted for this object, If MIB-view is not granted yet for this object then no-access error will be returned.ro
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.14179.2.40.1.2.1
ciscoSnmpHandshakeMIBConform
OBJECT IDENTIFIER
.1.3.6.1.4.1.14179.2.40.2
ciscoSnmpHandshakeMIBCompliances
OBJECT IDENTIFIER
.1.3.6.1.4.1.14179.2.40.2.1
ciscoSnmpHandshakeMIBComplianceThe compliance statement for the SNMP entities that implement the ciscoSnmpHandshakeMIB module.
Unknown
.1.3.6.1.4.1.14179.2.40.2.1.1
ciscoSnmpHandshakeMIBGroups
OBJECT IDENTIFIER
.1.3.6.1.4.1.14179.2.40.2.2
ciscoSnmpHandshakeGroupThis collection of objects represents the information about attributes needed to completed SNMP handhshake
Unknown
.1.3.6.1.4.1.14179.2.40.2.2.1