CISCO-SNMP-VACM-EXT-MIB
The CISCO-SNMP-VACM-EXT-MIB extends Cisco's View-based Access Control Model (VACM) to enable multiple group mappings for a single security model and security name combination, thereby granularly controlling SNMP read/write access permissions beyond standard RFC 3415 constraints. This module manages the `vacmSecurityToGroupTable` extensions to allow distinct access policies for the same user identity across different security contexts.
Imported Objects
Objects
10 total| Object Name |
|---|
ciscoSnmpVacmExtMIBThe management information definitions to extend
the View-based Access Control Model (RFC3415) for
SNMP.
This MIB extends the 'SNMP-VIEW-BASED-ACM-MIB' to
allow each combination of a 'securityModel' and a
'securityName' to be mapped into additional
groupNames. The groups identified by these mappings
are in addition to those identified by
'vacmGroupName' of the 'vacmSecurityToGroupTable'. MODULE-IDENTITY .1.3.6.1.4.1.9.9.409 |
ciscoSnmpVacmExtMIBObjects OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.409.1 |
cvacmSecurityToGroupTableAn Extension table to the 'vacmSecurityToGroupTable'
defined in 'SNMP-VIEW-BASED-ACM-MIB.
This table provides a mechanism to map a combination
of 'securityModel' and 'securityName' into one or more
groups in addition to the 'vacmGroupName' mapped in
the 'vacmSecurityToGroupTable'. These groups provide
additional access control policies for a principal.
The agent must allow the same group mapping entry to be
present in both the 'cvacmSecurityToGroupTable' and the
'vacmSecurityToGroupTable'.
A row in this table can not exist without a corresponding
row for the same combination of 'securityModel' and
'securityName in the 'vacmSecurityToGroupTable'.
While creating a row in this table, if there is no
corresponding row for the same combination of
'securityModel' and 'securityName in the
'vacmSecurityToGroupTable', the same mapping entry in
is created in the 'vacmSecurityToGroupTable' by the
agent using the values of instance variables of the entry
in this table.
The deletion of a row in the 'vacmSecurityToGroupTable'
also causes the deletion of all the group mapping
entries for the same combination of 'vacmSecurityModel'
and 'vacmSecurityName' in the 'cvacmSecurityToGroupTable'.
The deletion of a row in this table does not affect
'vacmSecurityToGroupTable'entries. SEQUENCE OF CvacmSecurityToGroupEntry .1.3.6.1.4.1.9.9.409.1.1 |
cvacmSecurityToGroupEntryAn entry (conceptual row) in the
'cvacmSecurityToGroupTable'. Each row represents one
groupName mapping for the combination of 'securityModel'
and 'securityName' in the system. CvacmSecurityToGroupEntry .1.3.6.1.4.1.9.9.409.1.1.1 |
cvacmSecurityGrpNameThe name of the group for the mapping represented by
this row. This is in addition to the 'vacmGroupName'
mapped in the 'vacmSecurityToGroupTable'. For example
a user principal represented by 'securityName' maps
to a group represented by 'cvacmSecurityGrpName' under
a security model represented by 'securityModel'.
This groupName is used as index into the
'vacmAccessTable' to select an access control policy.
However, a value in this table does not imply that an
instance with the value exists in table 'vacmAccesTable'. SnmpAdminString .1.3.6.1.4.1.9.9.409.1.1.1.1 |
cvacmSecurityGrpStorageTypeThe storage type for this conceptual row.
Conceptual rows having the value 'permanent' need not
allow write-access to any columnar objects in the row.rw StorageType (SNMPv2-TC) .1.3.6.1.4.1.9.9.409.1.1.1.2 |
cvacmSecurityGrpStatusThe status of this conceptual row. The value of
this object has no effect on whether other objects
in this conceptual row can be modified.rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.9.9.409.1.1.1.3 |
ciscoSnmpVacmExtMIBConformance OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.409.2 |
ciscoSnmpVacmExtMIBCompliances OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.409.2.1 |
ciscoSnmpVacmExtMIBGroups OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.409.2.2 |
More MIBs from Cisco
Browse all CiscoMIBs →The CISCO-ENTITY-VENDORTYPE-OID-MIB maps Cisco-specific hardware component identifiers to the ENTITY-MIB's entPhysicalTable, enabling precise differentiation of physical device types such as line cards, power supplies, and fans within Cisco infrastructure. This mapping ensures that SNMP management systems can accurately correlate physical inventory entries with vendor-specific component definitions for accurate device discovery and monitoring.
The CISCO-UNIFIED-COMPUTING-EQUIPMENT-MIB provides SNMP-based monitoring and management of Cisco Unified Computing System (UCS) hardware components, including chassis, blades, fabric interconnects, and power supplies. It exposes critical operational metrics such as device status, port states, temperature readings, fan speeds, and power consumption data for infrastructure health assessment.
The CISCO-UNIFIED-COMPUTING-ADAPTOR-MIB enables SNMP-based monitoring and management of physical and virtual network adapter interfaces, including link status, traffic counters, error statistics, and port configuration parameters, within the Cisco Unified Computing System (UCS) fabric interconnects and blade servers.
The CISCO-UNIFIED-COMPUTING-TC-MIB module defines standard textual conventions and data type definitions required for monitoring Cisco Unified Computing System (UCS) hardware components, including server blades, fabric interconnects, and chassis resources. These definitions enable consistent interpretation of specific UCS metrics such as power supply status, fan speeds, thermal readings, and port utilization across SNMP management applications.
The CISCO-UNIFIED-COMPUTING-FABRIC-MIB enables SNMP-based monitoring and management of the Cisco UCS Fabric Interconnects and associated fabric switching infrastructure, exposing metrics for port states, link utilization, error counters, and fabric topology status. It facilitates granular visibility into the physical and logical fabric layers, including uplink/downlink interfaces, VLAN configurations, and fabric failover conditions within the unified computing environment.
The STARENT-MIB module provides SNMP management and monitoring capabilities for Cisco ASR 5000 and ASR 5500 multimedia core platforms, specifically exposing metrics related to 2G/3G/4G and WiFi subscriber sessions, inline service states, and carrier-class high-availability status.