CISCOSB-SECURITY-SUITE
AI MIB Summary
The CISCOSB-SECURITY-SUITE MIB module enables monitoring of Denial of Service (DoS), SYN flood, and known virus attack blocking events on Cisco Security Board (CISCOSB) devices. It provides visibility into specific intrusion prevention metrics and security event counters generated by the device's attack mitigation subsystem.
The private MIB module definition for blocking attacks such as DoS(=Denial Of Service), SYN and well known viruses Attacks in CISCOSB devices.
Main OID:
rlSecuritySuiteMib.1.3.6.1.4.1.9.6.1.101.120
44
Objects
Active
Status
5
Dependencies
Imported Objects
Objects
44 total| Object Name |
|---|
rlSecuritySuiteMibThe private MIB module definition for blocking attacks
such as DoS(=Denial Of Service), SYN and well known viruses Attacks
in CISCOSB devices. MODULE-IDENTITY .1.3.6.1.4.1.9.6.1.101.120 |
rlSecuritySuiteGlobalEnableThis scalar globally enables/disables the DoS attack Suite.rw RlsecuritySuiteGlobalEnableType .1.3.6.1.4.1.9.6.1.101.120.1 |
rlSecuritySuiteKnownDoSAttacksTableThis table enables/disable well-know DoS attacks,
applied globally to all ifIndexes. SEQUENCE OF RlSecuritySuiteKnownDoSAttacksEntry .1.3.6.1.4.1.9.6.1.101.120.2 |
rlSecuritySuiteKnownDoSAttacksEntryEach entry in this table describes one well known DoS attack address RlSecuritySuiteKnownDoSAttacksEntry .1.3.6.1.4.1.9.6.1.101.120.2.1 |
rlSecuritySuiteKnownDoSAttackA well-known DoS attack to enable RlSecuritySuiteKnownDosAttackType .1.3.6.1.4.1.9.6.1.101.120.2.1.1 |
rlSecuritySuiteKnownDoSAttackEnableEnable/Disable a well-known DoS attackrw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.9.6.1.101.120.2.1.2 |
rlSecuritySuiteKnownDoSAttacksDetailsTableThis read-only table used to present the detailed attributes
of each well-known DoS attack. Used for presentation propose only. SEQUENCE OF RlSecuritySuiteKnownDoSAttacksDetailsEntry .1.3.6.1.4.1.9.6.1.101.120.3 |
rlSecuritySuiteKnownDoSAttacksDetailsEntryEach entry in this table describes one well known DoS attack address , RlSecuritySuiteKnownDoSAttacksDetailsEntry .1.3.6.1.4.1.9.6.1.101.120.3.1 |
rlSecuritySuiteKnownDoSAttackProtoclSpecifies the protocol type of the relevant well-known attackro RlSecuritySuiteKnownDosAttackProtocolType .1.3.6.1.4.1.9.6.1.101.120.3.1.1 |
rlSecuritySuiteKnownDoSAttackSrcTcpUdpPortSpecifies the source tcp/udp port of the relevant well-known attackro INTEGER .1.3.6.1.4.1.9.6.1.101.120.3.1.2 |
rlSecuritySuiteKnownDoSAttackDestTcpUdpPortSpecifies the destination tcp/udp port of the relevant well-known attackro INTEGER .1.3.6.1.4.1.9.6.1.101.120.3.1.3 |
rlSecuritySuiteReservedMartianAddressesThis scalar globally enables/disables discarding of the IP
well-known addresses described below:
| Address block | Present use
|
|0.0.0.0/8 | Addresses in this block refer to source hosts
|(except 0.0.0.0/32 | on 'this' network.
| as source address) |
|
|127.0.0.0/8 | This block is assigned for use as the Internet host loop-back address.
|-
|192.0.2.0/24 | This block is assigned as 'TEST-NET'
| | for use in documentation and example code.
|
|224.0.0.0/4 as source. | This block, formerly known as the Class D address space,
| | is allocated for use in IPv4 multicast address assignments.
|
|240.0.0.0/4 |
|(except 255.255.255.255/32 | This block, formerly known as the Class E address space, is reserved.
| as destination address) |
|rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.9.6.1.101.120.4 |
rlSecuritySuiteMartianAddrAllTableThis read-only table specifies all current configured Martian addresses -
both pre-defined (=reserved) and used-configured (=static) addresses SEQUENCE OF RlSecuritySuiteMartianAddrAllEntry .1.3.6.1.4.1.9.6.1.101.120.5 |
rlSecuritySuiteMartianAddrAllEntryEach entry in this table describes one Martian address ,
packets with this address as IP source or IP destination, are discarded. RlSecuritySuiteMartianAddrAllEntry .1.3.6.1.4.1.9.6.1.101.120.5.1 |
rlSecuritySuiteMartianAddrAn IP address to discard all packets with that address as source
or destination IpAddress .1.3.6.1.4.1.9.6.1.101.120.5.1.1 |
rlSecuritySuiteMartianAddrNetMaskSpecify the net mask that comprise the destination IP address prefix. IpAddress .1.3.6.1.4.1.9.6.1.101.120.5.1.2 |
rlSecuritySuiteAllMartianEntryTypeSpecific the entry origin: pre-defined (reserved) of statically configured.ro RlSecuritySuiteAllMartianEntryType .1.3.6.1.4.1.9.6.1.101.120.5.1.3 |
rlSecuritySuiteMartianAddrTableThis table specifies the Martian addresses -
the addresses that packets with these IP addressed as source or
destination are discarded. SEQUENCE OF RlDoSAttackMartianAddrEntry .1.3.6.1.4.1.9.6.1.101.120.6 |
rlSecuritySuiteMartianAddrEntryEach entry in this table describes one Martian address ,
packets with this address as IP source or IP destination, are discarded. RlDoSAttackMartianAddrEntry .1.3.6.1.4.1.9.6.1.101.120.6.1 |
rlSecuritySuiteMartianAddrStatusThe status of a table entry.
It is used to delete/Add an entry from this table.rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.9.6.1.101.120.6.1.1 |
rlSecuritySuiteDoSSynAttackTableThis table contains IP address and rate, to limit DoS SYN attacks from
a specific IP address and interface(s) SEQUENCE OF RlSecuritySuiteDoSSynAttackEntry .1.3.6.1.4.1.9.6.1.101.120.7 |
rlSecuritySuiteDoSSynAttackEntryEach entry in this table describes one Martian address ,
packets with this address as IP source or IP destination, are discarded. RlSecuritySuiteDoSSynAttackEntry .1.3.6.1.4.1.9.6.1.101.120.7.1 |
rlSecuritySuiteDoSSynAttackIfIndexInterface which the attack is applied on InterfaceIndex (IF-MIB) .1.3.6.1.4.1.9.6.1.101.120.7.1.1 |
rlSecuritySuiteDoSSynAttackAddrAn IP address to discard all packets with that address as destination IpAddress .1.3.6.1.4.1.9.6.1.101.120.7.1.2 |
rlSecuritySuiteDoSSynAttackNetMaskRelevant when rlSecuritySuiteSynAttackRangeType equals prefix(2).
Specify the number of bits that comprise the destination
IP address prefix. IpAddress .1.3.6.1.4.1.9.6.1.101.120.7.1.3 |
rlSecuritySuiteDoSSynAttackSynRateSpecify the maximum connections per second allowed from this IP address
and rlSecuritySuiteSynAttackPortListrw INTEGER .1.3.6.1.4.1.9.6.1.101.120.7.1.4 |
rlSecuritySuiteDoSSynAttackStatusThe status of a table entry.
It is used to delete/Add an entry from this table.rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.9.6.1.101.120.7.1.6 |
rlSecuritySuiteDenyTypesTableThis table specifies the ip address and TCP ports that
TCP SYN packets from them on a specific interfaces are dropped. SEQUENCE OF RlSecuritySuiteDenyTypesEntry .1.3.6.1.4.1.9.6.1.101.120.8 |
rlSecuritySuiteDenyTypesEntryEach entry in this table describes one ip address, TCP port and
list of ifIndexes, that packets with these attributes are discarded. RlSecuritySuiteDenyTypesEntry .1.3.6.1.4.1.9.6.1.101.120.8.1 |
rlSecuritySuiteDenyIfIndexInterface which the attack is applied on InterfaceIndex (IF-MIB) .1.3.6.1.4.1.9.6.1.101.120.8.1.1 |
rlSecuritySuiteDenyAttackTypeThe specific deny attack type RlSecuritySuiteDenyAttackType .1.3.6.1.4.1.9.6.1.101.120.8.1.2 |
rlSecuritySuiteDenyDestAddrAn IP address to discard all packets with that address as destination IpAddress .1.3.6.1.4.1.9.6.1.101.120.8.1.3 |
rlSecuritySuiteDenyNetMaskRelevant when rlSecuritySuiteDenyTCPRangeType equals mask(1).
Specify the number of bits that comprise the destination
IP address prefix. IpAddress .1.3.6.1.4.1.9.6.1.101.120.8.1.4 |
rlSecuritySuiteDenyDestPortDestination TCP port.
Use 65553 to specify all ports.
This key-field is relevant in specific attack types (not all)
Use 0 when not relevant. INTEGER .1.3.6.1.4.1.9.6.1.101.120.8.1.5 |
rlSecuritySuiteDenyStatusThe status of a table entry.
It is used to delete/Add an entry from this table.rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.9.6.1.101.120.8.1.6 |
rlSecuritySuiteDenySynFinTcpThis scalar globally enable or disable dropping of tcp packets with both SYN and FIN flags enabled.rw RlSecuritySuiteDenySynFinTcp .1.3.6.1.4.1.9.6.1.101.120.9 |
rlSecuritySuiteSynProtectionModeThis scalar globally set protection mode on TCP SYN traffic.
Disabled - the system doesn't support protection against TCP SYN attack.
Report - the system doesn't support protection against TCP SYN attack,but reports about it.
Block - the systems supports protection against TCP SYN attack by blocking this traffic on the port.rw RlSecuritySuiteSynProtectionMode .1.3.6.1.4.1.9.6.1.101.120.10 |
rlSecuritySuiteSynProtectionTresholdThis scalar globally set protection mode treshold value in packet per second
on TCP SYN traffic.rw INTEGER .1.3.6.1.4.1.9.6.1.101.120.11 |
rlSecuritySuiteSynProtectionRecoveryTimeoutThis scalar globally set protection reovery time out in secounds.rw INTEGER .1.3.6.1.4.1.9.6.1.101.120.12 |
rlSecuritySuiteSynProtectionPortTableThis table keeps SYN protection status per port. SEQUENCE OF RlSecuritySuiteSynProtectionPortEntry .1.3.6.1.4.1.9.6.1.101.120.13 |
rlSecuritySuiteSynProtectionPortEntryEach entry in this table describes TCP SYN protection status for one port. RlSecuritySuiteSynProtectionPortEntry .1.3.6.1.4.1.9.6.1.101.120.13.1 |
rlSecuritySuiteSynProtectionPortModeThe port's TCP SYN protection mode.ro RlSecuritySuiteSynProtectionPortMode .1.3.6.1.4.1.9.6.1.101.120.13.1.1 |
rlSecuritySuiteSynProtectionPortModeLastTimeAttackThe port's TCP SYN protection last attack time mode.ro RlSecuritySuiteSynProtectionPortMode .1.3.6.1.4.1.9.6.1.101.120.13.1.2 |
rlSecuritySuiteSynProtectionPortLastTimeAttackThe port's TCP SYN protection last attack time.ro DisplayString (SNMPv2-TC) .1.3.6.1.4.1.9.6.1.101.120.13.1.3 |