Home/Catalog/ENTERASYS-8021X-REKEYING-MIB

ENTERASYS-8021X-REKEYING-MIB

AI MIB Summary

The ENTERASYS-8021X-REKEYING-MIB configures and monitors rapid rekeying intervals and status for IEEE 802.1x authentication sessions on Enterasys Networks wireless LAN infrastructure. It specifically manages the periodic rotation of wireless encryption keys to maintain cryptographic freshness without requiring full session re-authentication.

This MIB module defines a portion of the SNMP enterprise MIBs under Enterasys Networks' enterprise OID pertaining to IEEE 802.1x authentication. This MIB is designed to supplement and be used in connection with the standard IEEE 802.1x MIB. It provides configuration controls for Enterasys Networks' rapid rekeying feature -- a feature that enhances wireless LAN security by changing the network's radio keys on a regular basis.
Main OID:
etsys8021xRekeyingMIB.1.3.6.1.4.1.5624.1.2.17
16
Objects
Active
Status
5
Dependencies

Imported Objects

Objects

16 total
Object Name
etsys8021xRekeyingMIBThis MIB module defines a portion of the SNMP enterprise MIBs under Enterasys Networks' enterprise OID pertaining to IEEE 802.1x authentication. This MIB is designed to supplement and be used in connection with the standard IEEE 802.1x MIB. It provides configuration controls for Enterasys Networks' rapid rekeying feature -- a feature that enhances wireless LAN security by changing the network's radio keys on a regular basis.
MODULE-IDENTITY
.1.3.6.1.4.1.5624.1.2.17
etsysDot1xRekeyingObjects
OBJECT IDENTIFIER
.1.3.6.1.4.1.5624.1.2.17.1
etsysDot1xRekeyBaseBranch
OBJECT IDENTIFIER
.1.3.6.1.4.1.5624.1.2.17.1.1
etsysDot1xRekeyConfigTableA table that contains encryption-key-related configuration objects for ports on which Authenticator PAEs can run.
SEQUENCE OF EtsysDot1xRekeyConfigEntry
.1.3.6.1.4.1.5624.1.2.17.1.1.1
etsysDot1xRekeyConfigEntryEach conceptual row holds encryption key configuration information for the Authenticator PAEs associated with one port.
EtsysDot1xRekeyConfigEntry
.1.3.6.1.4.1.5624.1.2.17.1.1.1.1
etsysDot1xRekeyEnabledDetermines how an access point selects radio encryption keys. If the selected port/Authenticator PAE does not support the EAPOL-Key feature (e.g., because radio keys are not applicable to Ethernet ports), this object's value will be FALSE and attempts to write TRUE will fail. Normally, if radio keys are present, the manager enters them into the access point through some manual process. The manager or the users may also need to configure the keys into each laptop (access points can distribute the keys automatically to 802.1x EAP-TLS clients). However laptops get keys, the keys remain static until somebody goes to the trouble of changing them. If the keys stay unchanged for long periods, this can make it easier for a determined attacker to launch a cryptographic attack. When rapid rekeying is enabled, an access point ignores its manually-set keys. It generates pseudo-random keys on a periodic basis, using IEEE 802.1x key distribution to deliver the keys to new and current clients. Do not enable rapid rekeying unless ALL of your clients support IEEE 802.1x and an authentication method (e.g., EAP-TLS) that supports key distribution. Before enabling rapid rekeying, make sure that you have set 'dot1xAuthKeyTxEnabled' to TRUE. Changing the keys without telling any of the clients about the changes is not a very useful mode of operation.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.5624.1.2.17.1.1.1.1.1
etsysDot1xRekeyPeriodWhen rapid rekeying (periodic changing of radio keys) is enabled, the value of this object determines the period, in seconds, between key changes.rw
Unsigned32
.1.3.6.1.4.1.5624.1.2.17.1.1.1.1.2
etsysDot1xRekeyLengthDetermines the number of bits/bytes used in the encryption keys. Currently supports either 128-bit (16-octet) encryption keys or 40-bit (5-octet) encryption keys.rw
Enumeration
.1.3.6.1.4.1.5624.1.2.17.1.1.1.1.3
etsysDot1xRekeyAsymmetricDetermines the association between the supplicant and authenticator transmit keys. If true(1), the authenticator and supplicant will use different encryption keys in order to transmit data. If false(2), the authenticator and supplicant will use a single key pattern to encrypt the transmitted data.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.5624.1.2.17.1.1.1.1.4
etsysDot1xRekeyPairwiseDetermines whether Rapid Rekeying tumbles Pairwise keys (when it is enabled, and the radio card supports them). If true(1), it indicates that the access point should tumble both Pairwise and Group keys. If false(2), it indicates that the access point should tumble only Group keys.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.5624.1.2.17.1.1.1.1.5
etsysDot1xRekeyingConformance
OBJECT IDENTIFIER
.1.3.6.1.4.1.5624.1.2.17.2
etsysDot1xRekeyingGroups
OBJECT IDENTIFIER
.1.3.6.1.4.1.5624.1.2.17.2.1
etsysDot1xRekeyingBaseGroupA collection of objects providing rekeying configuration information about a port on which Authenticator PAEs can run.
Unknown
.1.3.6.1.4.1.5624.1.2.17.2.1.1
etsysDot1xRekeyingPairwiseGroupA collection of objects providing rekeying configuration information related to Pairwise keys.
Unknown
.1.3.6.1.4.1.5624.1.2.17.2.1.2
etsysDot1xRekeyingCompliances
OBJECT IDENTIFIER
.1.3.6.1.4.1.5624.1.2.17.2.2
etsysDot1xRekeyingComplianceThe compliance statement for devices that support the Enterasys IEEE 802.1x extensions MIB.
Unknown
.1.3.6.1.4.1.5624.1.2.17.2.2.1

More MIBs from Enterasys

Browse all EnterasysMIBs →
ENTERASYS-OIDS-MIB

The ENTERASYS-OIDS-MIB module provides the foundational Object Identifier (OID) definitions required for SNMP-based monitoring of Enterasys Networks hardware system attributes, including device identity, software versions, and hardware inventory. It serves as the structural registry enabling network management systems to map and retrieve specific system-level metrics from Enterasys switches, routers, and wireless controllers.

678 objects→
ENTERASYS-CLASS-OF-SERVICE-MIB

The ENTERASYS-CLASS-OF-SERVICE-MIB manages transmission and reception attributes for Quality of Service (QoS) classification on Extreme Networks (formerly Enterasys) edge and access devices. It enables SNMP-based configuration and monitoring of traffic prioritization policies, including queue mapping, scheduling, and bandwidth allocation parameters.

361 objects→
ENTERASYS-FIREWALL-MIB

The ENTERASYS-FIREWALL-MIB enables SNMP-based configuration, policy management, and real-time monitoring of Enterasys firewall appliances, specifically exposing metrics for access control rules, session states, and interface traffic statistics.

220 objects→
ENTERASYS-LSNAT-MIB

The ENTERASYS-LSNAT-MIB provides management access to Layer 4 Session NAT (LSNAT) entities on Enterasys Networks hardware, enabling the monitoring of active session states, translation table entries, and packet/byte counters for protocol-specific NAT mappings.

177 objects→
ENTERASYS-POLICY-PROFILE-MIB

The ENTERASYS-POLICY-PROFILE-MIB enables SNMP-based monitoring and configuration of per-user policy profiles on Enterasys network edge and access devices. It facilitates the retrieval and management of specific user authentication and authorization parameters, including assigned access control lists and traffic shaping rules, to enforce granular network access policies.

165 objects→
ENTERASYS-TWCB-MIB-2

The ENTERASYS-TWCB-MIB-2 module enables monitoring and management of Time-Weighted Cost-Based (TWCB) routing metrics and interface attributes on Enterasys Networks switches. It provides specific counters and gauges for tracking path costs and link states to support advanced traffic engineering and load balancing decisions.

134 objects→