Home/Catalog/ENTERASYS-MAC-LOCKING-MIB

ENTERASYS-MAC-LOCKING-MIB

AI MIB Summary

The ENTERASYS-MAC-LOCKING-MIB enables SNMP-based configuration and status monitoring of per-port MAC address locking features on Enterasys Networks switches. It exposes specific objects to enforce port security policies by binding authorized MAC addresses to switch ports and tracking associated lock states.

This MIB module defines the portion of the SNMP enterprise MIBs under Enterasys Networks' enterprise OID pertaining to MAC Locking. This MIB is designed to provide configuration and status objects pertaining to per port MAC Locking.
Main OID:
etsysMACLockingMIB.1.3.6.1.4.1.5624.1.2.21
50
Objects
Active
Status
6
Dependencies

Imported Objects

Objects

50 total
Object Name
etsysMACLockingMIBThis MIB module defines the portion of the SNMP enterprise MIBs under Enterasys Networks' enterprise OID pertaining to MAC Locking. This MIB is designed to provide configuration and status objects pertaining to per port MAC Locking.
MODULE-IDENTITY
.1.3.6.1.4.1.5624.1.2.21
etsysMACLockingObjects
OBJECT IDENTIFIER
.1.3.6.1.4.1.5624.1.2.21.1
etsysMACLockingTrapBranch
OBJECT IDENTIFIER
.1.3.6.1.4.1.5624.1.2.21.1.0
etsysMACLockingMACViolationIf MAC Locking is globally enabled and specifically enabled for this port, then this trap is sent when a packet is received with a source MAC that differs from all the currently locked MACs for the port specified in this instance of the notification.
NOTIFICATION-TYPE
.1.3.6.1.4.1.5624.1.2.21.1.0.1
etsysMACLockingMACThresholdMAC database threshold notification. The device will send this notification when the MAC address threshold configured in the etsysMACLockingFirstArrivalStationsAllocated object has been reached so that the administrator can take appropriate action.
NOTIFICATION-TYPE
.1.3.6.1.4.1.5624.1.2.21.1.0.2
etsysMACLockingSystemBranch
OBJECT IDENTIFIER
.1.3.6.1.4.1.5624.1.2.21.1.1
etsysMACLockingSystemEnableThis object is a configuration convenience. While disabled(2), all per port configuration is ignored, but changeable. When set to enabled(1), the per port configuration becomes active.rw
EnabledStatus (P-BRIDGE-MIB)
.1.3.6.1.4.1.5624.1.2.21.1.1.1
etsysMACLockingPortConfigBranch
OBJECT IDENTIFIER
.1.3.6.1.4.1.5624.1.2.21.1.2
etsysMACLockingPortTableA table that provides for the configuration of MAC Locking for each port. Regardless of the value of etsysMACLockingSystemEnable, this table is automatically populated with one row per supported port. MAC Locking is not supported on media types whose addresses cannot be adequately represented by the MacAddress convention
SEQUENCE OF EtsysMACLockingPortEntry
.1.3.6.1.4.1.5624.1.2.21.1.2.1
etsysMACLockingPortEntryEach conceptual row allows control over whether MAC locking is enabled for the port corresponding to the row. Similarly, each row provides control over whether violation traps are sent. Information in this table is persistent.
EtsysMACLockingPortEntry
.1.3.6.1.4.1.5624.1.2.21.1.2.1.1
etsysMACLockingPortThe interface number for this row.
InterfaceIndex (IF-MIB)
.1.3.6.1.4.1.5624.1.2.21.1.2.1.1.1
etsysMACLockingEnableWhen set to enabled(1) any static entries currently created on this port become active and the first n MACs which are received on this port are locked, where n is equal to etsysMACLockingFirstArrivalStationsAllocated. When set to disabled(2), all entries in the etsysMACLockingStationTable are cleared, and the port forwards without regard to MAC locking.rw
EnabledStatus (P-BRIDGE-MIB)
.1.3.6.1.4.1.5624.1.2.21.1.2.1.1.2
etsysMACLockingViolationEnableWhen set to enabled(1), the agent issues violation traps for violations detected by the agent. Arrival of violation traps at the management station is not guaranteed and the trap generation rate is not required to match the violation detection rate. A best effort delivery is acceptable. When disabled(2), no traps are sent.rw
EnabledStatus (P-BRIDGE-MIB)
.1.3.6.1.4.1.5624.1.2.21.1.2.1.1.3
etsysMACLockingLastViolationAddressThe last source MAC received on this port which was a violation. A violation is defined to be when the maximum number of firstArrival entries exists for this port in the etsysMACLockingStationTable and the source MAC address of the received packet differs from all entries found for this port in the etsysMACLockingStationTable.ro
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.5624.1.2.21.1.2.1.1.4
etsysMACLockingFirstArrivalStationsAllowedThe agent sets this number for the benefit of management to use when determining the permissible range of values for the etsysMACLockingFirstArrivalStationsAllocated object. The default value of this object is device dependent.ro
Unsigned32
.1.3.6.1.4.1.5624.1.2.21.1.2.1.1.5
etsysMACLockingFirstArrivalStationsAllocatedManagement sets this number in the range of 0 to etsysMACLockingFirstArrivalStationsAllowed. This number limits the number of locked MACs on this port using the first arrival method. The default value of this object SHOULD be the same as the default value of etsysMACLockingFirstArrivalStationsAllowed.rw
Unsigned32
.1.3.6.1.4.1.5624.1.2.21.1.2.1.1.6
etsysMACLockingStaticStationsAllowedThe agent sets this number for the benefit of management to use when determining the permissible range of values for the etsysMACLockingStaticStationsAllocated object. The default value of this object is device dependent.ro
Unsigned32
.1.3.6.1.4.1.5624.1.2.21.1.2.1.1.7
etsysMACLockingStaticStationsAllocatedManagement sets this number in the range of 0 to etsysMACLockingStaticStationsAllowed. This limits the number of statically provisioned, locked MACs on this port. The default value of this object SHOULD be the same as the default value of etsysMACLockingStaticStationsAllowed.rw
Unsigned32
.1.3.6.1.4.1.5624.1.2.21.1.2.1.1.8
etsysMACLockingMoveFirstArrivalToStaticWhen set to true(1), moves First Arrival MACs locked on the port, in lexicographical order, into Statically Locked MACs on the port. The move continues until all First Arrival MACs are moved or until the number of allowable static entries (etsysMACLockingStaticStationsAllocated) has been exhausted. If there is an insufficient number Static entries available to accommodate all the First Arrival MACs, then only the First Arrival MACs already moved to statically locked MACs will be static entries, the remaining First Arrival MACs will remain as First Arrival entries and a MIB_ERROR is returned. When read this object will always return false(2).rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.5624.1.2.21.1.2.1.1.9
etsysMACLockingStaticStationsCountReturns the number of Statically Locked MACs currently locked on the port.ro
Unsigned32
.1.3.6.1.4.1.5624.1.2.21.1.2.1.1.10
etsysMACLockingClearStaticStationsWhen set to true(1), clears out all the Statically Locked MACs on this port. When read this object will always return false(2).rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.5624.1.2.21.1.2.1.1.11
etsysMACLockingFirstArrivalAgingWhen set to true(1), firstArrival MACs that have aged out of the forwarding database will be removed for the associated port lockrw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.5624.1.2.21.1.2.1.1.12
etsysMACLockingViolationSyslogEnableWhen set to enabled(1), the agent issues syslog messages for violations detected by the agent. Arrival of violation syslog messages at the management station is not guaranteed and the messages generation rate is not required to match the violation detection rate. A best effort delivery is acceptable. When disabled(2), no syslog messages are sent as a result of MAC locking violations.rw
EnabledStatus (P-BRIDGE-MIB)
.1.3.6.1.4.1.5624.1.2.21.1.2.1.1.13
etsysMACLockingThresholdEnableWhen set to enabled(1), the agent issues a trap when the MAC address threshold as defined in the etsysMACLockingFirstArrivalStationsAllocated object has been reached. Arrival of these traps at the management station is not guaranteed and the trap generation rate is not required to match the detection rate. A best effort delivery is acceptable. When disabled(2), no traps are sent as a result of the threshold being reached.rw
EnabledStatus (P-BRIDGE-MIB)
.1.3.6.1.4.1.5624.1.2.21.1.2.1.1.14
etsysMACLockingThresholdSyslogEnableWhen set to enabled(1), the agent issues a syslog message when the MAC address threshold as defined in the etsysMACLockingFirstArrivalStationsAllocated object has been reached. Arrival of these messages is not guaranteed and the message generation rate is not required to match the detection rate. A best effort delivery is acceptable. When disabled(2), no messages are sent as a result of the threshold being reached.rw
EnabledStatus (P-BRIDGE-MIB)
.1.3.6.1.4.1.5624.1.2.21.1.2.1.1.15
etsysMACLockingStaticStationBranch
OBJECT IDENTIFIER
.1.3.6.1.4.1.5624.1.2.21.1.3
etsysMACLockingStaticStationTableThis table lists all statically locked MAC addresses for each port. When MAC locking is enabled on a port, all active rows in this table will appear in the etsysMACLockingStationTable with the object etsysMACLockingLockedEntryCause set to static(2). Rows in this table are persistent between resets.
SEQUENCE OF EtsysMACLockingStaticStationEntry
.1.3.6.1.4.1.5624.1.2.21.1.3.1
etsysMACLockingStaticStationEntryEach conceptual row contains a user specified locked MAC address.
EtsysMACLockingStaticStationEntry
.1.3.6.1.4.1.5624.1.2.21.1.3.1.1
etsysMACLockingLockedAddressThe MAC that has been locked to this port.
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.5624.1.2.21.1.3.1.1.1
etsysMACLockingStaticEntryRowStatusThe status column has six defined values: - 'active', which indicates that a row shall also exist or be created in etsysMACLockingStationTable with the same index and the object etsysMACLockingLockedEntryCause in that row shall be static(1); - 'notInService', which indicates the existence or causes the creation of a row in this table. However, no corresponding row shall exist or be created in etsysMACLockingStationTable; - 'notReady', will never be read in any row of this table since existence is the only requirement for this tables rows; - 'createAndGo', which causes a new row to be created in both this table and in the etsysMACLockingStationTable with the same index and the object etsysMACLockingLockedEntryCause shall have the value static(1); - 'createAndWait', which causes a new row to be created in this table. However, no corresponding row shall be created in etsysMACLockingStationTable; and, - 'destroy', which causes the agent to remove this tables row along with the corresponding row in etsysMACLockingStationTable.rw
RowStatus (SNMPv2-TC)
.1.3.6.1.4.1.5624.1.2.21.1.3.1.1.2
etsysMACLockingStationBranch
OBJECT IDENTIFIER
.1.3.6.1.4.1.5624.1.2.21.1.4
etsysMACLockingStationTableThis table lists any locked MAC address for each port along with their entry types. On each port in the system, MACs can be locked. For each MAC locked to a port, a row appears in this table. When MAC locking is enabled on a port, the first n packets received by the port has its source MAC locked to the port and the locked cause displays firstArrival(2) The value n is equal to the etsysMACLockingFirstArrivalStationsAllocated object. Additionally, management may explicitly lock a MAC to a port by using the etsysMACLockingStationStaticTable. For each entry in the static table that is active(1), a corresponding entry appears in this table with its etsysMACLockingLockedEntryCause object set to static(1).
SEQUENCE OF EtsysMACLockingStationEntry
.1.3.6.1.4.1.5624.1.2.21.1.4.1
etsysMACLockingStationEntryEach conceptual row contains a locked cause which describes how the MAC was locked on the port. If etsysMACLockingSystemEnable is disabled(2), then this table will be empty. This table contains entries for those ports which have MAC locking enabled and have locked MACs.
EtsysMACLockingStationEntry
.1.3.6.1.4.1.5624.1.2.21.1.4.1.1
etsysMACLockingLockedEntryCauseWhen management statically provisions a MAC onto this port, then this object is returns static(1). If this MAC was dynamically locked, then this object returns firstArrival(2). If first arrival aging is enabled on the port and the MAC address is dynamically locked, then this object returns agingFirstArrival(3).ro
Enumeration
.1.3.6.1.4.1.5624.1.2.21.1.4.1.1.1
etsysMACLockingRemoveStationWhen this is object is set to true(1) the MAC address specified by the indexing will be removed from etsysMACLockingStationTable. If the etsysMACLockingLockedEntryCause leaf for this table entry is of type static(1), then the associated entry will also be removed from the etsysMACLockingStaticStationTable. A set to false(2) will have no effect. This object will always return false(2).rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.5624.1.2.21.1.4.1.1.2
etsysMACLockingConformance
OBJECT IDENTIFIER
.1.3.6.1.4.1.5624.1.2.21.2
etsysMACLockingGroups
OBJECT IDENTIFIER
.1.3.6.1.4.1.5624.1.2.21.2.1
etsysMACLockingSystemGroupA collection of objects providing global configuration for the MAC Locking feature.
Unknown
.1.3.6.1.4.1.5624.1.2.21.2.1.1
etsysMACLockingPortGroupA collection of objects providing port based configuration and status of MAC Locking.
Unknown
.1.3.6.1.4.1.5624.1.2.21.2.1.2
etsysMACLockingStationGroup********* THIS GROUP IS DEPRECATED ********** A list of currently locked MACs.deprecated
Unknown
.1.3.6.1.4.1.5624.1.2.21.2.1.3
etsysMACLockingStaticStationGroupA list of statically provisioned locked MACs. This group is mandatory if static MAC locking is supported, otherwise it is optional.
Unknown
.1.3.6.1.4.1.5624.1.2.21.2.1.4
etsysMACLockingPortFirstArrivalGroupA collection of objects providing port based configuration of firstArrival MAC Locking.
Unknown
.1.3.6.1.4.1.5624.1.2.21.2.1.5
etsysMACLockingStationGroup2A collection of objects providing status and configuration of all currently locked MAC addresses.
Unknown
.1.3.6.1.4.1.5624.1.2.21.2.1.6
etsysMACLockingNotificationGroupThe MAC Locking notifications.
Unknown
.1.3.6.1.4.1.5624.1.2.21.2.1.7
etsysMACLockingPortMessageGroupA collection of objects providing port based configuration and status for MAC Locking syslog messages and notifications.
Unknown
.1.3.6.1.4.1.5624.1.2.21.2.1.8
etsysMACLockingCompliances
OBJECT IDENTIFIER
.1.3.6.1.4.1.5624.1.2.21.2.2
etsysMACLockingCompliance******** THIS COMPLIANCE IS DEPRECATED ******** The compliance statement for devices that support MAC Locking.deprecated
Unknown
.1.3.6.1.4.1.5624.1.2.21.2.2.1
etsysMACLockingNotificationComplianceThe compliance statement for all devices that support notifications and syslog messages for MAC Locking events.
Unknown
.1.3.6.1.4.1.5624.1.2.21.2.2.1.4
etsysMACLockingPortFirstArrivalComplianceThe compliance statement for all devices that support aging first arrival mac lock entries on a per port basis.
Unknown
.1.3.6.1.4.1.5624.1.2.21.2.2.2
etsysMACLockingCompliance2The compliance statement for devices that support MAC Locking.
Unknown
.1.3.6.1.4.1.5624.1.2.21.2.2.3
ENTERASYS-MAC-LOCKING-MIB - SNMP MIB Reference | MIBs Explorer