EdgeSwitch-DOT1X-ADVANCED-FEATURES-MIB
AI MIB Summary
The EdgeSwitch-DOT1X-ADVANCED-FEATURES-MIB provides vendor-specific monitoring and management capabilities for IEEE 802.1X authentication sessions on Ubiquiti EdgeSwitch devices running FastPath firmware. This module exposes advanced operational metrics, including session states, authentication failure counters, and dynamic policy enforcement parameters, to facilitate granular troubleshooting of port-based network access control.
The Ubiquiti Private MIB for FastPath Dot1x Advanced Features
Main OID:
fastPathdot1xAdvanced.1.3.6.1.4.1.4413.1.1.36
58
Objects
Active
Status
5
Dependencies
Imported Objects
Objects
58 total| Object Name |
|---|
fastPathdot1xAdvancedThe Ubiquiti Private MIB for FastPath Dot1x Advanced Features MODULE-IDENTITY .1.3.6.1.4.1.4413.1.1.36 |
agentDot1xEnhancementConfigGroup OBJECT IDENTIFIER .1.3.6.1.4.1.4413.1.1.36.1 |
agentDot1xRadiusVlanAssignmentEnable/Disable dot1x Vlan Assignment Support on the switch.rw Enumeration .1.3.6.1.4.1.4413.1.1.36.1.1 |
agentDot1xDynamicVlanCreationModeEnable/Disable dot1x dynamic vlan creation Support on the switch.rw Enumeration .1.3.6.1.4.1.4413.1.1.36.1.2 |
agentDot1xEapolFloodModeEnable/Disable dot1x eapol flooding mode on the switch.rw Enumeration .1.3.6.1.4.1.4413.1.1.36.1.3 |
agentDot1xPortConfigGroup OBJECT IDENTIFIER .1.3.6.1.4.1.4413.1.1.36.2 |
agentDot1xPortConfigTableA table for dot1x enhanced Port details and associated functionality. SEQUENCE OF AgentDot1xPortConfigEntry .1.3.6.1.4.1.4413.1.1.36.2.1 |
agentDot1xPortConfigEntryRepresents entry for port config table. AgentDot1xPortConfigEntry .1.3.6.1.4.1.4413.1.1.36.2.1.1 |
agentDot1xPortControlModeDot1x port control mode of this port.The Port control mode .
The port control mode for this interface can take the following values ,
force-unauthorized - the port is in unauthorized mode,
auto-Port based mode. If a client authenticates suscessfully, then the interface is authorized .
Otherwise, the port is in unauthorized mode.
If more than one clients are attached to the port , then only one client needs to authenticate to allow other clients access.
force-authorized - The port is placed in authorized mode
macBased - If more than one client is attached to the port, then each client needs to authenticate separately.
This object depcreates dot1xAuthAuthControlledPortControl object in IEEE8021-PAE-MIBrw Dot1xPortControlMode .1.3.6.1.4.1.4413.1.1.36.2.1.1.1 |
agentDot1xGuestVlanIdSpecifies the Guest Vlan of the port. A port will
be moved to its Guest Vlan if no client sucessfully
authenticates on that port for the Guest Vlan Period.
A value of zero indicates no Guest Vlan is configured for the interface.rw Unsigned32 .1.3.6.1.4.1.4413.1.1.36.2.1.1.2 |
agentDot1xGuestVlanPeriodThe value, in seconds, of the guestVlanPeriod constant
currently in use for Guest Vlan Assignment for the
port .rw Unsigned32 .1.3.6.1.4.1.4413.1.1.36.2.1.1.3 |
agentDot1xUnauthenticatedVlanSpecifies the Unauthenticated Vlan of the port. A port will
be moved to its unauthenticated Vlan if the client authenticates unsucessfully
on that port .
A value of zero indicates no Unauthenticated Vlan is configured for the port.rw Unsigned32 .1.3.6.1.4.1.4413.1.1.36.2.1.1.4 |
agentDot1xMaxUsersSpecifies the maximum users or clients that can authenticate on this port when the port control mode is macBased.rw Unsigned32 .1.3.6.1.4.1.4413.1.1.36.2.1.1.5 |
agentDot1xPortVlanAssignedSpecifies the vlan the port is assigned to by Dot1x .
Only relevant if the port control mode of the port is auto.ro Unsigned32 .1.3.6.1.4.1.4413.1.1.36.2.1.1.6 |
agentDot1xPortVlanAssignedReasonReason the port is assigned to the vlan specified by agentDot1xPortVlanAssigned .
Only relevant if the port control mode of the port is auto.ro Enumeration .1.3.6.1.4.1.4413.1.1.36.2.1.1.7 |
agentDot1xPortSessionTimeoutSpecifies the session timeout value assigned by the Radius server for this port .
Only relevant if the port control mode of the port is auto.ro Unsigned32 .1.3.6.1.4.1.4413.1.1.36.2.1.1.8 |
agentDot1xPortTerminationActionSpecifies the session termination action assigned by the Radius Server .This is the action taken when the session times out .
Only relevant if the port control mode of the port is auto.ro Dot1xSessionTerminationAction .1.3.6.1.4.1.4413.1.1.36.2.1.1.9 |
agentDot1xPortMABenabledSpecifies if Mac-based bypass authentication is configured for the port.rw Enumeration .1.3.6.1.4.1.4413.1.1.36.2.1.1.10 |
agentDot1xPortMABenabledOperationalDisplays the operational value of the Mac-based authentication bypass mode (MAB) on the port.ro Enumeration .1.3.6.1.4.1.4413.1.1.36.2.1.1.11 |
agentDot1xClientConfigGroup OBJECT IDENTIFIER .1.3.6.1.4.1.4413.1.1.36.3 |
agentDot1xClientConfigTableA table for dot1x Client details and associated functionality. SEQUENCE OF AgentDot1xClientConfigEntry .1.3.6.1.4.1.4413.1.1.36.3.1 |
agentDot1xClientConfigEntryRepresents entry for port config table. AgentDot1xClientConfigEntry .1.3.6.1.4.1.4413.1.1.36.3.1.1 |
agentDot1xClientMacAddressSpecifies the client MAC address of the client.ro MacAddress (SNMPv2-TC) .1.3.6.1.4.1.4413.1.1.36.3.1.1.1 |
agentDot1xLogicalPortSpecifies the client MAC address of the client .ro Unsigned32 .1.3.6.1.4.1.4413.1.1.36.3.1.1.2 |
agentDot1xInterfaceSpecifies the physical interface to which the client is attached .ro Unsigned32 .1.3.6.1.4.1.4413.1.1.36.3.1.1.3 |
agentDot1xClientAuthPAEstateThe current value of the Authenticator PAE state
machine for the client.ro Enumeration .1.3.6.1.4.1.4413.1.1.36.3.1.1.4 |
agentDot1xClientBackendStateThe current state of the Backend Authentication
state machine.ro Enumeration .1.3.6.1.4.1.4413.1.1.36.3.1.1.5 |
agentDot1xClientUserNameSpecifies the username with which the client is authenticated to the Radius server .
This value is only valid when the client is in authenticated state.ro DisplayString (SNMPv2-TC) .1.3.6.1.4.1.4413.1.1.36.3.1.1.6 |
agentDot1xClientSessionTimeSpecifies the time elapsed in seconds since the client was authenticated in this session.
This value is only valid when the client is in authenticated state.ro Unsigned32 .1.3.6.1.4.1.4413.1.1.36.3.1.1.7 |
agentDot1xClientFilterIDSpecifies the Filter ID or Diffserv Policy name to be applied to the session .
This vlaue is populated only if it has been assigned by the RADIUS server.
This value is only valid when the client is in authenticated state.ro DisplayString (SNMPv2-TC) .1.3.6.1.4.1.4413.1.1.36.3.1.1.8 |
agentDot1xClientVlanAssignedSpecifies the vlan the client is associated with by Dot1x .
This value is only valid when the client is in authenticated state.ro Unsigned32 .1.3.6.1.4.1.4413.1.1.36.3.1.1.9 |
agentDot1xClientVlanAssignedReasonReason the client is associated to the vlan specified by agentDot1xClientVlanAssigned .
This value is only valid when the client is in authenticated state.ro Enumeration .1.3.6.1.4.1.4413.1.1.36.3.1.1.10 |
agentDot1xClientSessionTimeoutSpecifies the session time remaining for the client if assigned by the Radius server .
A value of 0 indicates that no session timeout was assigned by the RADIUS server.
This value is only valid when the client is in authenticated state.ro Unsigned32 .1.3.6.1.4.1.4413.1.1.36.3.1.1.11 |
agentDot1xClientTerminationActionSpecifies the session termination action assigned by the Radius Server .
This is the action taken when the session times out .
This value is only valid when the client is in authenticated state.ro Dot1xSessionTerminationAction .1.3.6.1.4.1.4413.1.1.36.3.1.1.12 |
agentDot1xMonitorModeConfigGroup OBJECT IDENTIFIER .1.3.6.1.4.1.4413.1.1.36.4 |
agentDot1xMonitorModeEnabledEnable/Disable Dot1x Monitor mode
Support on the switch.rw Enumeration .1.3.6.1.4.1.4413.1.1.36.4.1 |
agentDot1xMonitorModeClientsRetrieves the number of clients that got
authenticated by Monitor mode globally.ro Unsigned32 .1.3.6.1.4.1.4413.1.1.36.4.2 |
agentDot1xNonMonitorModeClientsRetrieves the number of clients that are granted access by Dot1x with no monitor mode enabled.ro Unsigned32 .1.3.6.1.4.1.4413.1.1.36.4.3 |
agentDot1xAuthHistoryResultsGroup OBJECT IDENTIFIER .1.3.6.1.4.1.4413.1.1.36.5 |
agentDot1xPortAuthHistoryResultTableA table to display the dot1x monitor mode results. SEQUENCE OF AgentDot1xPortAuthHistoryResultEntry .1.3.6.1.4.1.4413.1.1.36.5.1 |
agentDot1xPortAuthHistoryResultEntryRepresents Dot1x Authentication results for a Dot1x Authentication History table. AgentDot1xPortAuthHistoryResultEntry .1.3.6.1.4.1.4413.1.1.36.5.1.1 |
agentDot1xAuthHistoryResultIfaceIndexThis object represents the physical Bridge Port on which dot1x Auth event
might be received.ro Unsigned32 .1.3.6.1.4.1.4413.1.1.36.5.1.1.1 |
agentDot1xAuthHistoryResultIndexReference to the Dot1x Authentication history table maintained.ro Unsigned32 .1.3.6.1.4.1.4413.1.1.36.5.1.1.2 |
agentDot1xAuthHistoryResultTimeStampSpecifies the exact time of Dot1x Authentication
event information occurred maintained in the
history table.ro DateAndTime (SNMPv2-TC) .1.3.6.1.4.1.4413.1.1.36.5.1.1.3 |
agentDot1xAuthHistoryResultAgeTime since the authentication entry was added to the history table. It is displayed in days, hours, minutes, and seconds.ro TimeTicks (SNMPv2-SMI) .1.3.6.1.4.1.4413.1.1.36.5.1.1.4 |
agentDot1xAuthHistoryResultMacAddressSpecifies the client MAC Address maintained in
the Dot1x Authentication history table.ro MacAddress (SNMPv2-TC) .1.3.6.1.4.1.4413.1.1.36.5.1.1.5 |
agentDot1xAuthHistoryResultVlanIdSpecifies the VLANID maintained in the history
table. It is the VLANID which is failed to
associate to the port during authentication process.
The VLANID is identified distinctly by the Reason
code for the respective entry. Valid only when the
reason code is set to 13 (VLAN assignment failure).
In all the other cases, VLANID is set to 0.ro Unsigned32 .1.3.6.1.4.1.4413.1.1.36.5.1.1.6 |
agentDot1xAuthHistoryResultAuthStatusSpecifies the Dot1x Authentication status (Success or Failure) for the Dot1x Authentication event takes place.ro Enumeration .1.3.6.1.4.1.4413.1.1.36.5.1.1.7 |
agentDot1xAuthHistoryResultAccessStatusAuthentication access status indicates the exact status of the dot1x client.
Granted means the client is allowed access to the network using dot1x or monitor mode.
Denied means the client is not allowed access to the network.ro Enumeration .1.3.6.1.4.1.4413.1.1.36.5.1.1.8 |
agentDot1xAuthHistoryResultFilterIDSpecifies the Filter ID or Diffserv Policy name assigned by the RADIUS server.
This value is only valid when the client is in authenticated state.ro DisplayString (SNMPv2-TC) .1.3.6.1.4.1.4413.1.1.36.5.1.1.9 |
agentDot1xAuthHistoryResultVlanAssignedSpecifies the VLANID maintained in the history
table (It is the VLANID Assigned to a Port or Client authenticate).ro Unsigned32 .1.3.6.1.4.1.4413.1.1.36.5.1.1.10 |
agentDot1xAuthHistoryResultVlanAssignedTypeSpecifies the VLAN Assigned Reason maintained in the history
table.ro Enumeration .1.3.6.1.4.1.4413.1.1.36.5.1.1.11 |
agentDot1xAuthHistoryResultReasonCodeSpecifies the Dot1x authentication reason
refered by the result index on a port.ro Enumeration .1.3.6.1.4.1.4413.1.1.36.5.1.1.12 |
agentDot1xAuthHistoryResultsClearWhen set to enable(1), all Dot1x Authentication History information will be reset.rw Enumeration .1.3.6.1.4.1.4413.1.1.36.5.2 |
agentDot1xPortAuthHistoryResultClearTableA table to clear the dot1x monitor mode results per interface. SEQUENCE OF AgentDot1xPortAuthHistoryResultClearEntry .1.3.6.1.4.1.4413.1.1.36.5.3 |
agentDot1xPortAuthHistoryResultClearEntryRepresents to clear the Dot1x Authentication results for a Dot1x Authentication History table. AgentDot1xPortAuthHistoryResultClearEntry .1.3.6.1.4.1.4413.1.1.36.5.3.1 |
agentDot1xAuthHistoryResultIfIndexThis object represents the physical Bridge Port on which dot1x Auth event
might be received.ro Unsigned32 .1.3.6.1.4.1.4413.1.1.36.5.3.1.1 |
agentDot1xPortAuthHistoryResultsClearWhen set to enable(1), all Dot1x Authentication History information for
the given port will be reset. The value is write-only. Attempt to read
will return disable(2).rw Enumeration .1.3.6.1.4.1.4413.1.1.36.5.3.1.2 |