GB15629dot11-WAPI-MIB
AI MIB Summary
The GB15629dot11-WAPI-MIB module enables monitoring and management of the Wireless Authentication and Privacy Infrastructure (WAPI) security subsystem on Huawei network devices, specifically tracking WAPI session states, authentication failures, and compliance with the GB 15629-2003 standard.
Manage WAPI module.
Main OID:
gb15629dot11wapiMIB.1.2.156.11235.15629.11.1.1
75
Objects
Active
Status
4
Dependencies
Imported Objects
Objects
75 total| Object Name |
|---|
member-body OBJECT IDENTIFIER .1.2 |
cn OBJECT IDENTIFIER .1.2.156 |
bwips OBJECT IDENTIFIER .1.2.156.11235 |
gb15629 OBJECT IDENTIFIER .1.2.156.11235.15629 |
gb15629-11 OBJECT IDENTIFIER .1.2.156.11235.15629.11 |
gb15629-11-mibs OBJECT IDENTIFIER .1.2.156.11235.15629.11.1 |
gb15629dot11wapiMIBManage WAPI module. MODULE-IDENTITY .1.2.156.11235.15629.11.1.1 |
wapiMIBObjects OBJECT IDENTIFIER .1.2.156.11235.15629.11.1.1.1 |
gb15629dot11wapiConfigTableThe table containing WAPI configuration objects. SEQUENCE OF Gb15629dot11wapiConfigEntry .1.2.156.11235.15629.11.1.1.1.1 |
gb15629dot11wapiConfigEntryAn entry in the gb15629dot11wapiConfigTable. Gb15629dot11wapiConfigEntry .1.2.156.11235.15629.11.1.1.1.1.1 |
gb15629dot11wapiConfigVersionThe highest WAPI version this entity supports.ro Integer32 .1.2.156.11235.15629.11.1.1.1.1.1.1 |
gb15629dot11wapiControlledAuthControlThis object indicates whether the entity enables
authentication. When the value is FALSE, it shall indicate that
authentication is not enabled on this entity, and the status of
the controlled port is 'authenticated'. When the value is TURE,
it shall indicate that authentication is enabled, and the status
of controlled port is decided by
gb15629dot11wapiControlledPortControl.ro TruthValue (SNMPv2-TC) .1.2.156.11235.15629.11.1.1.1.1.1.2 |
gb15629dot11wapiControlledPortControlThis object indicates the controlling type of the entity's port.
This object is available when
gb15629dot11wapiControlledAuthControl is TURE. When the value is
zero, it means 'automatic', and the status of the controlled port
is decided by authentication result. When the value is one,
it means 'forcible unauthenticated', and the status of the
controlled port is 'unauthenticated'.ro INTEGER .1.2.156.11235.15629.11.1.1.1.1.1.3 |
gb15629dot11wapiOptionImplementedThis object indicates whether the entity support WAPI. When the
value is TURE, it shall indicate that the entity support WAPI.
Otherwise, it shall indicate that the entity doesn't support WAPI.ro TruthValue (SNMPv2-TC) .1.2.156.11235.15629.11.1.1.1.1.1.4 |
gb15629dot11wapiPreauthenticationImplementedThis object indicates whether the entity support WAPI
preauthentication. This object can't be set to TURE, unless
gb15629dot11wapiOptionImplemented is TURE.ro TruthValue (SNMPv2-TC) .1.2.156.11235.15629.11.1.1.1.1.1.5 |
gb15629dot11wapiEnabledWhen this object is set to TRUE, it shall indicate that WAPI is
enabled on this entity. The entity will advertise the WAPI
information element in its beacon and probe response frames.rw TruthValue (SNMPv2-TC) .1.2.156.11235.15629.11.1.1.1.1.1.6 |
gb15629dot11wapiPreauthenticationEnabledWhen this object is set to TRUE, it shall indicate that WAPI
preauthentication is enabled on this entity. Otherwise, it shall
indicate that WAPI preauthentication is disabled on this entity.
This object requires that gb15629dot11WAPIEnabled also be set to
TRUE.rw TruthValue (SNMPv2-TC) .1.2.156.11235.15629.11.1.1.1.1.1.7 |
gb15629dot11wapiConfigUnicastKeysSupportedThis object indicates how many unicast keys the entity supports
for WAPI.ro Unsigned32 .1.2.156.11235.15629.11.1.1.1.1.1.8 |
gb15629dot11wapiConfigUnicastRekeyMethodThis object selects a mechanism for rekeying the WAPI USK. The
default is time-based, once per day. Rekeying the USK is only
applicable to an entity acting as a role of AE or ASUE.rw Enumeration .1.2.156.11235.15629.11.1.1.1.1.1.9 |
gb15629dot11wapiConfigUnicastRekeyTimeThe time in seconds after which the WAPI USK shall be refreshed.
The timer shall start at the moment the USK was set using the
MLME-SETWPIKEYS request primitive.rw Unsigned32 .1.2.156.11235.15629.11.1.1.1.1.1.10 |
gb15629dot11wapiConfigUnicastRekeyPacketsA packet count (in 1000s of packets) after which the WAPI USK
shall be refreshed. The packet counter shall start at the moment
the USK was set using the MLME-SETKEYS request primitive and it
shall count all packets encrypted using the current USK.rw Unsigned32 .1.2.156.11235.15629.11.1.1.1.1.1.11 |
gb15629dot11wapiConfigMulticastCipherThis object indicates the multicast cipher suite selector the
entity must use. The multicast cipher suite in the WAPI
information element shall take its value from this variable.
It consists of an OUI (the first 3 octets) and a cipher suite
identifier (the last octet).rw OCTET STRING .1.2.156.11235.15629.11.1.1.1.1.1.12 |
gb15629dot11wapiConfigMulticastRekeyMethodThis object selects a mechanism for rekeying the WAPI MSK. The
default is time-based, once per day. Rekeying the MSK is only
applicable to an entity acting as a role of AE or ASUE.rw Enumeration .1.2.156.11235.15629.11.1.1.1.1.1.13 |
gb15629dot11wapiConfigMulticastRekeyTimeThe time in seconds after which the WAPI MSK shall be refreshed.
The timer shall start at the moment the MSK was set using the
MLME-SETWPIKEYS request primitive.rw Unsigned32 .1.2.156.11235.15629.11.1.1.1.1.1.14 |
gb15629dot11wapiConfigMulticastRekeyPacketsA packet count (in 1000s of packets) after which the WAPI MSK
shall be refreshed. The packet counter shall start at the moment
the MSK was set using the MLME-SETKEYS request primitive and it
shall count all packets encrypted using the current MSK.rw Unsigned32 .1.2.156.11235.15629.11.1.1.1.1.1.15 |
gb15629dot11wapiConfigMulticastRekeyStrictThis object signals that the MSK shall be refreshed whenever a
STA leaves the BSS that possesses the MSK.rw TruthValue (SNMPv2-TC) .1.2.156.11235.15629.11.1.1.1.1.1.16 |
gb15629dot11wapiConfigPSKValueThe PSK value when WAPI in PSK mode is the selected AKM suite.
In that case, the BK will obtain its value from this object.
This object is logically write-only. Reading this variable shall
return unsuccessful status or null or zero.rw OCTET STRING .1.2.156.11235.15629.11.1.1.1.1.1.17 |
gb15629dot11wapiConfigPSKPassPhraseThe PSK value when WAPI in PSK mode is the selected AKM suite,
is configured by gb15629dot11wapiConfigPSKValue.
An alternative manner of setting the PSK uses the password-to-key
algorithm. This variable provides a means to enter a
pass-phrase. When this object is written, the WAPI entity shall
use the password-to-key algorithm to derive a preshared
and populate gb15629dot11wapiConfigPSKValue with this key.
This object is logically write-only. Reading this variable shall
return unsuccessful status or null or zero.rw DisplayString (SNMPv2-TC) .1.2.156.11235.15629.11.1.1.1.1.1.18 |
gb15629dot11wapiConfigCertificateUpdateCountThe number of times message in the WAPI certificate
authenticating handshake will be retried per certificate
authenticating handshake attempt.rw Unsigned32 .1.2.156.11235.15629.11.1.1.1.1.1.19 |
gb15629dot11wapiConfigMulticastUpdateCountThe number of times message in the WAPI multicast key handshake
will be retried per MSK handshake attempt.rw Unsigned32 .1.2.156.11235.15629.11.1.1.1.1.1.20 |
gb15629dot11wapiConfigUnicastUpdateCountThe number of times message in the WAPI unicast key handshake
will be retried per 3-way handshake attempt.rw Unsigned32 .1.2.156.11235.15629.11.1.1.1.1.1.21 |
gb15629dot11wapiConfigMulticastCipherSizeThis object indicates the length in bits of the multicast
cipher key. This should be 256 for SMS4. first 128 bits for
encrypting, last 128 bits for integrity checking.ro Unsigned32 .1.2.156.11235.15629.11.1.1.1.1.1.22 |
gb15629dot11wapiConfigBKLifetimeThe maximum lifetime of a BK in the BK cache.rw Unsigned32 .1.2.156.11235.15629.11.1.1.1.1.1.23 |
gb15629dot11wapiConfigBKReauthThresholdThe percentage of the BK lifetime that should expire before an
reauthentication occurs.rw Unsigned32 .1.2.156.11235.15629.11.1.1.1.1.1.24 |
gb15629dot11wapiConfigSATimeoutThe maximum time a security association shall take to set up.rw Unsigned32 .1.2.156.11235.15629.11.1.1.1.1.1.25 |
gb15629dot11wapiAuthenticationSuiteSelectedThe selector of the last AKM suite negotiated.ro OCTET STRING .1.2.156.11235.15629.11.1.1.1.1.1.26 |
gb15629dot11wapiUnicastCipherSelectedThe selector of the last unicast cipher negotiated.ro OCTET STRING .1.2.156.11235.15629.11.1.1.1.1.1.27 |
gb15629dot11wapiMulticastCipherSelectedThe selector of the last multicast cipher negotiated.ro OCTET STRING .1.2.156.11235.15629.11.1.1.1.1.1.28 |
gb15629dot11wapiBKIDUsedThe selector of the last BKID used in the last unicast
cipher key handshake.ro OCTET STRING .1.2.156.11235.15629.11.1.1.1.1.1.29 |
gb15629dot11wapiAuthenticationSuiteRequestedThe selector of the last AKM suite requested.ro OCTET STRING .1.2.156.11235.15629.11.1.1.1.1.1.30 |
gb15629dot11wapiUnicastCipherRequestedThe selector of the last unicast cipher requested.ro OCTET STRING .1.2.156.11235.15629.11.1.1.1.1.1.31 |
gb15629dot11wapiMulticastCipherRequestedThe selector of the last multicast cipher requested.ro OCTET STRING .1.2.156.11235.15629.11.1.1.1.1.1.32 |
gb15629dot11wapiConfigUnicastCiphersTableThis table lists the unicast ciphers supported by this entity.
It allows enabling and disabling of each unicast cipher by
network management. The unicast cipher suite list in the WAPI
information element is formed using the information in this
table. SEQUENCE OF Gb15629dot11wapiConfigUnicastCiphersEntry .1.2.156.11235.15629.11.1.1.1.2 |
gb15629dot11wapiConfigUnicastCiphersEntryThe table entry, indexed by the interface index (or all
interfaces) and the unicast cipher. Gb15629dot11wapiConfigUnicastCiphersEntry .1.2.156.11235.15629.11.1.1.1.2.1 |
gb15629dot11wapiConfigUnicastCipherIndexThe auxiliary index into the
gb15629dot11wapiConfigUnicastCiphersTable. Unsigned32 .1.2.156.11235.15629.11.1.1.1.2.1.1 |
gb15629dot11wapiConfigUnicastCipherThe selector of a supported unicast cipher. It consists of an
OUI(the first 3 octets) and a cipher suite identifier
(the last octet).ro OCTET STRING .1.2.156.11235.15629.11.1.1.1.2.1.2 |
gb15629dot11wapiConfigUnicastCipherEnabledThis object enables or disables the unicast cipher.rw TruthValue (SNMPv2-TC) .1.2.156.11235.15629.11.1.1.1.2.1.3 |
gb15629dot11wapiConfigUnicastCipherSizeThis object indicates the length in bits of the unicast cipher
key. This should be 256 for SMS4, first 128 bits for encrypting,
last 128 bits for integrity checking.ro Unsigned32 .1.2.156.11235.15629.11.1.1.1.2.1.4 |
gb15629dot11wapiConfigAuthenticationSuitesTableThis table lists the AKM suites supported by this entity. Each
AKM suite can be individually enabled and disabled. The AKM
suite list in the WAPI information element is formed using the
information in this table. SEQUENCE OF Gb15629dot11wapiConfigAuthenticationSuitesEntry .1.2.156.11235.15629.11.1.1.1.3 |
gb15629dot11wapiConfigAuthenticationSuitesEntryAn entry (row) in the
gb15629dot11wapiConfigAuthenticationSuitesTable. Gb15629dot11wapiConfigAuthenticationSuitesEntry .1.2.156.11235.15629.11.1.1.1.3.1 |
gb15629dot11wapiConfigAuthenticationSuiteIndexThe auxiliary variable used as an index into the
gb15629dot11wapiConfigAuthenticationSuitesTable. Unsigned32 .1.2.156.11235.15629.11.1.1.1.3.1.1 |
gb15629dot11wapiConfigAuthenticationSuiteThe selector of an AKM suite. It consists of an OUI (the first 3
octets) and a cipher suite identifier (the last octet).ro OCTET STRING .1.2.156.11235.15629.11.1.1.1.3.1.2 |
gb15629dot11wapiConfigAuthenticationSuiteEnabledThis variable indicates the corresponding AKM suite is enabled
or disabled.rw TruthValue (SNMPv2-TC) .1.2.156.11235.15629.11.1.1.1.3.1.3 |
gb15629dot11wapiStatsTableThis table maintains per-STA statistics in an WAPI. The entry
with gb15629dot11wapiStatsSTAAddress set to FF-FF-FF-FF-FF-FF
shall contain statistics for broadcast/multicast traffic. SEQUENCE OF Gb15629dot11wapiStatsEntry .1.2.156.11235.15629.11.1.1.1.4 |
gb15629dot11wapiStatsEntryAn entry in the gb15629dot11wapiStatsTable. Gb15629dot11wapiStatsEntry .1.2.156.11235.15629.11.1.1.1.4.1 |
gb15629dot11wapiStatsIndexAn auxiliary index into the gb15629dot11wapiStatsTable. Unsigned32 .1.2.156.11235.15629.11.1.1.1.4.1.1 |
gb15629dot11wapiStatsSTAAddressThe MAC address of the STA to which the statistics in this
conceptual row belong.ro MacAddress (SNMPv2-TC) .1.2.156.11235.15629.11.1.1.1.4.1.2 |
gb15629dot11wapiStatsVersionThe WAPI version with which the STA associated.ro Unsigned32 .1.2.156.11235.15629.11.1.1.1.4.1.3 |
gb15629dot11wapiStatsControlledPortStatusThis object indicates the status of the authentication
entity's controlled port. When the value is TURE, it means
'authenticated'. Otherwise, it means 'unauthenticated'.ro TruthValue (SNMPv2-TC) .1.2.156.11235.15629.11.1.1.1.4.1.4 |
gb15629dot11wapiStatsSelectedUnicastCipherThe unicast cipher suite selector used during association.ro OCTET STRING .1.2.156.11235.15629.11.1.1.1.4.1.5 |
gb15629dot11wapiStatsWPIReplayCountersThe number of WPI MPDUs discarded by the replay mechanism.ro Counter32 .1.2.156.11235.15629.11.1.1.1.4.1.6 |
gb15629dot11wapiStatsWPIDecryptableErrorsThe number of WPI MPDUs discarded because of unavailable cipher
key when WPI-SMS4 decrypting.ro Counter32 .1.2.156.11235.15629.11.1.1.1.4.1.7 |
gb15629dot11wapiStatsWPIMICErrorsThe number of WPI MPDUs discarded because of MIC checking
failure when WPI-SMS4 decrypting.ro Counter32 .1.2.156.11235.15629.11.1.1.1.4.1.8 |
gb15629dot11wapiStatsWAISignatureErrorsThis counter increases when the received WAI packets' signature
is wrong.ro Counter32 .1.2.156.11235.15629.11.1.1.1.4.1.9 |
gb15629dot11wapiStatsWAIHMACErrorsThis counter increases when the received WAI packets'
message authentication key checking error occurs.ro Counter32 .1.2.156.11235.15629.11.1.1.1.4.1.10 |
gb15629dot11wapiStatsWAIAuthenticationResultFailuresThis counter increases when the WAI authentication result
is unsuccessful.ro Counter32 .1.2.156.11235.15629.11.1.1.1.4.1.11 |
gb15629dot11wapiStatsWAIDiscardCountersThis counter increases when the received WAI packet is
discarded.ro Counter32 .1.2.156.11235.15629.11.1.1.1.4.1.12 |
gb15629dot11wapiStatsWAITimeoutCountersThis counter increases when the WAI packet overtime is
detected.ro Counter32 .1.2.156.11235.15629.11.1.1.1.4.1.13 |
gb15629dot11wapiStatsWAIFormatErrorsThis counter increases when the WAI packets' format error occursro Counter32 .1.2.156.11235.15629.11.1.1.1.4.1.14 |
gb15629dot11wapiStatsWAICertificateHandshakeFailuresThis counter increases when the WAI certificate authenticates
unsuccessfully.ro Counter32 .1.2.156.11235.15629.11.1.1.1.4.1.15 |
gb15629dot11wapiStatsWAIUnicastHandshakeFailuresThis counter increases when the WAI unicast cipher key
negotiates unsuccessfully.ro Counter32 .1.2.156.11235.15629.11.1.1.1.4.1.16 |
gb15629dot11wapiStatsWAIMulticastHandshakeFailuresThis counter increases when the WAI multicast cipher key
announces unsuccessfully.ro Counter32 .1.2.156.11235.15629.11.1.1.1.4.1.17 |
wapiMIBConformance OBJECT IDENTIFIER .1.2.156.11235.15629.11.1.1.2 |
gb15629dot11wapiGroups OBJECT IDENTIFIER .1.2.156.11235.15629.11.1.1.2.1 |
gb15629wapiCompliances OBJECT IDENTIFIER .1.2.156.11235.15629.11.1.1.2.2 |