Home/Catalog/GB15629dot11-WAPI-MIB

GB15629dot11-WAPI-MIB

AI MIB Summary

The GB15629dot11-WAPI-MIB module enables monitoring and management of the Wireless Authentication and Privacy Infrastructure (WAPI) security subsystem on Huawei network devices, specifically tracking WAPI session states, authentication failures, and compliance with the GB 15629-2003 standard.

Manage WAPI module.
Main OID:
gb15629dot11wapiMIB.1.2.156.11235.15629.11.1.1
75
Objects
Active
Status
4
Dependencies

Imported Objects

Objects

75 total
Object Name
member-body
OBJECT IDENTIFIER
.1.2
cn
OBJECT IDENTIFIER
.1.2.156
bwips
OBJECT IDENTIFIER
.1.2.156.11235
gb15629
OBJECT IDENTIFIER
.1.2.156.11235.15629
gb15629-11
OBJECT IDENTIFIER
.1.2.156.11235.15629.11
gb15629-11-mibs
OBJECT IDENTIFIER
.1.2.156.11235.15629.11.1
gb15629dot11wapiMIBManage WAPI module.
MODULE-IDENTITY
.1.2.156.11235.15629.11.1.1
wapiMIBObjects
OBJECT IDENTIFIER
.1.2.156.11235.15629.11.1.1.1
gb15629dot11wapiConfigTableThe table containing WAPI configuration objects.
SEQUENCE OF Gb15629dot11wapiConfigEntry
.1.2.156.11235.15629.11.1.1.1.1
gb15629dot11wapiConfigEntryAn entry in the gb15629dot11wapiConfigTable.
Gb15629dot11wapiConfigEntry
.1.2.156.11235.15629.11.1.1.1.1.1
gb15629dot11wapiConfigVersionThe highest WAPI version this entity supports.ro
Integer32
.1.2.156.11235.15629.11.1.1.1.1.1.1
gb15629dot11wapiControlledAuthControlThis object indicates whether the entity enables authentication. When the value is FALSE, it shall indicate that authentication is not enabled on this entity, and the status of the controlled port is 'authenticated'. When the value is TURE, it shall indicate that authentication is enabled, and the status of controlled port is decided by gb15629dot11wapiControlledPortControl.ro
TruthValue (SNMPv2-TC)
.1.2.156.11235.15629.11.1.1.1.1.1.2
gb15629dot11wapiControlledPortControlThis object indicates the controlling type of the entity's port. This object is available when gb15629dot11wapiControlledAuthControl is TURE. When the value is zero, it means 'automatic', and the status of the controlled port is decided by authentication result. When the value is one, it means 'forcible unauthenticated', and the status of the controlled port is 'unauthenticated'.ro
INTEGER
.1.2.156.11235.15629.11.1.1.1.1.1.3
gb15629dot11wapiOptionImplementedThis object indicates whether the entity support WAPI. When the value is TURE, it shall indicate that the entity support WAPI. Otherwise, it shall indicate that the entity doesn't support WAPI.ro
TruthValue (SNMPv2-TC)
.1.2.156.11235.15629.11.1.1.1.1.1.4
gb15629dot11wapiPreauthenticationImplementedThis object indicates whether the entity support WAPI preauthentication. This object can't be set to TURE, unless gb15629dot11wapiOptionImplemented is TURE.ro
TruthValue (SNMPv2-TC)
.1.2.156.11235.15629.11.1.1.1.1.1.5
gb15629dot11wapiEnabledWhen this object is set to TRUE, it shall indicate that WAPI is enabled on this entity. The entity will advertise the WAPI information element in its beacon and probe response frames.rw
TruthValue (SNMPv2-TC)
.1.2.156.11235.15629.11.1.1.1.1.1.6
gb15629dot11wapiPreauthenticationEnabledWhen this object is set to TRUE, it shall indicate that WAPI preauthentication is enabled on this entity. Otherwise, it shall indicate that WAPI preauthentication is disabled on this entity. This object requires that gb15629dot11WAPIEnabled also be set to TRUE.rw
TruthValue (SNMPv2-TC)
.1.2.156.11235.15629.11.1.1.1.1.1.7
gb15629dot11wapiConfigUnicastKeysSupportedThis object indicates how many unicast keys the entity supports for WAPI.ro
Unsigned32
.1.2.156.11235.15629.11.1.1.1.1.1.8
gb15629dot11wapiConfigUnicastRekeyMethodThis object selects a mechanism for rekeying the WAPI USK. The default is time-based, once per day. Rekeying the USK is only applicable to an entity acting as a role of AE or ASUE.rw
Enumeration
.1.2.156.11235.15629.11.1.1.1.1.1.9
gb15629dot11wapiConfigUnicastRekeyTimeThe time in seconds after which the WAPI USK shall be refreshed. The timer shall start at the moment the USK was set using the MLME-SETWPIKEYS request primitive.rw
Unsigned32
.1.2.156.11235.15629.11.1.1.1.1.1.10
gb15629dot11wapiConfigUnicastRekeyPacketsA packet count (in 1000s of packets) after which the WAPI USK shall be refreshed. The packet counter shall start at the moment the USK was set using the MLME-SETKEYS request primitive and it shall count all packets encrypted using the current USK.rw
Unsigned32
.1.2.156.11235.15629.11.1.1.1.1.1.11
gb15629dot11wapiConfigMulticastCipherThis object indicates the multicast cipher suite selector the entity must use. The multicast cipher suite in the WAPI information element shall take its value from this variable. It consists of an OUI (the first 3 octets) and a cipher suite identifier (the last octet).rw
OCTET STRING
.1.2.156.11235.15629.11.1.1.1.1.1.12
gb15629dot11wapiConfigMulticastRekeyMethodThis object selects a mechanism for rekeying the WAPI MSK. The default is time-based, once per day. Rekeying the MSK is only applicable to an entity acting as a role of AE or ASUE.rw
Enumeration
.1.2.156.11235.15629.11.1.1.1.1.1.13
gb15629dot11wapiConfigMulticastRekeyTimeThe time in seconds after which the WAPI MSK shall be refreshed. The timer shall start at the moment the MSK was set using the MLME-SETWPIKEYS request primitive.rw
Unsigned32
.1.2.156.11235.15629.11.1.1.1.1.1.14
gb15629dot11wapiConfigMulticastRekeyPacketsA packet count (in 1000s of packets) after which the WAPI MSK shall be refreshed. The packet counter shall start at the moment the MSK was set using the MLME-SETKEYS request primitive and it shall count all packets encrypted using the current MSK.rw
Unsigned32
.1.2.156.11235.15629.11.1.1.1.1.1.15
gb15629dot11wapiConfigMulticastRekeyStrictThis object signals that the MSK shall be refreshed whenever a STA leaves the BSS that possesses the MSK.rw
TruthValue (SNMPv2-TC)
.1.2.156.11235.15629.11.1.1.1.1.1.16
gb15629dot11wapiConfigPSKValueThe PSK value when WAPI in PSK mode is the selected AKM suite. In that case, the BK will obtain its value from this object. This object is logically write-only. Reading this variable shall return unsuccessful status or null or zero.rw
OCTET STRING
.1.2.156.11235.15629.11.1.1.1.1.1.17
gb15629dot11wapiConfigPSKPassPhraseThe PSK value when WAPI in PSK mode is the selected AKM suite, is configured by gb15629dot11wapiConfigPSKValue. An alternative manner of setting the PSK uses the password-to-key algorithm. This variable provides a means to enter a pass-phrase. When this object is written, the WAPI entity shall use the password-to-key algorithm to derive a preshared and populate gb15629dot11wapiConfigPSKValue with this key. This object is logically write-only. Reading this variable shall return unsuccessful status or null or zero.rw
DisplayString (SNMPv2-TC)
.1.2.156.11235.15629.11.1.1.1.1.1.18
gb15629dot11wapiConfigCertificateUpdateCountThe number of times message in the WAPI certificate authenticating handshake will be retried per certificate authenticating handshake attempt.rw
Unsigned32
.1.2.156.11235.15629.11.1.1.1.1.1.19
gb15629dot11wapiConfigMulticastUpdateCountThe number of times message in the WAPI multicast key handshake will be retried per MSK handshake attempt.rw
Unsigned32
.1.2.156.11235.15629.11.1.1.1.1.1.20
gb15629dot11wapiConfigUnicastUpdateCountThe number of times message in the WAPI unicast key handshake will be retried per 3-way handshake attempt.rw
Unsigned32
.1.2.156.11235.15629.11.1.1.1.1.1.21
gb15629dot11wapiConfigMulticastCipherSizeThis object indicates the length in bits of the multicast cipher key. This should be 256 for SMS4. first 128 bits for encrypting, last 128 bits for integrity checking.ro
Unsigned32
.1.2.156.11235.15629.11.1.1.1.1.1.22
gb15629dot11wapiConfigBKLifetimeThe maximum lifetime of a BK in the BK cache.rw
Unsigned32
.1.2.156.11235.15629.11.1.1.1.1.1.23
gb15629dot11wapiConfigBKReauthThresholdThe percentage of the BK lifetime that should expire before an reauthentication occurs.rw
Unsigned32
.1.2.156.11235.15629.11.1.1.1.1.1.24
gb15629dot11wapiConfigSATimeoutThe maximum time a security association shall take to set up.rw
Unsigned32
.1.2.156.11235.15629.11.1.1.1.1.1.25
gb15629dot11wapiAuthenticationSuiteSelectedThe selector of the last AKM suite negotiated.ro
OCTET STRING
.1.2.156.11235.15629.11.1.1.1.1.1.26
gb15629dot11wapiUnicastCipherSelectedThe selector of the last unicast cipher negotiated.ro
OCTET STRING
.1.2.156.11235.15629.11.1.1.1.1.1.27
gb15629dot11wapiMulticastCipherSelectedThe selector of the last multicast cipher negotiated.ro
OCTET STRING
.1.2.156.11235.15629.11.1.1.1.1.1.28
gb15629dot11wapiBKIDUsedThe selector of the last BKID used in the last unicast cipher key handshake.ro
OCTET STRING
.1.2.156.11235.15629.11.1.1.1.1.1.29
gb15629dot11wapiAuthenticationSuiteRequestedThe selector of the last AKM suite requested.ro
OCTET STRING
.1.2.156.11235.15629.11.1.1.1.1.1.30
gb15629dot11wapiUnicastCipherRequestedThe selector of the last unicast cipher requested.ro
OCTET STRING
.1.2.156.11235.15629.11.1.1.1.1.1.31
gb15629dot11wapiMulticastCipherRequestedThe selector of the last multicast cipher requested.ro
OCTET STRING
.1.2.156.11235.15629.11.1.1.1.1.1.32
gb15629dot11wapiConfigUnicastCiphersTableThis table lists the unicast ciphers supported by this entity. It allows enabling and disabling of each unicast cipher by network management. The unicast cipher suite list in the WAPI information element is formed using the information in this table.
SEQUENCE OF Gb15629dot11wapiConfigUnicastCiphersEntry
.1.2.156.11235.15629.11.1.1.1.2
gb15629dot11wapiConfigUnicastCiphersEntryThe table entry, indexed by the interface index (or all interfaces) and the unicast cipher.
Gb15629dot11wapiConfigUnicastCiphersEntry
.1.2.156.11235.15629.11.1.1.1.2.1
gb15629dot11wapiConfigUnicastCipherIndexThe auxiliary index into the gb15629dot11wapiConfigUnicastCiphersTable.
Unsigned32
.1.2.156.11235.15629.11.1.1.1.2.1.1
gb15629dot11wapiConfigUnicastCipherThe selector of a supported unicast cipher. It consists of an OUI(the first 3 octets) and a cipher suite identifier (the last octet).ro
OCTET STRING
.1.2.156.11235.15629.11.1.1.1.2.1.2
gb15629dot11wapiConfigUnicastCipherEnabledThis object enables or disables the unicast cipher.rw
TruthValue (SNMPv2-TC)
.1.2.156.11235.15629.11.1.1.1.2.1.3
gb15629dot11wapiConfigUnicastCipherSizeThis object indicates the length in bits of the unicast cipher key. This should be 256 for SMS4, first 128 bits for encrypting, last 128 bits for integrity checking.ro
Unsigned32
.1.2.156.11235.15629.11.1.1.1.2.1.4
gb15629dot11wapiConfigAuthenticationSuitesTableThis table lists the AKM suites supported by this entity. Each AKM suite can be individually enabled and disabled. The AKM suite list in the WAPI information element is formed using the information in this table.
SEQUENCE OF Gb15629dot11wapiConfigAuthenticationSuitesEntry
.1.2.156.11235.15629.11.1.1.1.3
gb15629dot11wapiConfigAuthenticationSuitesEntryAn entry (row) in the gb15629dot11wapiConfigAuthenticationSuitesTable.
Gb15629dot11wapiConfigAuthenticationSuitesEntry
.1.2.156.11235.15629.11.1.1.1.3.1
gb15629dot11wapiConfigAuthenticationSuiteIndexThe auxiliary variable used as an index into the gb15629dot11wapiConfigAuthenticationSuitesTable.
Unsigned32
.1.2.156.11235.15629.11.1.1.1.3.1.1
gb15629dot11wapiConfigAuthenticationSuiteThe selector of an AKM suite. It consists of an OUI (the first 3 octets) and a cipher suite identifier (the last octet).ro
OCTET STRING
.1.2.156.11235.15629.11.1.1.1.3.1.2
gb15629dot11wapiConfigAuthenticationSuiteEnabledThis variable indicates the corresponding AKM suite is enabled or disabled.rw
TruthValue (SNMPv2-TC)
.1.2.156.11235.15629.11.1.1.1.3.1.3
gb15629dot11wapiStatsTableThis table maintains per-STA statistics in an WAPI. The entry with gb15629dot11wapiStatsSTAAddress set to FF-FF-FF-FF-FF-FF shall contain statistics for broadcast/multicast traffic.
SEQUENCE OF Gb15629dot11wapiStatsEntry
.1.2.156.11235.15629.11.1.1.1.4
gb15629dot11wapiStatsEntryAn entry in the gb15629dot11wapiStatsTable.
Gb15629dot11wapiStatsEntry
.1.2.156.11235.15629.11.1.1.1.4.1
gb15629dot11wapiStatsIndexAn auxiliary index into the gb15629dot11wapiStatsTable.
Unsigned32
.1.2.156.11235.15629.11.1.1.1.4.1.1
gb15629dot11wapiStatsSTAAddressThe MAC address of the STA to which the statistics in this conceptual row belong.ro
MacAddress (SNMPv2-TC)
.1.2.156.11235.15629.11.1.1.1.4.1.2
gb15629dot11wapiStatsVersionThe WAPI version with which the STA associated.ro
Unsigned32
.1.2.156.11235.15629.11.1.1.1.4.1.3
gb15629dot11wapiStatsControlledPortStatusThis object indicates the status of the authentication entity's controlled port. When the value is TURE, it means 'authenticated'. Otherwise, it means 'unauthenticated'.ro
TruthValue (SNMPv2-TC)
.1.2.156.11235.15629.11.1.1.1.4.1.4
gb15629dot11wapiStatsSelectedUnicastCipherThe unicast cipher suite selector used during association.ro
OCTET STRING
.1.2.156.11235.15629.11.1.1.1.4.1.5
gb15629dot11wapiStatsWPIReplayCountersThe number of WPI MPDUs discarded by the replay mechanism.ro
Counter32
.1.2.156.11235.15629.11.1.1.1.4.1.6
gb15629dot11wapiStatsWPIDecryptableErrorsThe number of WPI MPDUs discarded because of unavailable cipher key when WPI-SMS4 decrypting.ro
Counter32
.1.2.156.11235.15629.11.1.1.1.4.1.7
gb15629dot11wapiStatsWPIMICErrorsThe number of WPI MPDUs discarded because of MIC checking failure when WPI-SMS4 decrypting.ro
Counter32
.1.2.156.11235.15629.11.1.1.1.4.1.8
gb15629dot11wapiStatsWAISignatureErrorsThis counter increases when the received WAI packets' signature is wrong.ro
Counter32
.1.2.156.11235.15629.11.1.1.1.4.1.9
gb15629dot11wapiStatsWAIHMACErrorsThis counter increases when the received WAI packets' message authentication key checking error occurs.ro
Counter32
.1.2.156.11235.15629.11.1.1.1.4.1.10
gb15629dot11wapiStatsWAIAuthenticationResultFailuresThis counter increases when the WAI authentication result is unsuccessful.ro
Counter32
.1.2.156.11235.15629.11.1.1.1.4.1.11
gb15629dot11wapiStatsWAIDiscardCountersThis counter increases when the received WAI packet is discarded.ro
Counter32
.1.2.156.11235.15629.11.1.1.1.4.1.12
gb15629dot11wapiStatsWAITimeoutCountersThis counter increases when the WAI packet overtime is detected.ro
Counter32
.1.2.156.11235.15629.11.1.1.1.4.1.13
gb15629dot11wapiStatsWAIFormatErrorsThis counter increases when the WAI packets' format error occursro
Counter32
.1.2.156.11235.15629.11.1.1.1.4.1.14
gb15629dot11wapiStatsWAICertificateHandshakeFailuresThis counter increases when the WAI certificate authenticates unsuccessfully.ro
Counter32
.1.2.156.11235.15629.11.1.1.1.4.1.15
gb15629dot11wapiStatsWAIUnicastHandshakeFailuresThis counter increases when the WAI unicast cipher key negotiates unsuccessfully.ro
Counter32
.1.2.156.11235.15629.11.1.1.1.4.1.16
gb15629dot11wapiStatsWAIMulticastHandshakeFailuresThis counter increases when the WAI multicast cipher key announces unsuccessfully.ro
Counter32
.1.2.156.11235.15629.11.1.1.1.4.1.17
wapiMIBConformance
OBJECT IDENTIFIER
.1.2.156.11235.15629.11.1.1.2
gb15629dot11wapiGroups
OBJECT IDENTIFIER
.1.2.156.11235.15629.11.1.1.2.1
gb15629wapiCompliances
OBJECT IDENTIFIER
.1.2.156.11235.15629.11.1.1.2.2