Home/Catalog/H3C-DOT11-WIDS-MIB

H3C-DOT11-WIDS-MIB

This MIB provides information about WIDS feature. GLOSSARY Wireless Intrusion Detection Sensor (WIDS) WIDS is designed to be employed in an area that is serviced by an existing wireless network. It aids in the early detection of malicious outsider attacks and intrusions via wireless networks. Rogue AP A rogue access point is any Wi-Fi access point connected to the network without authorization. As it is not authorized, if there is any weakness in the AP, the hacker will have chance to compromise the network. Rogue Station It is similiar to Rogue AP, while it is a station. Monitor AP An AP will scan or listen to the air, and try to detect wireless attack in the network. Some AP products will work only in monitor role, while some AP products could switch between normal AP role (only provide wireless access service)and monitor AP role. Ad Hoc Mode Station could work under Ad hoc mode, then they could directly do peer-to-peer communication without other device support.
Main OID:
h3cDot11WIDS.1.3.6.1.4.1.2011.10.2.75.5
201
Objects
Active
Status
3
Dependencies

Imported Objects

Objects

201 total
Object Name
h3cDot11WIDSThis MIB provides information about WIDS feature. GLOSSARY Wireless Intrusion Detection Sensor (WIDS) WIDS is designed to be employed in an area that is serviced by an existing wireless network. It aids in the early detection of malicious outsider attacks and intrusions via wireless networks. Rogue AP A rogue access point is any Wi-Fi access point connected to the network without authorization. As it is not authorized, if there is any weakness in the AP, the hacker will have chance to compromise the network. Rogue Station It is similiar to Rogue AP, while it is a station. Monitor AP An AP will scan or listen to the air, and try to detect wireless attack in the network. Some AP products will work only in monitor role, while some AP products could switch between normal AP role (only provide wireless access service)and monitor AP role. Ad Hoc Mode Station could work under Ad hoc mode, then they could directly do peer-to-peer communication without other device support.
MODULE-IDENTITY
.1.3.6.1.4.1.2011.10.2.75.5
h3cDot11WIDSConfigGroup
OBJECT IDENTIFIER
.1.3.6.1.4.1.2011.10.2.75.5.1
h3cDot11WIDSGlobalConfigGroup
OBJECT IDENTIFIER
.1.3.6.1.4.1.2011.10.2.75.5.1.1
h3cDot11WIDSScanModeRepresents the scope of channels to be scanned. The following value are supported all(1) - Do scan on all the channels. auto(2) - Do scan for the channels that automatically selected by WIDS.rw
Enumeration
.1.3.6.1.4.1.2011.10.2.75.5.1.1.1
h3cDot11WIDSScanChannelListRepresents the channel scope to be scanned when h3cDot11WIDSScanMode is configurated as channelSpec mode. Each channel value will be separated by comma character.rwobsolete
OCTET STRING
.1.3.6.1.4.1.2011.10.2.75.5.1.1.2
h3cDot11CntMsrModeRepresents the countermeasures mode.rw
Bits
.1.3.6.1.4.1.2011.10.2.75.5.1.1.3
h3cDot11DevAgingTimeRepresents the age time for entries in the detected device table. If an entry is not detected within the interval, it is deleted from the detected device table. If the deleted entry is that of a rogue, it is added into the rogue history table.rw
Integer32
.1.3.6.1.4.1.2011.10.2.75.5.1.1.4
h3cDot11DynBlkListEnableRepresents whether the dynamic blacklist feature is enabled or not. 'true' : Enable the dynamic blacklist feature to filter out unwanted clients, which will not get associated. 'false' : Disable the dynamic blacklist feature.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.1.1.5
h3cDot11DynBlkListLifeTimeRepresents the lifetime for dynamic blacklist entries. If a dynamic blacklist entry is not detected within the lifetime, the entry will be removed from the dynamic blacklist. The lifetime becomes active only if dynamic blacklist feature is enabled.rw
Integer32
.1.3.6.1.4.1.2011.10.2.75.5.1.1.6
h3cDot11FloodAtkDctEnableRepresents whether detection of flood attack is enabled or not. 'true' : Enable the detection of flood attack. 'false' : Disable the detection of flood attack.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.1.1.7
h3cDot11SpoofAtkDctEnableRepresents whether detection of Spoof attack is enabled or not. 'true' : Enable the detection of Spoof attack. 'false' : Disable the detection of Spoof attack.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.1.1.8
h3cDot11WeakIVAtkDctEnableRepresents whether detection of weak-iv attack is enabled or not. 'true' : Enable the detection of weak-iv attack. 'false' : Disable the detection of weak-iv attack.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.1.1.9
h3cDot11ResetWIDSRogueHistoryThis object is used to clear all entries from the rogue history table. It will return false for get operation.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.1.1.10
h3cDot11ResetWIDSHistroyThis object is used to clear the history information of attacks detected in the WLAN system. It will return false for get operation.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.1.1.11
h3cDot11ResetWIDSStatisticsThis object is used to clear the statistics of attacks detected in the WLAN system. It will return false for get operation.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.1.1.12
h3cDot11ResetAllDynBlkListThis object is used to remove all entries from the dynamic blacklist. It will return false for get operation.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.1.1.13
h3cDot11ResetAllStcBlkListThis object is used to remove all entries from the static blacklist. It will return false for get operation.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.1.1.14
h3cDot11ResetAllWhtBlkListThis object is used to remove all entries from the static whitelist. It will return false for get operation.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.1.1.15
h3cDot11ResetAllDctRogueAPThis object is used to clear the information of all detected rogue APs. It will return false for get operation.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.1.1.16
h3cDot11ResetAllDctRogueStaThis object is used to clear the information of all detected rogue clients. It will return false for get operation.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.1.1.17
h3cDot11ResetAllDctAdhocThis object is used to clear the information of all detected ad hoc devices. It will return false for get operation.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.1.1.18
h3cDot11ResetAllDctDeviceThis object is used to clear the information of all detected devices. It will return false for get operation.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.1.1.19
h3cDot11ResetAllDctSSIDThis object is used to clear the information of all detected SSIDs. It will return false for get operation.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.1.1.20
h3cDot11WidsFloodIntervalThe interval of WIDS flood detection.rw
Unsigned32 UNITS "second"
.1.3.6.1.4.1.2011.10.2.75.5.1.1.21
h3cDot11WidsBlackListThresholdWhen flood attack exceeds the value of this node, the MAC address will be added into black list.rw
Unsigned32
.1.3.6.1.4.1.2011.10.2.75.5.1.1.22
h3cDot11SSIDFilterOnOffRepresents whether the SSID permit feature is enabled or not.rw
Enumeration
.1.3.6.1.4.1.2011.10.2.75.5.1.1.23
h3cDot11BSSIDFilterOnOffRepresents whether the BSSID permit feature is enabled or not.rw
Enumeration
.1.3.6.1.4.1.2011.10.2.75.5.1.1.24
h3cDot11WIDSPermitVendorTableThe table provides the permitted vendor list, and each vendor will be identified by OUI. The legal device should be made by the permitted vendors.
SEQUENCE OF H3cDot11WIDSPermitVendorEntry
.1.3.6.1.4.1.2011.10.2.75.5.1.2
h3cDot11WIDSPermitVendorEntryEach entry provides the information of permitted vendor.
H3cDot11WIDSPermitVendorEntry
.1.3.6.1.4.1.2011.10.2.75.5.1.2.1
h3cDot11VendorOUIRepresents the vendor OUI information of the wireless device.
OCTET STRING
.1.3.6.1.4.1.2011.10.2.75.5.1.2.1.1
h3cDot11PermitVendorRowStatusThe status of this table entry.rw
RowStatus (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.1.2.1.2
h3cDot11VendorNameRepresents the vendor name of the wireless device.ro
OCTET STRING
.1.3.6.1.4.1.2011.10.2.75.5.1.2.1.3
h3cDot11WIDSPermitSSIDTableThe table represents the list of SSID could be permitted in the wireless network.
SEQUENCE OF H3cDot11WIDSPermitSSIDEntry
.1.3.6.1.4.1.2011.10.2.75.5.1.3
h3cDot11WIDSPermitSSIDEntryEach entry provides the information of permitted SSID.
H3cDot11WIDSPermitSSIDEntry
.1.3.6.1.4.1.2011.10.2.75.5.1.3.1
h3cDot11PermitSSIDRepresents the permitted SSID in the wireless network.
H3cDot11SSIDStringType
.1.3.6.1.4.1.2011.10.2.75.5.1.3.1.1
h3cDot11PermitSSIDRowStatusThe status of this table entry.rw
RowStatus (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.1.3.1.2
h3cDot11PermitSSIDDetectedRepresents whether the permitted SSID is detected or not.ro
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.1.3.1.3
h3cDot11WIDSIgnoreListTableThe table provides the MAC address list of stations or APs, and WIDS always take them as legal stations or APs.
SEQUENCE OF H3cDot11WIDSIgnoreListEntry
.1.3.6.1.4.1.2011.10.2.75.5.1.4
h3cDot11WIDSIgnoreListEntryEach entry contains the MAC address of station or AP, and WIDS always take it as legal station or AP.
H3cDot11WIDSIgnoreListEntry
.1.3.6.1.4.1.2011.10.2.75.5.1.4.1
h3cDot11IgnoreMACRepresents the MAC address of station or AP, and WIDS always take it as legal station or AP.
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.1.4.1.1
h3cDot11IgnoreListRowStatusThe status of this table entry.rw
RowStatus (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.1.4.1.2
h3cDot11IgnoreMACDetectedRepresents whether the MAC address detected or not.ro
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.1.4.1.3
h3cDot11IgnoreDevTypeRepresents the type of the MAC address detected. The value of this object always is unknown if the MAC address is not detected.ro
H3cDot11WIDSDevType
.1.3.6.1.4.1.2011.10.2.75.5.1.4.1.4
h3cDot11WIDSAttackListTableThe table provides the MAC address list of rogue APs or rogue stations, the WIDS will take countermeasure as per the MAC address list.
SEQUENCE OF H3cDot11WIDSAttackListEntry
.1.3.6.1.4.1.2011.10.2.75.5.1.5
h3cDot11WIDSAttackListEntryEach entry contains the MAC address of rogue AP or rogue station, and the countermeasure will be taken for it.
H3cDot11WIDSAttackListEntry
.1.3.6.1.4.1.2011.10.2.75.5.1.5.1
h3cDot11AttackDeviceMacRepresents the MAC address of rogue AP or rogue station, and the countermeasure will be taken for it.
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.1.5.1.1
h3cDot11AttackListRowStatusThe status of this table entry.rw
RowStatus (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.1.5.1.2
h3cDot11AttackDevDetectedRepresents whether the assigned MAC address in attack list is detected or not.ro
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.1.5.1.3
h3cDot11AttackDevTypeRepresents the type of detected MAC address in attack list. If the MAC address is not detected, it will return unknown(5) for get operation.ro
H3cDot11WIDSDevType
.1.3.6.1.4.1.2011.10.2.75.5.1.5.1.4
h3cDot11StaticWhiteListTableThe table provides the information of whitelist.
SEQUENCE OF H3cDot11StaticWhiteListEntry
.1.3.6.1.4.1.2011.10.2.75.5.1.6
h3cDot11StaticWhiteListEntryEach entry contains the information of whitelist.
H3cDot11StaticWhiteListEntry
.1.3.6.1.4.1.2011.10.2.75.5.1.6.1
h3cDot11StaticWhiteListMACRepresents the MAC addresses in whitelist.
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.1.6.1.1
h3cDot11StaticWhiteListRowStatusThe status of this table entry.rw
RowStatus (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.1.6.1.2
h3cDot11StaticBlackListTableThe table provides the information of static blacklist.
SEQUENCE OF H3cDot11StaticBlackListEntry
.1.3.6.1.4.1.2011.10.2.75.5.1.7
h3cDot11StaticBlackListEntryEach entry contains the information of static blacklist.
H3cDot11StaticBlackListEntry
.1.3.6.1.4.1.2011.10.2.75.5.1.7.1
h3cDot11StaticBlackListMACRepresents the MAC addresses in static blacklist.
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.1.7.1.1
h3cDot11StaticBlackListRowStatusThe status of this table entry.rw
RowStatus (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.1.7.1.2
h3cDot11WIDSPermitBSSIDTableThe table represents the list of BSSID could be permitted in the wireless network.
SEQUENCE OF H3cDot11WIDSPermitBSSIDEntry
.1.3.6.1.4.1.2011.10.2.75.5.1.8
h3cDot11WIDSPermitBSSIDEntryEach entry provides the information of permitted BSSID.
H3cDot11WIDSPermitBSSIDEntry
.1.3.6.1.4.1.2011.10.2.75.5.1.8.1
h3cDot11PermitBSSIDRepresents the permitted BSSID in the wireless network.
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.1.8.1.1
h3cDot11PermitBSSIDDetectedRepresents whether the permitted BSSID is detected or not.ro
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.1.8.1.2
h3cDot11PermitBSSIDRowStatusRepresents the row status of permit BSSID table.rw
RowStatus (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.1.8.1.3
h3cDot11WIDSDetectGroup
OBJECT IDENTIFIER
.1.3.6.1.4.1.2011.10.2.75.5.2
h3cDot11WIDSRogueAPTableThe table represents the list of possible BSS information for rogue APs detected by the WIDS.
SEQUENCE OF H3cDot11WIDSRogueAPEntry
.1.3.6.1.4.1.2011.10.2.75.5.2.1
h3cDot11WIDSRogueAPEntryEach entry contains possible BSS information of each rogue AP detected by WIDS.
H3cDot11WIDSRogueAPEntry
.1.3.6.1.4.1.2011.10.2.75.5.2.1.1
h3cDot11RogueAPBSSMACRepresents the BSS MAC address of rogue AP.
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.2.1.1.1
h3cDot11RogueAPVendorNameRepresents the vendor name of rogue AP.ro
OCTET STRING
.1.3.6.1.4.1.2011.10.2.75.5.2.1.1.2
h3cDot11RogueAPMonitorNumRepresents the number of monitor APs which detected the rogue AP.ro
Integer32
.1.3.6.1.4.1.2011.10.2.75.5.2.1.1.3
h3cDot11RogueAPFirstDetectTmRepresents the time that AP was detected as a rogue AP for the first time.ro
TimeTicks (SNMPv2-SMI)
.1.3.6.1.4.1.2011.10.2.75.5.2.1.1.4
h3cDot11RogueAPLastDetectTmRepresents the time that AP was detected as a rogue AP for the last time.ro
TimeTicks (SNMPv2-SMI)
.1.3.6.1.4.1.2011.10.2.75.5.2.1.1.5
h3cDot11RogueAPSSIDRepresents the SSID broadcasted by rogue AP.ro
H3cDot11SSIDStringType (H3C-DOT11-REF-MIB)
.1.3.6.1.4.1.2011.10.2.75.5.2.1.1.6
h3cDot11RogueAPMaxSigStrengthRepresents the maximal value of signal strength that WIDS received from the rogue AP.ro
Integer32 UNITS "dBm"
.1.3.6.1.4.1.2011.10.2.75.5.2.1.1.7
h3cDot11RogueAPChannelRepresents on which radio channel of the rogue AP the maximal signal strength was received.ro
H3cDot11ChannelScopeType (H3C-DOT11-REF-MIB)
.1.3.6.1.4.1.2011.10.2.75.5.2.1.1.8
h3cDot11RogueAPBeaconIntervalRepresents the interval for Beacon management frame of rogue AP.ro
Integer32 UNITS "millisecond"
.1.3.6.1.4.1.2011.10.2.75.5.2.1.1.9
h3cDot11RogueAPAttackedStatusRepresents whether the countermeasure have taken for the rogue AP.ro
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.2.1.1.10
h3cDot11RogueAPToIgnoreRepresents whether the rogue AP will be taken as a rogue AP. If the value is true, NMS should not display the rogue AP as NMS display rogue AP list, and the MAC address will be automatically added into h3cDot11WIDSIgnoreListTable. If the value is false, NMS will take it as a rogue AP.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.2.1.1.11
h3cDot11RogueAPEncryptStatusRepresents whether the rogue AP encrypt the frame or not.ro
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.2.1.1.12
h3cDot11RogueAPResetThis object is used to clear information of assigned AP. The information of AP which detect assigned rogue AP will be cleared together. It will return false for get operation.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.2.1.1.13
h3cDot11RogueAPFirstDetectTmStrRepresents the time that AP was detected as a rogue AP for the first time.ro
OCTET STRING
.1.3.6.1.4.1.2011.10.2.75.5.2.1.1.14
h3cDot11RogueAPLastDetectTmStrRepresents the time that AP was detected as a rogue AP for the last time.ro
OCTET STRING
.1.3.6.1.4.1.2011.10.2.75.5.2.1.1.15
h3cDot11WIDSRogueAPExtTableAs each rogue AP could be detected by multiple monitor APs, each monitor AP could have some kind of detailed information about a specific rogue AP. In the h3cDot11WIDSRogueAPTable table, the detailed information for a specific rogue AP will be summarized from information in the h3cDot11WIDSRogueAPExtTable table. For example, multiple monitor APs could receive RF signal of one rogue AP, and each monitor AP has its maximum signal strength by itself. The information will be kept as h3cDot11DetectMaxAPSigStrength in the h3cDot11WIDSRogueAPExtTable table. While only the maximum value among all the h3cDot11DetectMaxAPSigStrength for each monitor AP will be kept in the h3cDot11WIDSRogueAPTable as h3cDot11RogueAPMaxSigStrength.
SEQUENCE OF H3cDot11WIDSRogueAPExtEntry
.1.3.6.1.4.1.2011.10.2.75.5.2.2
h3cDot11WIDSRogueAPExtEntryEach entry contains information of the rogue AP detected by each monitor AP.
H3cDot11WIDSRogueAPExtEntry
.1.3.6.1.4.1.2011.10.2.75.5.2.2.1
h3cDot11WIDSAPIDTo uniquely identify each AP, and relation-ship between h3cDot11WIDSAPID and AP device will be static.
H3cDot11ObjectIDType (H3C-DOT11-REF-MIB)
.1.3.6.1.4.1.2011.10.2.75.5.2.2.1.1
h3cDot11DetectCurAPSigStrengthRepresents the current value of signal strength that WIDS monitor AP received from the rogue AP.ro
Integer32 UNITS "dBm"
.1.3.6.1.4.1.2011.10.2.75.5.2.2.1.2
h3cDot11DetectAPByChannelRepresents on which radio channel that WIDS monitor AP detected the rogue AP.ro
H3cDot11ChannelScopeType (H3C-DOT11-REF-MIB)
.1.3.6.1.4.1.2011.10.2.75.5.2.2.1.3
h3cDot11DetectAPByRadioIDRepresents on which radio the monitor AP has detected the rogue AP.ro
H3cDot11RadioScopeType (H3C-DOT11-REF-MIB)
.1.3.6.1.4.1.2011.10.2.75.5.2.2.1.4
h3cDot11AttackAPStatusRepresents whether monitor AP have taken countermeasure on the rogue AP.ro
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.2.2.1.5
h3cDot11DetectAPFirstTmRepresents the time that monitor AP detected the rogue AP for the first time.ro
TimeTicks (SNMPv2-SMI)
.1.3.6.1.4.1.2011.10.2.75.5.2.2.1.6
h3cDot11DetectAPLastTmRepresents the time that monitor AP detected the rogue AP for the last time.ro
TimeTicks (SNMPv2-SMI)
.1.3.6.1.4.1.2011.10.2.75.5.2.2.1.7
h3cDot11WIDSRogueStaTableThe table represents the list of rogue stations detected by the WIDS.
SEQUENCE OF H3cDot11WIDSRogueStaEntry
.1.3.6.1.4.1.2011.10.2.75.5.2.3
h3cDot11WIDSRogueStaEntryEach entry contains information of each rogue station.
H3cDot11WIDSRogueStaEntry
.1.3.6.1.4.1.2011.10.2.75.5.2.3.1
h3cDot11RogueStaMACRepresents the MAC address of rogue station.
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.2.3.1.1
h3cDot11RogueStaVendorNameRepresents the vendor name of rogue station.ro
OCTET STRING
.1.3.6.1.4.1.2011.10.2.75.5.2.3.1.2
h3cDot11RogueStaMonitorNumRepresents the number of monitor APs which detected the rogue station.ro
Integer32
.1.3.6.1.4.1.2011.10.2.75.5.2.3.1.3
h3cDot11RogueStaFirstDetectTmRepresents the time that station was detected as a rogue station for the first time.ro
TimeTicks (SNMPv2-SMI)
.1.3.6.1.4.1.2011.10.2.75.5.2.3.1.4
h3cDot11RogueStaLastDetectTmRepresents the time that station was detected as a rogue station for the last time.ro
TimeTicks (SNMPv2-SMI)
.1.3.6.1.4.1.2011.10.2.75.5.2.3.1.5
h3cDot11RogueStaAccessBSSIDRepresents BSS MAC address that rogue station try to access.ro
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.2.3.1.6
h3cDot11RogueStaMaxSigStrengthRepresents the maximal value of signal strength that WIDS received from the rogue station.ro
Integer32 UNITS "dBm"
.1.3.6.1.4.1.2011.10.2.75.5.2.3.1.7
h3cDot11RogueStaChannelRepresents on which radio channel the maximal signal strength was received.ro
H3cDot11ChannelScopeType (H3C-DOT11-REF-MIB)
.1.3.6.1.4.1.2011.10.2.75.5.2.3.1.8
h3cDot11RogueStaAttackedStatusRepresents whether the countermeasure have taken for the rogue station.ro
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.2.3.1.9
h3cDot11RogueStaToIgnoreRepresents whether the rogue AP will be taken as a rogue station. If the value is true, NMS should not display the rogue station as NMS display rogue station list, and the MAC address will be automatically added into h3cDot11WIDSIgnoreListTable. If the value is false, NMS will take it as a rogue station.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.2.3.1.10
h3cDot11RogueStaAdHocStatusRepresents whether the rogue station work on the Ad Hoc mode or not.ro
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.2.3.1.11
h3cDot11RogueStaResetThis object is used to clear information of assigned station. The information of AP which detects assigned rogue station will be cleared together. It will return false for get operation.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.2.3.1.12
h3cDot11RogueStaFirstDetectTmStrRepresents the time that station was detected as a rogue station for the first time.ro
OCTET STRING
.1.3.6.1.4.1.2011.10.2.75.5.2.3.1.13
h3cDot11RogueStaLastDetectTmStrRepresents the time that station was detected as a rogue station for the last time.ro
OCTET STRING
.1.3.6.1.4.1.2011.10.2.75.5.2.3.1.14
h3cDot11WIDSRogueStaExtTableAs each rogue station could be detected by multiple monitor APs, each monitor AP could have some kind of detailed information about a specific rogue station. In the h3cDot11WIDSRogueStaTable table, the detailed information for a specific rogue station will be summarized from information in the h3cDot11WIDSRogueStaExtTable table. For example, multiple monitor APs could receive RF signal of one rogue station, and each monitor AP has its maximum signal strength by itself. The information will be kept as h3cDot11DetectMaxStaSigStrength in the h3cDot11WIDSRogueStaExtTable table. While only the maximum value among all the h3cDot11DetectMaxStaSigStrength for each monitor AP will be kept in the h3cDot11WIDSRogueStaTable as h3cDot11RogueStaMaxSigStrength.
SEQUENCE OF H3cDot11WIDSRogueStaExtEntry
.1.3.6.1.4.1.2011.10.2.75.5.2.4
h3cDot11WIDSRogueStaExtEntryEach entry contains information of rogue station detected by each monitor AP.
H3cDot11WIDSRogueStaExtEntry
.1.3.6.1.4.1.2011.10.2.75.5.2.4.1
h3cDot11DetectCurStaSigStrengthRepresents the current value of signal strength that WIDS monitor AP received from the rogue station.ro
Integer32 UNITS "dBm"
.1.3.6.1.4.1.2011.10.2.75.5.2.4.1.1
h3cDot11DetectStaByChannelRepresents on which radio channel the maximal signal strength was received.ro
H3cDot11ChannelScopeType (H3C-DOT11-REF-MIB)
.1.3.6.1.4.1.2011.10.2.75.5.2.4.1.2
h3cDot11DetectStaByRadioIDRepresents which radio on the monitor AP has detected the rogue station.ro
H3cDot11RadioScopeType (H3C-DOT11-REF-MIB)
.1.3.6.1.4.1.2011.10.2.75.5.2.4.1.3
h3cDot11AttackStaStatusRepresents whether monitor AP have taken countermeasure for the rogue station.ro
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.2.4.1.4
h3cDot11DetectStaFirstTmRepresents the time that monitor AP detected the rogue station for the first time.ro
TimeTicks (SNMPv2-SMI)
.1.3.6.1.4.1.2011.10.2.75.5.2.4.1.5
h3cDot11DetectStaLastTmRepresents the time that monitor AP detected the rogue station for the last time.ro
TimeTicks (SNMPv2-SMI)
.1.3.6.1.4.1.2011.10.2.75.5.2.4.1.6
h3cDot11WIDSDetectedDevTableThis Table contains information of detected devices.
SEQUENCE OF H3cDot11WIDSDetectedDevEntry
.1.3.6.1.4.1.2011.10.2.75.5.2.5
h3cDot11WIDSDetectedDevEntryEach entry contains information of detected devices.
H3cDot11WIDSDetectedDevEntry
.1.3.6.1.4.1.2011.10.2.75.5.2.5.1
h3cDot11WIDSDevMACRepresents MAC address of the device detected.
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.2.5.1.1
h3cDot11WIDSDevTypeRepresents type of the device detected.ro
H3cDot11WIDSDevType
.1.3.6.1.4.1.2011.10.2.75.5.2.5.1.2
h3cDot11WIDSDevPermitTypeRepresents whether the device detected is a rogue device or not.ro
H3cDot11WIDSDevPermitType
.1.3.6.1.4.1.2011.10.2.75.5.2.5.1.3
h3cDot11WIDSDevVendorRepresents Vendor of the detected device.ro
OCTET STRING
.1.3.6.1.4.1.2011.10.2.75.5.2.5.1.4
h3cDot11WIDSDevMonitorNumRepresents the number of active APs that detect the device.ro
Integer32
.1.3.6.1.4.1.2011.10.2.75.5.2.5.1.5
h3cDot11WIDSDevSSIDRepresents the service set identifier for the ESS of the device.ro
OCTET STRING
.1.3.6.1.4.1.2011.10.2.75.5.2.5.1.6
h3cDot11WIDSDevBSSIDRepresents the basic service set identifier of the detected device.ro
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.2.5.1.7
h3cDot11WIDSDevChannelRepresents the channel in which the device was last detected.ro
H3cDot11ChannelScopeType (H3C-DOT11-REF-MIB)
.1.3.6.1.4.1.2011.10.2.75.5.2.5.1.8
h3cDot11WIDSDevMaxRSSIRepresents the maximum detected RSSI of the device.ro
Integer32 UNITS "dbm"
.1.3.6.1.4.1.2011.10.2.75.5.2.5.1.9
h3cDot11WIDSDevBeaconIntvlRepresents the beacon interval for the detected AP.ro
Integer32 UNITS "millionsecond"
.1.3.6.1.4.1.2011.10.2.75.5.2.5.1.10
h3cDot11WIDSDevFstDctTimeRepresents the time at which the device was first detected.ro
DateAndTime (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.2.5.1.11
h3cDot11WIDSDevLstDctTimeRepresents the time at which the rogue AP was detected last time.ro
DateAndTime (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.2.5.1.12
h3cDot11WIDSDevResetThis object is used to clears the information of the device detected in the WLAN. It will return false for get operation.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.2.5.1.13
h3cDot11WIDSDevSnrRepresents SNR of the device detected.ro
Integer32 UNITS "dB"
.1.3.6.1.4.1.2011.10.2.75.5.2.5.1.14
h3cDot11WIDSRptAPTableThis Table contains information of the AP which detected device in the WLAN.
SEQUENCE OF H3cDot11WIDSRptAPEntry
.1.3.6.1.4.1.2011.10.2.75.5.2.6
h3cDot11WIDSRptAPEntryEach entry contains information of the AP which detected device in the WLAN.
H3cDot11WIDSRptAPEntry
.1.3.6.1.4.1.2011.10.2.75.5.2.6.1
h3cDot11WIDSRptAPMACRepresents the MAC address of the AP that detected the device.
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.2.6.1.1
h3cDot11WIDSRptAPNameRepresents the name of the AP that detected the device.ro
OCTET STRING
.1.3.6.1.4.1.2011.10.2.75.5.2.6.1.2
h3cDot11WIDSRptAPRadioIDRepresents the radio index of the AP that detected the device.ro
H3cDot11RadioScopeType (H3C-DOT11-REF-MIB)
.1.3.6.1.4.1.2011.10.2.75.5.2.6.1.3
h3cDot11WIDSRptAPMaxRSSIRepresents the maximum detected RSSI of the device.ro
Integer32
.1.3.6.1.4.1.2011.10.2.75.5.2.6.1.4
h3cDot11WIDSRptAPFstDctTimeRepresents the time at which the rogue AP was detected first time.ro
DateAndTime (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.2.6.1.5
h3cDot11WIDSRptAPLstDctTimeRepresents the time at which the rogue AP was detected last time.ro
DateAndTime (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.2.6.1.6
h3cDot11DynBlackListTableThis table contains information of dynamic blacklist entries.
SEQUENCE OF H3cDot11DynBlackListEntry
.1.3.6.1.4.1.2011.10.2.75.5.2.7
h3cDot11DynBlackListEntryEach entry contains information of dynamic blacklist.
H3cDot11DynBlackListEntry
.1.3.6.1.4.1.2011.10.2.75.5.2.7.1
h3cDot11DynBlackListMACRepresents the MAC address of the device inserted into the dynamic blacklist.
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.2.7.1.1
h3cDot11DynBlackListTimeRepresents the time elapsed since the entry was last updated.ro
Unsigned32 UNITS "second"
.1.3.6.1.4.1.2011.10.2.75.5.2.7.1.2
h3cDot11DynBlackListReasonRepresents the reason why the entry was added into the dynamic blacklist.ro
OCTET STRING
.1.3.6.1.4.1.2011.10.2.75.5.2.7.1.3
h3cDot11DynBlackListResetThis object is used to remove designated entry from the dynamic blacklist. The value which read from this object always is false.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.2.7.1.4
h3cDot11DynBlackListTimeTicksRepresents the time elapsed since the entry was last updated in units TimeTicks.ro
TimeTicks (SNMPv2-SMI)
.1.3.6.1.4.1.2011.10.2.75.5.2.7.1.5
h3cDot11WIDSRogueHistoryTableThis table contains information of all expired rogue devices which have been deleted from the list of detected rogue devices because they could not be detected within the device aging duration.
SEQUENCE OF H3cDot11WIDSRogueHistoryEntry
.1.3.6.1.4.1.2011.10.2.75.5.2.8
h3cDot11WIDSRogueHistoryEntryEach entry contains information of an expired rogue device which has been deleted from the list of detected rogue devices because they could not be detected within the device aging duration.
H3cDot11WIDSRogueHistoryEntry
.1.3.6.1.4.1.2011.10.2.75.5.2.8.1
h3cDot11WIDSRogueHisIndexRepresents index of this entry.
Integer32
.1.3.6.1.4.1.2011.10.2.75.5.2.8.1.1
h3cDot11WIDSRogueHisMACRepresents the MAC address of the device.ro
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.2.8.1.2
h3cDot11WIDSRogueHisVendorRepresents the vendor for the device.ro
OCTET STRING
.1.3.6.1.4.1.2011.10.2.75.5.2.8.1.3
h3cDot11WIDSRogueHisTypeRepresents the type of the device.ro
H3cDot11WIDSDevType
.1.3.6.1.4.1.2011.10.2.75.5.2.8.1.4
h3cDot11WIDSRogueHisChlRepresents the channel in which the device was last detected.ro
H3cDot11ChannelScopeType (H3C-DOT11-REF-MIB)
.1.3.6.1.4.1.2011.10.2.75.5.2.8.1.5
h3cDot11WIDSRogueHisSSIDRepresents the service set identifier for the ESS of the device.ro
OCTET STRING
.1.3.6.1.4.1.2011.10.2.75.5.2.8.1.6
h3cDot11WIDSRogueHisLastDctTimeRepresents the time at which the device was last detected.ro
DateAndTime (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.2.8.1.7
h3cDot11WIDSAtkHistroyTableThis table contains information of the history of attacks detected in the WLAN system.
SEQUENCE OF H3cDot11WIDSAtkHistroyEntry
.1.3.6.1.4.1.2011.10.2.75.5.2.9
h3cDot11WIDSAtkHistroyEntryEach entry contains information of the history of attacks detected in the WLAN system.
H3cDot11WIDSAtkHistroyEntry
.1.3.6.1.4.1.2011.10.2.75.5.2.9.1
h3cDot11WIDSAtkHisIndexRepresents index of this entry.
Integer32
.1.3.6.1.4.1.2011.10.2.75.5.2.9.1.1
h3cDot11WIDSAtkHisMACRepresents the Mac address. In case of spoof attacks, this field provides the BSSID which was spoofed. In case of other attacks, this field provides the MAC address of the device which initiated the attack.ro
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.2.9.1.2
h3cDot11WIDSAtkHisTypeRepresents the type of attack.ro
H3cDot11WIDSAtkType
.1.3.6.1.4.1.2011.10.2.75.5.2.9.1.3
h3cDot11WIDSAtkHisChlRepresents the channel in which the attack was detected.ro
H3cDot11ChannelScopeType (H3C-DOT11-REF-MIB)
.1.3.6.1.4.1.2011.10.2.75.5.2.9.1.4
h3cDot11WIDSAtkHisRSSIRepresents the average RSSI of the designated attack.ro
Integer32
.1.3.6.1.4.1.2011.10.2.75.5.2.9.1.5
h3cDot11WIDSAtkHisDctTimeRepresents the time at which this attack was detected.ro
DateAndTime (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.2.9.1.6
h3cDot11WIDSAtkHisAPNameRepresents the name of the AP which detected this attack.ro
OCTET STRING
.1.3.6.1.4.1.2011.10.2.75.5.2.9.1.7
h3cDot11WIDSAtkStatis
OBJECT IDENTIFIER
.1.3.6.1.4.1.2011.10.2.75.5.2.10
h3cDot11WIDSAtkStasStartTimeRepresents current attack tracking time. It is started at the system startup and is refreshed each hour subsequently.ro
DateAndTime (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.2.10.1
h3cDot11WIDSAtkStasTableThis table contains information of the counts of attacks detected.
SEQUENCE OF H3cDot11WIDSAtkStasEntry
.1.3.6.1.4.1.2011.10.2.75.5.2.10.2
h3cDot11WIDSAtkStasEntryEach entry contains information of the counts of attacks detected.
H3cDot11WIDSAtkStasEntry
.1.3.6.1.4.1.2011.10.2.75.5.2.10.2.1
h3cDot11WIDSAtkStasTypeRepresents the type of attack.
H3cDot11WIDSAtkType
.1.3.6.1.4.1.2011.10.2.75.5.2.10.2.1.1
h3cDot11WIDSAtkStasCurCntRepresents the count of attacks detected since the time specified by the current attack tracking time. The current attack tracking time is started at the system startup and is refreshed each hour subsequently.ro
Unsigned32
.1.3.6.1.4.1.2011.10.2.75.5.2.10.2.1.2
h3cDot11WIDSAtkStasTotalCntRepresents the total count of the attacks detected since the system startup.ro
Unsigned32
.1.3.6.1.4.1.2011.10.2.75.5.2.10.2.1.3
h3cDot11BlackListTableThis table contains information of blacklist entries, including dynamic and static.
SEQUENCE OF H3cDot11BlackListEntry
.1.3.6.1.4.1.2011.10.2.75.5.2.11
h3cDot11BlackListEntryEach entry contains information of blacklist.
H3cDot11BlackListEntry
.1.3.6.1.4.1.2011.10.2.75.5.2.11.1
h3cDot11BlackListMACThis object represents the MAC address of the device inserted into the table.
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.2.11.1.1
h3cDot11BlackListTimeRepresents the time elapsed since the entry was last updated. If it is static blacklist, the value is always 0.ro
Unsigned32 UNITS "minutes"
.1.3.6.1.4.1.2011.10.2.75.5.2.11.1.2
h3cDot11BlackListReasonRepresents the reason why the entry was added into the blacklist.ro
OCTET STRING
.1.3.6.1.4.1.2011.10.2.75.5.2.11.1.3
h3cDot11BlackListRowStatusThis object represents the status of this table entry.rw
RowStatus (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.2.11.1.4
h3cDot11BlackListTimeTicksRepresents the time elapsed since the entry was last updated in timetick. If it is static blacklist, the value is always 0.ro
TimeTicks (SNMPv2-SMI)
.1.3.6.1.4.1.2011.10.2.75.5.2.11.1.5
h3cDot11WIDSNotifyGroup
OBJECT IDENTIFIER
.1.3.6.1.4.1.2011.10.2.75.5.3
h3cDot11WIDSTraps
OBJECT IDENTIFIER
.1.3.6.1.4.1.2011.10.2.75.5.3.1
h3cDot11WIDSDetectRogueTrapThe notification represents that a rogue AP or a station was detected by WIDS. The NMS would refer to MIB table under h3cDot11WIDSDetectGroup group to get more detailed information.
NOTIFICATION-TYPE
.1.3.6.1.4.1.2011.10.2.75.5.3.1.1
h3cDot11WIDSAdHocTrapThe notification represents a rogue Ad hoc station was detected.
NOTIFICATION-TYPE
.1.3.6.1.4.1.2011.10.2.75.5.3.1.2
h3cDot11WIDSUnauthorSSIDTrapThe notification represents which unauthorized SSID are accessed in the network. The notification will be sent to NMS when an unauthorized SSID is detected on the network for the first time.
NOTIFICATION-TYPE
.1.3.6.1.4.1.2011.10.2.75.5.3.1.3
h3cDot11WIDSDisappearRogueTrapThe notification represents that a rogue device has aged out and moved to history table or the device type has been changed to friendly. The notification will be sent to NMS whenever a rogue disappears.
NOTIFICATION-TYPE
.1.3.6.1.4.1.2011.10.2.75.5.3.1.4
h3cDot11WIDSDetectAttackThis notification occurs when some type of attack is detected.
NOTIFICATION-TYPE
.1.3.6.1.4.1.2011.10.2.75.5.3.1.5
h3cDot11WIDSDetectWBridgeThis notification occurs whenever a detected device is classified as rogue wireless-bridge.
NOTIFICATION-TYPE
.1.3.6.1.4.1.2011.10.2.75.5.3.1.6
h3cDot11WIDSFloodTrapThis notification occurs when flood attack is detected.
NOTIFICATION-TYPE
.1.3.6.1.4.1.2011.10.2.75.5.3.1.7
h3cDot11WIDSSpoofTrapThis notification occurs when spoof attack is detected.
NOTIFICATION-TYPE
.1.3.6.1.4.1.2011.10.2.75.5.3.1.8
h3cDot11WIDSWeakIVTrapThis notification occurs when weak IV attack is detected.
NOTIFICATION-TYPE
.1.3.6.1.4.1.2011.10.2.75.5.3.1.9
h3cDot11WIDSTrapVarObjects
OBJECT IDENTIFIER
.1.3.6.1.4.1.2011.10.2.75.5.3.2
h3cDot11WIDSRogueMACRepresents which rogue AP or station.ro
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.3.2.1
h3cDot11WIDSRogueTypeRepresents the rogue type. The following value are supported rogueAp(1) - A rogue AP rogueStation(2) - A rogue Stationro
Enumeration
.1.3.6.1.4.1.2011.10.2.75.5.3.2.2
h3cDot11WIDSMonitorMACRepresents which monitor detected the rogue AP or station.ro
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.3.2.3
h3cDot11WIDSAdHocMACRepresents the MAC address of Ad hoc station.ro
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.3.2.4
h3cDot11UnauthorSSIDNameRepresents an unauthorized SSID.ro
H3cDot11SSIDStringType (H3C-DOT11-REF-MIB)
.1.3.6.1.4.1.2011.10.2.75.5.3.2.5
h3cDot11MonitorAPIDRepresents monitor AP's APID.ro
H3cDot11ObjectIDType (H3C-DOT11-REF-MIB)
.1.3.6.1.4.1.2011.10.2.75.5.3.2.6
h3cDot11MonitorApRadioIDRepresents monitor AP's radio IDro
H3cDot11RadioScopeType (H3C-DOT11-REF-MIB)
.1.3.6.1.4.1.2011.10.2.75.5.3.2.7
h3cDot11WIDSAtkMacRepresents mac address of attack source.ro
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.3.2.8
h3cDot11WIDSAtkFrameTypeRepresents attack frame type.ro
OCTET STRING
.1.3.6.1.4.1.2011.10.2.75.5.3.2.9
h3cDot11WIDSAtkChannelRepresents attack channel.ro
H3cDot11ChannelScopeType (H3C-DOT11-REF-MIB)
.1.3.6.1.4.1.2011.10.2.75.5.3.2.10
h3cDot11WIDSAtkTimeRepresents when attacking happened.ro
OCTET STRING
.1.3.6.1.4.1.2011.10.2.75.5.3.2.11
h3cDot11WIDSAtkDestMacRepresents mac address of attack destination.ro
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.75.5.3.2.12
h3cDot11WIDSFirstTrapTimeRepresents the first trap time.ro
TimeTicks (SNMPv2-SMI)
.1.3.6.1.4.1.2011.10.2.75.5.3.2.13
H3C-DOT11-WIDS-MIB - SNMP MIB Reference | MIBs Explorer