H3C-WAPI-MIB
AI MIB Summary
The H3C-WAPI-MIB module enables configuration management and real-time state monitoring of the Wireless Authentication and Privacy Infrastructure (WAPI) security protocol on H3C network devices. It provides specific objects to track WAPI session establishment, authentication status, and cryptographic key management parameters for compliance and operational visibility.
H3C-WAPI-MIB is an extension of MIB in WAPI protocol. This MIB contains objects to manage configuration and monitor running state for WAPI feature.
Main OID:
h3cwapiMIB.1.3.6.1.4.1.2011.10.2.77
51
Objects
Active
Status
5
Dependencies
Imported Objects
Objects
51 total| Object Name |
|---|
h3cwapiMIBH3C-WAPI-MIB is an extension of MIB in WAPI
protocol. This MIB contains objects to
manage configuration and monitor running state
for WAPI feature. MODULE-IDENTITY .1.3.6.1.4.1.2011.10.2.77 |
h3cwapiMIBObjects OBJECT IDENTIFIER .1.3.6.1.4.1.2011.10.2.77.1 |
h3cwapiModeEnabledWhen this object is set to TRUE, it shall indicate that WAPI
is enabled. Otherwise, it shall indicate that WAPI is disabled.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.2011.10.2.77.1.1 |
h3cwapiASIPAddressTypeThis object is used to set global IP addresses
type (IPv4 or IPv6) of AS.rw InetAddressType (INET-ADDRESS-MIB) .1.3.6.1.4.1.2011.10.2.77.1.2 |
h3cwapiASIPAddressThis object is used to set the global IP address of AS.rw InetAddress (INET-ADDRESS-MIB) .1.3.6.1.4.1.2011.10.2.77.1.3 |
h3cwapiCertificateInstalledThis object indicates whether the entity has installed
certificate. When the value is TURE, it shall indicate that
the entity has installed certificate. Otherwise, it shall
indicate that the entity hasn't installed certificate.ro TruthValue (SNMPv2-TC) .1.3.6.1.4.1.2011.10.2.77.1.4 |
h3cwapiMIBStatsObjects OBJECT IDENTIFIER .1.3.6.1.4.1.2011.10.2.77.2 |
h3cwapiStatsWAISignatureErrorsThis counter increases when the received packet of
WAI signature is wrong.ro Counter32 .1.3.6.1.4.1.2011.10.2.77.2.1 |
h3cwapiStatsWAIHMACErrorsThis counter increases when the received packet of
WAI message authentication key checking error occurs.ro Counter32 .1.3.6.1.4.1.2011.10.2.77.2.2 |
h3cwapiStatsWAIAuthRsltFailuresThis counter increases when the WAI authentication result is
unsuccessful.ro Counter32 .1.3.6.1.4.1.2011.10.2.77.2.3 |
h3cwapiStatsWAIDiscardCountersThis counter increases when the received packet of WAI are
discarded.ro Counter32 .1.3.6.1.4.1.2011.10.2.77.2.4 |
h3cwapiStatsWAITimeoutCountersThis counter increases when the packet of WAI overtime are
detected.ro Counter32 .1.3.6.1.4.1.2011.10.2.77.2.5 |
h3cwapiStatsWAIFormatErrorsThis counter increases when the WAI packet of WAI format
error is detected.ro Counter32 .1.3.6.1.4.1.2011.10.2.77.2.6 |
h3cwapiStatsWAICtfHskFailuresThis counter increases when the WAI certificate authenticates
unsuccessfully.ro Counter32 .1.3.6.1.4.1.2011.10.2.77.2.7 |
h3cwapiStatsWAIUniHskFailuresThis counter increases when the WAI unicast cipher key
negotiates unsuccessfully.ro Counter32 .1.3.6.1.4.1.2011.10.2.77.2.8 |
h3cwapiStatsWAIMulHskFailuresThis counter increases when the WAI multicast cipher key
announces unsuccessfully.ro Counter32 .1.3.6.1.4.1.2011.10.2.77.2.9 |
h3cwapiMIBTableObjects OBJECT IDENTIFIER .1.3.6.1.4.1.2011.10.2.77.3 |
h3cwapiConfigTableThe table containing WAPI configuration objects. SEQUENCE OF H3cwapiConfigEntry .1.3.6.1.4.1.2011.10.2.77.3.1 |
h3cwapiConfigEntryAn entry in the h3cwapiConfigTable. H3cwapiConfigEntry .1.3.6.1.4.1.2011.10.2.77.3.1.1 |
h3cwapiConfigASIPAddressTypeThis object is used to set IP addresses type of AS.rw InetAddressType (INET-ADDRESS-MIB) .1.3.6.1.4.1.2011.10.2.77.3.1.1.1 |
h3cwapiConfigASIPAddressThis object is used to set the IP address of AS.rw InetAddress (INET-ADDRESS-MIB) .1.3.6.1.4.1.2011.10.2.77.3.1.1.2 |
h3cwapiConfigAuthMethodThis object selects a mechanism for WAPI authentication method. The
default is certificate.rw Enumeration .1.3.6.1.4.1.2011.10.2.77.3.1.1.3 |
h3cwapiConfigAuthModeThis object selects a mechanism for WAPI authentication mode. When
the value is standard, it shall indicate that the entity acts accord
with the official definition. Otherwise, it shall indicate that the
entity finishs authentication by means of RADIUS. The default is standard.rw Enumeration .1.3.6.1.4.1.2011.10.2.77.3.1.1.4 |
h3cwapiConfigISPDomainThe ISP domain name.rw OCTET STRING .1.3.6.1.4.1.2011.10.2.77.3.1.1.5 |
h3cwapiConfigCertificateDomainThe PKI domain name.rw OCTET STRING .1.3.6.1.4.1.2011.10.2.77.3.1.1.6 |
h3cwapiConfigASNameThe name of AS.rw OCTET STRING .1.3.6.1.4.1.2011.10.2.77.3.1.1.7 |
h3cwapiConfigBKRekeyEnabledThis object indicates whether the BK rekey function is supported. When the
value is TURE, it shall indicate that the BK rekey function is supported.
Otherwise, it shall indicate that the BK rekey function is not supported.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.2011.10.2.77.3.1.1.8 |
h3cwapiConfigExtTableThe table containing WAPI configuration objects for SSID. SEQUENCE OF H3cwapiConfigExtEntry .1.3.6.1.4.1.2011.10.2.77.3.2 |
h3cwapiConfigExtEntryAn extend entry in the h3cwapiConfigExtTable. H3cwapiConfigExtEntry .1.3.6.1.4.1.2011.10.2.77.3.2.1 |
h3cwapiConfigServicePolicyIDRepresents the ID of each service policy. Integer32 .1.3.6.1.4.1.2011.10.2.77.3.2.1.1 |
h3cwapiConfigUnicastCipherEnabledThis object enables or disables the unicast cipher.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.2011.10.2.77.3.2.1.2 |
h3cwapiConfigUnicastCipherSizeThis object indicates the length in bits of the unicast cipher
key. This should be 256 for SMS4, first 128 bits for encrypting,
last 128 bits for integrity checking.ro Unsigned32 .1.3.6.1.4.1.2011.10.2.77.3.2.1.3 |
h3cwapiConfigAuthenticationSuiteEnabledThis variable indicates the corresponding AKM suite is enabled
or disabled.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.2011.10.2.77.3.2.1.4 |
h3cwapiConfigAuthenticationSuiteThe selector of an AKM suite. It consists of an OUI (the first 3
octets) and a cipher suite identifier (the last octet).ro OCTET STRING .1.3.6.1.4.1.2011.10.2.77.3.2.1.5 |
h3cwapiCfgExtASIPAddressTypeThis object is used to set IP addresses type of AS.rw InetAddressType (INET-ADDRESS-MIB) .1.3.6.1.4.1.2011.10.2.77.3.2.1.6 |
h3cwapiCfgExtASIPAddressThis object is used to set the IP address of AS.rw InetAddress (INET-ADDRESS-MIB) .1.3.6.1.4.1.2011.10.2.77.3.2.1.7 |
h3cwapiCfgExtASNameThis object is used to set the name of AS.rw OCTET STRING .1.3.6.1.4.1.2011.10.2.77.3.2.1.8 |
h3cwapiCfgExtCertDomainThis object is used to set the PKI domain name.rw OCTET STRING .1.3.6.1.4.1.2011.10.2.77.3.2.1.9 |
h3cwapiCfgExtCertInstalledThis object indicates whether the entity has installed
certificate. When the value is TURE, it shall indicate that
the SSID has installed certificate. Otherwise, it shall
indicate that the SSID hasn't installed certificate.ro TruthValue (SNMPv2-TC) .1.3.6.1.4.1.2011.10.2.77.3.2.1.10 |
h3cwapiTrap OBJECT IDENTIFIER .1.3.6.1.4.1.2011.10.2.77.4 |
h3cwapiTrapPrefix OBJECT IDENTIFIER .1.3.6.1.4.1.2011.10.2.77.4.0 |
h3cwapiUserwithInvalidCertificateThis trap is sent when a user intrudes upon network with invalid
certificate. NOTIFICATION-TYPE .1.3.6.1.4.1.2011.10.2.77.4.0.1 |
h3cwapiStationReplayAttackThis trap is sent when an attacker records and replays network
transactions. NOTIFICATION-TYPE .1.3.6.1.4.1.2011.10.2.77.4.0.2 |
h3cwapiTamperAttackThis trap is sent when an attacker monitors network traffic and
maliciously changes data in transit(for example, an attacker may
modify the contents of a WAI message). NOTIFICATION-TYPE .1.3.6.1.4.1.2011.10.2.77.4.0.3 |
h3cwapiLowSafeLevelAttackThis trap is sent when a station associates AP(Access Point),
creates packet of Unicast Key Negotiation Response with wrong
WIE(WAPI Information Element) of ASUE(Authentication Supplicant
Entity). NOTIFICATION-TYPE .1.3.6.1.4.1.2011.10.2.77.4.0.4 |
h3cwapiAddressRedirectionAttackThis trap is sent when an attacker maliciously changes destination
MAC address of WPI(WLAN Privacy Infrastructure) frame. NOTIFICATION-TYPE .1.3.6.1.4.1.2011.10.2.77.4.0.5 |
h3cwapiTrapInfo OBJECT IDENTIFIER .1.3.6.1.4.1.2011.10.2.77.4.1 |
h3cwapiTrapInfoMacAddrThe MAC address of the WAPI user.ro MacAddress (SNMPv2-TC) .1.3.6.1.4.1.2011.10.2.77.4.1.1 |
h3cwapiTrapInfoAPIdTo uniquely identify each AP.ro Integer32 .1.3.6.1.4.1.2011.10.2.77.4.1.2 |
h3cwapiTrapInfoRadioIdRepresents each radio.ro Integer32 .1.3.6.1.4.1.2011.10.2.77.4.1.3 |
h3cwapiTrapInfoBSSIdAs MAC Address format, it is to identify BSS.ro MacAddress (SNMPv2-TC) .1.3.6.1.4.1.2011.10.2.77.4.1.4 |