Home/Catalog/H3C-WAPI-MIB

H3C-WAPI-MIB

AI MIB Summary

The H3C-WAPI-MIB module enables configuration management and real-time state monitoring of the Wireless Authentication and Privacy Infrastructure (WAPI) security protocol on H3C network devices. It provides specific objects to track WAPI session establishment, authentication status, and cryptographic key management parameters for compliance and operational visibility.

H3C-WAPI-MIB is an extension of MIB in WAPI protocol. This MIB contains objects to manage configuration and monitor running state for WAPI feature.
Main OID:
h3cwapiMIB.1.3.6.1.4.1.2011.10.2.77
51
Objects
Active
Status
5
Dependencies

Imported Objects

Objects

51 total
Object Name
h3cwapiMIBH3C-WAPI-MIB is an extension of MIB in WAPI protocol. This MIB contains objects to manage configuration and monitor running state for WAPI feature.
MODULE-IDENTITY
.1.3.6.1.4.1.2011.10.2.77
h3cwapiMIBObjects
OBJECT IDENTIFIER
.1.3.6.1.4.1.2011.10.2.77.1
h3cwapiModeEnabledWhen this object is set to TRUE, it shall indicate that WAPI is enabled. Otherwise, it shall indicate that WAPI is disabled.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.77.1.1
h3cwapiASIPAddressTypeThis object is used to set global IP addresses type (IPv4 or IPv6) of AS.rw
InetAddressType (INET-ADDRESS-MIB)
.1.3.6.1.4.1.2011.10.2.77.1.2
h3cwapiASIPAddressThis object is used to set the global IP address of AS.rw
InetAddress (INET-ADDRESS-MIB)
.1.3.6.1.4.1.2011.10.2.77.1.3
h3cwapiCertificateInstalledThis object indicates whether the entity has installed certificate. When the value is TURE, it shall indicate that the entity has installed certificate. Otherwise, it shall indicate that the entity hasn't installed certificate.ro
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.77.1.4
h3cwapiMIBStatsObjects
OBJECT IDENTIFIER
.1.3.6.1.4.1.2011.10.2.77.2
h3cwapiStatsWAISignatureErrorsThis counter increases when the received packet of WAI signature is wrong.ro
Counter32
.1.3.6.1.4.1.2011.10.2.77.2.1
h3cwapiStatsWAIHMACErrorsThis counter increases when the received packet of WAI message authentication key checking error occurs.ro
Counter32
.1.3.6.1.4.1.2011.10.2.77.2.2
h3cwapiStatsWAIAuthRsltFailuresThis counter increases when the WAI authentication result is unsuccessful.ro
Counter32
.1.3.6.1.4.1.2011.10.2.77.2.3
h3cwapiStatsWAIDiscardCountersThis counter increases when the received packet of WAI are discarded.ro
Counter32
.1.3.6.1.4.1.2011.10.2.77.2.4
h3cwapiStatsWAITimeoutCountersThis counter increases when the packet of WAI overtime are detected.ro
Counter32
.1.3.6.1.4.1.2011.10.2.77.2.5
h3cwapiStatsWAIFormatErrorsThis counter increases when the WAI packet of WAI format error is detected.ro
Counter32
.1.3.6.1.4.1.2011.10.2.77.2.6
h3cwapiStatsWAICtfHskFailuresThis counter increases when the WAI certificate authenticates unsuccessfully.ro
Counter32
.1.3.6.1.4.1.2011.10.2.77.2.7
h3cwapiStatsWAIUniHskFailuresThis counter increases when the WAI unicast cipher key negotiates unsuccessfully.ro
Counter32
.1.3.6.1.4.1.2011.10.2.77.2.8
h3cwapiStatsWAIMulHskFailuresThis counter increases when the WAI multicast cipher key announces unsuccessfully.ro
Counter32
.1.3.6.1.4.1.2011.10.2.77.2.9
h3cwapiMIBTableObjects
OBJECT IDENTIFIER
.1.3.6.1.4.1.2011.10.2.77.3
h3cwapiConfigTableThe table containing WAPI configuration objects.
SEQUENCE OF H3cwapiConfigEntry
.1.3.6.1.4.1.2011.10.2.77.3.1
h3cwapiConfigEntryAn entry in the h3cwapiConfigTable.
H3cwapiConfigEntry
.1.3.6.1.4.1.2011.10.2.77.3.1.1
h3cwapiConfigASIPAddressTypeThis object is used to set IP addresses type of AS.rw
InetAddressType (INET-ADDRESS-MIB)
.1.3.6.1.4.1.2011.10.2.77.3.1.1.1
h3cwapiConfigASIPAddressThis object is used to set the IP address of AS.rw
InetAddress (INET-ADDRESS-MIB)
.1.3.6.1.4.1.2011.10.2.77.3.1.1.2
h3cwapiConfigAuthMethodThis object selects a mechanism for WAPI authentication method. The default is certificate.rw
Enumeration
.1.3.6.1.4.1.2011.10.2.77.3.1.1.3
h3cwapiConfigAuthModeThis object selects a mechanism for WAPI authentication mode. When the value is standard, it shall indicate that the entity acts accord with the official definition. Otherwise, it shall indicate that the entity finishs authentication by means of RADIUS. The default is standard.rw
Enumeration
.1.3.6.1.4.1.2011.10.2.77.3.1.1.4
h3cwapiConfigISPDomainThe ISP domain name.rw
OCTET STRING
.1.3.6.1.4.1.2011.10.2.77.3.1.1.5
h3cwapiConfigCertificateDomainThe PKI domain name.rw
OCTET STRING
.1.3.6.1.4.1.2011.10.2.77.3.1.1.6
h3cwapiConfigASNameThe name of AS.rw
OCTET STRING
.1.3.6.1.4.1.2011.10.2.77.3.1.1.7
h3cwapiConfigBKRekeyEnabledThis object indicates whether the BK rekey function is supported. When the value is TURE, it shall indicate that the BK rekey function is supported. Otherwise, it shall indicate that the BK rekey function is not supported.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.77.3.1.1.8
h3cwapiConfigExtTableThe table containing WAPI configuration objects for SSID.
SEQUENCE OF H3cwapiConfigExtEntry
.1.3.6.1.4.1.2011.10.2.77.3.2
h3cwapiConfigExtEntryAn extend entry in the h3cwapiConfigExtTable.
H3cwapiConfigExtEntry
.1.3.6.1.4.1.2011.10.2.77.3.2.1
h3cwapiConfigServicePolicyIDRepresents the ID of each service policy.
Integer32
.1.3.6.1.4.1.2011.10.2.77.3.2.1.1
h3cwapiConfigUnicastCipherEnabledThis object enables or disables the unicast cipher.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.77.3.2.1.2
h3cwapiConfigUnicastCipherSizeThis object indicates the length in bits of the unicast cipher key. This should be 256 for SMS4, first 128 bits for encrypting, last 128 bits for integrity checking.ro
Unsigned32
.1.3.6.1.4.1.2011.10.2.77.3.2.1.3
h3cwapiConfigAuthenticationSuiteEnabledThis variable indicates the corresponding AKM suite is enabled or disabled.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.77.3.2.1.4
h3cwapiConfigAuthenticationSuiteThe selector of an AKM suite. It consists of an OUI (the first 3 octets) and a cipher suite identifier (the last octet).ro
OCTET STRING
.1.3.6.1.4.1.2011.10.2.77.3.2.1.5
h3cwapiCfgExtASIPAddressTypeThis object is used to set IP addresses type of AS.rw
InetAddressType (INET-ADDRESS-MIB)
.1.3.6.1.4.1.2011.10.2.77.3.2.1.6
h3cwapiCfgExtASIPAddressThis object is used to set the IP address of AS.rw
InetAddress (INET-ADDRESS-MIB)
.1.3.6.1.4.1.2011.10.2.77.3.2.1.7
h3cwapiCfgExtASNameThis object is used to set the name of AS.rw
OCTET STRING
.1.3.6.1.4.1.2011.10.2.77.3.2.1.8
h3cwapiCfgExtCertDomainThis object is used to set the PKI domain name.rw
OCTET STRING
.1.3.6.1.4.1.2011.10.2.77.3.2.1.9
h3cwapiCfgExtCertInstalledThis object indicates whether the entity has installed certificate. When the value is TURE, it shall indicate that the SSID has installed certificate. Otherwise, it shall indicate that the SSID hasn't installed certificate.ro
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.77.3.2.1.10
h3cwapiTrap
OBJECT IDENTIFIER
.1.3.6.1.4.1.2011.10.2.77.4
h3cwapiTrapPrefix
OBJECT IDENTIFIER
.1.3.6.1.4.1.2011.10.2.77.4.0
h3cwapiUserwithInvalidCertificateThis trap is sent when a user intrudes upon network with invalid certificate.
NOTIFICATION-TYPE
.1.3.6.1.4.1.2011.10.2.77.4.0.1
h3cwapiStationReplayAttackThis trap is sent when an attacker records and replays network transactions.
NOTIFICATION-TYPE
.1.3.6.1.4.1.2011.10.2.77.4.0.2
h3cwapiTamperAttackThis trap is sent when an attacker monitors network traffic and maliciously changes data in transit(for example, an attacker may modify the contents of a WAI message).
NOTIFICATION-TYPE
.1.3.6.1.4.1.2011.10.2.77.4.0.3
h3cwapiLowSafeLevelAttackThis trap is sent when a station associates AP(Access Point), creates packet of Unicast Key Negotiation Response with wrong WIE(WAPI Information Element) of ASUE(Authentication Supplicant Entity).
NOTIFICATION-TYPE
.1.3.6.1.4.1.2011.10.2.77.4.0.4
h3cwapiAddressRedirectionAttackThis trap is sent when an attacker maliciously changes destination MAC address of WPI(WLAN Privacy Infrastructure) frame.
NOTIFICATION-TYPE
.1.3.6.1.4.1.2011.10.2.77.4.0.5
h3cwapiTrapInfo
OBJECT IDENTIFIER
.1.3.6.1.4.1.2011.10.2.77.4.1
h3cwapiTrapInfoMacAddrThe MAC address of the WAPI user.ro
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.77.4.1.1
h3cwapiTrapInfoAPIdTo uniquely identify each AP.ro
Integer32
.1.3.6.1.4.1.2011.10.2.77.4.1.2
h3cwapiTrapInfoRadioIdRepresents each radio.ro
Integer32
.1.3.6.1.4.1.2011.10.2.77.4.1.3
h3cwapiTrapInfoBSSIdAs MAC Address format, it is to identify BSS.ro
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.2011.10.2.77.4.1.4