HH3C-DOT11-WIDS-MIB
This MIB provides information about WIDS feature. GLOSSARY Wireless Intrusion Detection Sensor (WIDS) WIDS is designed to be employed in an area that is serviced by an existing wireless network. It aids in the early detection of malicious outsider attacks and intrusions via wireless networks. Rogue AP A rogue access point is any Wi-Fi access point connected to the network without authorization. As it is not authorized, if there is any weakness in the AP, the hacker will have chance to compromise the network. Rogue Station It is similiar to Rogue AP, while it is a station. Monitor AP An AP will scan or listen to the air, and try to detect wireless attack in the network. Some AP products will work only in monitor role, while some AP products could switch between normal AP role (only provide wireless access service)and monitor AP role. Ad Hoc Mode Station could work under Ad hoc mode, then they could directly do peer-to-peer communication without other device support.
Main OID:
hh3cDot11WIDS.1.3.6.1.4.1.25506.2.75.5
201
Objects
Active
Status
3
Dependencies
Imported Objects
Objects
201 total| Object Name |
|---|
hh3cDot11WIDSThis MIB provides information about WIDS feature. GLOSSARY Wireless Intrusion Detection Sensor (WIDS) WIDS is designed to be employed in an area that is serviced by an existing wireless network. It aids in the early detection of malicious outsider attacks and intrusions via wireless networks. Rogue AP A rogue access point is any Wi-Fi access point connected to the network without authorization. As it is not authorized, if there is any weakness in the AP, the hacker will have chance to compromise the network. Rogue Station It is similiar to Rogue AP, while it is a station. Monitor AP An AP will scan or listen to the air, and try to detect wireless attack in the network. Some AP products will work only in monitor role, while some AP products could switch between normal AP role (only provide wireless access service)and monitor AP role. Ad Hoc Mode Station could work under Ad hoc mode, then they could directly do peer-to-peer communication without other device support. MODULE-IDENTITY .1.3.6.1.4.1.25506.2.75.5 |
hh3cDot11WIDSConfigGroup OBJECT IDENTIFIER .1.3.6.1.4.1.25506.2.75.5.1 |
hh3cDot11WIDSGlobalConfigGroup OBJECT IDENTIFIER .1.3.6.1.4.1.25506.2.75.5.1.1 |
hh3cDot11WIDSScanModeRepresents the scope of channels to be scanned. The following value are supported all(1) - Do scan on all the channels. auto(2) - Do scan for the channels that automatically selected by WIDS.rw Enumeration .1.3.6.1.4.1.25506.2.75.5.1.1.1 |
hh3cDot11WIDSScanChannelListRepresents the channel scope to be scanned when hh3cDot11WIDSScanMode is configurated as channelSpec mode. Each channel value will be separated by comma character.rwobsolete OCTET STRING .1.3.6.1.4.1.25506.2.75.5.1.1.2 |
hh3cDot11CntMsrModeRepresents the countermeasures mode.rw Bits .1.3.6.1.4.1.25506.2.75.5.1.1.3 |
hh3cDot11DevAgingTimeRepresents the age time for entries in the detected device table. If an entry is not detected within the interval, it is deleted from the detected device table. If the deleted entry is that of a rogue, it is added into the rogue history table.rw Integer32 .1.3.6.1.4.1.25506.2.75.5.1.1.4 |
hh3cDot11DynBlkListEnableRepresents whether the dynamic blacklist feature is enabled or not. 'true' : Enable the dynamic blacklist feature to filter out unwanted clients, which will not get associated. 'false' : Disable the dynamic blacklist feature.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.1.1.5 |
hh3cDot11DynBlkListLifeTimeRepresents the lifetime for dynamic blacklist entries. If a dynamic blacklist entry is not detected within the lifetime, the entry will be removed from the dynamic blacklist. The lifetime becomes active only if dynamic blacklist feature is enabled.rw Integer32 .1.3.6.1.4.1.25506.2.75.5.1.1.6 |
hh3cDot11FloodAtkDctEnableRepresents whether detection of flood attack is enabled or not. 'true' : Enable the detection of flood attack. 'false' : Disable the detection of flood attack.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.1.1.7 |
hh3cDot11SpoofAtkDctEnableRepresents whether detection of Spoof attack is enabled or not. 'true' : Enable the detection of Spoof attack. 'false' : Disable the detection of Spoof attack.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.1.1.8 |
hh3cDot11WeakIVAtkDctEnableRepresents whether detection of weak-iv attack is enabled or not. 'true' : Enable the detection of weak-iv attack. 'false' : Disable the detection of weak-iv attack.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.1.1.9 |
hh3cDot11ResetWIDSRogueHistoryThis object is used to clear all entries from the rogue history table. It will return false for get operation.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.1.1.10 |
hh3cDot11ResetWIDSHistroyThis object is used to clear the history information of attacks detected in the WLAN system. It will return false for get operation.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.1.1.11 |
hh3cDot11ResetWIDSStatisticsThis object is used to clear the statistics of attacks detected in the WLAN system. It will return false for get operation.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.1.1.12 |
hh3cDot11ResetAllDynBlkListThis object is used to remove all entries from the dynamic blacklist. It will return false for get operation.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.1.1.13 |
hh3cDot11ResetAllStcBlkListThis object is used to remove all entries from the static blacklist. It will return false for get operation.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.1.1.14 |
hh3cDot11ResetAllWhtBlkListThis object is used to remove all entries from the static whitelist. It will return false for get operation.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.1.1.15 |
hh3cDot11ResetAllDctRogueAPThis object is used to clear the information of all detected rogue APs. It will return false for get operation.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.1.1.16 |
hh3cDot11ResetAllDctRogueStaThis object is used to clear the information of all detected rogue clients. It will return false for get operation.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.1.1.17 |
hh3cDot11ResetAllDctAdhocThis object is used to clear the information of all detected ad hoc devices. It will return false for get operation.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.1.1.18 |
hh3cDot11ResetAllDctDeviceThis object is used to clear the information of all detected devices. It will return false for get operation.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.1.1.19 |
hh3cDot11ResetAllDctSSIDThis object is used to clear the information of all detected SSIDs. It will return false for get operation.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.1.1.20 |
hh3cDot11WidsFloodIntervalThe interval of WIDS flood detection.rw Unsigned32 UNITS "second" .1.3.6.1.4.1.25506.2.75.5.1.1.21 |
hh3cDot11WidsBlackListThresholdWhen flood attack exceeds the value of this node, the MAC address will be added into black list.rw Unsigned32 .1.3.6.1.4.1.25506.2.75.5.1.1.22 |
hh3cDot11SSIDFilterOnOffRepresents whether the SSID permit feature is enabled or not.rw Enumeration .1.3.6.1.4.1.25506.2.75.5.1.1.23 |
hh3cDot11BSSIDFilterOnOffRepresents whether the BSSID permit feature is enabled or not.rw Enumeration .1.3.6.1.4.1.25506.2.75.5.1.1.24 |
hh3cDot11WIDSPermitVendorTableThe table provides the permitted vendor list, and each vendor will be identified by OUI. The legal device should be made by the permitted vendors. SEQUENCE OF Hh3cDot11WIDSPermitVendorEntry .1.3.6.1.4.1.25506.2.75.5.1.2 |
hh3cDot11WIDSPermitVendorEntryEach entry provides the information of permitted vendor. Hh3cDot11WIDSPermitVendorEntry .1.3.6.1.4.1.25506.2.75.5.1.2.1 |
hh3cDot11VendorOUIRepresents the vendor OUI information of the wireless device. OCTET STRING .1.3.6.1.4.1.25506.2.75.5.1.2.1.1 |
hh3cDot11PermitVendorRowStatusThe status of this table entry.rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.1.2.1.2 |
hh3cDot11VendorNameRepresents the vendor name of the wireless device.ro OCTET STRING .1.3.6.1.4.1.25506.2.75.5.1.2.1.3 |
hh3cDot11WIDSPermitSSIDTableThe table represents the list of SSID could be permitted in the wireless network. SEQUENCE OF Hh3cDot11WIDSPermitSSIDEntry .1.3.6.1.4.1.25506.2.75.5.1.3 |
hh3cDot11WIDSPermitSSIDEntryEach entry provides the information of permitted SSID. Hh3cDot11WIDSPermitSSIDEntry .1.3.6.1.4.1.25506.2.75.5.1.3.1 |
hh3cDot11PermitSSIDRepresents the permitted SSID in the wireless network. Hh3cDot11SSIDStringType .1.3.6.1.4.1.25506.2.75.5.1.3.1.1 |
hh3cDot11PermitSSIDRowStatusThe status of this table entry.rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.1.3.1.2 |
hh3cDot11PermitSSIDDetectedRepresents whether the permitted SSID is detected or not.ro TruthValue (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.1.3.1.3 |
hh3cDot11WIDSIgnoreListTableThe table provides the MAC address list of stations or APs, and WIDS always take them as legal stations or APs. SEQUENCE OF Hh3cDot11WIDSIgnoreListEntry .1.3.6.1.4.1.25506.2.75.5.1.4 |
hh3cDot11WIDSIgnoreListEntryEach entry contains the MAC address of station or AP, and WIDS always take it as legal station or AP. Hh3cDot11WIDSIgnoreListEntry .1.3.6.1.4.1.25506.2.75.5.1.4.1 |
hh3cDot11IgnoreMACRepresents the MAC address of station or AP, and WIDS always take it as legal station or AP. MacAddress (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.1.4.1.1 |
hh3cDot11IgnoreListRowStatusThe status of this table entry.rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.1.4.1.2 |
hh3cDot11IgnoreMACDetectedRepresents whether the MAC address detected or not.ro TruthValue (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.1.4.1.3 |
hh3cDot11IgnoreDevTypeRepresents the type of the MAC address detected. The value of this object always is unknown if the MAC address is not detected.ro Hh3cDot11WIDSDevType .1.3.6.1.4.1.25506.2.75.5.1.4.1.4 |
hh3cDot11WIDSAttackListTableThe table provides the MAC address list of rogue APs or rogue stations, the WIDS will take countermeasure as per the MAC address list. SEQUENCE OF Hh3cDot11WIDSAttackListEntry .1.3.6.1.4.1.25506.2.75.5.1.5 |
hh3cDot11WIDSAttackListEntryEach entry contains the MAC address of rogue AP or rogue station, and the countermeasure will be taken for it. Hh3cDot11WIDSAttackListEntry .1.3.6.1.4.1.25506.2.75.5.1.5.1 |
hh3cDot11AttackDeviceMacRepresents the MAC address of rogue AP or rogue station, and the countermeasure will be taken for it. MacAddress (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.1.5.1.1 |
hh3cDot11AttackListRowStatusThe status of this table entry.rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.1.5.1.2 |
hh3cDot11AttackDevDetectedRepresents whether the assigned MAC address in attack list is detected or not.ro TruthValue (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.1.5.1.3 |
hh3cDot11AttackDevTypeRepresents the type of detected MAC address in attack list. If the MAC address is not detected, it will return unknown(5) for get operation.ro Hh3cDot11WIDSDevType .1.3.6.1.4.1.25506.2.75.5.1.5.1.4 |
hh3cDot11StaticWhiteListTableThe table provides the information of whitelist. SEQUENCE OF Hh3cDot11StaticWhiteListEntry .1.3.6.1.4.1.25506.2.75.5.1.6 |
hh3cDot11StaticWhiteListEntryEach entry contains the information of whitelist. Hh3cDot11StaticWhiteListEntry .1.3.6.1.4.1.25506.2.75.5.1.6.1 |
hh3cDot11StaticWhiteListMACRepresents the MAC addresses in whitelist. MacAddress (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.1.6.1.1 |
hh3cDot11StaticWhiteListRowStatusThe status of this table entry.rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.1.6.1.2 |
hh3cDot11StaticBlackListTableThe table provides the information of static blacklist. SEQUENCE OF Hh3cDot11StaticBlackListEntry .1.3.6.1.4.1.25506.2.75.5.1.7 |
hh3cDot11StaticBlackListEntryEach entry contains the information of static blacklist. Hh3cDot11StaticBlackListEntry .1.3.6.1.4.1.25506.2.75.5.1.7.1 |
hh3cDot11StaticBlackListMACRepresents the MAC addresses in static blacklist. MacAddress (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.1.7.1.1 |
hh3cDot11StaticBlackListRowStatusThe status of this table entry.rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.1.7.1.2 |
hh3cDot11WIDSPermitBSSIDTableThe table represents the list of BSSID could be permitted in the wireless network. SEQUENCE OF Hh3cDot11WIDSPermitBSSIDEntry .1.3.6.1.4.1.25506.2.75.5.1.8 |
hh3cDot11WIDSPermitBSSIDEntryEach entry provides the information of permitted BSSID. Hh3cDot11WIDSPermitBSSIDEntry .1.3.6.1.4.1.25506.2.75.5.1.8.1 |
hh3cDot11PermitBSSIDRepresents the permitted BSSID in the wireless network. MacAddress (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.1.8.1.1 |
hh3cDot11PermitBSSIDDetectedRepresents whether the permitted BSSID is detected or not.ro TruthValue (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.1.8.1.2 |
hh3cDot11PermitBSSIDRowStatusRepresents the row status of permit BSSID table.rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.1.8.1.3 |
hh3cDot11WIDSDetectGroup OBJECT IDENTIFIER .1.3.6.1.4.1.25506.2.75.5.2 |
hh3cDot11WIDSRogueAPTableThe table represents the list of possible BSS information for rogue APs detected by the WIDS. SEQUENCE OF Hh3cDot11WIDSRogueAPEntry .1.3.6.1.4.1.25506.2.75.5.2.1 |
hh3cDot11WIDSRogueAPEntryEach entry contains possible BSS information of each rogue AP detected by WIDS. Hh3cDot11WIDSRogueAPEntry .1.3.6.1.4.1.25506.2.75.5.2.1.1 |
hh3cDot11RogueAPBSSMACRepresents the BSS MAC address of rogue AP. MacAddress (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.2.1.1.1 |
hh3cDot11RogueAPVendorNameRepresents the vendor name of rogue AP.ro OCTET STRING .1.3.6.1.4.1.25506.2.75.5.2.1.1.2 |
hh3cDot11RogueAPMonitorNumRepresents the number of monitor APs which detected the rogue AP.ro Integer32 .1.3.6.1.4.1.25506.2.75.5.2.1.1.3 |
hh3cDot11RogueAPFirstDetectTmRepresents the time that AP was detected as a rogue AP for the first time.ro TimeTicks (SNMPv2-SMI) .1.3.6.1.4.1.25506.2.75.5.2.1.1.4 |
hh3cDot11RogueAPLastDetectTmRepresents the time that AP was detected as a rogue AP for the last time.ro TimeTicks (SNMPv2-SMI) .1.3.6.1.4.1.25506.2.75.5.2.1.1.5 |
hh3cDot11RogueAPSSIDRepresents the SSID broadcasted by rogue AP.ro Hh3cDot11SSIDStringType (HH3C-DOT11-REF-MIB) .1.3.6.1.4.1.25506.2.75.5.2.1.1.6 |
hh3cDot11RogueAPMaxSigStrengthRepresents the maximal value of signal strength that WIDS received from the rogue AP.ro Integer32 UNITS "dBm" .1.3.6.1.4.1.25506.2.75.5.2.1.1.7 |
hh3cDot11RogueAPChannelRepresents on which radio channel of the rogue AP the maximal signal strength was received.ro Hh3cDot11ChannelScopeType (HH3C-DOT11-REF-MIB) .1.3.6.1.4.1.25506.2.75.5.2.1.1.8 |
hh3cDot11RogueAPBeaconIntervalRepresents the interval for Beacon management frame of rogue AP.ro Integer32 UNITS "millisecond" .1.3.6.1.4.1.25506.2.75.5.2.1.1.9 |
hh3cDot11RogueAPAttackedStatusRepresents whether the countermeasure have taken for the rogue AP.ro TruthValue (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.2.1.1.10 |
hh3cDot11RogueAPToIgnoreRepresents whether the rogue AP will be taken as a rogue AP. If the value is true, NMS should not display the rogue AP as NMS display rogue AP list, and the MAC address will be automatically added into hh3cDot11WIDSIgnoreListTable. If the value is false, NMS will take it as a rogue AP.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.2.1.1.11 |
hh3cDot11RogueAPEncryptStatusRepresents whether the rogue AP encrypt the frame or not.ro TruthValue (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.2.1.1.12 |
hh3cDot11RogueAPResetThis object is used to clear information of assigned AP. The information of AP which detect assigned rogue AP will be cleared together. It will return false for get operation.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.2.1.1.13 |
hh3cDot11RogueAPFirstDetectTmStrRepresents the time that AP was detected as a rogue AP for the first time.ro OCTET STRING .1.3.6.1.4.1.25506.2.75.5.2.1.1.14 |
hh3cDot11RogueAPLastDetectTmStrRepresents the time that AP was detected as a rogue AP for the last time.ro OCTET STRING .1.3.6.1.4.1.25506.2.75.5.2.1.1.15 |
hh3cDot11WIDSRogueAPExtTableAs each rogue AP could be detected by multiple monitor APs, each monitor AP could have some kind of detailed information about a specific rogue AP. In the hh3cDot11WIDSRogueAPTable table, the detailed information for a specific rogue AP will be summarized from information in the hh3cDot11WIDSRogueAPExtTable table. For example, multiple monitor APs could receive RF signal of one rogue AP, and each monitor AP has its maximum signal strength by itself. The information will be kept as hh3cDot11DetectMaxAPSigStrength in the hh3cDot11WIDSRogueAPExtTable table. While only the maximum value among all the hh3cDot11DetectMaxAPSigStrength for each monitor AP will be kept in the hh3cDot11WIDSRogueAPTable as hh3cDot11RogueAPMaxSigStrength. SEQUENCE OF Hh3cDot11WIDSRogueAPExtEntry .1.3.6.1.4.1.25506.2.75.5.2.2 |
hh3cDot11WIDSRogueAPExtEntryEach entry contains information of the rogue AP detected by each monitor AP. Hh3cDot11WIDSRogueAPExtEntry .1.3.6.1.4.1.25506.2.75.5.2.2.1 |
hh3cDot11WIDSAPIDTo uniquely identify each AP, and relation-ship between hh3cDot11WIDSAPID and AP device will be static. Hh3cDot11ObjectIDType (HH3C-DOT11-REF-MIB) .1.3.6.1.4.1.25506.2.75.5.2.2.1.1 |
hh3cDot11DetectCurAPSigStrengthRepresents the current value of signal strength that WIDS monitor AP received from the rogue AP.ro Integer32 UNITS "dBm" .1.3.6.1.4.1.25506.2.75.5.2.2.1.2 |
hh3cDot11DetectAPByChannelRepresents on which radio channel that WIDS monitor AP detected the rogue AP.ro Hh3cDot11ChannelScopeType (HH3C-DOT11-REF-MIB) .1.3.6.1.4.1.25506.2.75.5.2.2.1.3 |
hh3cDot11DetectAPByRadioIDRepresents on which radio the monitor AP has detected the rogue AP.ro Hh3cDot11RadioScopeType (HH3C-DOT11-REF-MIB) .1.3.6.1.4.1.25506.2.75.5.2.2.1.4 |
hh3cDot11AttackAPStatusRepresents whether monitor AP have taken countermeasure on the rogue AP.ro TruthValue (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.2.2.1.5 |
hh3cDot11DetectAPFirstTmRepresents the time that monitor AP detected the rogue AP for the first time.ro TimeTicks (SNMPv2-SMI) .1.3.6.1.4.1.25506.2.75.5.2.2.1.6 |
hh3cDot11DetectAPLastTmRepresents the time that monitor AP detected the rogue AP for the last time.ro TimeTicks (SNMPv2-SMI) .1.3.6.1.4.1.25506.2.75.5.2.2.1.7 |
hh3cDot11WIDSRogueStaTableThe table represents the list of rogue stations detected by the WIDS. SEQUENCE OF Hh3cDot11WIDSRogueStaEntry .1.3.6.1.4.1.25506.2.75.5.2.3 |
hh3cDot11WIDSRogueStaEntryEach entry contains information of each rogue station. Hh3cDot11WIDSRogueStaEntry .1.3.6.1.4.1.25506.2.75.5.2.3.1 |
hh3cDot11RogueStaMACRepresents the MAC address of rogue station. MacAddress (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.2.3.1.1 |
hh3cDot11RogueStaVendorNameRepresents the vendor name of rogue station.ro OCTET STRING .1.3.6.1.4.1.25506.2.75.5.2.3.1.2 |
hh3cDot11RogueStaMonitorNumRepresents the number of monitor APs which detected the rogue station.ro Integer32 .1.3.6.1.4.1.25506.2.75.5.2.3.1.3 |
hh3cDot11RogueStaFirstDetectTmRepresents the time that station was detected as a rogue station for the first time.ro TimeTicks (SNMPv2-SMI) .1.3.6.1.4.1.25506.2.75.5.2.3.1.4 |
hh3cDot11RogueStaLastDetectTmRepresents the time that station was detected as a rogue station for the last time.ro TimeTicks (SNMPv2-SMI) .1.3.6.1.4.1.25506.2.75.5.2.3.1.5 |
hh3cDot11RogueStaAccessBSSIDRepresents BSS MAC address that rogue station try to access.ro MacAddress (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.2.3.1.6 |
hh3cDot11RogueStaMaxSigStrengthRepresents the maximal value of signal strength that WIDS received from the rogue station.ro Integer32 UNITS "dBm" .1.3.6.1.4.1.25506.2.75.5.2.3.1.7 |
hh3cDot11RogueStaChannelRepresents on which radio channel the maximal signal strength was received.ro Hh3cDot11ChannelScopeType (HH3C-DOT11-REF-MIB) .1.3.6.1.4.1.25506.2.75.5.2.3.1.8 |
hh3cDot11RogueStaAttackedStatusRepresents whether the countermeasure have taken for the rogue station.ro TruthValue (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.2.3.1.9 |
hh3cDot11RogueStaToIgnoreRepresents whether the rogue AP will be taken as a rogue station. If the value is true, NMS should not display the rogue station as NMS display rogue station list, and the MAC address will be automatically added into hh3cDot11WIDSIgnoreListTable. If the value is false, NMS will take it as a rogue station.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.2.3.1.10 |
hh3cDot11RogueStaAdHocStatusRepresents whether the rogue station work on the Ad Hoc mode or not.ro TruthValue (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.2.3.1.11 |
hh3cDot11RogueStaResetThis object is used to clear information of assigned station. The information of AP which detects assigned rogue station will be cleared together. It will return false for get operation.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.2.3.1.12 |
hh3cDot11RogueStaFirstDetectTmStrRepresents the time that station was detected as a rogue station for the first time.ro OCTET STRING .1.3.6.1.4.1.25506.2.75.5.2.3.1.13 |
hh3cDot11RogueStaLastDetectTmStrRepresents the time that station was detected as a rogue station for the last time.ro OCTET STRING .1.3.6.1.4.1.25506.2.75.5.2.3.1.14 |
hh3cDot11WIDSRogueStaExtTableAs each rogue station could be detected by multiple monitor APs, each monitor AP could have some kind of detailed information about a specific rogue station. In the hh3cDot11WIDSRogueStaTable table, the detailed information for a specific rogue station will be summarized from information in the hh3cDot11WIDSRogueStaExtTable table. For example, multiple monitor APs could receive RF signal of one rogue station, and each monitor AP has its maximum signal strength by itself. The information will be kept as hh3cDot11DetectMaxStaSigStrength in the hh3cDot11WIDSRogueStaExtTable table. While only the maximum value among all the hh3cDot11DetectMaxStaSigStrength for each monitor AP will be kept in the hh3cDot11WIDSRogueStaTable as hh3cDot11RogueStaMaxSigStrength. SEQUENCE OF Hh3cDot11WIDSRogueStaExtEntry .1.3.6.1.4.1.25506.2.75.5.2.4 |
hh3cDot11WIDSRogueStaExtEntryEach entry contains information of rogue station detected by each monitor AP. Hh3cDot11WIDSRogueStaExtEntry .1.3.6.1.4.1.25506.2.75.5.2.4.1 |
hh3cDot11DetectCurStaSigStrengthRepresents the current value of signal strength that WIDS monitor AP received from the rogue station.ro Integer32 UNITS "dBm" .1.3.6.1.4.1.25506.2.75.5.2.4.1.1 |
hh3cDot11DetectStaByChannelRepresents on which radio channel the maximal signal strength was received.ro Hh3cDot11ChannelScopeType (HH3C-DOT11-REF-MIB) .1.3.6.1.4.1.25506.2.75.5.2.4.1.2 |
hh3cDot11DetectStaByRadioIDRepresents which radio on the monitor AP has detected the rogue station.ro Hh3cDot11RadioScopeType (HH3C-DOT11-REF-MIB) .1.3.6.1.4.1.25506.2.75.5.2.4.1.3 |
hh3cDot11AttackStaStatusRepresents whether monitor AP have taken countermeasure for the rogue station.ro TruthValue (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.2.4.1.4 |
hh3cDot11DetectStaFirstTmRepresents the time that monitor AP detected the rogue station for the first time.ro TimeTicks (SNMPv2-SMI) .1.3.6.1.4.1.25506.2.75.5.2.4.1.5 |
hh3cDot11DetectStaLastTmRepresents the time that monitor AP detected the rogue station for the last time.ro TimeTicks (SNMPv2-SMI) .1.3.6.1.4.1.25506.2.75.5.2.4.1.6 |
hh3cDot11WIDSDetectedDevTableThis Table contains information of detected devices. SEQUENCE OF Hh3cDot11WIDSDetectedDevEntry .1.3.6.1.4.1.25506.2.75.5.2.5 |
hh3cDot11WIDSDetectedDevEntryEach entry contains information of detected devices. Hh3cDot11WIDSDetectedDevEntry .1.3.6.1.4.1.25506.2.75.5.2.5.1 |
hh3cDot11WIDSDevMACRepresents MAC address of the device detected. MacAddress (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.2.5.1.1 |
hh3cDot11WIDSDevTypeRepresents type of the device detected.ro Hh3cDot11WIDSDevType .1.3.6.1.4.1.25506.2.75.5.2.5.1.2 |
hh3cDot11WIDSDevPermitTypeRepresents whether the device detected is a rogue device or not.ro Hh3cDot11WIDSDevPermitType .1.3.6.1.4.1.25506.2.75.5.2.5.1.3 |
hh3cDot11WIDSDevVendorRepresents Vendor of the detected device.ro OCTET STRING .1.3.6.1.4.1.25506.2.75.5.2.5.1.4 |
hh3cDot11WIDSDevMonitorNumRepresents the number of active APs that detect the device.ro Integer32 .1.3.6.1.4.1.25506.2.75.5.2.5.1.5 |
hh3cDot11WIDSDevSSIDRepresents the service set identifier for the ESS of the device.ro OCTET STRING .1.3.6.1.4.1.25506.2.75.5.2.5.1.6 |
hh3cDot11WIDSDevBSSIDRepresents the basic service set identifier of the detected device.ro MacAddress (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.2.5.1.7 |
hh3cDot11WIDSDevChannelRepresents the channel in which the device was last detected.ro Hh3cDot11ChannelScopeType (HH3C-DOT11-REF-MIB) .1.3.6.1.4.1.25506.2.75.5.2.5.1.8 |
hh3cDot11WIDSDevMaxRSSIRepresents the maximum detected RSSI of the device.ro Integer32 UNITS "dbm" .1.3.6.1.4.1.25506.2.75.5.2.5.1.9 |
hh3cDot11WIDSDevBeaconIntvlRepresents the beacon interval for the detected AP.ro Integer32 UNITS "millionsecond" .1.3.6.1.4.1.25506.2.75.5.2.5.1.10 |
hh3cDot11WIDSDevFstDctTimeRepresents the time at which the device was first detected.ro DateAndTime (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.2.5.1.11 |
hh3cDot11WIDSDevLstDctTimeRepresents the time at which the rogue AP was detected last time.ro DateAndTime (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.2.5.1.12 |
hh3cDot11WIDSDevResetThis object is used to clears the information of the device detected in the WLAN. It will return false for get operation.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.2.5.1.13 |
hh3cDot11WIDSDevSnrRepresents SNR of the device detected.ro Integer32 UNITS "dB" .1.3.6.1.4.1.25506.2.75.5.2.5.1.14 |
hh3cDot11WIDSRptAPTableThis Table contains information of the AP which detected device in the WLAN. SEQUENCE OF Hh3cDot11WIDSRptAPEntry .1.3.6.1.4.1.25506.2.75.5.2.6 |
hh3cDot11WIDSRptAPEntryEach entry contains information of the AP which detected device in the WLAN. Hh3cDot11WIDSRptAPEntry .1.3.6.1.4.1.25506.2.75.5.2.6.1 |
hh3cDot11WIDSRptAPMACRepresents the MAC address of the AP that detected the device. MacAddress (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.2.6.1.1 |
hh3cDot11WIDSRptAPNameRepresents the name of the AP that detected the device.ro OCTET STRING .1.3.6.1.4.1.25506.2.75.5.2.6.1.2 |
hh3cDot11WIDSRptAPRadioIDRepresents the radio index of the AP that detected the device.ro Hh3cDot11RadioScopeType (HH3C-DOT11-REF-MIB) .1.3.6.1.4.1.25506.2.75.5.2.6.1.3 |
hh3cDot11WIDSRptAPMaxRSSIRepresents the maximum detected RSSI of the device.ro Integer32 .1.3.6.1.4.1.25506.2.75.5.2.6.1.4 |
hh3cDot11WIDSRptAPFstDctTimeRepresents the time at which the rogue AP was detected first time.ro DateAndTime (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.2.6.1.5 |
hh3cDot11WIDSRptAPLstDctTimeRepresents the time at which the rogue AP was detected last time.ro DateAndTime (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.2.6.1.6 |
hh3cDot11DynBlackListTableThis table contains information of dynamic blacklist entries. SEQUENCE OF Hh3cDot11DynBlackListEntry .1.3.6.1.4.1.25506.2.75.5.2.7 |
hh3cDot11DynBlackListEntryEach entry contains information of dynamic blacklist. Hh3cDot11DynBlackListEntry .1.3.6.1.4.1.25506.2.75.5.2.7.1 |
hh3cDot11DynBlackListMACRepresents the MAC address of the device inserted into the dynamic blacklist. MacAddress (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.2.7.1.1 |
hh3cDot11DynBlackListTimeRepresents the time elapsed since the entry was last updated.ro Unsigned32 UNITS "second" .1.3.6.1.4.1.25506.2.75.5.2.7.1.2 |
hh3cDot11DynBlackListReasonRepresents the reason why the entry was added into the dynamic blacklist.ro OCTET STRING .1.3.6.1.4.1.25506.2.75.5.2.7.1.3 |
hh3cDot11DynBlackListResetThis object is used to remove designated entry from the dynamic blacklist. The value which read from this object always is false.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.2.7.1.4 |
hh3cDot11DynBlackListTimeTicksRepresents the time elapsed since the entry was last updated in units TimeTicks.ro TimeTicks (SNMPv2-SMI) .1.3.6.1.4.1.25506.2.75.5.2.7.1.5 |
hh3cDot11WIDSRogueHistoryTableThis table contains information of all expired rogue devices which have been deleted from the list of detected rogue devices because they could not be detected within the device aging duration. SEQUENCE OF Hh3cDot11WIDSRogueHistoryEntry .1.3.6.1.4.1.25506.2.75.5.2.8 |
hh3cDot11WIDSRogueHistoryEntryEach entry contains information of an expired rogue device which has been deleted from the list of detected rogue devices because they could not be detected within the device aging duration. Hh3cDot11WIDSRogueHistoryEntry .1.3.6.1.4.1.25506.2.75.5.2.8.1 |
hh3cDot11WIDSRogueHisIndexRepresents index of this entry. Integer32 .1.3.6.1.4.1.25506.2.75.5.2.8.1.1 |
hh3cDot11WIDSRogueHisMACRepresents the MAC address of the device.ro MacAddress (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.2.8.1.2 |
hh3cDot11WIDSRogueHisVendorRepresents the vendor for the device.ro OCTET STRING .1.3.6.1.4.1.25506.2.75.5.2.8.1.3 |
hh3cDot11WIDSRogueHisTypeRepresents the type of the device.ro Hh3cDot11WIDSDevType .1.3.6.1.4.1.25506.2.75.5.2.8.1.4 |
hh3cDot11WIDSRogueHisChlRepresents the channel in which the device was last detected.ro Hh3cDot11ChannelScopeType (HH3C-DOT11-REF-MIB) .1.3.6.1.4.1.25506.2.75.5.2.8.1.5 |
hh3cDot11WIDSRogueHisSSIDRepresents the service set identifier for the ESS of the device.ro OCTET STRING .1.3.6.1.4.1.25506.2.75.5.2.8.1.6 |
hh3cDot11WIDSRogueHisLastDctTimeRepresents the time at which the device was last detected.ro DateAndTime (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.2.8.1.7 |
hh3cDot11WIDSAtkHistroyTableThis table contains information of the history of attacks detected in the WLAN system. SEQUENCE OF Hh3cDot11WIDSAtkHistroyEntry .1.3.6.1.4.1.25506.2.75.5.2.9 |
hh3cDot11WIDSAtkHistroyEntryEach entry contains information of the history of attacks detected in the WLAN system. Hh3cDot11WIDSAtkHistroyEntry .1.3.6.1.4.1.25506.2.75.5.2.9.1 |
hh3cDot11WIDSAtkHisIndexRepresents index of this entry. Integer32 .1.3.6.1.4.1.25506.2.75.5.2.9.1.1 |
hh3cDot11WIDSAtkHisMACRepresents the Mac address. In case of spoof attacks, this field provides the BSSID which was spoofed. In case of other attacks, this field provides the MAC address of the device which initiated the attack.ro MacAddress (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.2.9.1.2 |
hh3cDot11WIDSAtkHisTypeRepresents the type of attack.ro Hh3cDot11WIDSAtkType .1.3.6.1.4.1.25506.2.75.5.2.9.1.3 |
hh3cDot11WIDSAtkHisChlRepresents the channel in which the attack was detected.ro Hh3cDot11ChannelScopeType (HH3C-DOT11-REF-MIB) .1.3.6.1.4.1.25506.2.75.5.2.9.1.4 |
hh3cDot11WIDSAtkHisRSSIRepresents the average RSSI of the designated attack.ro Integer32 .1.3.6.1.4.1.25506.2.75.5.2.9.1.5 |
hh3cDot11WIDSAtkHisDctTimeRepresents the time at which this attack was detected.ro DateAndTime (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.2.9.1.6 |
hh3cDot11WIDSAtkHisAPNameRepresents the name of the AP which detected this attack.ro OCTET STRING .1.3.6.1.4.1.25506.2.75.5.2.9.1.7 |
hh3cDot11WIDSAtkStatis OBJECT IDENTIFIER .1.3.6.1.4.1.25506.2.75.5.2.10 |
hh3cDot11WIDSAtkStasStartTimeRepresents current attack tracking time. It is started at the system startup and is refreshed each hour subsequently.ro DateAndTime (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.2.10.1 |
hh3cDot11WIDSAtkStasTableThis table contains information of the counts of attacks detected. SEQUENCE OF Hh3cDot11WIDSAtkStasEntry .1.3.6.1.4.1.25506.2.75.5.2.10.2 |
hh3cDot11WIDSAtkStasEntryEach entry contains information of the counts of attacks detected. Hh3cDot11WIDSAtkStasEntry .1.3.6.1.4.1.25506.2.75.5.2.10.2.1 |
hh3cDot11WIDSAtkStasTypeRepresents the type of attack. Hh3cDot11WIDSAtkType .1.3.6.1.4.1.25506.2.75.5.2.10.2.1.1 |
hh3cDot11WIDSAtkStasCurCntRepresents the count of attacks detected since the time specified by the current attack tracking time. The current attack tracking time is started at the system startup and is refreshed each hour subsequently.ro Unsigned32 .1.3.6.1.4.1.25506.2.75.5.2.10.2.1.2 |
hh3cDot11WIDSAtkStasTotalCntRepresents the total count of the attacks detected since the system startup.ro Unsigned32 .1.3.6.1.4.1.25506.2.75.5.2.10.2.1.3 |
hh3cDot11BlackListTableThis table contains information of blacklist entries, including dynamic and static. SEQUENCE OF Hh3cDot11BlackListEntry .1.3.6.1.4.1.25506.2.75.5.2.11 |
hh3cDot11BlackListEntryEach entry contains information of blacklist. Hh3cDot11BlackListEntry .1.3.6.1.4.1.25506.2.75.5.2.11.1 |
hh3cDot11BlackListMACThis object represents the MAC address of the device inserted into the table. MacAddress (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.2.11.1.1 |
hh3cDot11BlackListTimeRepresents the time elapsed since the entry was last updated. If it is static blacklist, the value is always 0.ro Unsigned32 UNITS "minutes" .1.3.6.1.4.1.25506.2.75.5.2.11.1.2 |
hh3cDot11BlackListReasonRepresents the reason why the entry was added into the blacklist.ro OCTET STRING .1.3.6.1.4.1.25506.2.75.5.2.11.1.3 |
hh3cDot11BlackListRowStatusThis object represents the status of this table entry.rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.2.11.1.4 |
hh3cDot11BlackListTimeTicksRepresents the time elapsed since the entry was last updated in timetick. If it is static blacklist, the value is always 0.ro TimeTicks (SNMPv2-SMI) .1.3.6.1.4.1.25506.2.75.5.2.11.1.5 |
hh3cDot11WIDSNotifyGroup OBJECT IDENTIFIER .1.3.6.1.4.1.25506.2.75.5.3 |
hh3cDot11WIDSTraps OBJECT IDENTIFIER .1.3.6.1.4.1.25506.2.75.5.3.1 |
hh3cDot11WIDSDetectRogueTrapThe notification represents that a rogue AP or a station was detected by WIDS. The NMS would refer to MIB table under hh3cDot11WIDSDetectGroup group to get more detailed information. NOTIFICATION-TYPE .1.3.6.1.4.1.25506.2.75.5.3.1.1 |
hh3cDot11WIDSAdHocTrapThe notification represents a rogue Ad hoc station was detected. NOTIFICATION-TYPE .1.3.6.1.4.1.25506.2.75.5.3.1.2 |
hh3cDot11WIDSUnauthorSSIDTrapThe notification represents which unauthorized SSID are accessed in the network. The notification will be sent to NMS when an unauthorized SSID is detected on the network for the first time. NOTIFICATION-TYPE .1.3.6.1.4.1.25506.2.75.5.3.1.3 |
hh3cDot11WIDSDisappearRogueTrapThe notification represents that a rogue device has aged out and moved to history table or the device type has been changed to friendly. The notification will be sent to NMS whenever a rogue disappears. NOTIFICATION-TYPE .1.3.6.1.4.1.25506.2.75.5.3.1.4 |
hh3cDot11WIDSDetectAttackThis notification occurs when some type of attack is detected. NOTIFICATION-TYPE .1.3.6.1.4.1.25506.2.75.5.3.1.5 |
hh3cDot11WIDSDetectWBridgeThis notification occurs whenever a detected device is classified as rogue wireless-bridge. NOTIFICATION-TYPE .1.3.6.1.4.1.25506.2.75.5.3.1.6 |
hh3cDot11WIDSFloodTrapThis notification occurs when flood attack is detected. NOTIFICATION-TYPE .1.3.6.1.4.1.25506.2.75.5.3.1.7 |
hh3cDot11WIDSSpoofTrapThis notification occurs when spoof attack is detected. NOTIFICATION-TYPE .1.3.6.1.4.1.25506.2.75.5.3.1.8 |
hh3cDot11WIDSWeakIVTrapThis notification occurs when weak IV attack is detected. NOTIFICATION-TYPE .1.3.6.1.4.1.25506.2.75.5.3.1.9 |
hh3cDot11WIDSTrapVarObjects OBJECT IDENTIFIER .1.3.6.1.4.1.25506.2.75.5.3.2 |
hh3cDot11WIDSRogueMACRepresents which rogue AP or station.ro MacAddress (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.3.2.1 |
hh3cDot11WIDSRogueTypeRepresents the rogue type. The following value are supported rogueAp(1) - A rogue AP rogueStation(2) - A rogue Stationro Enumeration .1.3.6.1.4.1.25506.2.75.5.3.2.2 |
hh3cDot11WIDSMonitorMACRepresents which monitor detected the rogue AP or station.ro MacAddress (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.3.2.3 |
hh3cDot11WIDSAdHocMACRepresents the MAC address of Ad hoc station.ro MacAddress (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.3.2.4 |
hh3cDot11UnauthorSSIDNameRepresents an unauthorized SSID.ro Hh3cDot11SSIDStringType (HH3C-DOT11-REF-MIB) .1.3.6.1.4.1.25506.2.75.5.3.2.5 |
hh3cDot11MonitorAPIDRepresents monitor AP's APID.ro Hh3cDot11ObjectIDType (HH3C-DOT11-REF-MIB) .1.3.6.1.4.1.25506.2.75.5.3.2.6 |
hh3cDot11MonitorApRadioIDRepresents monitor AP's radio IDro Hh3cDot11RadioScopeType (HH3C-DOT11-REF-MIB) .1.3.6.1.4.1.25506.2.75.5.3.2.7 |
hh3cDot11WIDSAtkMacRepresents mac address of attack source.ro MacAddress (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.3.2.8 |
hh3cDot11WIDSAtkFrameTypeRepresents attack frame type.ro OCTET STRING .1.3.6.1.4.1.25506.2.75.5.3.2.9 |
hh3cDot11WIDSAtkChannelRepresents attack channel.ro Hh3cDot11ChannelScopeType (HH3C-DOT11-REF-MIB) .1.3.6.1.4.1.25506.2.75.5.3.2.10 |
hh3cDot11WIDSAtkTimeRepresents when attacking happened.ro OCTET STRING .1.3.6.1.4.1.25506.2.75.5.3.2.11 |
hh3cDot11WIDSAtkDestMacRepresents mac address of attack destination.ro MacAddress (SNMPv2-TC) .1.3.6.1.4.1.25506.2.75.5.3.2.12 |
hh3cDot11WIDSFirstTrapTimeRepresents the first trap time.ro TimeTicks (SNMPv2-SMI) .1.3.6.1.4.1.25506.2.75.5.3.2.13 |