Home/Catalog/HH3C-WAPI-MIB

HH3C-WAPI-MIB

AI MIB Summary

The HH3C-WAPI-MIB module enables the configuration and runtime monitoring of WAPI (Wireless LAN Authentication and Privacy Infrastructure) security parameters and operational states on H3C network devices. It provides specific management objects for tracking WAPI session establishment, authentication status, and cryptographic key management metrics.

HH3C-WAPI-MIB is an extension of MIB in WAPI protocol. This MIB contains objects to manage configuration and monitor running state for WAPI feature.
Main OID:
hh3cwapiMIB.1.3.6.1.4.1.25506.2.77
51
Objects
Active
Status
5
Dependencies

Imported Objects

Objects

51 total
Object Name
hh3cwapiMIBHH3C-WAPI-MIB is an extension of MIB in WAPI protocol. This MIB contains objects to manage configuration and monitor running state for WAPI feature.
MODULE-IDENTITY
.1.3.6.1.4.1.25506.2.77
hh3cwapiMIBObjects
OBJECT IDENTIFIER
.1.3.6.1.4.1.25506.2.77.1
hh3cwapiModeEnabledWhen this object is set to TRUE, it shall indicate that WAPI is enabled. Otherwise, it shall indicate that WAPI is disabled.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.25506.2.77.1.1
hh3cwapiASIPAddressTypeThis object is used to set global IP addresses type (IPv4 or IPv6) of AS.rw
InetAddressType (INET-ADDRESS-MIB)
.1.3.6.1.4.1.25506.2.77.1.2
hh3cwapiASIPAddressThis object is used to set the global IP address of AS.rw
InetAddress (INET-ADDRESS-MIB)
.1.3.6.1.4.1.25506.2.77.1.3
hh3cwapiCertificateInstalledThis object indicates whether the entity has installed certificate. When the value is TURE, it shall indicate that the entity has installed certificate. Otherwise, it shall indicate that the entity hasn't installed certificate.ro
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.25506.2.77.1.4
hh3cwapiMIBStatsObjects
OBJECT IDENTIFIER
.1.3.6.1.4.1.25506.2.77.2
hh3cwapiStatsWAISignatureErrorsThis counter increases when the received packet of WAI signature is wrong.ro
Counter32
.1.3.6.1.4.1.25506.2.77.2.1
hh3cwapiStatsWAIHMACErrorsThis counter increases when the received packet of WAI message authentication key checking error occurs.ro
Counter32
.1.3.6.1.4.1.25506.2.77.2.2
hh3cwapiStatsWAIAuthRsltFailuresThis counter increases when the WAI authentication result is unsuccessful.ro
Counter32
.1.3.6.1.4.1.25506.2.77.2.3
hh3cwapiStatsWAIDiscardCountersThis counter increases when the received packet of WAI are discarded.ro
Counter32
.1.3.6.1.4.1.25506.2.77.2.4
hh3cwapiStatsWAITimeoutCountersThis counter increases when the packet of WAI overtime are detected.ro
Counter32
.1.3.6.1.4.1.25506.2.77.2.5
hh3cwapiStatsWAIFormatErrorsThis counter increases when the WAI packet of WAI format error is detected.ro
Counter32
.1.3.6.1.4.1.25506.2.77.2.6
hh3cwapiStatsWAICtfHskFailuresThis counter increases when the WAI certificate authenticates unsuccessfully.ro
Counter32
.1.3.6.1.4.1.25506.2.77.2.7
hh3cwapiStatsWAIUniHskFailuresThis counter increases when the WAI unicast cipher key negotiates unsuccessfully.ro
Counter32
.1.3.6.1.4.1.25506.2.77.2.8
hh3cwapiStatsWAIMulHskFailuresThis counter increases when the WAI multicast cipher key announces unsuccessfully.ro
Counter32
.1.3.6.1.4.1.25506.2.77.2.9
hh3cwapiMIBTableObjects
OBJECT IDENTIFIER
.1.3.6.1.4.1.25506.2.77.3
hh3cwapiConfigTableThe table containing WAPI configuration objects.
SEQUENCE OF Hh3cwapiConfigEntry
.1.3.6.1.4.1.25506.2.77.3.1
hh3cwapiConfigEntryAn entry in the hh3cwapiConfigTable.
Hh3cwapiConfigEntry
.1.3.6.1.4.1.25506.2.77.3.1.1
hh3cwapiConfigASIPAddressTypeThis object is used to set IP addresses type of AS.rw
InetAddressType (INET-ADDRESS-MIB)
.1.3.6.1.4.1.25506.2.77.3.1.1.1
hh3cwapiConfigASIPAddressThis object is used to set the IP address of AS.rw
InetAddress (INET-ADDRESS-MIB)
.1.3.6.1.4.1.25506.2.77.3.1.1.2
hh3cwapiConfigAuthMethodThis object selects a mechanism for WAPI authentication method. The default is certificate.rw
Enumeration
.1.3.6.1.4.1.25506.2.77.3.1.1.3
hh3cwapiConfigAuthModeThis object selects a mechanism for WAPI authentication mode. When the value is standard, it shall indicate that the entity acts accord with the official definition. Otherwise, it shall indicate that the entity finishs authentication by means of RADIUS. The default is standard.rw
Enumeration
.1.3.6.1.4.1.25506.2.77.3.1.1.4
hh3cwapiConfigISPDomainThe ISP domain name.rw
OCTET STRING
.1.3.6.1.4.1.25506.2.77.3.1.1.5
hh3cwapiConfigCertificateDomainThe PKI domain name.rw
OCTET STRING
.1.3.6.1.4.1.25506.2.77.3.1.1.6
hh3cwapiConfigASNameThe name of AS.rw
OCTET STRING
.1.3.6.1.4.1.25506.2.77.3.1.1.7
hh3cwapiConfigBKRekeyEnabledThis object indicates whether the BK rekey function is supported. When the value is TURE, it shall indicate that the BK rekey function is supported. Otherwise, it shall indicate that the BK rekey function is not supported.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.25506.2.77.3.1.1.8
hh3cwapiConfigExtTableThe table containing WAPI configuration objects for SSID.
SEQUENCE OF Hh3cwapiConfigExtEntry
.1.3.6.1.4.1.25506.2.77.3.2
hh3cwapiConfigExtEntryAn extend entry in the hh3cwapiConfigExtTable.
Hh3cwapiConfigExtEntry
.1.3.6.1.4.1.25506.2.77.3.2.1
hh3cwapiConfigServicePolicyIDRepresents the ID of each service policy.
Integer32
.1.3.6.1.4.1.25506.2.77.3.2.1.1
hh3cwapiConfigUnicastCipherEnabledThis object enables or disables the unicast cipher.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.25506.2.77.3.2.1.2
hh3cwapiConfigUnicastCipherSizeThis object indicates the length in bits of the unicast cipher key. This should be 256 for SMS4, first 128 bits for encrypting, last 128 bits for integrity checking.ro
Unsigned32
.1.3.6.1.4.1.25506.2.77.3.2.1.3
hh3cwapiConfigAuthenticationSuiteEnabledThis variable indicates the corresponding AKM suite is enabled or disabled.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.25506.2.77.3.2.1.4
hh3cwapiConfigAuthenticationSuiteThe selector of an AKM suite. It consists of an OUI (the first 3 octets) and a cipher suite identifier (the last octet).ro
OCTET STRING
.1.3.6.1.4.1.25506.2.77.3.2.1.5
hh3cwapiCfgExtASIPAddressTypeThis object is used to set IP addresses type of AS.rw
InetAddressType (INET-ADDRESS-MIB)
.1.3.6.1.4.1.25506.2.77.3.2.1.6
hh3cwapiCfgExtASIPAddressThis object is used to set the IP address of AS.rw
InetAddress (INET-ADDRESS-MIB)
.1.3.6.1.4.1.25506.2.77.3.2.1.7
hh3cwapiCfgExtASNameThis object is used to set the name of AS.rw
OCTET STRING
.1.3.6.1.4.1.25506.2.77.3.2.1.8
hh3cwapiCfgExtCertDomainThis object is used to set the PKI domain name.rw
OCTET STRING
.1.3.6.1.4.1.25506.2.77.3.2.1.9
hh3cwapiCfgExtCertInstalledThis object indicates whether the entity has installed certificate. When the value is TURE, it shall indicate that the SSID has installed certificate. Otherwise, it shall indicate that the SSID hasn't installed certificate.ro
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.25506.2.77.3.2.1.10
hh3cwapiTrap
OBJECT IDENTIFIER
.1.3.6.1.4.1.25506.2.77.4
hh3cwapiTrapPrefix
OBJECT IDENTIFIER
.1.3.6.1.4.1.25506.2.77.4.0
hh3cwapiUserwithInvalidCertificateThis trap is sent when a user intrudes upon network with invalid certificate.
NOTIFICATION-TYPE
.1.3.6.1.4.1.25506.2.77.4.0.1
hh3cwapiStationReplayAttackThis trap is sent when an attacker records and replays network transactions.
NOTIFICATION-TYPE
.1.3.6.1.4.1.25506.2.77.4.0.2
hh3cwapiTamperAttackThis trap is sent when an attacker monitors network traffic and maliciously changes data in transit(for example, an attacker may modify the contents of a WAI message).
NOTIFICATION-TYPE
.1.3.6.1.4.1.25506.2.77.4.0.3
hh3cwapiLowSafeLevelAttackThis trap is sent when a station associates AP(Access Point), creates packet of Unicast Key Negotiation Response with wrong WIE(WAPI Information Element) of ASUE(Authentication Supplicant Entity).
NOTIFICATION-TYPE
.1.3.6.1.4.1.25506.2.77.4.0.4
hh3cwapiAddressRedirectionAttackThis trap is sent when an attacker maliciously changes destination MAC address of WPI(WLAN Privacy Infrastructure) frame.
NOTIFICATION-TYPE
.1.3.6.1.4.1.25506.2.77.4.0.5
hh3cwapiTrapInfo
OBJECT IDENTIFIER
.1.3.6.1.4.1.25506.2.77.4.1
hh3cwapiTrapInfoMacAddrThe MAC address of the WAPI user.ro
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.25506.2.77.4.1.1
hh3cwapiTrapInfoAPIdTo uniquely identify each AP.ro
Integer32
.1.3.6.1.4.1.25506.2.77.4.1.2
hh3cwapiTrapInfoRadioIdRepresents each radio.ro
Integer32
.1.3.6.1.4.1.25506.2.77.4.1.3
hh3cwapiTrapInfoBSSIdAs MAC Address format, it is to identify BSS.ro
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.25506.2.77.4.1.4