HH3C-WAPI-MIB
AI MIB Summary
The HH3C-WAPI-MIB module enables the configuration and runtime monitoring of WAPI (Wireless LAN Authentication and Privacy Infrastructure) security parameters and operational states on H3C network devices. It provides specific management objects for tracking WAPI session establishment, authentication status, and cryptographic key management metrics.
HH3C-WAPI-MIB is an extension of MIB in WAPI protocol. This MIB contains objects to manage configuration and monitor running state for WAPI feature.
Main OID:
hh3cwapiMIB.1.3.6.1.4.1.25506.2.77
51
Objects
Active
Status
5
Dependencies
Imported Objects
Objects
51 total| Object Name |
|---|
hh3cwapiMIBHH3C-WAPI-MIB is an extension of MIB in WAPI
protocol. This MIB contains objects to
manage configuration and monitor running state
for WAPI feature. MODULE-IDENTITY .1.3.6.1.4.1.25506.2.77 |
hh3cwapiMIBObjects OBJECT IDENTIFIER .1.3.6.1.4.1.25506.2.77.1 |
hh3cwapiModeEnabledWhen this object is set to TRUE, it shall indicate that WAPI
is enabled. Otherwise, it shall indicate that WAPI is disabled.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.25506.2.77.1.1 |
hh3cwapiASIPAddressTypeThis object is used to set global IP addresses
type (IPv4 or IPv6) of AS.rw InetAddressType (INET-ADDRESS-MIB) .1.3.6.1.4.1.25506.2.77.1.2 |
hh3cwapiASIPAddressThis object is used to set the global IP address of AS.rw InetAddress (INET-ADDRESS-MIB) .1.3.6.1.4.1.25506.2.77.1.3 |
hh3cwapiCertificateInstalledThis object indicates whether the entity has installed
certificate. When the value is TURE, it shall indicate that
the entity has installed certificate. Otherwise, it shall
indicate that the entity hasn't installed certificate.ro TruthValue (SNMPv2-TC) .1.3.6.1.4.1.25506.2.77.1.4 |
hh3cwapiMIBStatsObjects OBJECT IDENTIFIER .1.3.6.1.4.1.25506.2.77.2 |
hh3cwapiStatsWAISignatureErrorsThis counter increases when the received packet of
WAI signature is wrong.ro Counter32 .1.3.6.1.4.1.25506.2.77.2.1 |
hh3cwapiStatsWAIHMACErrorsThis counter increases when the received packet of
WAI message authentication key checking error occurs.ro Counter32 .1.3.6.1.4.1.25506.2.77.2.2 |
hh3cwapiStatsWAIAuthRsltFailuresThis counter increases when the WAI authentication result is
unsuccessful.ro Counter32 .1.3.6.1.4.1.25506.2.77.2.3 |
hh3cwapiStatsWAIDiscardCountersThis counter increases when the received packet of WAI are
discarded.ro Counter32 .1.3.6.1.4.1.25506.2.77.2.4 |
hh3cwapiStatsWAITimeoutCountersThis counter increases when the packet of WAI overtime are
detected.ro Counter32 .1.3.6.1.4.1.25506.2.77.2.5 |
hh3cwapiStatsWAIFormatErrorsThis counter increases when the WAI packet of WAI format
error is detected.ro Counter32 .1.3.6.1.4.1.25506.2.77.2.6 |
hh3cwapiStatsWAICtfHskFailuresThis counter increases when the WAI certificate authenticates
unsuccessfully.ro Counter32 .1.3.6.1.4.1.25506.2.77.2.7 |
hh3cwapiStatsWAIUniHskFailuresThis counter increases when the WAI unicast cipher key
negotiates unsuccessfully.ro Counter32 .1.3.6.1.4.1.25506.2.77.2.8 |
hh3cwapiStatsWAIMulHskFailuresThis counter increases when the WAI multicast cipher key
announces unsuccessfully.ro Counter32 .1.3.6.1.4.1.25506.2.77.2.9 |
hh3cwapiMIBTableObjects OBJECT IDENTIFIER .1.3.6.1.4.1.25506.2.77.3 |
hh3cwapiConfigTableThe table containing WAPI configuration objects. SEQUENCE OF Hh3cwapiConfigEntry .1.3.6.1.4.1.25506.2.77.3.1 |
hh3cwapiConfigEntryAn entry in the hh3cwapiConfigTable. Hh3cwapiConfigEntry .1.3.6.1.4.1.25506.2.77.3.1.1 |
hh3cwapiConfigASIPAddressTypeThis object is used to set IP addresses type of AS.rw InetAddressType (INET-ADDRESS-MIB) .1.3.6.1.4.1.25506.2.77.3.1.1.1 |
hh3cwapiConfigASIPAddressThis object is used to set the IP address of AS.rw InetAddress (INET-ADDRESS-MIB) .1.3.6.1.4.1.25506.2.77.3.1.1.2 |
hh3cwapiConfigAuthMethodThis object selects a mechanism for WAPI authentication method. The
default is certificate.rw Enumeration .1.3.6.1.4.1.25506.2.77.3.1.1.3 |
hh3cwapiConfigAuthModeThis object selects a mechanism for WAPI authentication mode. When
the value is standard, it shall indicate that the entity acts accord
with the official definition. Otherwise, it shall indicate that the
entity finishs authentication by means of RADIUS. The default is standard.rw Enumeration .1.3.6.1.4.1.25506.2.77.3.1.1.4 |
hh3cwapiConfigISPDomainThe ISP domain name.rw OCTET STRING .1.3.6.1.4.1.25506.2.77.3.1.1.5 |
hh3cwapiConfigCertificateDomainThe PKI domain name.rw OCTET STRING .1.3.6.1.4.1.25506.2.77.3.1.1.6 |
hh3cwapiConfigASNameThe name of AS.rw OCTET STRING .1.3.6.1.4.1.25506.2.77.3.1.1.7 |
hh3cwapiConfigBKRekeyEnabledThis object indicates whether the BK rekey function is supported. When the
value is TURE, it shall indicate that the BK rekey function is supported.
Otherwise, it shall indicate that the BK rekey function is not supported.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.25506.2.77.3.1.1.8 |
hh3cwapiConfigExtTableThe table containing WAPI configuration objects for SSID. SEQUENCE OF Hh3cwapiConfigExtEntry .1.3.6.1.4.1.25506.2.77.3.2 |
hh3cwapiConfigExtEntryAn extend entry in the hh3cwapiConfigExtTable. Hh3cwapiConfigExtEntry .1.3.6.1.4.1.25506.2.77.3.2.1 |
hh3cwapiConfigServicePolicyIDRepresents the ID of each service policy. Integer32 .1.3.6.1.4.1.25506.2.77.3.2.1.1 |
hh3cwapiConfigUnicastCipherEnabledThis object enables or disables the unicast cipher.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.25506.2.77.3.2.1.2 |
hh3cwapiConfigUnicastCipherSizeThis object indicates the length in bits of the unicast cipher
key. This should be 256 for SMS4, first 128 bits for encrypting,
last 128 bits for integrity checking.ro Unsigned32 .1.3.6.1.4.1.25506.2.77.3.2.1.3 |
hh3cwapiConfigAuthenticationSuiteEnabledThis variable indicates the corresponding AKM suite is enabled
or disabled.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.25506.2.77.3.2.1.4 |
hh3cwapiConfigAuthenticationSuiteThe selector of an AKM suite. It consists of an OUI (the first 3
octets) and a cipher suite identifier (the last octet).ro OCTET STRING .1.3.6.1.4.1.25506.2.77.3.2.1.5 |
hh3cwapiCfgExtASIPAddressTypeThis object is used to set IP addresses type of AS.rw InetAddressType (INET-ADDRESS-MIB) .1.3.6.1.4.1.25506.2.77.3.2.1.6 |
hh3cwapiCfgExtASIPAddressThis object is used to set the IP address of AS.rw InetAddress (INET-ADDRESS-MIB) .1.3.6.1.4.1.25506.2.77.3.2.1.7 |
hh3cwapiCfgExtASNameThis object is used to set the name of AS.rw OCTET STRING .1.3.6.1.4.1.25506.2.77.3.2.1.8 |
hh3cwapiCfgExtCertDomainThis object is used to set the PKI domain name.rw OCTET STRING .1.3.6.1.4.1.25506.2.77.3.2.1.9 |
hh3cwapiCfgExtCertInstalledThis object indicates whether the entity has installed
certificate. When the value is TURE, it shall indicate that
the SSID has installed certificate. Otherwise, it shall
indicate that the SSID hasn't installed certificate.ro TruthValue (SNMPv2-TC) .1.3.6.1.4.1.25506.2.77.3.2.1.10 |
hh3cwapiTrap OBJECT IDENTIFIER .1.3.6.1.4.1.25506.2.77.4 |
hh3cwapiTrapPrefix OBJECT IDENTIFIER .1.3.6.1.4.1.25506.2.77.4.0 |
hh3cwapiUserwithInvalidCertificateThis trap is sent when a user intrudes upon network with invalid
certificate. NOTIFICATION-TYPE .1.3.6.1.4.1.25506.2.77.4.0.1 |
hh3cwapiStationReplayAttackThis trap is sent when an attacker records and replays network
transactions. NOTIFICATION-TYPE .1.3.6.1.4.1.25506.2.77.4.0.2 |
hh3cwapiTamperAttackThis trap is sent when an attacker monitors network traffic and
maliciously changes data in transit(for example, an attacker may
modify the contents of a WAI message). NOTIFICATION-TYPE .1.3.6.1.4.1.25506.2.77.4.0.3 |
hh3cwapiLowSafeLevelAttackThis trap is sent when a station associates AP(Access Point),
creates packet of Unicast Key Negotiation Response with wrong
WIE(WAPI Information Element) of ASUE(Authentication Supplicant
Entity). NOTIFICATION-TYPE .1.3.6.1.4.1.25506.2.77.4.0.4 |
hh3cwapiAddressRedirectionAttackThis trap is sent when an attacker maliciously changes destination
MAC address of WPI(WLAN Privacy Infrastructure) frame. NOTIFICATION-TYPE .1.3.6.1.4.1.25506.2.77.4.0.5 |
hh3cwapiTrapInfo OBJECT IDENTIFIER .1.3.6.1.4.1.25506.2.77.4.1 |
hh3cwapiTrapInfoMacAddrThe MAC address of the WAPI user.ro MacAddress (SNMPv2-TC) .1.3.6.1.4.1.25506.2.77.4.1.1 |
hh3cwapiTrapInfoAPIdTo uniquely identify each AP.ro Integer32 .1.3.6.1.4.1.25506.2.77.4.1.2 |
hh3cwapiTrapInfoRadioIdRepresents each radio.ro Integer32 .1.3.6.1.4.1.25506.2.77.4.1.3 |
hh3cwapiTrapInfoBSSIdAs MAC Address format, it is to identify BSS.ro MacAddress (SNMPv2-TC) .1.3.6.1.4.1.25506.2.77.4.1.4 |