Home/Catalog/HP-ICF-USER-PROFILE-MIB

HP-ICF-USER-PROFILE-MIB

AI MIB Summary

The HP-ICF-USER-PROFILE-MIB enables SNMP-based monitoring and configuration of user access profiles on Hewlett-Packard Intelligent Call Flow (ICF) systems, specifically managing authentication credentials, privilege levels, and session restrictions for network users. This module facilitates granular control over user authorization policies and profile attributes to enforce security boundaries within the ICF infrastructure.

This MIB module contains the definitions of Managed Objects for user access profiles.
Main OID:
hpicfUsrProfileMIB.1.3.6.1.4.1.11.2.14.11.1.12.1
68
Objects
Active
Status
6
Dependencies

Imported Objects

Objects

68 total
Object Name
hpicfUsrProfileMIBThis MIB module contains the definitions of Managed Objects for user access profiles.
MODULE-IDENTITY
.1.3.6.1.4.1.11.2.14.11.1.12.1
hpicfUsrProfileCapability
OBJECT IDENTIFIER
.1.3.6.1.4.1.11.2.14.11.1.12.1.0
hpicfUsrProfileCapabilityByPortMapA string of octets containing on bit per access profile primitive as follows: bit 0 - PVID/native/untagged ingress VLAN bit 1 - Tagged Egress VLAN bit 2 - Ingress VLAN Filter bit 3 - Priority Regeneration bit 4 - Max. Ingress Bandwidth bit 5 - Max. Egress Bandwidth bit 6 - Filter List bit 7 - Hitcount Support bit 8 - through 64 - reserved When a bit is set to one, it indicates that device supports the selected access profile primitive only on a per port ('hpicfUsrProfileUserPortNumber') basis. The concequence is that the device can only enforce the same access primitive setting for all users ('hpicfUsrProfileUserMacAddr') on a given port.ro
OCTET STRING
.1.3.6.1.4.1.11.2.14.11.1.12.1.0.1
hpicfUsrProfileCapabilityByUserMapA string of octets containing one bit per access profile primitive as follows: bit 0 - PVID/native/untagged ingress VLAN bit 1 - Tagged Egress VLAN bit 2 - Ingress VLAN Filter bit 3 - Priority Regeneration bit 4 - Max. Ingress Bandwidth bit 5 - Max. Egress Bandwidth bit 6 - Filter List bit 7 - Hitcount Support bit 8 - through 64 - reserved When a bit is set to one, it indicates that device supports the selected access profile primitive on a per 'hpicfUsrProfileUserMacAddr' basis. The consequence is that the device can enforce unique per user access profile primitives for each user on a given port ('hpicfUsrProfileUserPortNumber').ro
OCTET STRING
.1.3.6.1.4.1.11.2.14.11.1.12.1.0.2
hpicfUsrProfileConfig
OBJECT IDENTIFIER
.1.3.6.1.4.1.11.2.14.11.1.12.1.1
hpicfUsrProfileConfigFilterListTableA table that contains configuration objects for filter lists.
SEQUENCE OF HpicfUsrProfileConfigFilterListEntry
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.1
hpicfUsrProfileConfigFilterListEntryThe configuration information for a user's filtering profile.
HpicfUsrProfileConfigFilterListEntry
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.1.1
hpicfUsrProfileFilterListIndexThe identifier used to select a list of filter rules. A filter list entry must be created before a filter rule entry can be added.
Integer32
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.1.1.1
hpicfUsrProfileConfigFilterListRowStatusThis object indicates the status of this entry. Must NOT be active in order to modify an hpicfUsrProfileConfigFilterRuleEntry that is indexed on this entry's hpicfUsrProfileListIndex. This object must be in the notReady or notInService states in order for an hpicfUsrProfileConfigFilterRuleEntry to be added, removed, or modified. In order to be changed to an active rowStatus, at least one rule sharing the list index must have an active hpicfUsrProfileConfigFilterRuleRowStatus.rw
RowStatus (SNMPv2-TC)
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.1.1.2
hpicfUsrProfileConfigNasRulesIpv6Setting this attribute to enabled(1) enables the usage of IPv6 destinations in ACEs. When set to disabled(2) any implicit IP destinations will be translated as IPv4 only.rw
Enumeration
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.1.1.3
hpicfUsrProfileConfigFilterRuleTableA table that contains configuration objects for filter lists.
SEQUENCE OF HpicfUsrProfileConfigFilterRuleEntry
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.2
hpicfUsrProfileConfigFilterRuleEntryThe configuration information for a user's filtering profile.
HpicfUsrProfileConfigFilterRuleEntry
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.2.1
hpicfUsrProfileFilterRuleListIndexThe identifier used to select a list of filter rules. This filter rule list index must correspond to a created but not active filter list index in order for a rule entry to be created.
Integer32
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.2.1.1
hpicfUsrProfileFilterRuleIndexA numeric value assigned to each rule within a list belong to the same hpicfUsrProfileFilterListIndex. Rules within a given list will be evaluated in ascending order.
Integer32
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.2.1.2
hpicfUsrProfileConfigFilterRuleSpecifies a single filter rule using the same syntax used for the hp-nas-filter-rule RADIUS attribute.rw
OCTET STRING
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.2.1.3
hpicfUsrProfileConfigFilterRuleRowStatusThis object indicates the status of this entry. Must NOT be active in order to modify an hpicfUsrProfileConfigFilterRuleEntry. However, if an hpicfUsrProfileConfigFilterListRowStatus is set to destroy, all HpicfUsrProfileConfigFilterRuleEntry entries sharing the common hpicfUsrProfileFilterListIndex will also be destroyed regardless of the value of hpicfUsrProfileConfigFilterRuleRowStatus.rw
RowStatus (SNMPv2-TC)
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.2.1.4
hpicfUsrProfileConfigTableA table that contains configuration objects for access profiles.
SEQUENCE OF HpicfUsrProfileConfigEntry
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.3
hpicfUsrProfileConfigEntryThe configuration information for an access profile.
HpicfUsrProfileConfigEntry
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.3.1
hpicfUsrProfileConfigIndexA unique numeric value assigned to each access profile in this table.
Integer32
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.3.1.1
hpicfUsrProfileConfigPvidSpecifies the port VID (PVID), also known, as native VLAN to be used with this access profile. To specify no pvid, set value to 4095, not 0.rw
VlanIndex (Q-BRIDGE-MIB)
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.3.1.2
hpicfUsrProfileConfigPvidEnableSetting this attribute TRUE enables the usage of 'hpicfUsrProfilePvid' when this access profile is active.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.3.1.3
hpicfUsrProfileConfigTaggedEgressVlanMap1kA string of octets containing one bit per VLAN for VLANS with 'VlanIndex' values of 0 through 1023. The first octet corresponds to VLANs with 'VlanIndex' values of 0 through 7, the second octet to VLANs 8 through 15, etc. The most significant bit of each octet corresponds to the lowest 'VlanIndex' value in that octet. Bit 0 in the 1K map is ignored/discarded. If variable hpicfUsrProfileConfigPvidEnable is TRUE, some bit other than bit 0 in the 1K map must be set. To specify an empty tagged vlan map, vlanIndex value 4095 in the 4K map must be set. Setting a bit to '1' specifies the usage the corresponding VLAN with this access profile.rw
OCTET STRING
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.3.1.4
hpicfUsrProfileConfigTaggedEgressVlanMap2kA string of octets containing one bit per VLAN for VLANS with 'VlanIndex' values of 1024 through 2047. The first octet corresponds to VLANs with 'VlanIndex' values of 1024 through 1031, the second octet to VLANs 1032 through 1039, etc. The most significant bit of each octet corresponds to the lowest 'VlanIndex' value in that octet. Setting a bit to '1' specifies the usage the corresponding VLAN with this access profile.rw
OCTET STRING
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.3.1.5
hpicfUsrProfileConfigTaggedEgressVlanMap3kA string of octets containing one bit per VLAN for VLANS with 'VlanIndex' values of 2048 through 3071. The first octet corresponds to VLANs with 'VlanIndex' values of 2048 through 3071, the second octet to VLANs 2056 through 2063, etc. The most significant bit of each octet corresponds to the lowest 'VlanIndex' value in that octet. Setting a bit to '1' specifies the usage the corresponding VLAN with this access profile.rw
OCTET STRING
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.3.1.6
hpicfUsrProfileConfigTaggedEgressVlanMap4kA string of octets containing one bit per VLAN for VLANS with 'VlanIndex' values of 3072 through 4095. The first octet corresponds to VLANs with 'VlanIndex' values of 3072 through 3079, the second octet to VLANs 3080 through 3087, etc. The most significant bit of each octet corresponds to the lowest 'VlanIndex' value in that octet. Setting a bit to '1' specifies the usage the corresponding VLAN with this access profile.rw
OCTET STRING
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.3.1.7
hpicfUsrProfileConfigTaggedEgressVlanEnableSetting this attribute TRUE enables the usage of 'hpicfUsrProfileTaggedVlanMapXXX' when this access profile is being enforced.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.3.1.8
hpicfUsrProfileConfigIngressVlanFilterEnableSetting this attribute TRUE causes the system to only allow ingress traffic from those VLANs on which egress traffic is permitted.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.3.1.9
hpicfUsrProfileConfigPriorityRegenTableSpecifies the IEEE 802 priority regeneration table for this access profile. Syntax of octet string is same as for 'User-Priority-Table' RADIUS attribute as defined in RFC4675.rw
OCTET STRING
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.3.1.10
hpicfUsrProfileConfigPriorityRegenTableEnableSetting this attribute TRUE enables the usage of the 'hpicfUsrProfilePriorityRegenTable' when this access profile is active.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.3.1.11
hpicfUsrProfileConfigMaxIngressBandwidthSpecifies the maximum ingress bandwidth for this access profile. Bandwidth value is specified in Kbps.rw
Unsigned32
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.3.1.12
hpicfUsrProfileConfigMaxIngressBandwidthEnableSetting this attribute TRUE enables the usage of the 'hpicfUsrProfileMaxIngressBandwidth' when this access profile is active.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.3.1.13
hpicfUsrProfileConfigMaxEgressBandwidthSpecifies the maximum egress bandwidth for this access profile. Bandwidth value is specified in Kbps.rw
Unsigned32
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.3.1.14
hpicfUsrProfileConfigMaxEgressBandwidthEnableSetting this attribute TRUE enables the usage of 'hpicfUsrProfileMaxEgressBandwidth' when this access profile is active.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.3.1.15
hpicfUsrProfileConfigFilterListIndexSelects the filter from 'hpicfUsrProfileConfigFilterTable' to associate with this access profile. The rowStatus of the filter must be in an active state.rw
Integer32
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.3.1.16
hpicfUsrProfileConfigFilterListEnableSetting this attribute TRUE enables the usage of 'hpicfUsrProfileConfigFilterListIndex' when this access profile is active.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.3.1.17
hpicfUsrProfileConfigEntryRowStatusThis object indicates the status of this entry. Must NOT be active in order to change some other column of this config entry.rw
RowStatus (SNMPv2-TC)
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.3.1.18
hpicfUsrProfileConfigBindTableA table that contains configuration objects for the access profile-to-user bindings.
SEQUENCE OF HpicfUsrProfileConfigBindEntry
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.4
hpicfUsrProfileConfigBindEntryThe configuration information for a access profile-to-user binding.
HpicfUsrProfileConfigBindEntry
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.4.1
hpicfUsrProfileUserPortNumberThe interface index associated with this user. On wired ProCurve products, the interface index is the physical port. On wireless products it is the instance (whether real or virtual) of an AP.
InterfaceIndex (IF-MIB)
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.4.1.1
hpicfUsrProfileUserMacAddrThe 48-bit IEEE media access control address of the user.
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.4.1.2
hpicfUsrProfileSelectorSetting this attribute to a value between 1 and 16384 selects an access profile from 'hpicfUsrProfileConfigTable' to apply to the user.rw
Integer32
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.4.1.3
hpicfUsrProfileConfigBindEntryRowStatusThis object indicates the status of this entry. Must NOT be active in order to change some other column of this bind entry.rw
RowStatus (SNMPv2-TC)
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.4.1.4
hpicfUsrProfileConfigConflictResolveQoSThis object controls how a device behaves when QoS conflicts arise. A conflict can arise if a device only supports the QoS access primitive on a per-port basis, but device is being configured with profiles that have per-user unique setting. Applying these profiles to the same port will cause the conflict to arise because the device cannot enforce a per-user unique QoS setting. This object specifies two alternatives, as follows: 'non-strict' - Device does not signal errors when multiple access profiles are applied to a port. The device will apply the QoS settings specified in the last profile applied to the port. 'strict' - Device does signal an error when an attempt to apply an access profile to a port that already has an active access profile with a different QoS setting. Device will not activate the access profile in question after error is signaled.rw
Enumeration
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.5
hpicfUsrProfileConfigConflictResolveMaxIngressBandwidthThis object controls how a device behaves when ingress BW conflicts arise. A conflict can arise if a device only supports the ingress BW access primitive on a per-port basis, but device is being configured with profiles that have per-user unique setting. Applying these profiles to the same port will cause the conflict to arise because the device cannot enforce a per-user unique ingress BW setting. This object specifies two alternatives, as follows: 'non-strict' - Device does not signal errors when multiple access profiles are applied to a port. The device will apply the ingress BW settings specified in the last profile applied to the port. 'strict' - Device does signal an error when an attempt to apply an access profile to a port that already has an active access profile with a different ingress BW setting. Device will not activate the access profile in question after error is signaled.rw
Enumeration
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.6
hpicfUsrProfileConfigConflictResolveMaxEgressBandwidthThis object controls how a device behaves when egress BW conflicts arise. A conflict can arise if a device only supports the egress BW access primitive on a per-port basis, but device is being configured with profiles that have per-user unique setting. Applying these profiles to the same port will cause the conflict to arise because the device cannot enforce a per-user egress BW setting. This object specifies two alternatives, as follows: 'non-strict' - Device does not signal errors when multiple access profiles are applied to a port. The device will apply the egress BW settings specified in the last profile applied to the port. 'strict' - Device does signal an error when an attempt to apply an access profile to a port that already has an active access profile with a different egress BW setting. Device will not activate the access profile in question after error is signaled.rw
Enumeration
.1.3.6.1.4.1.11.2.14.11.1.12.1.1.7
hpicfUsrProfileStats
OBJECT IDENTIFIER
.1.3.6.1.4.1.11.2.14.11.1.12.1.2
hpicfUsrProfileLastUpdateA snapshot of the module sysUpTime at the time of the last update to the access profiles in effect. A value of 0 indicates that the hpicfUsrProfileLastUpdate object is not supported by the device and a fresh copy of the hpicfUsrProfileTable will always need to be obtained by the management application.ro
TimeTicks (SNMPv2-SMI)
.1.3.6.1.4.1.11.2.14.11.1.12.1.2.1
hpicfUsrProfileStatsFilterTableA table that contains statistic objects for filter lists.
SEQUENCE OF HpicfUsrProfileStatsFilterEntry
.1.3.6.1.4.1.11.2.14.11.1.12.1.2.2
hpicfUsrProfileStatsFilterEntryStatistic information for a user's filtering profile.
HpicfUsrProfileStatsFilterEntry
.1.3.6.1.4.1.11.2.14.11.1.12.1.2.2.1
hpicfUsrProfileStatsFilterRuleSpecifies a single filter rule using the same syntax used for the hp-nas-filter-rule RADIUS attribute.ro
OCTET STRING
.1.3.6.1.4.1.11.2.14.11.1.12.1.2.2.1.1
hpicfUsrProfileStatsFilterRuleHitCountSpecifies the number of times (hit count) the user's traffic has matched this rule.ro
Counter64
.1.3.6.1.4.1.11.2.14.11.1.12.1.2.2.1.2
hpicfUsrProfileStatsFilterRuleHitCountEnabledWhen this attribute is TRUE it signifies the 'hpicfUsrProfileStatsFilterRuleHitCount' contains a valid value. A FALSE value signifies it does not contain a valid value.ro
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.11.2.14.11.1.12.1.2.2.1.3
hpicfUsrProfileStatsTableThis table describes the access profiles currently in effect.
SEQUENCE OF HpicfUsrProfileStatsEntry
.1.3.6.1.4.1.11.2.14.11.1.12.1.2.3
hpicfUsrProfileStatsEntryAn entry in the user access profile table.
HpicfUsrProfileStatsEntry
.1.3.6.1.4.1.11.2.14.11.1.12.1.2.3.1
hpicfUsrProfileStatsPvidActive port VID (PVID) for this user.ro
VlanIndex (Q-BRIDGE-MIB)
.1.3.6.1.4.1.11.2.14.11.1.12.1.2.3.1.1
hpicfUsrProfileStatsTaggedEgressVlanMap1kA string of octets containing one bit per VLAN for VLANS with 'VlanIndex' values of 0 through 1023. The first octet corresponds to VLANs with 'VlanIndex' values of 0 through 7, the second octet to VLANs 8 through 15, etc. The most significant bit of each octet corresponds to the lowest 'VlanIndex' value in that octet. When a bit is set to '1', it means the corresponding tagged VLAN as active for this user.ro
OCTET STRING
.1.3.6.1.4.1.11.2.14.11.1.12.1.2.3.1.2
hpicfUsrProfileStatsTaggedEgressVlanMap2kA string of octets containing one bit per VLAN for VLANS with 'VlanIndex' values of 1024 through 2047. The first octet corresponds to VLANs with 'VlanIndex' values of 1024 through 1031, the second octet to VLANs 1032 through 1039, etc. The most significant bit of each octet corresponds to the lowest 'VlanIndex' value in that octet. When a bit is set to '1', it indicates the corresponding tagged VLAN as active for this user.ro
OCTET STRING
.1.3.6.1.4.1.11.2.14.11.1.12.1.2.3.1.3
hpicfUsrProfileStatsTaggedEgressVlanMap3kA string of octets containing one bit per VLAN for VLANS with 'VlanIndex' values of 2048 through 3071. The first octet corresponds to VLANs with 'VlanIndex' values of 2048 through 2055, the second octet to VLANs 2056 through 2063, etc. The most significant bit of each octet corresponds to the lowest 'VlanIndex' value in that octet. When a bit is set to '1', it indicates the corresponding tagged VLAN as active for this user.ro
OCTET STRING
.1.3.6.1.4.1.11.2.14.11.1.12.1.2.3.1.4
hpicfUsrProfileStatsTaggedEgressVlanMap4kA string of octets containing one bit per VLAN for VLANS with 'VlanIndex' values of 3072 through 4095. The first octet corresponds to VLANs with 'VlanIndex' values of 3072 through 3079, the second octet to VLANs 3080 through 3087, etc. The most significant bit of each octet corresponds to the lowest 'VlanIndex' value in that octet. When a bit is set to '1', it indicates the corresponding tagged VLAN as active for this user.ro
OCTET STRING
.1.3.6.1.4.1.11.2.14.11.1.12.1.2.3.1.5
hpicfUsrProfileStatsIngressVlanFilterEnableWhen this attribute is TRUE causes the system is only allowing ingress traffic from those VLANs on which egress traffic is permitted.ro
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.11.2.14.11.1.12.1.2.3.1.6
hpicfUsrProfileStatsPriorityRegenTableSpecifies the IEEE 802 priority regeneration table active for this access profile. Syntax of octet string is same as for 'User-Priority-Table' RADIUS attribute as defined in RFC4675.ro
OCTET STRING
.1.3.6.1.4.1.11.2.14.11.1.12.1.2.3.1.7
hpicfUsrProfileStatsMaxIngressBandwidthSpecifies the maximum ingress bandwidth for this access profile. Bandwidth value is specified in Kbps.ro
Unsigned32
.1.3.6.1.4.1.11.2.14.11.1.12.1.2.3.1.8
hpicfUsrProfileStatsMaxEgressBandwidthSpecifies the maximum egress bandwidth for this access profile. Bandwidth value is specified in Kbps.ro
Unsigned32
.1.3.6.1.4.1.11.2.14.11.1.12.1.2.3.1.9
hpicfUsrProfileStatsFilterListIndexA value of 0 indicates that no filter rule set is active for the user. A value between 1 and 16384 selects the active filter rule set from 'hpicfUsrProfileStatsFilterTable'.ro
Integer32
.1.3.6.1.4.1.11.2.14.11.1.12.1.2.3.1.10
hpicfUsrProfileStatsAccessModeIndicates whether profile was applied via SNMP or via RADIUS. Application by SNMP has precedence over RADIUS. Where there are no attribute conflicts, profile attributes may be a combination of those applied by both SNMP and RADIUS. In such case, the variable value will still be SNMP.ro
Enumeration
.1.3.6.1.4.1.11.2.14.11.1.12.1.2.3.1.11
hpicfUsrProfileConformance
OBJECT IDENTIFIER
.1.3.6.1.4.1.11.2.14.11.1.12.1.3
hpicfUsrProfileGroup
OBJECT IDENTIFIER
.1.3.6.1.4.1.11.2.14.11.1.12.1.3.1
hpicfUsrProfileCompliances
OBJECT IDENTIFIER
.1.3.6.1.4.1.11.2.14.11.1.12.1.3.2
HP-ICF-USER-PROFILE-MIB - SNMP MIB Reference | MIBs Explorer