Home/Catalog/JUNIPER-USER-AAA-MIB

JUNIPER-USER-AAA-MIB

Updated Sep 8, 2020
AI MIB Summary

The JUNIPER-USER-AAA-MIB enables monitoring and management of authentication, authorization, and accounting (AAA) events on Juniper Networks devices, specifically tracking user login sessions, authentication failures, privilege level changes, and accounting record generation. This module provides granular visibility into access control policies and user activity logs essential for security auditing and session management on Juniper routers and switches.

This module defines the objects pertaining to User authentication, authorization and accounting
Main OID:
jnxUserAAAMib.1.3.6.1.4.1.2636.3.51.1
97
Objects
Active
Status
7
Dependencies

Imported Objects

Objects

97 total
Object Name
jnxUserAAAMibThis module defines the objects pertaining to User authentication, authorization and accounting
MODULE-IDENTITY
.1.3.6.1.4.1.2636.3.51.1
jnxUserAAANotifications
OBJECT IDENTIFIER
.1.3.6.1.4.1.2636.3.51.1.0
jnxAccessAuthServiceUpAn access authentication trap signifies that the specified service has started.
NOTIFICATION-TYPE
.1.3.6.1.4.1.2636.3.51.1.0.1
jnxAccessAuthServiceDownAn access authentication trap signifies that the specified service has been stopped.
NOTIFICATION-TYPE
.1.3.6.1.4.1.2636.3.51.1.0.2
jnxAccessAuthServerDisabledAn access authentication trap signifies that the External authentication server is not responding.
NOTIFICATION-TYPE
.1.3.6.1.4.1.2636.3.51.1.0.3
jnxAccessAuthServerEnabledAn access authentication trap signifies that the AAA client has changed the status of the External authentication server to UP.
NOTIFICATION-TYPE
.1.3.6.1.4.1.2636.3.51.1.0.4
jnxAccessAuthAddressPoolHighThresholdAn access authentication trap signifies that the address pool has reached its high threshold.
NOTIFICATION-TYPE
.1.3.6.1.4.1.2636.3.51.1.0.5
jnxAccessAuthAddressPoolAbateThresholdAn access authentication trap signifies that the address pool has reached its abate threshold
NOTIFICATION-TYPE
.1.3.6.1.4.1.2636.3.51.1.0.6
jnxAccessAuthAddressPoolOutOfAddressesAn access authentication trap signifies that an Out Of Addresses event occured on the pool.
NOTIFICATION-TYPE
.1.3.6.1.4.1.2636.3.51.1.0.7
jnxAccessAuthAddressPoolOutOfMemoryAn access authentication trap signifies that an Out Of Memory event occured on the pool.
NOTIFICATION-TYPE
.1.3.6.1.4.1.2636.3.51.1.0.8
jnxUserAAAObjects
OBJECT IDENTIFIER
.1.3.6.1.4.1.2636.3.51.1.1
jnxUserAAAGlobalStats
OBJECT IDENTIFIER
.1.3.6.1.4.1.2636.3.51.1.1.1
jnxTotalAuthenticationRequestsTotal authentication requests received.ro
Counter64
.1.3.6.1.4.1.2636.3.51.1.1.1.1
jnxTotalAuthenticationResponsesTotal authentication responses.ro
Counter64
.1.3.6.1.4.1.2636.3.51.1.1.1.2
jnxUserAAAAccessAuthStats
OBJECT IDENTIFIER
.1.3.6.1.4.1.2636.3.51.1.1.2
jnxUserAAAStatTableThis table exposes the user authentication statistics.
SEQUENCE OF JnxAuthStatEntry
.1.3.6.1.4.1.2636.3.51.1.1.2.1
jnxUserAAAStatEntryStatistic entry collects for authentication.
JnxAuthStatEntry
.1.3.6.1.4.1.2636.3.51.1.1.2.1.1
jnxUserAAAStatAuthTypeThe entry indicates the authentication type. It uniquely identifies the statistics counters related to its authentication.
JnxAuthenticateType
.1.3.6.1.4.1.2636.3.51.1.1.2.1.1.1
jnxUserAAAStatRequestReceivedThe number of request received.ro
Counter64
.1.3.6.1.4.1.2636.3.51.1.1.2.1.1.2
jnxUserAAAStatAccessAcceptedThe number of access granted. It is an aggregated statistics for this type of authenticaiton.ro
Counter64
.1.3.6.1.4.1.2636.3.51.1.1.2.1.1.3
jnxUserAAAStatAccessRejectedThis number of access request rejected. It is an aggregated statistics for this type of authentication.ro
Counter64
.1.3.6.1.4.1.2636.3.51.1.1.2.1.1.4
jnxUserAAATrapVars
OBJECT IDENTIFIER
.1.3.6.1.4.1.2636.3.51.1.1.3
jnxUserAAAServerNameThe server name which identifies the authentication server.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.2636.3.51.1.1.3.1
jnxUserAAAAddressPoolNameThe address pool name which identifies the local address pool.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.2636.3.51.1.1.3.2
jnxUserAAAAccessPool
OBJECT IDENTIFIER
.1.3.6.1.4.1.2636.3.51.1.1.4
jnxUserAAAAccessPoolGeneral
OBJECT IDENTIFIER
.1.3.6.1.4.1.2636.3.51.1.1.4.1
jnxUserAAAAccessPoolTableThe entries in this table specify the address pools.
SEQUENCE OF JnxUserAAAAccessPool
.1.3.6.1.4.1.2636.3.51.1.1.4.1.1
jnxUserAAAAccessPoolEntryA read-only description of the local address pools.
JnxUserAAAAccessPool
.1.3.6.1.4.1.2636.3.51.1.1.4.1.1.1
jnxUserAAAAccessPoolIdentThe address identifier key.
Unsigned32
.1.3.6.1.4.1.2636.3.51.1.1.4.1.1.1.1
jnxUserAAAAccessPoolRoutingInstanceThe routing instance of the address pool.ro
DisplayString
.1.3.6.1.4.1.2636.3.51.1.1.4.1.1.1.2
jnxUserAAAAccessPoolNameThe address pool name.ro
DisplayString
.1.3.6.1.4.1.2636.3.51.1.1.4.1.1.1.3
jnxUserAAAAccessPoolLinkNameThe address pool link name.ro
DisplayString
.1.3.6.1.4.1.2636.3.51.1.1.4.1.1.1.4
jnxUserAAAAccessPoolFamilyTypeThe family type of this pool.ro
InetAddressType (INET-ADDRESS-MIB)
.1.3.6.1.4.1.2636.3.51.1.1.4.1.1.1.5
jnxUserAAAAccessPoolInetNetworkThe Match criteria for this pool. Network or Prefixro
InetAddress
.1.3.6.1.4.1.2636.3.51.1.1.4.1.1.1.6
jnxUserAAAAccessPoolInetPrefixLengthThe Prefix Length for an IPv6 poolro
InetAddressPrefixLength (INET-ADDRESS-MIB)
.1.3.6.1.4.1.2636.3.51.1.1.4.1.1.1.7
jnxUserAAAAccessPoolOutOfMemoryThe Number of times this pool has flagged an Out of Memory condition.ro
Counter64
.1.3.6.1.4.1.2636.3.51.1.1.4.1.1.1.8
jnxUserAAAAccessPoolOutOfAddressesThe Number of times this pool has flagged an Out of Address condition.ro
Counter64
.1.3.6.1.4.1.2636.3.51.1.1.4.1.1.1.9
jnxUserAAAAccessPoolAddressTotalThe total number of Addresses or prefixes in this pool.ro
CounterBasedGauge64 (HCNUM-TC)
.1.3.6.1.4.1.2636.3.51.1.1.4.1.1.1.10
jnxUserAAAAccessPoolAddressesInUseThe total number of Addresses or prefixes given out from this pool.ro
CounterBasedGauge64 (HCNUM-TC)
.1.3.6.1.4.1.2636.3.51.1.1.4.1.1.1.11
jnxUserAAAAccessPoolAddressUsageThe percentage of addresses used in this pool or linked pool. If this pool is the head of a linked chain of pools, this number reflects the Usage for the whole chain. Conversely, if this pool it part of a linked chain of pools but not the head of the chain, the value will not be used.ro
INTEGER
.1.3.6.1.4.1.2636.3.51.1.1.4.1.1.1.12
jnxUserAAAAccessPoolAddressUsageHighThe configured high percentage threshold of addresses used in this pool or linked pool. An SNMP trap is generated when this threshold is exceeded. This trap will only be generated for unlinked pools or pools that are the head of a linked chain of pools Conversely, if this pool it part of a linked chain of pools but not the head of the chain, then no traps will be generated.ro
INTEGER
.1.3.6.1.4.1.2636.3.51.1.1.4.1.1.1.13
jnxUserAAAAccessPoolAddressUsageAbateThe configured abate percentage threshold of addresses used in this pool or linked pool. An SNMP trap clear is generated when address use falls below this threshold percentage. This trap will only be generated for unlinked pools or pools that are the head of a linked chain of pools Conversely, if this pool it part of a linked chain of pools but not the head of the chain, then no traps will be generated.ro
INTEGER
.1.3.6.1.4.1.2636.3.51.1.1.4.1.1.1.14
jnxUserAAAAssignment
OBJECT IDENTIFIER
.1.3.6.1.4.1.2636.3.51.1.1.5
jnxUserAAAGeneral
OBJECT IDENTIFIER
.1.3.6.1.4.1.2636.3.51.1.1.5.1
jnxUserAAADomainDelimitersThe list of delimiters used to separate the user's name from the user's domain in the username field. The default is '@'.ro
DisplayString
.1.3.6.1.4.1.2636.3.51.1.1.5.1.1
jnxUserAAADomainParseDirectionThe direction in which the user's name is parsed: either search for domain delimiter from left to right or right to left; first delimiter marks boundry. The default is right to left.ro
Enumeration
.1.3.6.1.4.1.2636.3.51.1.1.5.1.2
jnxUserAAADomain
OBJECT IDENTIFIER
.1.3.6.1.4.1.2636.3.51.1.1.5.2
jnxUserAAADomainTableThe entries in this table specify the assignment of a remote access user to a logical system, based on the user's domain.
SEQUENCE OF JnxUserAAADomainEntry
.1.3.6.1.4.1.2636.3.51.1.1.5.2.1
jnxUserAAADomainEntryA specification of the logical system to which users on a specified domain should be assigned.
JnxUserAAADomainEntry
.1.3.6.1.4.1.2636.3.51.1.1.5.2.1.1
jnxUserAAADomainNameThe domain name uniquely identifying this entry.
DisplayString
.1.3.6.1.4.1.2636.3.51.1.1.5.2.1.1.1
jnxUserAAADomainStripDomainEnables/disables the domain name stripping feature, which causes the system to strip the domain name before sending the access-request to RADIUS for authentication.ro
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2636.3.51.1.1.5.2.1.1.2
jnxUserAAADomainLogicalSystemThe name of the logical system, which will be used by the AAA subsystem for this session. If not specified, will be mapped to default.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.2636.3.51.1.1.5.2.1.1.3
jnxUserAAADomainRoutingInstanceThe name of the routing instance, which will be used by the AAA subsystem for this session. If not specified, will be mapped to default.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.2636.3.51.1.1.5.2.1.1.4
jnxUserAAADomainAddrPoolNameThe configured the address-pool-name for the domain name.ro
DisplayString
.1.3.6.1.4.1.2636.3.51.1.1.5.2.1.1.5
jnxUserAAADomainDynamicPorfileThe configured dynamic-profile which will be used for this session upon succeeding validation.rodeprecated
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.2636.3.51.1.1.5.2.1.1.6
jnxUserAAADomainTargetLogicalSystemThe configured target logical-system that this session will need to be mapped to. If not specified, will be mapped to default.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.2636.3.51.1.1.5.2.1.1.7
jnxUserAAADomainTargetRoutingInstanceThe configured routing-instance that this session will need to be mapped to.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.2636.3.51.1.1.5.2.1.1.8
jnxUserAAADomainTunnelProfileThe associated tunnel profile.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.2636.3.51.1.1.5.2.1.1.9
jnxUserAAADomainDynamicProfileThe configured dynamic-profile to be used for this session.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.2636.3.51.1.1.5.2.1.1.10
jnxUserAAADomainStripUsernameDisplays the strip-username configuration.ro
Enumeration
.1.3.6.1.4.1.2636.3.51.1.1.5.2.1.1.11
jnxUserAAADomainOverridePasswordDisplays the override-password configuration.ro
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2636.3.51.1.1.5.2.1.1.12
jnxUserAAADomainTunnelTableThe entries in this table specify the tunnels associated with a domain.
SEQUENCE OF JnxUserAAADomainTunnelEntry
.1.3.6.1.4.1.2636.3.51.1.1.5.2.2
jnxUserAAADomainTunnelEntryA specification of the tunnels associated with a domain.
JnxUserAAADomainTunnelEntry
.1.3.6.1.4.1.2636.3.51.1.1.5.2.2.1
jnxUserAAADomainTunnelNameThe domain name associated with this entry.
OCTET STRING
.1.3.6.1.4.1.2636.3.51.1.1.5.2.2.1.1
jnxUserAAADomainTunnelDefIdThe tunnel definition id value associated with this entry.
Integer32
.1.3.6.1.4.1.2636.3.51.1.1.5.2.2.1.2
jnxUserAAADomainTunnelPreferenceThe tunnel's preference value associated with this entry.ro
Integer32
.1.3.6.1.4.1.2636.3.51.1.1.5.2.2.1.3
jnxUserAAADomainTunnelRemoteGwNameThis name specifies the hostname expected from the peer (the LNS) when a tunnel is setup.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.2636.3.51.1.1.5.2.2.1.4
jnxUserAAADomainTunnelRemoteGwAddressIP address of LNS tunnel endpointro
IpAddress
.1.3.6.1.4.1.2636.3.51.1.1.5.2.2.1.5
jnxUserAAADomainTunnelSourceGwNameThis name specifies the hostname expected from the peer (the LNS) when a tunnel is setup.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.2636.3.51.1.1.5.2.2.1.6
jnxUserAAADomainTunnelSourceGwAddressThe source address of the tunnel (overrides the default address for this LS/RI.)ro
IpAddress
.1.3.6.1.4.1.2636.3.51.1.1.5.2.2.1.7
jnxUserAAADomainTunnelSecretThe tunnel password associated with this entry.ro
DisplayString
.1.3.6.1.4.1.2636.3.51.1.1.5.2.2.1.8
jnxUserAAADomainTunnelLogicalSystemsThe logical systems associated with this entty.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.2636.3.51.1.1.5.2.2.1.9
jnxUserAAADomainTunnelRoutingInstanceThe routing instance associated with this entty.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.2636.3.51.1.1.5.2.2.1.10
jnxUserAAADomainTunnelMediumThe tunnel medium associated with this entry. The medium dictates the format of the tunnel address.ro
Enumeration
.1.3.6.1.4.1.2636.3.51.1.1.5.2.2.1.11
jnxUserAAADomainTunnelTypeThe tunnel type associated with this entry.ro
Enumeration
.1.3.6.1.4.1.2636.3.51.1.1.5.2.2.1.12
jnxUserAAADomainTunnelIdThe tunnel identifier associated with this entry.ro
DisplayString
.1.3.6.1.4.1.2636.3.51.1.1.5.2.2.1.13
jnxUserAAADomainTunnelMaxSessionsThe maximum number of tunnel sessions allowed in this tunnel entry.ro
Unsigned32
.1.3.6.1.4.1.2636.3.51.1.1.5.2.2.1.14
jnxUserAAADomainPadnTableThe entries in this table specify the PPPoE active discovery network (PADN) parameters associated with a domain.
SEQUENCE OF JnxUserAAADomainPadnEntry
.1.3.6.1.4.1.2636.3.51.1.1.5.2.3
jnxUserAAADomainPadnEntryA specification of the PPPoE active discovery network parameters associated with a domain.
JnxUserAAADomainPadnEntry
.1.3.6.1.4.1.2636.3.51.1.1.5.2.3.1
jnxUserAAADomainPadnIpAddressThe IP address of this entry.
IpAddress
.1.3.6.1.4.1.2636.3.51.1.1.5.2.3.1.1
jnxUserAAADomainPadnIpMaskThe IP mask of this entry.
IpAddress
.1.3.6.1.4.1.2636.3.51.1.1.5.2.3.1.2
jnxUserAAADomainPadnDistanceThe administrative distance metric of this entry.ro
Integer32
.1.3.6.1.4.1.2636.3.51.1.1.5.2.3.1.3
jnxUserAAAAccessProfile
OBJECT IDENTIFIER
.1.3.6.1.4.1.2636.3.51.1.1.6
jnxUserAAAAccessProfileGeneral
OBJECT IDENTIFIER
.1.3.6.1.4.1.2636.3.51.1.1.6.1
jnxUserAAAAccessProfileTableThe entries in this table specify the assignment of authentication methods for a particular subscriber type.
SEQUENCE OF JnxUserAAAAccessProfileEntry
.1.3.6.1.4.1.2636.3.51.1.1.6.1.1
jnxUserAAAAccessProfileEntryA specification of the authentication methods for a particular subscriber type.
JnxUserAAAAccessProfileEntry
.1.3.6.1.4.1.2636.3.51.1.1.6.1.1.1
jnxUserAAAAccessProfileNameThe access profile name.
DisplayString
.1.3.6.1.4.1.2636.3.51.1.1.6.1.1.1.1
jnxUserAAAAccessProfileAuthenticationOrderThe set of authentication mechanisms configured on this system. Each octet in this object contains one of the values defined in the JnxAuthenticateType TEXTUAL-CONVENTION. The system will sequence through each octet of this object starting at octet 1 and attempt to use the corresponding authentication protocol defined by JnxAuthenticateType. If an authentication protocol is configured and attempts to reach the authentication server fail, the system will move to the next octet in this object and retry the authentication in the form dictated by the corresponding authentication protocoltype. The process of sequencing thru each octet will stop if the authentication server is successfully contacted, or there are no more configured octets in this object.ro
OCTET STRING
.1.3.6.1.4.1.2636.3.51.1.1.6.1.1.1.2
jnxUserAAAAccessProfileAccountingOrderThe set of accounting mechanisms configured on this system. Each octet in this object contains one of the values defined in the JnxAccountingType TEXTUAL-CONVENTION. The system will sequence through each octet of this object starting at octet 1 and attempt to use the corresponding accounting protocol defined by JnxAccountingType. If an accounting protocol is configured and attempts to reach the accounting server fail, the system will move to the next octet in this object and retry the accounting in the form dictated by the corresponding accounting protocoltype. The process of sequencing thru each octet will stop if the accounting server is successfully contacted, or there are no more configured octets in this object.ro
OCTET STRING
.1.3.6.1.4.1.2636.3.51.1.1.6.1.1.1.3
jnxUserAAAAccessProfileAuthorizationOrderThe set of accounting mechanisms configured on this system. Each octet in this object contains one of the values defined in the JnxAuthorizationType TEXTUAL-CONVENTION. The system will sequence through each octet of this object starting at octet 1 and attempt to use the corresponding accounting protocol defined by JnxAuthorizationType. If an accounting protocol is configured and attempts to reach the accounting server fail, the system will move to the next octet in this object and retry the accounting in the form dictated by the corresponding accounting protocoltype. The process of sequencing thru each octet will stop if the accounting server is successfully contacted, or there are no more configured octets in this object.ro
OCTET STRING
.1.3.6.1.4.1.2636.3.51.1.1.6.1.1.1.4
jnxUserAAAAccessProfileProvisioningOrderThe set of provisioning mechanisms configured on this system. Each octet in this object contains one of the values defined in the JnxProvisioningType TEXTUAL-CONVENTION. The system will sequence through each octet of this object starting at octet 1 and attempt to use the corresponding accounting protocol defined by JnxProvisioningType. If an accounting protocol is configured and attempts to reach the accounting server fail, the system will move to the next octet in this object and retry the accounting in the form dictated by the corresponding accounting protocoltype. The process of sequencing thru each octet will stop if the accounting server is successfully contacted, or there are no more configured octets in this object.ro
OCTET STRING
.1.3.6.1.4.1.2636.3.51.1.1.6.1.1.1.5
jnxUserAAAAccessProfileAccStopOnFailureEnables/disables the Acct-Stop message if a user fails authentication, but AAA-server grants access.ro
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2636.3.51.1.1.6.1.1.1.6
jnxUserAAAAccessProfileAccStopOnDenyEnables/disables the Acct-Stop message if AAA-server denies access.ro
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2636.3.51.1.1.6.1.1.1.7
jnxUserAAAAccessProfileImmediateUpdateEnables/disables the Acct-Update message on receipt of a Acct-response for the Acct-Start message.ro
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2636.3.51.1.1.6.1.1.1.8
jnxUserAAAAccessProfileCoaImmediateUpdateEnables/disables the Acct-Update message on completion of processing a change of authorization.ro
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.2636.3.51.1.1.6.1.1.1.9
jnxUserAAAAccessProfileIntervalThe interval in minutes between accounting updates(Interim-stats off, if not specified).ro
Integer32 UNITS "minutes"
.1.3.6.1.4.1.2636.3.51.1.1.6.1.1.1.10
jnxUserAAAAccessProfileStatTypeThe type of statistics are collected. These are the configured types: time - the option to report only uptime volume-time - the option to report both volume and uptimero
Enumeration
.1.3.6.1.4.1.2636.3.51.1.1.6.1.1.1.11
JUNIPER-USER-AAA-MIB - SNMP MIB Reference | MIBs Explorer