JUNIPER-USER-AAA-MIB
Updated Sep 8, 2020AI MIB Summary
The JUNIPER-USER-AAA-MIB enables monitoring and management of authentication, authorization, and accounting (AAA) events on Juniper Networks devices, specifically tracking user login sessions, authentication failures, privilege level changes, and accounting record generation. This module provides granular visibility into access control policies and user activity logs essential for security auditing and session management on Juniper routers and switches.
This module defines the objects pertaining to User authentication, authorization and accounting
Main OID:
jnxUserAAAMib.1.3.6.1.4.1.2636.3.51.1
97
Objects
Active
Status
7
Dependencies
Imported Objects
Objects
97 total| Object Name |
|---|
jnxUserAAAMibThis module defines the objects pertaining to User authentication,
authorization and accounting MODULE-IDENTITY .1.3.6.1.4.1.2636.3.51.1 |
jnxUserAAANotifications OBJECT IDENTIFIER .1.3.6.1.4.1.2636.3.51.1.0 |
jnxAccessAuthServiceUpAn access authentication trap signifies that the
specified service has started. NOTIFICATION-TYPE .1.3.6.1.4.1.2636.3.51.1.0.1 |
jnxAccessAuthServiceDownAn access authentication trap signifies that the
specified service has been stopped. NOTIFICATION-TYPE .1.3.6.1.4.1.2636.3.51.1.0.2 |
jnxAccessAuthServerDisabledAn access authentication trap signifies that
the External authentication server is not responding. NOTIFICATION-TYPE .1.3.6.1.4.1.2636.3.51.1.0.3 |
jnxAccessAuthServerEnabledAn access authentication trap signifies that the
AAA client has changed the status of the External authentication server to UP. NOTIFICATION-TYPE .1.3.6.1.4.1.2636.3.51.1.0.4 |
jnxAccessAuthAddressPoolHighThresholdAn access authentication trap signifies that
the address pool has reached its high threshold. NOTIFICATION-TYPE .1.3.6.1.4.1.2636.3.51.1.0.5 |
jnxAccessAuthAddressPoolAbateThresholdAn access authentication trap signifies that
the address pool has reached its abate threshold NOTIFICATION-TYPE .1.3.6.1.4.1.2636.3.51.1.0.6 |
jnxAccessAuthAddressPoolOutOfAddressesAn access authentication trap signifies that
an Out Of Addresses event occured on the pool. NOTIFICATION-TYPE .1.3.6.1.4.1.2636.3.51.1.0.7 |
jnxAccessAuthAddressPoolOutOfMemoryAn access authentication trap signifies that
an Out Of Memory event occured on the pool. NOTIFICATION-TYPE .1.3.6.1.4.1.2636.3.51.1.0.8 |
jnxUserAAAObjects OBJECT IDENTIFIER .1.3.6.1.4.1.2636.3.51.1.1 |
jnxUserAAAGlobalStats OBJECT IDENTIFIER .1.3.6.1.4.1.2636.3.51.1.1.1 |
jnxTotalAuthenticationRequestsTotal authentication requests received.ro Counter64 .1.3.6.1.4.1.2636.3.51.1.1.1.1 |
jnxTotalAuthenticationResponsesTotal authentication responses.ro Counter64 .1.3.6.1.4.1.2636.3.51.1.1.1.2 |
jnxUserAAAAccessAuthStats OBJECT IDENTIFIER .1.3.6.1.4.1.2636.3.51.1.1.2 |
jnxUserAAAStatTableThis table exposes the user authentication statistics. SEQUENCE OF JnxAuthStatEntry .1.3.6.1.4.1.2636.3.51.1.1.2.1 |
jnxUserAAAStatEntryStatistic entry collects for authentication. JnxAuthStatEntry .1.3.6.1.4.1.2636.3.51.1.1.2.1.1 |
jnxUserAAAStatAuthTypeThe entry indicates the authentication type. It
uniquely identifies the statistics counters related to
its authentication. JnxAuthenticateType .1.3.6.1.4.1.2636.3.51.1.1.2.1.1.1 |
jnxUserAAAStatRequestReceivedThe number of request received.ro Counter64 .1.3.6.1.4.1.2636.3.51.1.1.2.1.1.2 |
jnxUserAAAStatAccessAcceptedThe number of access granted. It is an aggregated
statistics for this type of authenticaiton.ro Counter64 .1.3.6.1.4.1.2636.3.51.1.1.2.1.1.3 |
jnxUserAAAStatAccessRejectedThis number of access request rejected. It is an aggregated
statistics for this type of authentication.ro Counter64 .1.3.6.1.4.1.2636.3.51.1.1.2.1.1.4 |
jnxUserAAATrapVars OBJECT IDENTIFIER .1.3.6.1.4.1.2636.3.51.1.1.3 |
jnxUserAAAServerNameThe server name which identifies the authentication server.ro DisplayString (SNMPv2-TC) .1.3.6.1.4.1.2636.3.51.1.1.3.1 |
jnxUserAAAAddressPoolNameThe address pool name which identifies the local address pool.ro DisplayString (SNMPv2-TC) .1.3.6.1.4.1.2636.3.51.1.1.3.2 |
jnxUserAAAAccessPool OBJECT IDENTIFIER .1.3.6.1.4.1.2636.3.51.1.1.4 |
jnxUserAAAAccessPoolGeneral OBJECT IDENTIFIER .1.3.6.1.4.1.2636.3.51.1.1.4.1 |
jnxUserAAAAccessPoolTableThe entries in this table specify the address pools. SEQUENCE OF JnxUserAAAAccessPool .1.3.6.1.4.1.2636.3.51.1.1.4.1.1 |
jnxUserAAAAccessPoolEntryA read-only description of the local address pools. JnxUserAAAAccessPool .1.3.6.1.4.1.2636.3.51.1.1.4.1.1.1 |
jnxUserAAAAccessPoolIdentThe address identifier key. Unsigned32 .1.3.6.1.4.1.2636.3.51.1.1.4.1.1.1.1 |
jnxUserAAAAccessPoolRoutingInstanceThe routing instance of the address pool.ro DisplayString .1.3.6.1.4.1.2636.3.51.1.1.4.1.1.1.2 |
jnxUserAAAAccessPoolNameThe address pool name.ro DisplayString .1.3.6.1.4.1.2636.3.51.1.1.4.1.1.1.3 |
jnxUserAAAAccessPoolLinkNameThe address pool link name.ro DisplayString .1.3.6.1.4.1.2636.3.51.1.1.4.1.1.1.4 |
jnxUserAAAAccessPoolFamilyTypeThe family type of this pool.ro InetAddressType (INET-ADDRESS-MIB) .1.3.6.1.4.1.2636.3.51.1.1.4.1.1.1.5 |
jnxUserAAAAccessPoolInetNetworkThe Match criteria for this pool. Network or Prefixro InetAddress .1.3.6.1.4.1.2636.3.51.1.1.4.1.1.1.6 |
jnxUserAAAAccessPoolInetPrefixLengthThe Prefix Length for an IPv6 poolro InetAddressPrefixLength (INET-ADDRESS-MIB) .1.3.6.1.4.1.2636.3.51.1.1.4.1.1.1.7 |
jnxUserAAAAccessPoolOutOfMemoryThe Number of times this pool has flagged an Out of Memory condition.ro Counter64 .1.3.6.1.4.1.2636.3.51.1.1.4.1.1.1.8 |
jnxUserAAAAccessPoolOutOfAddressesThe Number of times this pool has flagged an Out of Address condition.ro Counter64 .1.3.6.1.4.1.2636.3.51.1.1.4.1.1.1.9 |
jnxUserAAAAccessPoolAddressTotalThe total number of Addresses or prefixes in this pool.ro CounterBasedGauge64 (HCNUM-TC) .1.3.6.1.4.1.2636.3.51.1.1.4.1.1.1.10 |
jnxUserAAAAccessPoolAddressesInUseThe total number of Addresses or prefixes given out from this pool.ro CounterBasedGauge64 (HCNUM-TC) .1.3.6.1.4.1.2636.3.51.1.1.4.1.1.1.11 |
jnxUserAAAAccessPoolAddressUsageThe percentage of addresses used in this pool or linked pool.
If this pool is the head of a linked chain of pools, this number
reflects the Usage for the whole chain. Conversely, if this pool
it part of a linked chain of pools but not the head of the chain,
the value will not be used.ro INTEGER .1.3.6.1.4.1.2636.3.51.1.1.4.1.1.1.12 |
jnxUserAAAAccessPoolAddressUsageHighThe configured high percentage threshold of addresses used in this
pool or linked pool. An SNMP trap is generated when this threshold
is exceeded. This trap will only be generated for unlinked pools or
pools that are the head of a linked chain of pools Conversely, if
this pool it part of a linked chain of pools but not the head of the
chain, then no traps will be generated.ro INTEGER .1.3.6.1.4.1.2636.3.51.1.1.4.1.1.1.13 |
jnxUserAAAAccessPoolAddressUsageAbateThe configured abate percentage threshold of addresses used in this
pool or linked pool. An SNMP trap clear is generated when address use
falls below this threshold percentage. This trap will only be generated
for unlinked pools or pools that are the head of a linked chain of
pools Conversely, if this pool it part of a linked chain of pools but
not the head of the chain, then no traps will be generated.ro INTEGER .1.3.6.1.4.1.2636.3.51.1.1.4.1.1.1.14 |
jnxUserAAAAssignment OBJECT IDENTIFIER .1.3.6.1.4.1.2636.3.51.1.1.5 |
jnxUserAAAGeneral OBJECT IDENTIFIER .1.3.6.1.4.1.2636.3.51.1.1.5.1 |
jnxUserAAADomainDelimitersThe list of delimiters used to separate the user's name from the
user's domain in the username field. The default is '@'.ro DisplayString .1.3.6.1.4.1.2636.3.51.1.1.5.1.1 |
jnxUserAAADomainParseDirectionThe direction in which the user's name is parsed: either search
for domain delimiter from left to right or right to left; first
delimiter marks boundry. The default is right to left.ro Enumeration .1.3.6.1.4.1.2636.3.51.1.1.5.1.2 |
jnxUserAAADomain OBJECT IDENTIFIER .1.3.6.1.4.1.2636.3.51.1.1.5.2 |
jnxUserAAADomainTableThe entries in this table specify the assignment of a remote access
user to a logical system, based on the user's domain. SEQUENCE OF JnxUserAAADomainEntry .1.3.6.1.4.1.2636.3.51.1.1.5.2.1 |
jnxUserAAADomainEntryA specification of the logical system to which users on a specified
domain should be assigned. JnxUserAAADomainEntry .1.3.6.1.4.1.2636.3.51.1.1.5.2.1.1 |
jnxUserAAADomainNameThe domain name uniquely identifying this entry. DisplayString .1.3.6.1.4.1.2636.3.51.1.1.5.2.1.1.1 |
jnxUserAAADomainStripDomainEnables/disables the domain name stripping feature, which causes
the system to strip the domain name before sending the
access-request to RADIUS for authentication.ro TruthValue (SNMPv2-TC) .1.3.6.1.4.1.2636.3.51.1.1.5.2.1.1.2 |
jnxUserAAADomainLogicalSystemThe name of the logical system, which will be used by the AAA
subsystem for this session. If not specified, will be mapped to
default.ro DisplayString (SNMPv2-TC) .1.3.6.1.4.1.2636.3.51.1.1.5.2.1.1.3 |
jnxUserAAADomainRoutingInstanceThe name of the routing instance, which will be used by the AAA
subsystem for this session. If not specified, will be mapped to
default.ro DisplayString (SNMPv2-TC) .1.3.6.1.4.1.2636.3.51.1.1.5.2.1.1.4 |
jnxUserAAADomainAddrPoolNameThe configured the address-pool-name for the domain name.ro DisplayString .1.3.6.1.4.1.2636.3.51.1.1.5.2.1.1.5 |
jnxUserAAADomainDynamicPorfileThe configured dynamic-profile which will be used for this session
upon succeeding validation.rodeprecated DisplayString (SNMPv2-TC) .1.3.6.1.4.1.2636.3.51.1.1.5.2.1.1.6 |
jnxUserAAADomainTargetLogicalSystemThe configured target logical-system that this session will need to
be mapped to. If not specified, will be mapped to default.ro DisplayString (SNMPv2-TC) .1.3.6.1.4.1.2636.3.51.1.1.5.2.1.1.7 |
jnxUserAAADomainTargetRoutingInstanceThe configured routing-instance that this session will need to be
mapped to.ro DisplayString (SNMPv2-TC) .1.3.6.1.4.1.2636.3.51.1.1.5.2.1.1.8 |
jnxUserAAADomainTunnelProfileThe associated tunnel profile.ro DisplayString (SNMPv2-TC) .1.3.6.1.4.1.2636.3.51.1.1.5.2.1.1.9 |
jnxUserAAADomainDynamicProfileThe configured dynamic-profile to be used for this session.ro DisplayString (SNMPv2-TC) .1.3.6.1.4.1.2636.3.51.1.1.5.2.1.1.10 |
jnxUserAAADomainStripUsernameDisplays the strip-username configuration.ro Enumeration .1.3.6.1.4.1.2636.3.51.1.1.5.2.1.1.11 |
jnxUserAAADomainOverridePasswordDisplays the override-password configuration.ro TruthValue (SNMPv2-TC) .1.3.6.1.4.1.2636.3.51.1.1.5.2.1.1.12 |
jnxUserAAADomainTunnelTableThe entries in this table specify the tunnels associated with a
domain. SEQUENCE OF JnxUserAAADomainTunnelEntry .1.3.6.1.4.1.2636.3.51.1.1.5.2.2 |
jnxUserAAADomainTunnelEntryA specification of the tunnels associated with a domain. JnxUserAAADomainTunnelEntry .1.3.6.1.4.1.2636.3.51.1.1.5.2.2.1 |
jnxUserAAADomainTunnelNameThe domain name associated with this entry. OCTET STRING .1.3.6.1.4.1.2636.3.51.1.1.5.2.2.1.1 |
jnxUserAAADomainTunnelDefIdThe tunnel definition id value associated with this entry. Integer32 .1.3.6.1.4.1.2636.3.51.1.1.5.2.2.1.2 |
jnxUserAAADomainTunnelPreferenceThe tunnel's preference value associated with this entry.ro Integer32 .1.3.6.1.4.1.2636.3.51.1.1.5.2.2.1.3 |
jnxUserAAADomainTunnelRemoteGwNameThis name specifies the hostname expected from the peer (the LNS)
when a tunnel is setup.ro DisplayString (SNMPv2-TC) .1.3.6.1.4.1.2636.3.51.1.1.5.2.2.1.4 |
jnxUserAAADomainTunnelRemoteGwAddressIP address of LNS tunnel endpointro IpAddress .1.3.6.1.4.1.2636.3.51.1.1.5.2.2.1.5 |
jnxUserAAADomainTunnelSourceGwNameThis name specifies the hostname expected from the peer (the LNS)
when a tunnel is setup.ro DisplayString (SNMPv2-TC) .1.3.6.1.4.1.2636.3.51.1.1.5.2.2.1.6 |
jnxUserAAADomainTunnelSourceGwAddressThe source address of the tunnel (overrides the default address for
this LS/RI.)ro IpAddress .1.3.6.1.4.1.2636.3.51.1.1.5.2.2.1.7 |
jnxUserAAADomainTunnelSecretThe tunnel password associated with this entry.ro DisplayString .1.3.6.1.4.1.2636.3.51.1.1.5.2.2.1.8 |
jnxUserAAADomainTunnelLogicalSystemsThe logical systems associated with this entty.ro DisplayString (SNMPv2-TC) .1.3.6.1.4.1.2636.3.51.1.1.5.2.2.1.9 |
jnxUserAAADomainTunnelRoutingInstanceThe routing instance associated with this entty.ro DisplayString (SNMPv2-TC) .1.3.6.1.4.1.2636.3.51.1.1.5.2.2.1.10 |
jnxUserAAADomainTunnelMediumThe tunnel medium associated with this entry. The medium dictates
the format of the tunnel address.ro Enumeration .1.3.6.1.4.1.2636.3.51.1.1.5.2.2.1.11 |
jnxUserAAADomainTunnelTypeThe tunnel type associated with this entry.ro Enumeration .1.3.6.1.4.1.2636.3.51.1.1.5.2.2.1.12 |
jnxUserAAADomainTunnelIdThe tunnel identifier associated with this entry.ro DisplayString .1.3.6.1.4.1.2636.3.51.1.1.5.2.2.1.13 |
jnxUserAAADomainTunnelMaxSessionsThe maximum number of tunnel sessions allowed in this tunnel
entry.ro Unsigned32 .1.3.6.1.4.1.2636.3.51.1.1.5.2.2.1.14 |
jnxUserAAADomainPadnTableThe entries in this table specify the PPPoE active discovery
network (PADN) parameters associated with a domain. SEQUENCE OF JnxUserAAADomainPadnEntry .1.3.6.1.4.1.2636.3.51.1.1.5.2.3 |
jnxUserAAADomainPadnEntryA specification of the PPPoE active discovery network parameters
associated with a domain. JnxUserAAADomainPadnEntry .1.3.6.1.4.1.2636.3.51.1.1.5.2.3.1 |
jnxUserAAADomainPadnIpAddressThe IP address of this entry. IpAddress .1.3.6.1.4.1.2636.3.51.1.1.5.2.3.1.1 |
jnxUserAAADomainPadnIpMaskThe IP mask of this entry. IpAddress .1.3.6.1.4.1.2636.3.51.1.1.5.2.3.1.2 |
jnxUserAAADomainPadnDistanceThe administrative distance metric of this entry.ro Integer32 .1.3.6.1.4.1.2636.3.51.1.1.5.2.3.1.3 |
jnxUserAAAAccessProfile OBJECT IDENTIFIER .1.3.6.1.4.1.2636.3.51.1.1.6 |
jnxUserAAAAccessProfileGeneral OBJECT IDENTIFIER .1.3.6.1.4.1.2636.3.51.1.1.6.1 |
jnxUserAAAAccessProfileTableThe entries in this table specify the assignment of authentication
methods for a particular subscriber type. SEQUENCE OF JnxUserAAAAccessProfileEntry .1.3.6.1.4.1.2636.3.51.1.1.6.1.1 |
jnxUserAAAAccessProfileEntryA specification of the authentication methods for a particular
subscriber type. JnxUserAAAAccessProfileEntry .1.3.6.1.4.1.2636.3.51.1.1.6.1.1.1 |
jnxUserAAAAccessProfileNameThe access profile name. DisplayString .1.3.6.1.4.1.2636.3.51.1.1.6.1.1.1.1 |
jnxUserAAAAccessProfileAuthenticationOrderThe set of authentication mechanisms configured on this system. Each
octet in this object contains one of the values defined in the
JnxAuthenticateType TEXTUAL-CONVENTION.
The system will sequence through each octet of this object starting at
octet 1 and attempt to use the corresponding authentication protocol
defined by JnxAuthenticateType.
If an authentication protocol is configured and attempts to reach the
authentication server fail, the system will move to the next octet in
this object and retry the authentication in the form dictated by the
corresponding authentication protocoltype. The process of sequencing
thru each octet will stop if the authentication server is successfully
contacted, or there are no more configured octets in this object.ro OCTET STRING .1.3.6.1.4.1.2636.3.51.1.1.6.1.1.1.2 |
jnxUserAAAAccessProfileAccountingOrderThe set of accounting mechanisms configured on this system. Each
octet in this object contains one of the values defined in the
JnxAccountingType TEXTUAL-CONVENTION.
The system will sequence through each octet of this object starting at
octet 1 and attempt to use the corresponding accounting protocol
defined by JnxAccountingType.
If an accounting protocol is configured and attempts to reach the
accounting server fail, the system will move to the next octet in
this object and retry the accounting in the form dictated by the
corresponding accounting protocoltype. The process of sequencing
thru each octet will stop if the accounting server is successfully
contacted, or there are no more configured octets in this object.ro OCTET STRING .1.3.6.1.4.1.2636.3.51.1.1.6.1.1.1.3 |
jnxUserAAAAccessProfileAuthorizationOrderThe set of accounting mechanisms configured on this system. Each
octet in this object contains one of the values defined in the
JnxAuthorizationType TEXTUAL-CONVENTION.
The system will sequence through each octet of this object starting at
octet 1 and attempt to use the corresponding accounting protocol
defined by JnxAuthorizationType.
If an accounting protocol is configured and attempts to reach the
accounting server fail, the system will move to the next octet in
this object and retry the accounting in the form dictated by the
corresponding accounting protocoltype. The process of sequencing
thru each octet will stop if the accounting server is successfully
contacted, or there are no more configured octets in this object.ro OCTET STRING .1.3.6.1.4.1.2636.3.51.1.1.6.1.1.1.4 |
jnxUserAAAAccessProfileProvisioningOrderThe set of provisioning mechanisms configured on this system. Each
octet in this object contains one of the values defined in the
JnxProvisioningType TEXTUAL-CONVENTION.
The system will sequence through each octet of this object starting at
octet 1 and attempt to use the corresponding accounting protocol
defined by JnxProvisioningType.
If an accounting protocol is configured and attempts to reach the
accounting server fail, the system will move to the next octet in
this object and retry the accounting in the form dictated by the
corresponding accounting protocoltype. The process of sequencing
thru each octet will stop if the accounting server is successfully
contacted, or there are no more configured octets in this object.ro OCTET STRING .1.3.6.1.4.1.2636.3.51.1.1.6.1.1.1.5 |
jnxUserAAAAccessProfileAccStopOnFailureEnables/disables the Acct-Stop message if a user fails
authentication, but AAA-server grants access.ro TruthValue (SNMPv2-TC) .1.3.6.1.4.1.2636.3.51.1.1.6.1.1.1.6 |
jnxUserAAAAccessProfileAccStopOnDenyEnables/disables the Acct-Stop message if AAA-server denies
access.ro TruthValue (SNMPv2-TC) .1.3.6.1.4.1.2636.3.51.1.1.6.1.1.1.7 |
jnxUserAAAAccessProfileImmediateUpdateEnables/disables the Acct-Update message on receipt of a
Acct-response for the Acct-Start message.ro TruthValue (SNMPv2-TC) .1.3.6.1.4.1.2636.3.51.1.1.6.1.1.1.8 |
jnxUserAAAAccessProfileCoaImmediateUpdateEnables/disables the Acct-Update message on completion of
processing a change of authorization.ro TruthValue (SNMPv2-TC) .1.3.6.1.4.1.2636.3.51.1.1.6.1.1.1.9 |
jnxUserAAAAccessProfileIntervalThe interval in minutes between accounting updates(Interim-stats
off, if not specified).ro Integer32 UNITS "minutes" .1.3.6.1.4.1.2636.3.51.1.1.6.1.1.1.10 |
jnxUserAAAAccessProfileStatTypeThe type of statistics are collected. These are the configured
types:
time - the option to report only uptime
volume-time - the option to report both volume and uptimero Enumeration .1.3.6.1.4.1.2636.3.51.1.1.6.1.1.1.11 |