LINKSYS-BRIDGE-SECURITY
AI MIB Summary
The LINKSYS-BRIDGE-SECURITY MIB module provides management access to Linksys bridge security features, specifically monitoring and configuring DHCP Snooping, Dynamic ARP Inspection, and IP Source Guard policies. This module exposes counters and status indicators for these Layer 2 security mechanisms to validate traffic filtering rules and detect spoofing attempts on the network segment.
The private MIB module definition for DHCP Snoop, ARP Inspection and Ip source Guard features.
Main OID:
rlBridgeSecurity.1.3.6.1.4.1.89.112
84
Objects
Active
Status
5
Dependencies
Imported Objects
Objects
84 total| Object Name |
|---|
rlBridgeSecurityThe private MIB module definition for DHCP Snoop, ARP Inspection
and Ip source Guard features. MODULE-IDENTITY .1.3.6.1.4.1.89.112 |
rlIpDhcpSnoop OBJECT IDENTIFIER .1.3.6.1.4.1.89.112.1 |
rlIpDhcpSnoopMibVersionMIB's version, the current version is 1.ro INTEGER .1.3.6.1.4.1.89.112.1.1 |
rlIpDhcpSnoopEnableSpecifies a system DHCP Snoop enable state.rw Enumeration .1.3.6.1.4.1.89.112.1.2 |
rlIpDhcpSnoopFileEnableSpecifies a system DHCP Snoop file enable state.rw Enumeration .1.3.6.1.4.1.89.112.1.3 |
rlIpDhcpSnoopClearActionUsed to clear DHCP Snoop Table.rw Enumeration .1.3.6.1.4.1.89.112.1.4 |
rlIpDhcpSnoopFileUpdateTimeConfigures in seconds the period of time between file updates.
The valid range is 600 - 86400.rw INTEGER .1.3.6.1.4.1.89.112.1.5 |
rlIpDhcpSnoopVerifyMacAddressConfigures on an un-trusted port whether the source MAC address in a DHCP packet matches
the client hardware address.rw Enumeration .1.3.6.1.4.1.89.112.1.6 |
rlIpDhcpSnoopCurrentEntiresNumberContain the current number of DHCP snooping entries for all types.ro INTEGER .1.3.6.1.4.1.89.112.1.7 |
rlIpDhcpOpt82InsertionEnableSpecifies a DHCP option 82 insertion enable state.rw Enumeration .1.3.6.1.4.1.89.112.1.8 |
rlIpDhcpOpt82RxOnUntrustedEnableSpecifies a DHCP option 82 receive on untrusted port enable state.rw Enumeration .1.3.6.1.4.1.89.112.1.9 |
rlIpDhcpSnoopStaticTableThe table specifies all DHCP Snoop Static (configured by user) entries.
The entry contains a local IP address of the DHCP client, a Port interface to which a DHCP client is connected to the switch. SEQUENCE OF RlIpDhcpSnoopStaticEntry .1.3.6.1.4.1.89.112.1.10 |
rlIpDhcpSnoopStaticEntryThe row definition for this table. RlIpDhcpSnoopStaticEntry .1.3.6.1.4.1.89.112.1.10.1 |
rlIpDhcpSnoopStaticVLANTagA DHCP Snoop Static entry vlan tag. VlanId (Q-BRIDGE-MIB) .1.3.6.1.4.1.89.112.1.10.1.1 |
rlIpDhcpSnoopStaticMACAddressA DHCP Snoop Static entry mac address MacAddress (SNMPv2-TC) .1.3.6.1.4.1.89.112.1.10.1.2 |
rlIpDhcpSnoopStaticIPAddressA DHCP Snoop Static entry IP address.rw IpAddress .1.3.6.1.4.1.89.112.1.10.1.3 |
rlIpDhcpSnoopStaticPortInterfaceA DHCP Snoop Static entry Port interface.rw InterfaceIndex (IF-MIB) .1.3.6.1.4.1.89.112.1.10.1.4 |
rlIpDhcpSnoopStaticRowStatusA status can be destroy, active or createAndGorw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.89.112.1.10.1.5 |
rlIpDhcpSnoopTableDHCP Snoop entry. Use to add/delete a dynamic entries and to view all entries (dynamic and static) SEQUENCE OF RlIpDhcpSnoopEntry .1.3.6.1.4.1.89.112.1.11 |
rlIpDhcpSnoopEntryThe row definition for this table. RlIpDhcpSnoopEntry .1.3.6.1.4.1.89.112.1.11.1 |
rlIpDhcpSnoopVLANTagA DHCP Snoop entry vlan tag. VlanId (Q-BRIDGE-MIB) .1.3.6.1.4.1.89.112.1.11.1.1 |
rlIpDhcpSnoopMACAddressA DHCP Snoop entry mac address MacAddress (SNMPv2-TC) .1.3.6.1.4.1.89.112.1.11.1.2 |
rlIpDhcpSnoopTypeA DHCP Snoop entry type: static or dynamic.rw RlIpDhcpSnoopType .1.3.6.1.4.1.89.112.1.11.1.3 |
rlIpDhcpSnoopLeaseTimeA DHCP Snoop lease time. For static entry the lease time is 0xFFFFFFFFrw Unsigned32 .1.3.6.1.4.1.89.112.1.11.1.4 |
rlIpDhcpSnoopIPAddressThe IP address of the DHCP client referred to in this table entry.rw IpAddress .1.3.6.1.4.1.89.112.1.11.1.5 |
rlIpDhcpSnoopPortInterfaceIdentifies the port Interface ifindex, which connected to DHCP client identified with the entry.rw InterfaceIndex (IF-MIB) .1.3.6.1.4.1.89.112.1.11.1.6 |
rlIpDhcpSnoopRowStatusEntry status. A valid status is CreateandGo or Delete.rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.89.112.1.11.1.7 |
rlIpDhcpSnoopEnableVlanTableAn Ip Dhcp Snooping enabled VLAN table. SEQUENCE OF RlIpDhcpSnoopEnableVlanEntry .1.3.6.1.4.1.89.112.1.12 |
rlIpDhcpSnoopEnableVlanEntryAn Ip Dhcp Snooping enabled VLAN entry. RlIpDhcpSnoopEnableVlanEntry .1.3.6.1.4.1.89.112.1.12.1 |
rlIpDhcpSnoopEnableVlanTagA DHCP Snoop entry vlan tag. VlanId (Q-BRIDGE-MIB) .1.3.6.1.4.1.89.112.1.12.1.1 |
rlIpDhcpSnoopEnableVlanRowStatusEntry status. A valid status is CreateandGo and Delete.rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.89.112.1.12.1.2 |
rlIpDhcpSnoopTrustedPortTableDHCP Snoop Trusted ports entry. The entry created when port is configured as trusted. SEQUENCE OF RlIpDhcpSnoopTrustedPortEntry .1.3.6.1.4.1.89.112.1.13 |
rlIpDhcpSnoopTrustedPortEntryThe row definition for this table. RlIpDhcpSnoopTrustedPortEntry .1.3.6.1.4.1.89.112.1.13.1 |
rlIpDhcpSnoopTrustedPortRowStatusEntry status. A valid status is CreateandGo or Delete.rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.89.112.1.13.1.2 |
rlIpSourceGuard OBJECT IDENTIFIER .1.3.6.1.4.1.89.112.2 |
rlIpSourceGuardMibVersionMIB's version, the current version is 1.ro INTEGER .1.3.6.1.4.1.89.112.2.1 |
rlIpSourceGuardEnableFALSE - There is no Ip Source Guard in the system.
TRUE - Ip Source Guard is enabled on system.rw Enumeration .1.3.6.1.4.1.89.112.2.2 |
rlIpSourceGuardRetryToInsertWhen setted to retryToInsertNow all IP Source Guard inactive entries
due to resource problem reinserted in the Policy.
On get always return noAction.rw Enumeration .1.3.6.1.4.1.89.112.2.3 |
rlIpSourceGuardRetryTimeConfigures in seconds the period of time the application retries to
insert inactive by resource problem rules. The actual range is 10-600.
0 used to sign that the timer is not active.rw INTEGER .1.3.6.1.4.1.89.112.2.4 |
rlIpSourceGuardPortTableIP Source Guard ports entry. The entry created when IP Source Guard
enabled on port. SEQUENCE OF RlIpSourceGuardPortEntry .1.3.6.1.4.1.89.112.2.5 |
rlIpSourceGuardPortEntryThe row definition for this table. RlIpSourceGuardPortEntry .1.3.6.1.4.1.89.112.2.5.1 |
rlIpSourceGuardPortRowStatusEntry status. A valid status is CreateAndGo or Delete.rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.89.112.2.5.1.2 |
rlIpSourceGuardTableIP Source Guard entry. Use to view all entries (dynamic and static) SEQUENCE OF RlIpSourceGuardEntry .1.3.6.1.4.1.89.112.2.6 |
rlIpSourceGuardEntryThe row definition for this table. RlIpSourceGuardEntry .1.3.6.1.4.1.89.112.2.6.1 |
rlIpSourceGuardIPAddressThe IP address of the Ip Source Guard entry. IpAddress .1.3.6.1.4.1.89.112.2.6.1.1 |
rlIpSourceGuardVLANTagA Ip Source Guard entry vlan tag. VlanId (Q-BRIDGE-MIB) .1.3.6.1.4.1.89.112.2.6.1.2 |
rlIpSourceGuardMACAddressA Ip Source Guard entry mac addressro MacAddress (SNMPv2-TC) .1.3.6.1.4.1.89.112.2.6.1.3 |
rlIpSourceGuardTypeA Ip Source Guard entry type: static or dynamic.ro RlIpSourceGuardType .1.3.6.1.4.1.89.112.2.6.1.4 |
rlIpSourceGuardStatusIdentifies the status of Ip Source Guard entry.ro RlIpSourceGuardStatus .1.3.6.1.4.1.89.112.2.6.1.5 |
rlIpSourceGuardFailReasonIdentifies the reason for in-activity of Ip Source Guard entry.ro RlIpSourceGuardFailReason .1.3.6.1.4.1.89.112.2.6.1.6 |
rlIpSourceGuardPermittedRuleCounterTableThe table includes, per vlan, the IP Source Guard permitted rules counters. SEQUENCE OF RlIpSourceGuardPermittedRuleCounterEntry .1.3.6.1.4.1.89.112.2.7 |
rlIpSourceGuardPermittedRuleCounterEntryThe row definition for this table. RlIpSourceGuardPermittedRuleCounterEntry .1.3.6.1.4.1.89.112.2.7.1 |
rlIpSourceGuardPermittedRuleCounterVLANTagIp Source Guard permitted rules counters entry Vlan tag. VlanId (Q-BRIDGE-MIB) .1.3.6.1.4.1.89.112.2.7.1.1 |
rlIpSourceGuardPermittedRuleCounterNumOfStaticRulesNumber of static rules added by IP Source Guard for the permitted Hostsro Counter32 .1.3.6.1.4.1.89.112.2.7.1.2 |
rlIpSourceGuardPermittedRuleCounterNumOfDhcpRulesNumber of rules added by IP Source Guard for the permitted Hosts,
as a result of DHCP Snooping dynamic information.ro Counter32 .1.3.6.1.4.1.89.112.2.7.1.3 |
rlIpArpInspect OBJECT IDENTIFIER .1.3.6.1.4.1.89.112.3 |
rlIpArpInspectMibVersionMIB's version, the current version is 1.ro INTEGER .1.3.6.1.4.1.89.112.3.1 |
rlIpArpInspectEnableSpecifies a system ARP Inspection enable state.rw Enumeration .1.3.6.1.4.1.89.112.3.2 |
rlIpArpInspectLogIntervalSpecify the minimal interval between successive ARP SYSLOG messages.
0 - message is immediately generated.
0xFFFFFFFF - messages would not be generated. A legal range is 0-86400.rw Unsigned32 .1.3.6.1.4.1.89.112.3.3 |
rlIpArpInspectValidationDefined a specific check on incoming ARP packets:
Source MAC: Compare the source MAC address in the Ethernet header against
the sender MAC address in the ARP body. This check is performed on both ARP requests and responses.
Destination MAC: Compare the destination MAC address in the Ethernet header against
the target MAC address in ARP body. This check is performed for ARP responses.
IP addresses: Compare the ARP body for invalid and unexpected IP addresses.
Addresses include 0.0.0.0, 255.255.255.255, and all IP multicast addresses.rw Enumeration .1.3.6.1.4.1.89.112.3.4 |
rlIpArpInspectListTableThe table specifies all ARP Inspection List entries.
The entry contains a list name, list IP address, a list Mac address. SEQUENCE OF RlIpArpInspectListEntry .1.3.6.1.4.1.89.112.3.5 |
rlIpArpInspectListEntryThe row definition for this table. RlIpArpInspectListEntry .1.3.6.1.4.1.89.112.3.5.1 |
rlIpArpInspectListNameThe Name of the Access List. RlIpArpInspectListNameType .1.3.6.1.4.1.89.112.3.5.1.1 |
rlIpArpInspectListIPAddressARP Inspection List IP address. IpAddress .1.3.6.1.4.1.89.112.3.5.1.2 |
rlIpArpInspectListMACAddressARP Inspection List mac addressrw MacAddress (SNMPv2-TC) .1.3.6.1.4.1.89.112.3.5.1.3 |
rlIpArpInspectListRowStatusA status can be destroy, active or createAndGorw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.89.112.3.5.1.4 |
rlIpArpInspectEnableVlanTableAn Ip ARP Inspection enabled VLAN table. SEQUENCE OF RlIpArpInspectEnableVlanEntry .1.3.6.1.4.1.89.112.3.6 |
rlIpArpInspectEnableVlanEntryAn Ip ARP Inspection enabled VLAN entry. RlIpArpInspectEnableVlanEntry .1.3.6.1.4.1.89.112.3.6.1 |
rlIpArpInspectEnableVlanTagAn Ip ARP Inspection entry vlan tag. VlanId (Q-BRIDGE-MIB) .1.3.6.1.4.1.89.112.3.6.1.1 |
rlIpArpInspectAssignedListNameAn Ip ARP Inspection assigned ACL name.rw RlIpArpInspectListNameType .1.3.6.1.4.1.89.112.3.6.1.2 |
rlIpArpInspectEnableVlanRowStatusEntry status. A valid status is CreateandGo and Delete.rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.89.112.3.6.1.3 |
rlIpArpInspectVlanNumOfArpForwardedTotal number of forwarded ARP packets, packets which were validated by ARP inspectionro Counter32 .1.3.6.1.4.1.89.112.3.6.1.4 |
rlIpArpInspectVlanNumOfArpDroppedNumber of dropped ARP packets, which were validated by ARP inspection
(mismatch , not-found and dropped for any reason)ro Counter32 .1.3.6.1.4.1.89.112.3.6.1.5 |
rlIpArpInspectVlanNumOfArpMismatchedNumber of dropped ARP packets, which were validated by ARP inspection
and inconsistency was found for IP and MAC (mismatch)ro Counter32 .1.3.6.1.4.1.89.112.3.6.1.6 |
rlIpArpInspectVlanClearCountersActionIf true, clear (set to zero) all Arp Inspection counters: rlIpArpInspectVlanNumOfArpForwarded ,
rlIpArpInspectVlanNumOfArpDropped and rlIpArpInspectVlanNumOfArpMismatchedrw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.89.112.3.6.1.7 |
rlIpArpInspectTrustedPortTableARP Inspection Trusted ports entry. The entry created when port is configured as trusted. SEQUENCE OF RlIpArpInspectTrustedPortEntry .1.3.6.1.4.1.89.112.3.7 |
rlIpArpInspectTrustedPortEntryThe row definition for this table. RlIpArpInspectTrustedPortEntry .1.3.6.1.4.1.89.112.3.7.1 |
rlIpArpInspectTrustedPortRowStatusEntry status. A valid status is CreateandGo or Delete.rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.89.112.3.7.1.2 |
rlIpArpInspectClearCountersActionIf true, clear (set to zero) on all vlans: all Arp Inspection counters: rlIpArpInspectVlanNumOfArpForwarded ,
rlIpArpInspectVlanNumOfArpDropped and rlIpArpInspectVlanNumOfArpMismatchedrw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.89.112.3.8 |
rlProtocolFiltering OBJECT IDENTIFIER .1.3.6.1.4.1.89.112.4 |
rlProtocolFilteringTableProtocol filter configuration entry SEQUENCE OF RlProtocolFilteringEntry .1.3.6.1.4.1.89.112.4.1 |
rlProtocolFilteringEntryThe row definition for this table. RlProtocolFilteringEntry .1.3.6.1.4.1.89.112.4.1.1 |
rlProtocolFilteringListThe list of protocol to be filtered.rw ProtocolFilteringMap .1.3.6.1.4.1.89.112.4.1.1.1 |
rlProtocolFilteringRowStatusA status can be destroy, active or createAndGorw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.89.112.4.1.1.2 |