LUM-SYSTEM-MIB
AI MIB Summary
The LUM-SYSTEM-MIB module provides granular monitoring and configuration of system node parameters, date/time synchronization, license status, and authentication settings (RADIUS/TACACS+) for Lumex or LUM-series network appliances. It exposes specific metrics for user account management, authentication server configurations, and system licensing data to facilitate centralized identity and access control auditing.
The system MIB.
- General
- Node parameters
- Date and time
- License information
- RADIUS and TACACS+ authentication configuration
- User information
Main OID:
lumSystemMIBModule.1.3.6.1.4.1.8708.1.1.4
132
Objects
Active
Status
5
Dependencies
Imported Objects
Objects
132 total| Object Name |
|---|
lumSystemConfs OBJECT IDENTIFIER .1.3.6.1.4.1.4614.1.4.1 |
lumSystemGroups OBJECT IDENTIFIER .1.3.6.1.4.1.4614.1.4.1.1 |
lumSystemCompl OBJECT IDENTIFIER .1.3.6.1.4.1.4614.1.4.1.2 |
lumSystemMinimalGroups OBJECT IDENTIFIER .1.3.6.1.4.1.4614.1.4.1.3 |
lumSystemMinimalCompl OBJECT IDENTIFIER .1.3.6.1.4.1.4614.1.4.1.4 |
lumSystemMIBObjects OBJECT IDENTIFIER .1.3.6.1.4.1.4614.1.4.2 |
sysGeneral OBJECT IDENTIFIER .1.3.6.1.4.1.4614.1.4.2.1 |
sysGeneralTestAndIncrProtection against simultaneous access from
multiple managers. See SNMPv2-TC.rw TestAndIncr (SNMPv2-TC) .1.3.6.1.4.1.4614.1.4.2.1.1 |
sysGeneralMibSpecVersionThe MIB specification version.rw DisplayString (SNMPv2-TC) .1.3.6.1.4.1.4614.1.4.2.1.2 |
sysGeneralMibImplVersionThe MIB implementation version.rw DisplayString (SNMPv2-TC) .1.3.6.1.4.1.4614.1.4.2.1.3 |
sysGeneralLastChangeTimeThe time the state of MIB last changed.ro DateAndTime (SNMPv2-TC) .1.3.6.1.4.1.4614.1.4.2.1.4 |
sysGeneralTestObject that can be used to verify write access
(via SNMP).
This attribute can be written via SNMP.rwdeprecated Integer32 .1.3.6.1.4.1.4614.1.4.2.1.5 |
sysGeneralConfigLastChangeTimeThe time the configuration of the MIB last
changed.ro DateAndTime (SNMPv2-TC) .1.3.6.1.4.1.4614.1.4.2.1.6 |
sysGeneralLoginRecordsEnable/disable login records.
The log can be viewed with the 'last'
command.
off - Login records log disabled.
on - Login records log enable.rw Enumeration .1.3.6.1.4.1.4614.1.4.2.1.7 |
sysGeneralUserTableSizeNumber of rows available in the
user table.ro Unsigned32 .1.3.6.1.4.1.4614.1.4.2.1.8 |
sysGeneralWriteTestObject that can be used to verify write access
(via SNMP).
This attribute can be written via SNMP.rw DisplayString (SNMPv2-TC) .1.3.6.1.4.1.4614.1.4.2.1.9 |
sysNode OBJECT IDENTIFIER .1.3.6.1.4.1.4614.1.4.2.2 |
sysNodeNameAn administratively-assigned name for this
managed node. By convention, this is the nodes
fully-qualified domain name.
The node name may be composed of the following
characters:
A to Z ; uppercase characters
a to z ; lower case characters
0 to 9 ; numeric characters
- ; dash
. ; dot, is used as a separator
_ ; underscore, supported (but might not be supported by all DNS servers)
A host name (label) can start or end with a letter or a number
A host name (label) MUST NOT start or end with a '-' (dash)
A host name (label) MUST NOT consist of all numeric values
A host name (label) can be up to 63 charactersrw DisplayString .1.3.6.1.4.1.4614.1.4.2.2.1 |
sysNodeContactThe textual identification of the contact person
for this managed node, together with information
on how to contact this person. Set to the empty
string if not known.
Example: 'Joe, e-mail: joe@localhost.localdomain'rw DisplayString .1.3.6.1.4.1.4614.1.4.2.2.2 |
sysNodeLocationThe physical location of this node. Set to the
empty string if not known.
Example: 'Rack 5, in the system lab, third floor'rw DisplayString .1.3.6.1.4.1.4614.1.4.2.2.3 |
sysNodeObjectIdThe vendors authoritative identification of the
network management subsystem contained in the
entity. This value is allocated within the SMI
enterprises subtree (1.3.6.1.4.1) and provides an
easy and unambiguous means for determining
'what kind of box' is being managed.ro OBJECT IDENTIFIER .1.3.6.1.4.1.4614.1.4.2.2.4 |
sysNodePrimaryNameServerThe name or IP address of the name server.
Set to the empty string if not known.
Example: 'dns.localdomain'rw DisplayString .1.3.6.1.4.1.4614.1.4.2.2.5 |
sysNodeRunLevelNote: This attribute is deprecated!
Indicates the runlevel of the software.
halt - Shutdown the entire node.
single - Stop all applications and enter
single user mode.
normal - Normal operations.
reboot - Restart the entire node.
tbd: no network?
tbd: restart with default configurationrwdeprecated Enumeration .1.3.6.1.4.1.4614.1.4.2.2.6 |
sysNodeSecondaryNameServerThe name or IP address of the name server.
Set to the empty string if not known.
Example: 'dns.lumentis.se', '192.168.1.200'rw DisplayString .1.3.6.1.4.1.4614.1.4.2.2.7 |
sysNodeUptimeThe uptime in string format.ro DisplayString .1.3.6.1.4.1.4614.1.4.2.2.8 |
sysNodeNeTypeUser configurable identifier of the type of node.
Included in performance measurements reports.rw DisplayString .1.3.6.1.4.1.4614.1.4.2.2.9 |
sysNodeNeUserNameUser configurable network element name.
Included in performance measurements reports.rw DisplayString .1.3.6.1.4.1.4614.1.4.2.2.10 |
sysNodeNeDistinguishedNameUser configurable network element distinguished
name. Included in performance measurements
reports.rw DisplayString .1.3.6.1.4.1.4614.1.4.2.2.11 |
sysNodeBootTimeApplication start time.ro DateAndTime (SNMPv2-TC) .1.3.6.1.4.1.4614.1.4.2.2.12 |
sysNodeLocaleDetermines what rules should be used when formatting
and display items that are affected by language and
locality.
The following is currently affected:
Date and time
Decimal character
Unit used for temperatures
If locale is set to US English temperatures are
converted to degrees Fahrenheit.
Note: Only the default locale, 'C', is supported at
the moment.rw DisplayString .1.3.6.1.4.1.4614.1.4.2.2.13 |
sysNodeVersionThe build version.ro DisplayString .1.3.6.1.4.1.4614.1.4.2.2.14 |
sysNodeCLLICommon Language Location Identifier of NE.
Specifies the location
and function of telecommunications equipment or
of a relevant location such as international
border or the location of a supporting equipment,
such as a pole or a manhole.rw DisplayString .1.3.6.1.4.1.4614.1.4.2.2.15 |
sysNodeFICFrame Identifier Code or
Facility Interface Code for NE.
FIC identifies the type of interface that
the terminal equipment requires for compatible
interconnection with wireline carrier facilities.rw DisplayString .1.3.6.1.4.1.4614.1.4.2.2.16 |
sysNodeTIDTarget ID of NE. A unique
identifier which is a combination of the
CLLI and FIC (Location+Frame).ro DisplayString .1.3.6.1.4.1.4614.1.4.2.2.17 |
sysNodeLatitudeLatitude of the NE. A geographic coordinate
ranging from -90 to +90 degree specifying
the north-south position of a node
on the Earth surface.
Decimal Degree Representation is used as
the latitude format.rw DisplayString .1.3.6.1.4.1.4614.1.4.2.2.18 |
sysNodeLongitudeLongitude of the NE. A geographic
coordinate ranging from -180 to +180
degree specifying the east-west position
of the node on the Earth surface.
Decimal Degree Representation is used
as the longitude format.rw DisplayString .1.3.6.1.4.1.4614.1.4.2.2.19 |
sysHostList OBJECT IDENTIFIER .1.3.6.1.4.1.4614.1.4.2.3 |
sysHostTableThe well known host names list. SEQUENCE OF SysHostEntry .1.3.6.1.4.1.4614.1.4.2.3.1 |
sysHostEntryAn entry in well known host names list. SysHostEntry .1.3.6.1.4.1.4614.1.4.2.3.1.1 |
sysHostIndexAn arbitrary index assigned to each host
entry.ro Unsigned32 .1.3.6.1.4.1.4614.1.4.2.3.1.1.1 |
sysHostIpAddressThe IP address of a well known host.
Example: '192.168.1.200'rw DisplayString .1.3.6.1.4.1.4614.1.4.2.3.1.1.2 |
sysHostNamesThe name(s) of a well known host. Set to the
empty string if not known.
Example: 'dns.lumentis.se dns'rw DisplayString .1.3.6.1.4.1.4614.1.4.2.3.1.1.3 |
sysHostRowStatusManages creation and deletion of conceptual rows.
See also SNMPv2-TC.rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.4614.1.4.2.3.1.1.4 |
sysTime OBJECT IDENTIFIER .1.3.6.1.4.1.4614.1.4.2.4 |
sysTimeLocalThe local date and time.ro DateAndTime (SNMPv2-TC) .1.3.6.1.4.1.4614.1.4.2.4.1 |
sysTimeZoneThe name of the time zone in which node
is located.
A few examples:
'CET'
'EET'
'Europe/Stockholm'
'Europe/London'
'Europe/Copenhagen'
'Europe/Berlin'
'America/Chicago'
'America/Kentucky/Louisville'
'Asia/Tokyo'
Note: The notation used for naming the
timezones where the offset to Coordinated
Universal Time (UTC) is explicitly included,
i.e. 'GMT-2', may be confusing.
The offset indicates the time value
to be added to the local time to get UTC.
This means that the the offset is positive
for timezones west of UTC and and negative
east of UTC. This is the opposite of how
timezones are often described.
For example standard time in Sweden is
'GMT-1'. On timezone maps zones east of
UTC are often given a positive offset
so that the very same zone is called 'GMT+1'.
This attribute can be written via SNMP.rw DisplayString .1.3.6.1.4.1.4614.1.4.2.4.2 |
sysTimePrimaryServerThe IP address of the primary SNTP/NTP server.
Set to the 0.0.0.0 or empty string if not used.
Example: '192.36.143.150' (time1.stupi.se)rwdeprecated DisplayString .1.3.6.1.4.1.4614.1.4.2.4.3 |
sysTimeSecondaryServerThe IP address of the secondary SNTP/NTP server.
Set to the 0.0.0.0 or empty string if not used.
Example: '192.36.143.151' (time2.stupi.se)rwdeprecated DisplayString .1.3.6.1.4.1.4614.1.4.2.4.4 |
sysTimeChangeLocalTimeChange the local date and time.
Year - If no century is input the
current century is set by default.
Month - 1 to 12
Day - 1 to 31
Hour - 0 to 23
Minute - 0 to 59
Second - 0 to 59
Note: Setting of the local time is disabled if
either the primary or secondary time server
is set.rw CommandString .1.3.6.1.4.1.4614.1.4.2.4.5 |
sysTimePrimaryIpAddressThe IP address of the primary SNTP/NTP server.
Set to 0.0.0.0 if not used.
Example: '192.36.143.150' (time1.stupi.se)
This attribute can be written via SNMP.rw IpAddress .1.3.6.1.4.1.4614.1.4.2.4.6 |
sysTimeSecondaryIpAddressThe IP address of the primary SNTP/NTP server.
Set to 0.0.0.0 if not used.
Example: '192.36.143.150' (time1.stupi.se)
This attribute can be written via SNMP.rw IpAddress .1.3.6.1.4.1.4614.1.4.2.4.7 |
sysLogList OBJECT IDENTIFIER .1.3.6.1.4.1.4614.1.4.2.5 |
sysLogTableThe syslog configuration directives list.deprecated SEQUENCE OF SysLogEntry .1.3.6.1.4.1.4614.1.4.2.5.1 |
sysLogEntryAn entry in the syslog configuration
directives list.deprecated SysLogEntry .1.3.6.1.4.1.4614.1.4.2.5.1.1 |
sysLogIndexAn arbitrary index assigned to each syslog
configuration directive.rodeprecated Unsigned32 .1.3.6.1.4.1.4614.1.4.2.5.1.1.1 |
sysLogSelectiontbd description
tbd examplesrwdeprecated DisplayString .1.3.6.1.4.1.4614.1.4.2.5.1.1.2 |
sysLogActiontbd description
tbd examplesrwdeprecated DisplayString .1.3.6.1.4.1.4614.1.4.2.5.1.1.3 |
sysLogRowStatusManages creation and deletion of conceptual rows.
See also SNMPv2-TC.rwdeprecated RowStatus (SNMPv2-TC) .1.3.6.1.4.1.4614.1.4.2.5.1.1.4 |
sysUserList OBJECT IDENTIFIER .1.3.6.1.4.1.4614.1.4.2.6 |
sysUserTableThe local user list. SEQUENCE OF SysUserEntry .1.3.6.1.4.1.4614.1.4.2.6.1 |
sysUserEntryAn entry in the local user list.
Prompts for the following when
creating a new user:
Password for the current user (the user
in question or an administrator).
New password for the user.
New password again.
Profile for the new user
(default operator). SysUserEntry .1.3.6.1.4.1.4614.1.4.2.6.1.1 |
sysUserIndexAn arbitrary index assigned to each entry.ro Unsigned32 .1.3.6.1.4.1.4614.1.4.2.6.1.1.1 |
sysUserNameThe username must start with a lowercase alphabetical
character. The rest of the username should be lowercase
letters (a-z), numbers(0-9) or any of the following
characters: -._
It is also possible to add $ as the last character.rw DisplayString .1.3.6.1.4.1.4614.1.4.2.6.1.1.2 |
sysUserPasswdtbd description
tbd examplesrwdeprecated DisplayString .1.3.6.1.4.1.4614.1.4.2.6.1.1.3 |
sysUserDescrUser description string.ro DisplayString .1.3.6.1.4.1.4614.1.4.2.6.1.1.4 |
sysUserLastChangeTimetbd description
tbd examplesrodeprecated DateAndTime (SNMPv2-TC) .1.3.6.1.4.1.4614.1.4.2.6.1.1.5 |
sysUserExpireTimetbd description
tbd examplesrodeprecated DateAndTime (SNMPv2-TC) .1.3.6.1.4.1.4614.1.4.2.6.1.1.6 |
sysUserRowStatusManages creation and deletion of conceptual rows.
See also SNMPv2-TC.rwdeprecated RowStatus (SNMPv2-TC) .1.3.6.1.4.1.4614.1.4.2.6.1.1.7 |
sysUserProfileThe user authority profile.
'administrator' - No restrictions.
'operator' - Restrictions on user operations
and some systems management operations.
Otherwise read/write access.
'readonly' - Read only access.ro DisplayString .1.3.6.1.4.1.4614.1.4.2.6.1.1.8 |
sysUserUidUser id.ro Unsigned32 .1.3.6.1.4.1.4614.1.4.2.6.1.1.9 |
sysUserChangePasswordChange user password.
Permitted for the the user in question
and administrators.
Asks for the following:
User database to update, Local or TACACS.
The system supports update of either the
local password or the TACACS password on
a remote server. This choice is seen only
when applicable.
Password for the current user (the user
in question or an administrator).
New password for the user.
New password again.
Password can consist of any printable ASCII character
except for '&' and whitespace. There are no restrictions
on upper or lower case characters.
Password length: 1 - 40 character(s).
Default password is set when new user is created.rw CommandString .1.3.6.1.4.1.4614.1.4.2.6.1.1.10 |
sysUserClearPasswordClear the user password.
Only permitted for administrators.
Asks for the following:
Password for the current user.
Note: Only changes the local password.
If a RADIUS- or TACACS+-server is in use
they may override the local configuration.rw CommandString .1.3.6.1.4.1.4614.1.4.2.6.1.1.11 |
sysUserDisableDisable the user.
Clear or set the password to make the user
available again.
Only permitted for administrators.
Asks for the following:
Password for the current user.
Note: Only disables the user locally.
If a RADIUS- or TACACS+-server is in use
they may override the local configuration.rw CommandString .1.3.6.1.4.1.4614.1.4.2.6.1.1.12 |
sysUserEnableEnable the user.
Only permitted for administrators.
Asks for the following:
Password for the current user.
Note: Only enables the user locally.
If a RADIUS- or TACACS+-server is in use
they may override the local configuration.rw CommandString .1.3.6.1.4.1.4614.1.4.2.6.1.1.13 |
sysUserModeAdministrative status for the user.
Note: Only shows the local user configuration.
If a RADIUS- or TACACS+-server is in use
they may override the local configuration.ro Enumeration .1.3.6.1.4.1.4614.1.4.2.6.1.1.14 |
sysRadius OBJECT IDENTIFIER .1.3.6.1.4.1.4614.1.4.2.7 |
sysRadiusPrimaryServerThe IP address for the primary RADIUS-server.
The port number used is 1812 (accounting,
port 1813, is not enabled).
Time-out is 3 seconds.
Set to the 0.0.0.0 or empty string if not used.
If either the server or the secret are not set
the primary server is disabled.rodeprecated DisplayString .1.3.6.1.4.1.4614.1.4.2.7.1 |
sysRadiusPrimarySecretThe shared secret for the primary RADIUS-server.
Set to empty string if not used.
If either the server or the secret are not set
the primary server is disabled.ro DisplayString .1.3.6.1.4.1.4614.1.4.2.7.2 |
sysRadiusSecondaryServerThe IP address for the secondary RADIUS-server.
The port number used is 1812 (accounting,
port 1813, is not enabled).
Time-out is 3 seconds.
Set to the 0.0.0.0 or empty string if not used.
If either the server or the secret are not set
the secondary server is disabled.rodeprecated DisplayString .1.3.6.1.4.1.4614.1.4.2.7.3 |
sysRadiusSecondarySecretThe shared secret for the secondary RADIUS-server.
Set to empty string if not used.
If either the server or the secret are not set
the secondary server is disabled.ro DisplayString .1.3.6.1.4.1.4614.1.4.2.7.4 |
sysRadiusPrimaryIpAddressThe IP address for the primary RADIUS-server.
The port number used is 1812 (accounting,
port 1813, is not enabled).
Time-out is 3 seconds.
Set to 0.0.0.0 if not used.
If either the server or the secret are not set
the primary server is disabled.ro IpAddress .1.3.6.1.4.1.4614.1.4.2.7.5 |
sysRadiusSecondaryIpAddressThe IP address for the secondary RADIUS-server.
The port number used is 1812 (accounting,
port 1813, is not enabled).
Time-out is 3 seconds.
Set to 0.0.0.0 if not used.
If either the server or the secret are not set
the primary server is disabled.ro IpAddress .1.3.6.1.4.1.4614.1.4.2.7.6 |
sysRadiusPrimaryPortThe port number for the primary RADIUS server.ro Unsigned32 .1.3.6.1.4.1.4614.1.4.2.7.7 |
sysRadiusSecondaryPortThe port number used for the Secondary RADIUS server.ro Unsigned32 .1.3.6.1.4.1.4614.1.4.2.7.8 |
sysRadiusDefaultUserProfileThe user authority profile.
'administrator' - No restrictions.
'operator' - Restrictions on user operations
and some systems management operations.
Otherwise read/write access.
'readonly' - Read only access.
'no radius template' - The user 'radius' is used as template.
It should be created if RADIUS server is used.
Otherwise both primary and secondary servers are disabled.ro DisplayString .1.3.6.1.4.1.4614.1.4.2.7.9 |
sysLicense OBJECT IDENTIFIER .1.3.6.1.4.1.4614.1.4.2.8 |
sysLicenseExpireDateShows the date when the license will expire.ro DateAndTime (SNMPv2-TC) .1.3.6.1.4.1.4614.1.4.2.8.1 |
sysLicenseCustomerShows the name of the customer that holds the license.ro DisplayString .1.3.6.1.4.1.4614.1.4.2.8.2 |
sysLicenseExpiresSoonWarns that the license will expire in 7 days,
or less.ro FaultStatus .1.3.6.1.4.1.4614.1.4.2.8.3 |
sysLicenseExpiredIndicates that the license has expired, or the
license file is missing.ro FaultStatus .1.3.6.1.4.1.4614.1.4.2.8.4 |
sysLicenseExpiredCauseDescribes why the license expired alarm is
raised.
none - file is ok, no alarm.
missing - the license file is missing.
invalid - it is not a valid XML file, or
some tags are missing.
corrupt - the encryption key does not match
the content of the file.
expired - the license has expired.ro Enumeration .1.3.6.1.4.1.4614.1.4.2.8.5 |
sysLicenseFeatureEwsdisabled - the feature ENM can not be used.
enabled - the feature ENM can be used.
demo - the feature is only for demo use.
corrupt - the encryption key does not match.
expired - the feature has expired.ro Enumeration .1.3.6.1.4.1.4614.1.4.2.8.6 |
sysLicenseFeatureOspfdisabled - the feature OSPF can not be used.
enabled - the feature OSPF can be used.
demo - the feature is only for demo use.
corrupt - the encryption key does not match.
expired - the feature has expired.ro Enumeration .1.3.6.1.4.1.4614.1.4.2.8.7 |
sysLicenseFeatureSnmpdisabled - the feature SNMP can not be used.
enabled - the feature SNMP can be used.
demo - the feature is only for demo use.
corrupt - the encryption key does not match.
expired - the feature has expired.ro Enumeration .1.3.6.1.4.1.4614.1.4.2.8.8 |
sysLicenseFeatureGmplsdisabled - the feature GMPLS can not be used.
enabled - the feature GMPLS can be used.
demo - the feature is only for demo use.
corrupt - the encryption key does not match.
expired - the feature has expired.ro Enumeration .1.3.6.1.4.1.4614.1.4.2.8.9 |
sysLicenseFeatureRudbdisabled - the feature RUDB can not be used.
enabled - the feature RUDB can be used.
demo - the feature is only for demo use.
corrupt - the encryption key does not match.
expired - the feature has expired.
RUDB means 'remote used database' and include
TACACS and RADIUS.ro Enumeration .1.3.6.1.4.1.4614.1.4.2.8.10 |
sysLicenseInstallLicenseFileInstall a new license file.
The license file can either be fetched from a
remote server or installed from local
directory.
There are 3 cases:
1. Remote server. Give server addr and full path
installLicenseFile <ip-addr>/<full path>
installLicenseFile 192.168.10.27/tftp/license.xml
2. From a local directory
installLicenseFile <full path>
installLicenseFile /root/license.xml
3. From the local download directory
/tftpboot/downloaded
installLicenseFile <file name>
installLicenseFile license.xml
Regardless of the name of the file it will be
installed as
/etc/lumentis/license.xmlro CommandString .1.3.6.1.4.1.4614.1.4.2.8.11 |
sysTacacs OBJECT IDENTIFIER .1.3.6.1.4.1.4614.1.4.2.9 |
sysTacacsPrimaryServerThe IP address for the primary TACACS+-server.
The port number used is 49.
Time-out is 3 seconds.
Set to the 0.0.0.0 or empty string if not used.rodeprecated DisplayString .1.3.6.1.4.1.4614.1.4.2.9.1 |
sysTacacsSecondaryServerThe IP address for the secondary TACACS+-server.
The port number used is 49.
Time-out is 3 seconds.
Set to the 0.0.0.0 or empty string if not used.rodeprecated DisplayString .1.3.6.1.4.1.4614.1.4.2.9.2 |
sysTacacsSecretThe shared secret for the primary TACACS+-server.
Set to empty string if not used.ro DisplayString .1.3.6.1.4.1.4614.1.4.2.9.3 |
sysTacacsSecondarySecretThe shared secret for the secondary TACACS+-server.
Set to empty string if not used.ro DisplayString .1.3.6.1.4.1.4614.1.4.2.9.4 |
sysTacacsPrimaryIpAddressThe IP address for the primary TACACS+-server.
The port number used is 49.
Time-out is 3 seconds.
Set to 0.0.0.0 if not used.ro IpAddress .1.3.6.1.4.1.4614.1.4.2.9.5 |
sysTacacsSecondaryIpAddressThe IP address for the secondary TACACS+-server.
The port number used is 49.
Time-out is 3 seconds.
Set to 0.0.0.0 if not used.ro IpAddress .1.3.6.1.4.1.4614.1.4.2.9.6 |
sysAudit OBJECT IDENTIFIER .1.3.6.1.4.1.4614.1.4.2.10 |
sysSecurity OBJECT IDENTIFIER .1.3.6.1.4.1.4614.1.4.2.11 |
sysSecurityLocalConsoleAccessWhen this parameter is 'disabled' there
is no way to access the board via RS-232.
Note, the setting applies to all boards in all chassis.
enabled - Access is allowed
disabled - No access is allowed.
The boot monitor and LINUX login are blocked.
bootdisabled - The boot monitor is blocked while LINUX login is allowed.
Only administrator can change the local console access settings.ro Enumeration .1.3.6.1.4.1.4614.1.4.2.11.1 |
sysSecurityChangeLocalConsoleAccessProcedure to change 'Local Console Access'ro CommandString .1.3.6.1.4.1.4614.1.4.2.11.2 |
sysSecurityIpTablesStatusThis parameter shows if a system
function is enabled in the node.
unavailable - package not installed
unsecure - package installed but not in use
secure - package installed and in usero Enumeration .1.3.6.1.4.1.4614.1.4.2.11.3 |
sysSecurityLocalCraftAccessThe local craft ETH access is used for
connecting a PC which runs DHCP (Dynamic Host Control Protocol)
for accessing the web (GUI) interface.
Use lc in the address bar of the browser.
The IP address of the DCN also works.
When this parameter is 'disabled' there
is no way to access the board via Craft ETH port.
enabled - Access is allowed
disabled - No access is allowed.
Only administrator can change the local craft ETH access settings.
The Local Craft ETH runs in 1000Base-T mode (1G Eth) or lower speed
depending on the auto negotiation.rw EnableDisable .1.3.6.1.4.1.4614.1.4.2.11.4 |
sysSecurityChangeLocalCraftAccessProcedure to change 'Local Craft ETH Access'ro CommandString .1.3.6.1.4.1.4614.1.4.2.11.5 |
sysSecurityAuthenticationOrderThis parameter shows the authentication order which is
used by the system.
localFirst - First authenticate with respect to local user database. If it fails, try remote server(s).
If no remote servers are configured, the authentication will be Local-Only.
remoteFirst - First authenticate with respect to the remote servers. If all remote servers are unreachable, try the local user database.
If the remote authentication is denied, try the local user database.
strictRemoteFirst - First authenticate with respect to the remote servers. If all remote servers are unreachable, try the local user database.
If the remote authentication is denied, stop, access is denied.
Only administrator can change the authenticate order settings.ro Enumeration .1.3.6.1.4.1.4614.1.4.2.11.6 |
sysSecurityFileSystemAccessRestrictionsAccess rights to the file system of the node element. When 'restricted',
restrictions to the file system are activated, these restrictions depends
on the user authority profile.
disabled - Default access rights:
1. Administrators (including root) and operators can execute
CLI commands bash and telnet.
2. All users have full file system access using SFTP or
FTP (if enabled).
enabled - Restricted access rights to the file system. The following
restrictions are applied:
1. Only administrator users (including root) can execute
CLI commands bash and telnet.
2. When using SFTP:
Readonly and operator users can only access /tftpboot/ and
its subdirectories.
Administrator users (including root) have full file system
access.
3. When using FTP (if enabled):
Readonly, operator and all administrator users except root
can only access /tftpboot/ and its subdirectories.
The root user have full file system access.
When changed, the updated restrictions will be used at following FTP/SFTP
sessions.
On CU-SFP/III, active FTP sessions will be aborted at the point when file
system access is changed.
Only administrator can change the file system access restriction settings.ro EnableDisable .1.3.6.1.4.1.4614.1.4.2.11.7 |
sysSecurityCUFrontICNPortAccessThe CU front ICN port access is used for
internal connection between subracks.
When this parameter is 'disabled' there
is no way to access next node via ICN1 or ICN2.
enabled - Access is allowed
disabled - No access is allowed.
Only administrator can change the CU front ICN port access settings.ro EnableDisable .1.3.6.1.4.1.4614.1.4.2.11.8 |
sysSecurityChangeCUFrontICNPortAccessProcedure to change 'CU front ICN port access'ro CommandString .1.3.6.1.4.1.4614.1.4.2.11.9 |
sysSecuritySubrackICNPortAccessThe Subrack ICN port access is used for
internal connection between subracks.
When this parameter is 'disabled' there
is no way to access next subrack via ICN3 or ICN4.
enabled - Access is allowed
disabled - No access is allowed.
Only administrator can change the Subrack ICN port access settings.ro EnableDisable .1.3.6.1.4.1.4614.1.4.2.11.10 |
sysSecurityChangeSubrackICNPortAccessProcedure to change 'Subrack ICN port access'ro CommandString .1.3.6.1.4.1.4614.1.4.2.11.11 |
sysSecurityMgmtAccessProofOfConnStatusThis parameter shows if the NE has lost the signal
or not. The SNMP agent is regularly polling the NE
and if the NE is not polled within a certain time period
(set in parameter MgmtAccessProofOfConnectivity)
we have proof of connectivity loss, and this parameter
is set to disconnected.
undefined - NE connectivity status not determined
disconnected - NE lost connection
connected - NE is connectedro Enumeration .1.3.6.1.4.1.4614.1.4.2.11.12 |
sysSecurityMgmtAccessProofOfConnectivityNumber of minutes that has to pass with no SNMP agent polls
before the NE assumes that connectivity is lost.
Only administrator can change the proof of connectivity settings.ro Integer32 .1.3.6.1.4.1.4614.1.4.2.11.13 |
sysSecurityAutoEnableBlockedMgmtPortsA setting to turn off/on auto enabling of blocked management ports.
Management ports in this context means DCN and Local craft ETH (Local craft ETH
does not exist on all platforms). If the network element has not been polled by the SNMP agent
(DNA-M) within the time that is set by the attribute Proof of Connectivity, the
blocked management ports are automatically enabled (deblocked/unblocked).
If SNMP polling is detected again by the network element (after a discontinuity) the ports will
revert to their blocked state.
on - The function to auto enable blocked ports is turned on.
off - The function to auto enable blocked ports is turned off.
Only administrator can change the auto enable blocked management ports settings.ro OnOff .1.3.6.1.4.1.4614.1.4.2.11.14 |
sysSecurityBlockedMgmtPortsUnblockedBlocked management ports (i.e. local craft and DCN ports) are unblocked.
The blocking is overridden due to loss of management connectivity (SNMP).ro FaultStatus .1.3.6.1.4.1.4614.1.4.2.11.15 |
sysSecurityInstallCertificatesProcedure to install certificates
installCertificates <private-key-file-path> <public-key-file-path> <cert-chain-file-path>
Each <file-path> is absolute (starting with '/').
After this command, the files are automatically deleted.ro CommandString .1.3.6.1.4.1.4614.1.4.2.11.16 |
sysSecurityInstallFactoryDefaultCertificatesProcedure to install factory default certificates.ro CommandString .1.3.6.1.4.1.4614.1.4.2.11.17 |
sysManager OBJECT IDENTIFIER .1.3.6.1.4.1.4614.1.4.2.12 |
sysManagerNameThe name of Centralized Security Manager (DNA-M).
This attribute shall NOT be set locally.
The DNA-M managing the security features of the NE will set this.
Requires administrator privileges to change.rw DisplayString .1.3.6.1.4.1.4614.1.4.2.12.1 |
sysManagerIPAddressThe address of Centralized Security Manager (DNA-M).
This attribute shall NOT be set locally.
The DNA-M managing the security features of the NE will set this.
Requires administrator privileges to change.rw DisplayString .1.3.6.1.4.1.4614.1.4.2.12.2 |
sysManagerPolicyNameThe name of the Security Policy, defined in DNA-M, that is assigned to
this NE.
This attribute shall NOT be set locally.
The DNA-M managing the security features of the NE will set this.
Requires administrator privileges to change.rw DisplayString .1.3.6.1.4.1.4614.1.4.2.12.3 |
sysManagerPlatformNE platform information.
Used by Centralized Security Manager (DNA-M).ro Platform .1.3.6.1.4.1.4614.1.4.2.12.4 |
sysManagerFcmComplianceVersionFeature Capability Matrix Compliance version.
Used by Centralized Security Manager (DNA-M).ro DisplayString (SNMPv2-TC) .1.3.6.1.4.1.4614.1.4.2.12.5 |
sysLoginBanner OBJECT IDENTIFIER .1.3.6.1.4.1.4614.1.4.2.13 |
sysLoginBannerContentThe login banner can be used to display pre-login
information such as system information or a warning.
The login banner requires administrator privileges
to change and can be set through CLI, GUI or DNA-M.
Characters 0x20 to 0x25 and 0x27 to 0x7E in
ISO/IEC 8859-1 are accepted/valid. Ampersand ('&')
0x26 is not allowed (this is a general XTM restriction
for text fields). New-line shall be encoded as '\\n' if
the message is set through CLI.
Min length: 0 character.
Max length: 1020 characters.
Although formal SNMP type is restricted to 128
characters, the system can cope with 1020 characters
when managed from CLI/GUI or DNA-M.rw DisplayString (SNMPv2-TC) .1.3.6.1.4.1.4614.1.4.2.13.1 |
lumSystemMIBModuleThe system MIB.
- General
- Node parameters
- Date and time
- License information
- RADIUS and TACACS+ authentication configuration
- User information MODULE-IDENTITY .1.3.6.1.4.1.8708.1.1.4 |