SECURITY-MANAGEMENT-MIB
AI MIB Summary
The SECURITY-MANAGEMENT-MIB provides standardized SNMP objects to monitor and configure device security policies, access control lists, and authentication mechanisms for network infrastructure. It enables the tracking of security-related metrics such as failed login attempts, active management sessions, and firewall rule states across compliant hardware and software platforms.
Defines MIB objects related to device secured management.
Main OID:
secMngModule.1.3.6.1.4.1.6889.1.1.14.1
57
Objects
Active
Status
8
Dependencies
Imported Objects
Objects
57 total| Object Name |
|---|
avayaSecurity OBJECT IDENTIFIER .1.3.6.1.4.1.6889.1.1.14 |
secMngModuleDefines MIB objects related to device secured management. MODULE-IDENTITY .1.3.6.1.4.1.6889.1.1.14.1 |
secModeWhen the security mode flag = on - it indicates that device operates
in secured mode, =off - in non-secured mode. Otherwize when the value retuned
=Not relevant - secured mode is not supported in this device.ro OnOffType .1.3.6.1.4.1.6889.1.1.14.1.1 |
secTcpSynCookies OBJECT IDENTIFIER .1.3.6.1.4.1.6889.1.1.14.1.2 |
secTcpSynCkiOpStateMonitors the operational state of the TCP SYN cookies
defense mechanism.
The operational state of the SYN cookies can change
only after a reset, if the configuration state was
changed and the running configuration was saved to
the startup configuration before the reset.
Use secTcpSynCkiCfgState to monitor and change the
SYN cookies configuration state.
When the SYN cookies feature is turned on, it helps
protect the local host from SYN attacks (a type of
DoS attack).ro OnOffType .1.3.6.1.4.1.6889.1.1.14.1.2.1 |
secTcpSynCkiCfgStateControls and monitors the configuration state of the
TCP SYN cookies defense mechanism.
The operational state of the SYN cookies can change
only after reset, if the configuration state was
changed and the running configuration was saved to
the startup configuration before the reset.
Use secTcpSynCkiOpState to monitor the SYN cookies
operational state.
When the SYN cookies feature is turned on, it helps
protect the local host from SYN attacks (a type of
DoS attack).rw OnOffType .1.3.6.1.4.1.6889.1.1.14.1.2.2 |
secMngProtoTableList of security management protocols supported in the device. SEQUENCE OF SecMngProtoEntry .1.3.6.1.4.1.6889.1.1.14.1.3 |
secMngProtoEntryDescription. SecMngProtoEntry .1.3.6.1.4.1.6889.1.1.14.1.3.1 |
secMngProtoIdIndex to the secMngProtoTable. The index can take one of the following values that
correspond to supported management protocols
scpConfigFiles(1),
scpImageFiles(2),
ssh(3),
telnet(4),
snmpv3(5),
http(6),
https(7),
telnetClient(8),
icmpRedirection(9), - icmp redirection service state
icmp(10), - icmp services status
recoveryPassword(11), - recovery password state
sshClient(12),
snmpv1(13),
icmpEcho(14) - icmp service has been launched in EchoOnly mode
tftp(16),
dhcp(17),
dnsResolver(18,
scpClient(19),
tftpClient(20),
servicesTelnet(21), - reports telnet status on Services interface in G450
Missing entry indicates that
corresponding protocol is not supported.ro Enumeration .1.3.6.1.4.1.6889.1.1.14.1.3.1.1 |
secMngProtoStatusPortocol status. When the status is =on - it indicates that
correpsonding protocol is up and running, =off - protocol is down.
Otherwize when the value retuned =Not relevant - the protocol is not supported.ro ServiceStateType .1.3.6.1.4.1.6889.1.1.14.1.3.1.2 |
secMngConformance OBJECT IDENTIFIER .1.3.6.1.4.1.6889.1.1.14.1.4 |
secMngGroups OBJECT IDENTIFIER .1.3.6.1.4.1.6889.1.1.14.1.4.1 |
secMngCompliance OBJECT IDENTIFIER .1.3.6.1.4.1.6889.1.1.14.1.4.2 |
lsgLicManagementGroup of MIBs objects used for configuration/presentation of the
License information generated by Avaya Remote Feature
Activation (RFA) system. OBJECT IDENTIFIER .1.3.6.1.4.1.6889.1.1.14.1.5 |
lsgLicMngTableRFA based License management table. All elements are
displaying the feature activation status. License activation
controlled by the license file. The table is indexed by the
license feature keyword assuming that the same keyword describing a
feature cannot appear more than once per a license file. SEQUENCE OF LsgLicMngEntry .1.3.6.1.4.1.6889.1.1.14.1.5.1 |
lsgLicMngEntryEntry in lsgLicMngTable. LsgLicMngEntry .1.3.6.1.4.1.6889.1.1.14.1.5.1.1 |
lsgLicMngFeatureKeywordThis table entry contains a features keyword. The feature
keywords are text-based for example FEAT_VPN string. This
field is used as a table indexrw OCTET STRING .1.3.6.1.4.1.6889.1.1.14.1.5.1.1.1 |
lsgLicMngFeatureTypeLicense activation mechanism support two feature types
* Boolean on-off feature
* Features that describe quantities for example number
of concurrent VPN peersro Enumeration .1.3.6.1.4.1.6889.1.1.14.1.5.1.1.2 |
lsgLicMngAdminStatusAn administration status shows the feature activation status -
when set to On the feature is activated by the RFA licensing system.ro OnOffType .1.3.6.1.4.1.6889.1.1.14.1.5.1.1.3 |
lsgLicMngOperStatusThe operation status shows the actual status of the
corresponding feature - feature can be not operational
enabled if for example device must be reset for feature to
be activated or feature is not supported by a device.ro OnOffType .1.3.6.1.4.1.6889.1.1.14.1.5.1.1.4 |
lsgLicMngCountedValueFor counted features, this entry shows the associated quantityro Unsigned32 .1.3.6.1.4.1.6889.1.1.14.1.5.1.1.5 |
lsgLicMngLastErrorShows feature error statero Enumeration .1.3.6.1.4.1.6889.1.1.14.1.5.1.1.6 |
lsgLicMngConformanceDescription. OBJECT IDENTIFIER .1.3.6.1.4.1.6889.1.1.14.1.5.20 |
lsgLicMngGroupsDescription. OBJECT IDENTIFIER .1.3.6.1.4.1.6889.1.1.14.1.5.20.1 |
fips140Description. OBJECT IDENTIFIER .1.3.6.1.4.1.6889.1.1.14.1.6 |
fipsEnhancedSecurityFlgenhanceSecurity flag reports operation of a product in enhance security mode.
When running under enhanced security a product performs certain secure-related
activities safely, closely matching FIPS-140-2 standard. However the
flag doesn't necessary indicate that all device operations comply to
FIPS approved mode as some of security activities might be controlled
via different mechanisms for example manual configuration.
Security policy/Crypto Office guidance documents shall be used as
reference as for if this flag can be used as an evidence for operation
in FIPS approved mode. The flag is read only and set via product CLI.ro OnOffType .1.3.6.1.4.1.6889.1.1.14.1.6.1 |
avMssNotificationsSubtree hosting MSS notification traps OBJECT IDENTIFIER .1.3.6.1.4.1.6889.1.1.14.1.7 |
avMssNotificationPrefixDescription. OBJECT IDENTIFIER .1.3.6.1.4.1.6889.1.1.14.1.7.0 |
avMSSDenialOfServiceThe MSS notification sent on DoS attack NOTIFICATION-TYPE .1.3.6.1.4.1.6889.1.1.14.1.7.0.1 |
avMSSNotificationRateDefines the rate of MSS notification report.
MSS reports will be generated as per
rate if the event group counter
passes the threshold correspondingly.
The rate units are given in seconds with
minimum - 10 seconds
maximum - 8 hours (60 * 60 * 8)rw INTEGER .1.3.6.1.4.1.6889.1.1.14.1.7.2 |
avMSSVarbindsSubtree of access-for-notify arguments to
MSS notification varbinds list. OBJECT IDENTIFIER .1.3.6.1.4.1.6889.1.1.14.1.7.4 |
avMSSVarbindsDoSTypeEnumeration of DoS attacksro Enumeration .1.3.6.1.4.1.6889.1.1.14.1.7.4.1 |
avMSSVarbindsDescriptionTextual description of the DoS eventro DisplayString (SNMPv2-TC) .1.3.6.1.4.1.6889.1.1.14.1.7.4.2 |
avMSSVarbindsSrcAddrSource IP address in IP header. Set to 0.0.0.0 if address is unknownro IpAddress .1.3.6.1.4.1.6889.1.1.14.1.7.4.3 |
avMSSVarbindsDstAddrDestination IP address in IP header. Set to 0.0.0.0 if address is unknownro IpAddress .1.3.6.1.4.1.6889.1.1.14.1.7.4.4 |
avMSSVarbindsDstPortDestination port number in IP header. 0 if port is not applicable or
unknownro INTEGER .1.3.6.1.4.1.6889.1.1.14.1.7.4.5 |
avMSSVarbindsIpProtocolThe protocol field in IP headerro INTEGER .1.3.6.1.4.1.6889.1.1.14.1.7.4.6 |
avMSSVarbindsCountCounted number of events that occur in a given period
for a corresponding class of security violations (DoS,
not authorized access, etc).ro Counter64 .1.3.6.1.4.1.6889.1.1.14.1.7.4.7 |
avMSSVarbindsSrcMACAddrSource Physical address (MAC) of a packet identified
as a packet carrying DoS payload. Set to 00:00:00:00:00:00 when phyicial address
is not supported or unknown to the systemro PhysAddress (SNMPv2-TC) .1.3.6.1.4.1.6889.1.1.14.1.7.4.8 |
secMngNotificationsDescription. OBJECT IDENTIFIER .1.3.6.1.4.1.6889.1.1.14.1.10 |
secMngNotificationsPrefixDescription. OBJECT IDENTIFIER .1.3.6.1.4.1.6889.1.1.14.1.10.0 |
avConfigurationEncKeyMismatchFaultEncryption keys mismatch error. Configuration download
operation is aborted NOTIFICATION-TYPE .1.3.6.1.4.1.6889.1.1.14.1.10.0.1 |
avConfigurationMasterKeyChangeConfiguration Master key was changed NOTIFICATION-TYPE .1.3.6.1.4.1.6889.1.1.14.1.10.0.2 |
avPasswordToExpireAlertUser password is about to expire in n days NOTIFICATION-TYPE .1.3.6.1.4.1.6889.1.1.14.1.10.0.3 |
secMngVarbindsNotify only varbinds used for
notifications in secMngNotifications group OBJECT IDENTIFIER .1.3.6.1.4.1.6889.1.1.14.1.10.1 |
secMngNumOfDays2ExpireDescription.ro Unsigned32 UNITS "Days" .1.3.6.1.4.1.6889.1.1.14.1.10.1.1 |
avASGAuthenticationFilesInfo on authentication file(s) installed in a product OBJECT IDENTIFIER .1.3.6.1.4.1.6889.1.1.14.1.12 |
avASGAuthFileHeaderThe information on Authentication File stored
in ASG AF file header OBJECT IDENTIFIER .1.3.6.1.4.1.6889.1.1.14.1.12.3 |
avASGAuthFileAFIDThe productID value ascociated with the
Authentication File (format 7xxxxxxxxx)ro DisplayString .1.3.6.1.4.1.6889.1.1.14.1.12.3.1 |
avASGAuthFileGenDateDate of Authentication file generation
(format YYYY/MM/DD)ro DisplayString UNITS "YYYY/MM/DD" .1.3.6.1.4.1.6889.1.1.14.1.12.3.2 |
avASGAuthFileGenTimeA 8-character string in US short locale
time (format= HH:MM:SS)ro DisplayString .1.3.6.1.4.1.6889.1.1.14.1.12.3.3 |
avASGAuthFileReleaseMajor software release the AF file was generated forro DisplayString (SNMPv2-TC) .1.3.6.1.4.1.6889.1.1.14.1.12.3.4 |
avASGNotificationsDescription. OBJECT IDENTIFIER .1.3.6.1.4.1.6889.1.1.14.1.12.3.5 |
avASGNotificationsPrefixDescription. OBJECT IDENTIFIER .1.3.6.1.4.1.6889.1.1.14.1.12.3.5.0 |
avASGAFDownloadSuccessAF download successfully accomplished NOTIFICATION-TYPE .1.3.6.1.4.1.6889.1.1.14.1.12.3.5.0.1 |
avASGAFDownloadFailureAF download Failed NOTIFICATION-TYPE .1.3.6.1.4.1.6889.1.1.14.1.12.3.5.0.2 |
avSecLocalDateAndTimeSetting the Local current RTC date and time, when not registered with CMrw DateAndTime (SNMPv2-TC) .1.3.6.1.4.1.6889.1.1.14.1.13 |