SW-ACLMGMT-MIB
AI MIB Summary
The SW-ACLMGMT-MIB module enables the monitoring and management of Access Control List (ACL) configurations and statistics on proprietary enterprise network devices. It exposes specific metrics regarding ACL rule definitions, hit counts, and packet/byte counters to facilitate granular traffic filtering analysis and security policy auditing.
The Structure of Access Control List Information for the proprietary enterprise.
Main OID:
swAclMgmtMIB.1.3.6.1.4.1.171.11.5
100
Objects
Active
Status
6
Dependencies
Imported Objects
Objects
100 total| Object Name |
|---|
swAclMgmtMIBThe Structure of Access Control List Information for the
proprietary enterprise. MODULE-IDENTITY .1.3.6.1.4.1.171.11.5 |
swAclMaskMgmt OBJECT IDENTIFIER .1.3.6.1.4.1.171.11.5.1 |
swACLEthernetTableThis table contain ACL mask of Ethernet information.
Access profiles will be created on the switch by row creation and to
define which parts of each incoming frame's layer 2 part of header
the switch will examine. Masks can be entered that will be combined
with the values the switch finds in the specified frame header fields. SEQUENCE OF SwACLEthernetEntry .1.3.6.1.4.1.171.11.5.1.1 |
swACLEthernetEntryA list of information about ACL of Ethernet. SwACLEthernetEntry .1.3.6.1.4.1.171.11.5.1.1.1 |
swACLEthernetProfileIDThe ID of ACL mask entry ,and is unique in the mask list.ro INTEGER .1.3.6.1.4.1.171.11.5.1.1.1.1 |
swACLEthernetUsevlanSpecifies that the switch will examine the VLAN part of each packet header.rw Enumeration .1.3.6.1.4.1.171.11.5.1.1.1.2 |
swACLEthernetMacAddrMaskStateThis object indicates the status of MAC address mask.
other(1) - Neither source MAC address nor destination MAC address are
masked.
dst-mac-addr(2) - recieved frames's destination MAC address are
currently used to be filtered as it meets with the MAC
address entry of the table.
src-mac-addr(3) - recieved frames's source MAC address are currently
used to be filtered as it meets with the MAC address entry
of the table.
dst-src-mac-addr(4) - recieved frames's destination MAC address or
source MAC address are currently used to be filtered as it meets
with the MAC address entry of the table.rw Enumeration .1.3.6.1.4.1.171.11.5.1.1.1.3 |
swACLEthernetSrcMacAddrMaskThis object Specifies the MAC address mask for the source MAC address.rw MacAddress (SNMPv2-TC) .1.3.6.1.4.1.171.11.5.1.1.1.4 |
swACLEthernetDstMacAddrMaskThis object Specifies the MAC address mask for the destination MAC address.rw MacAddress (SNMPv2-TC) .1.3.6.1.4.1.171.11.5.1.1.1.5 |
swACLEthernetUse8021pSpecifies if the switch will examine the 802.1p priority value in the frame's header
or not.rw Enumeration .1.3.6.1.4.1.171.11.5.1.1.1.6 |
swACLEthernetUseEthernetTypeSpecifies if the switch will examine the Ethernet type value in each frame's header
or not.rw Enumeration .1.3.6.1.4.1.171.11.5.1.1.1.7 |
swACLEthernetPortThis object indicates the portlist of this entry.rw PortList (Q-BRIDGE-MIB) .1.3.6.1.4.1.171.11.5.1.1.1.8 |
swACLEthernetRowStatusThis object indicates the status of this entry.rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.171.11.5.1.1.1.9 |
swACLIpTableThis table contain ACL mask of IP information.
Access profiles will be created on the switch by row creation and to
define which parts of each incoming frame's IP layer part of header
the switch will examine. Masks can be entered that will be combined
with the values the switch finds in the specified frame header fields. SEQUENCE OF SwACLIpEntry .1.3.6.1.4.1.171.11.5.1.2 |
swACLIpEntryA list of information about ACL of IP Layer. SwACLIpEntry .1.3.6.1.4.1.171.11.5.1.2.1 |
swACLIpProfileIDThe ID of ACL mask entry ,and is unique in the mask list.ro INTEGER .1.3.6.1.4.1.171.11.5.1.2.1.1 |
swACLIpUsevlanThis object indicates if IP layer vlan is examined or not.rw Enumeration .1.3.6.1.4.1.171.11.5.1.2.1.2 |
swACLIpIpAddrMaskStateThis object indicates the status of IP address mask.
other(1) - Neither source IP address nor destination IP address are
masked.
dst-ip-addr(2) - recieved frames's destination IP address are
currently used to be filtered as it meets with the IP
address entry of the table.
src-ip-addr(3) - recieved frames's source IP address are currently
used to be filtered as it meets with the IP address entry of
the table.
dst-src-ip-addr(4) - recieved frames's destination IP address or
source IP address are currently used to be filtered as it meets
with the IP address entry of the table.rw Enumeration .1.3.6.1.4.1.171.11.5.1.2.1.3 |
swACLIpSrcIpAddrMaskThis object Specifies IP address mask for the source IP address.rw IpAddress .1.3.6.1.4.1.171.11.5.1.2.1.4 |
swACLIpDstIpAddrMaskThis object Specifies the IP address mask for the destination IP address.rw IpAddress .1.3.6.1.4.1.171.11.5.1.2.1.5 |
swACLIpUseDSCPThis object indicates DSCP protocol is is examined or not.rw Enumeration .1.3.6.1.4.1.171.11.5.1.2.1.6 |
swACLIpUseProtoTypeThat object indicates which protocol will be examined.rw Enumeration .1.3.6.1.4.1.171.11.5.1.2.1.7 |
swACLIpIcmpOptionThis object indicates which fields should be filled in of ICMP.
none(1)- two fields are null.
type(2)- type field should be filled in.
code(3)- code field should be filled in.
type-code(4)- not only type fileld but code field should be filled in.rw Enumeration .1.3.6.1.4.1.171.11.5.1.2.1.8 |
swACLIpIgmpOptionThis object indicates Options of IGMP is examined or not.rw Enumeration .1.3.6.1.4.1.171.11.5.1.2.1.9 |
swACLIpTcpOptionThis object indicates the status of filtered address of TCP.
other(1) - Neither source port nor destination port are
masked.
dst-addr(2) - recieved frames's destination port are
currently used to be filtered .
src-addr(3) - recieved frames's source port are currently
used to be filtered .
dst-src-addr(4) - both recieved frames's destination port and
source port are currently used to be filtered .rw Enumeration .1.3.6.1.4.1.171.11.5.1.2.1.10 |
swACLIpUdpOptionThis object indicates the status of filtered address of UDP .
other(1) - Neither source port nor destination port are
masked.
dst-addr(2) - recieved frames's destination port are
currently used to be filtered .
src-addr(3) - recieved frames's source port are currently
used to be filtered .
dst-src-addr(4) - recieved frames's destination port or
source port are currently used to be filtered.rw Enumeration .1.3.6.1.4.1.171.11.5.1.2.1.11 |
swACLIpTCPorUDPSrcPortMaskSpecifies a TCP port mask for the source port if swACLIpUseProtoType is TCP
Specifies a UDP port mask for the source port if swACLIpUseProtoType is UDP.rw OCTET STRING .1.3.6.1.4.1.171.11.5.1.2.1.12 |
swACLIpTCPorUDPDstPortMaskSpecifies a TCP port mask for the destination port if swACLIpUseProtoType is TCP
Specifies a UDP port mask for the destination port if swACLIpUseProtoType is UDP.rw OCTET STRING .1.3.6.1.4.1.171.11.5.1.2.1.13 |
swACLIpTCPFlagBitSpecifies a TCP connection flag mask.rw Enumeration .1.3.6.1.4.1.171.11.5.1.2.1.14 |
swACLIpProtoIDOptionSpecifies that the switch will examine each frame's Protocol ID field or not.rw Enumeration .1.3.6.1.4.1.171.11.5.1.2.1.16 |
swACLIpProtoIDMaskSpecifies that the rule applies to the IP protocol ID and the mask options
behind the IP header.rw OCTET STRING .1.3.6.1.4.1.171.11.5.1.2.1.17 |
swACLIpPortThis object indicates the portlist of this entry.rw PortList (Q-BRIDGE-MIB) .1.3.6.1.4.1.171.11.5.1.2.1.18 |
swACLIpRowStatusThis object indicates the status of this entry.rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.171.11.5.1.2.1.19 |
swACLIpTCPFlagBitMaskA value which indicates the set of TCP flags that this
entity may potentially offers. The value is a sum. This
sum initially takes the value zero, Then, for each flag, L,
in the range 1 through 6, that this node performs
transactions for, 2 raised to (L - 1) is added to the sum.
Note that values should be calculated accordingly:
Flag functionality
6 urg bit
5 ack bit
4 psh bit
3 rst bit
2 syn bit
1 fin bit
For example,it you want to enable urg bit and ack bit,you
should set vlaue 48(2^(5-1) + 2^(6-1)).rw INTEGER .1.3.6.1.4.1.171.11.5.1.2.1.115 |
swACLPayloadTableThis table contain ACL mask of payload information. SEQUENCE OF SwACLPayloadEntry .1.3.6.1.4.1.171.11.5.1.3 |
swACLPayloadEntryThis Entry contain ACL mask of payload information. SwACLPayloadEntry .1.3.6.1.4.1.171.11.5.1.3.1 |
swACLPayloadProfileIDThe ID of ACL mask entry ,and is unique in the mask list.ro INTEGER .1.3.6.1.4.1.171.11.5.1.3.1.1 |
swACLPayloadPortThe portlist of ACL mask entry .rw PortList (Q-BRIDGE-MIB) .1.3.6.1.4.1.171.11.5.1.3.1.2 |
swACLPayloadOffSet0to15The offset of ACL mask entry .rw OCTET STRING .1.3.6.1.4.1.171.11.5.1.3.1.3 |
swACLPayloadOffSet16to31The offset of ACL mask entry .rw OCTET STRING .1.3.6.1.4.1.171.11.5.1.3.1.4 |
swACLPayloadOffSet32to47The offset of ACL mask entry .rw OCTET STRING .1.3.6.1.4.1.171.11.5.1.3.1.5 |
swACLPayloadOffSet48to63The offset of ACL mask entry .rw OCTET STRING .1.3.6.1.4.1.171.11.5.1.3.1.6 |
swACLPayloadOffSet64to79The offset of ACL mask entry .rw OCTET STRING .1.3.6.1.4.1.171.11.5.1.3.1.7 |
swACLPayloadRowStatusThe status of the entry .rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.171.11.5.1.3.1.8 |
swAclRuleMgmt OBJECT IDENTIFIER .1.3.6.1.4.1.171.11.5.2 |
swACLEtherRuleTableThis table contain ACL rule of ethernet information. SEQUENCE OF SwACLEtherRuleEntry .1.3.6.1.4.1.171.11.5.2.1 |
swACLEtherRuleEntryA list of information about ACL rule of the layer 2 part of each packet. SwACLEtherRuleEntry .1.3.6.1.4.1.171.11.5.2.1.1 |
swACLEtherRuleProfileIDThe ID of ACL mask entry ,and is unique in the mask list.ro INTEGER .1.3.6.1.4.1.171.11.5.2.1.1.1 |
swACLEtherRuleAccessIDThe ID of ACL rule entry relate to swACLEtherRuleProfileID.ro INTEGER .1.3.6.1.4.1.171.11.5.2.1.1.2 |
swACLEtherRuleVlanSpecifies that the access will apply to only to this VLAN.rw SnmpAdminString .1.3.6.1.4.1.171.11.5.2.1.1.3 |
swACLEtherRuleSrcMacAddressSpecifies that the access will apply to only packets with
this source MAC address.rw MacAddress (SNMPv2-TC) .1.3.6.1.4.1.171.11.5.2.1.1.4 |
swACLEtherRuleDstMacAddressSpecifies that the access will apply to only packets
with this destination MAC address.rw MacAddress (SNMPv2-TC) .1.3.6.1.4.1.171.11.5.2.1.1.5 |
swACLEtherRule8021PSpecifies that the access will apply only to packets with
this 802.1p priority value.rw INTEGER .1.3.6.1.4.1.171.11.5.2.1.1.6 |
swACLEtherRuleEtherTypeSpecifies that the access will apply only to packets with this
hexidecimal 802.1Q Ethernet type value in the packet header.rw OCTET STRING .1.3.6.1.4.1.171.11.5.2.1.1.7 |
swACLEtherRuleEnablePrioritySpecifies that the access will apply only to packets with
priority value.rw Enumeration .1.3.6.1.4.1.171.11.5.2.1.1.8 |
swACLEtherRulePrioritySpecific the priority will change to the packets while the swACLEtherRuleReplacePriority
is enabled .rw INTEGER .1.3.6.1.4.1.171.11.5.2.1.1.9 |
swACLEtherRuleReplacePrioritySpecific the packets that match the access profile will changed the
802.1p priority tag field by the switch or not .rw Enumeration .1.3.6.1.4.1.171.11.5.2.1.1.10 |
swACLEtherRuleEnableReplaceDscpSpecific the packets that match the access profile will replaced the
DSCP field by the switch or not .rw Enumeration .1.3.6.1.4.1.171.11.5.2.1.1.11 |
swACLEtherRuleRepDscpspecify a value to be written to the DSCP field of an incoming packet
that meets the criteria specified in the first part of the command.
This value will over-write the value in the DSCP field of the packet.rw INTEGER .1.3.6.1.4.1.171.11.5.2.1.1.12 |
swACLEtherRulePermitThis object indicates the permit status of this entry.rw Enumeration .1.3.6.1.4.1.171.11.5.2.1.1.14 |
swACLEtherRuleRowStatusThis object indicates the status of this entry.rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.171.11.5.2.1.1.15 |
swACLIpRuleTable SEQUENCE OF SwACLIpRuleEntry .1.3.6.1.4.1.171.11.5.2.2 |
swACLIpRuleEntry SwACLIpRuleEntry .1.3.6.1.4.1.171.11.5.2.2.1 |
swACLIpRuleProfileIDThe ID of ACL mask entry ,and is unique in the mask list.ro INTEGER .1.3.6.1.4.1.171.11.5.2.2.1.1 |
swACLIpRuleAccessIDThe ID of ACL IP rule entry .ro INTEGER .1.3.6.1.4.1.171.11.5.2.2.1.2 |
swACLIpRuleVlanSpecifies that the access will apply to only to this VLAN.rw SnmpAdminString .1.3.6.1.4.1.171.11.5.2.2.1.3 |
swACLIpRuleSrcIpaddressSpecific an IP source address.rw IpAddress .1.3.6.1.4.1.171.11.5.2.2.1.4 |
swACLIpRuleDstIpaddressSpecific an IP destination address.rw IpAddress .1.3.6.1.4.1.171.11.5.2.2.1.5 |
swACLIpRuleDscpSpecific the value of dscp, the value can be configured 0 to 63rw INTEGER .1.3.6.1.4.1.171.11.5.2.2.1.6 |
swACLIpRuleProtocolSpecifies the IP protocol which has been configured in swACLIpEntry .ro Enumeration .1.3.6.1.4.1.171.11.5.2.2.1.7 |
swACLIpRuleTypeSpecific that the rule applies to the value of icmp type traffic.rw INTEGER .1.3.6.1.4.1.171.11.5.2.2.1.8 |
swACLIpRuleCodeSpecific that the rule applies to the value of icmp code traffic.rw INTEGER .1.3.6.1.4.1.171.11.5.2.2.1.9 |
swACLIpRuleSrcPortSpecific that the rule applies the range of tcp/udp source portrw INTEGER .1.3.6.1.4.1.171.11.5.2.2.1.10 |
swACLIpRuleDstPortSpecific the range of tcp/udp destination port rangerw INTEGER .1.3.6.1.4.1.171.11.5.2.2.1.11 |
swACLIpRuleFlagBitsA value which indicates the set of TCP flags that this
entity may potentially offers. The value is a sum. This
sum initially takes the value zero, Then, for each flag, L,
in the range 1 through 6, that this node performs
transactions for, 2 raised to (L - 1) is added to the sum.
Note that values should be calculated accordingly:
Flag functionality
6 urg bit
5 ack bit
4 rsh bit
3 rst bit
2 syn bit
1 fin bit
For example,it you want to enable urg bit and ack bit,you
should set vlaue 48(2^(5-1) + 2^(6-1)).rw INTEGER .1.3.6.1.4.1.171.11.5.2.2.1.12 |
swACLIpRuleProtoIDSpecific that the rule applies to the value of ip protocol id trafficrw INTEGER .1.3.6.1.4.1.171.11.5.2.2.1.13 |
swACLIpRuleUserMaskSpecific that the rule applies to the ip protocol id and the range of
options behind the IP header.rw OCTET STRING .1.3.6.1.4.1.171.11.5.2.2.1.14 |
swACLIpRuleEnablePrioritySpecifies that the access will apply only to packets with
priority value.rw Enumeration .1.3.6.1.4.1.171.11.5.2.2.1.15 |
swACLIpRulePrioritySpecifies that the access profile will apply to packets that contain
this value in their 802.1p priority field of their header.rw INTEGER .1.3.6.1.4.1.171.11.5.2.2.1.16 |
swACLIpRuleReplacePrioritySpecific the packets that match the access profile will changed the
802.1p priority tag field by the switch or not .rw Enumeration .1.3.6.1.4.1.171.11.5.2.2.1.17 |
swACLIpRuleEnableReplaceDscpIndicate weather the DSCP field can be over-write or not.rw Enumeration .1.3.6.1.4.1.171.11.5.2.2.1.18 |
swACLIpRuleRepDscpspecify a value to be written to the DSCP field of an incoming packet
that meets the criteria specified in the first part of the command.
This value will over-write the value in the DSCP field of the packet.rw INTEGER .1.3.6.1.4.1.171.11.5.2.2.1.19 |
swACLIpRulePermitrw Enumeration .1.3.6.1.4.1.171.11.5.2.2.1.21 |
swACLIpRuleRowStatusThis object indicates the status of this entry.rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.171.11.5.2.2.1.22 |
swACLPayloadRuleTable SEQUENCE OF SwACLPayloadRuleEntry .1.3.6.1.4.1.171.11.5.2.3 |
swACLPayloadRuleEntry SwACLPayloadRuleEntry .1.3.6.1.4.1.171.11.5.2.3.1 |
swACLPayloadRuleProfileIDThe ID of ACL RULE entry ,and is unique in the mask list.ro INTEGER .1.3.6.1.4.1.171.11.5.2.3.1.1 |
swACLPayloadRuleAccessIDth id of the entryro INTEGER .1.3.6.1.4.1.171.11.5.2.3.1.2 |
swACLPayloadRuleOffSet0to15The offset of ACL rule entry .rw OCTET STRING .1.3.6.1.4.1.171.11.5.2.3.1.4 |
swACLPayloadRuleOffSet16to31The offset of ACL rule entry .rw OCTET STRING .1.3.6.1.4.1.171.11.5.2.3.1.5 |
swACLPayloadRuleOffSet32to47The offset of ACL rule entry .rw OCTET STRING .1.3.6.1.4.1.171.11.5.2.3.1.6 |
swACLPayloadRuleOffSet48to63The offset of ACL rule entry .rw OCTET STRING .1.3.6.1.4.1.171.11.5.2.3.1.7 |
swACLPayloadRuleOffSet64to79The offset of ACL rule entry .rw OCTET STRING .1.3.6.1.4.1.171.11.5.2.3.1.8 |
swACLPayloadRuleEnablePriorityrw Enumeration .1.3.6.1.4.1.171.11.5.2.3.1.9 |
swACLPayloadRulePrioritySpecifies that the access profile will apply to packets that contain
this value in their 802.1p priority field of their header.rw INTEGER .1.3.6.1.4.1.171.11.5.2.3.1.10 |
swACLPayloadRuleReplacePriorityrw Enumeration .1.3.6.1.4.1.171.11.5.2.3.1.11 |
swACLPayloadRuleEnableReplaceDscpIndicate wether the DSCP field can be over-write or notrw Enumeration .1.3.6.1.4.1.171.11.5.2.3.1.12 |
swACLPayloadRuleRepDscpspecify a value to be written to the DSCP field of an incoming packet
that meets the criteria specified in the first part of the command.
This value will over-write the value in the DSCP field of the packet.rw INTEGER .1.3.6.1.4.1.171.11.5.2.3.1.13 |
swACLPayloadRulePermitThe offset of ACL rule entry .rw Enumeration .1.3.6.1.4.1.171.11.5.2.3.1.14 |
swACLPayloadRuleRowStatusThe status of ACL rule entry .rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.171.11.5.2.3.1.15 |