Home/Catalog/TRELLIX-SENSOR-CONF-MIB

TRELLIX-SENSOR-CONF-MIB

AI MIB Summary

The TRELLIX-SENSOR-CONF-MIB provides read-write management of Trellix IntruShield sensor node configurations, specifically defining parameters for node identification, EMS connectivity, chassis and card topology, network interface assignments, and packet logging or SSL security settings. This module enables administrators to programmatically configure the operational identity, hardware slot mapping, and service parameters of the IntruShield intrusion detection system.

The Configuration MIB for the Trellix IntruShield product. They are furthur broken down into the following groups: systemGrp - configuration of the IntruShield node identification. emsGrp - configuration of possible EMSs identification chassisGrp - configuration of the chassis slots managementCardGrp - configuration of the management card(s) tftpGrp - configuration of TFTP based services sensorCardGp - configuration of the sensor anlysis card(s) interfacePortGrp - configuration of interface port(s) responsePortGrp - configuration of response port(s) pktLogGrp - configuration of the Packet Logging Application sslGrp - SSL configuration
Main OID:
ivSensorConfigurationMIB.1.3.6.1.4.1.8962.2.1.2.1
938
Objects
Active
Status
5
Dependencies

Imported Objects

Objects

938 total
Object Name
ivSensorConfigurationMIBThe Configuration MIB for the Trellix IntruShield product. They are furthur broken down into the following groups: systemGrp - configuration of the IntruShield node identification. emsGrp - configuration of possible EMSs identification chassisGrp - configuration of the chassis slots managementCardGrp - configuration of the management card(s) tftpGrp - configuration of TFTP based services sensorCardGp - configuration of the sensor anlysis card(s) interfacePortGrp - configuration of interface port(s) responsePortGrp - configuration of response port(s) pktLogGrp - configuration of the Packet Logging Application sslGrp - SSL configuration
MODULE-IDENTITY
.1.3.6.1.4.1.8962.2.1.2.1
IMPORTSThe Configuration MIB for the Trellix IntruShield product. They are furthur broken down into the following groups: systemGrp - configuration of the IntruShield node identification. emsGrp - configuration of possible EMSs identification chassisGrp - configuration of the chassis slots managementCardGrp - configuration of the management card(s) tftpGrp - configuration of TFTP based services sensorCardGp - configuration of the sensor anlysis card(s) interfacePortGrp - configuration of interface port(s) responsePortGrp - configuration of response port(s) pktLogGrp - configuration of the Packet Logging Application sslGrp - SSL configuration
Unknown
.1.3.6.1.4.1.8962.2.1.2.1
systemGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.1
ivSysNameAn administratively assigned name for this IntruShied node. By convention, this is the node's fully-qualified domain name.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.1.1
ivSysLocationThe physical location of this node (e.g., `Building 6, IS room 443, 3rd floor').rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.1.2
ivSysContactThe textual identification of the contact person for this IntruShield node, together with information on how to contact this person.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.1.3
ivSysModelThis object is where the manufacturer specifies the model identification (number or type) of the network element.ro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.1.4
ivSysSerialNumberManufacturer-provided serial number.ro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.1.5
ivSysDescrA textual description of the entity. This value should include the full name and version identification of the system's hardware type, software operating system, and networking software. It is current that this only contains printable ASCII characters.ro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.1.6
ivSysObjectIDThe vendor's authoritative identification of the network management subsystem contained in the entity. This value is allocated within the SMI enterprises subtree (1.3.6.1.4.1) and provides an easy and unambiguous means for determining `what kind of box' is being managed. For example, if vendor `Flintstones, Inc.' was assigned the subtree 1.3.6.1.4.1.4242, it could assign the identifier 1.3.6.1.4.1.4242.1.1 to its `Fred Router'.ro
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.1.7
ivSysUpTimeThe time (in hundredths of a second) since the network management portion of the system was last re-initialized.ro
TimeTicks (SNMPv2-SMI)
.1.3.6.1.4.1.8962.2.1.2.1.1.8
ivSysLastCfgTimeIndicates time when configuration was changed last.ro
DateAndTime (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.1.9
ivSysDiskSpaceLeftReturns the numbers of kbytes left on the disk.ro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.1.10
ivSysAlertChannelStatusReturns the status of the alert channel connection with EMS.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.1.11
ivSysPacketLogChannelStatusReturns the status of the packet log channel connection with EMS.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.1.12
ivSysHealthReturns the health of the sensor. uninitialized means that the sensor does not have signatures hence does not detect attacksro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.1.13
ivSysResetPasswordThis object is used to reset the password back to default value. Returns not-applicable(0) upon read.rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.1.14
ivSysDeleteSignaturesThis object is used to delete the signatures on the sensor if present. This also reboots the sensor after deleting the signatures. Does nothing if signatures are not present. Returns not-applicable(0) upon read.rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.1.15
ivSysSlaveSerialNumberManufacturer-provided slave serial number. This is the serial number for a cluster-slave in a palomar clusterro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.1.16
ivSysUIDSeedThis object contains the portion of the seed value to be used for generating UIDs' for alerts and logs. In case there is a mismatch, the ISM would set the right value, which would used by the sensor for new alerts and logs.rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.1.17
ivSysFipsModeThis Object holds the status of the fips mode.If the sensor is operating in FIPS mode then this Object will have enable value or else disable value.rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.1.18
ivSysNumLbPortsThis object is set by the NSM to inform the sensors connected to the Load Balancer(LB) of the number of ports on the LB switch.rw
Integer32
.1.3.6.1.4.1.8962.2.1.2.1.1.19
ivSysUpTimeNewThe time (in hundredths of a second) since the network management portion of the system was last re-initialized.ro
Counter64
.1.3.6.1.4.1.8962.2.1.2.1.1.20
ivSysCapacityModeTo push new license from NSMro
Counter64
.1.3.6.1.4.1.8962.2.1.2.1.1.21
ivSysCurrentCapacityModeTo get current license mode of sensorrw
Counter64
.1.3.6.1.4.1.8962.2.1.2.1.1.22
ivSysDeviceModeTo get current device modero
Counter64
.1.3.6.1.4.1.8962.2.1.2.1.1.23
ivSysConfDeviceModeTo get configured device modero
Counter64
.1.3.6.1.4.1.8962.2.1.2.1.1.24
ivSysRebootStatusIf a system reboot is required and Why REBOOT_DEFAULT_STATUS (0) // No Reboot Required REBOOT_UPGRADE_DOWNLOAD (1) REBOOT_SETUP_CHANGE (2) REBOOT_IPV6_CONFIG_CHANGE (3) REBOOT_SSL_MODE_CHANGE (4) REBOOT_JUMBOFRAMEPARSING_CONFIG_CHANGE (5) REBOOT_PREV_256BYTES_LOGGING_CONFIG_CHANGE (6) NMS_USERS_WRITE_ACCESS_CONFIG_CHANGE (7) REBOOT_LAYER7_DCAP_NUM_FLOWS_CHANGE (8) REBOOT_LAYER7_DCAP_BUFF_SIZE_CHANGE (9) REBOOT_LAYER7_DCAP_STATUS_CHANGE (10) REBOOT_SBC_CORE_INCREMENT_CONFIG_CHANGE (11) REBOOT_REQUIRED_MAX_SNMPD_RESTART_EXCEEDED (12) REBOOT_REQUIRED_SBC_TLV_ERROR (13) REBOOT_SNORT_CONFIG_CHANGE (15) REBOOT_CAPACITY_MODE_CHANGE (16) REBOOT_SSL_FLOWALLOC_CHANGE (17)ro
Counter64
.1.3.6.1.4.1.8962.2.1.2.1.1.25
ivSysRebootReasonThis object contains reason for the sensor reboot. NULL is stored in the object if reboot is not requiredro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.1.26
systemIPCfgGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.2
ivSysIPAddressThis object contains the IP Address of the management card on the IntruShield node, that interfaces with the EMS.ro
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.2.1
ivSysMACAddressThis object contains the MAC address of the management card on the IntruShield node.ro
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.2.2
ivSysSubnetMaskThis object specifies the Subnet mask of the management card on the IntruShield node.ro
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.2.3
ivSysGatewayThis object specifies the gateway address of the management card on the IntruShield node.ro
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.2.4
ivSysIPv6AddressThis object contains the IPv6 Address of the management card on the IntruShield node, that interfaces with the EMS.ro
Ipv6Address (IPV6-TC)
.1.3.6.1.4.1.8962.2.1.2.1.2.5
ivSysIpv6SubnetMaskThis object specifies the number of bits that need to set to '1' from left to right, int the Ipv6 address Subnet mask of the management card on the IntruShield node.ro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.2.6
ivSysIpv6GatewayThis object specifies the gateway Ipv6 address of the management card on the IntruShield node.ro
Ipv6Address (IPV6-TC)
.1.3.6.1.4.1.8962.2.1.2.1.2.7
ivSysVmHostIPAddressThis object contains the IP Address of the Vm Host on which VIPS will be running. This mib object will be available only on V-series sensors.ro
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.2.8
ivSysVmHostIPv6AddressThis object contains the IP Address of the Vm Host on which VIPS will be running. This mib object will be available only on v-series sensors.ro
Ipv6Address (IPV6-TC)
.1.3.6.1.4.1.8962.2.1.2.1.2.9
ivSysVmHostNameThis object contains the Vm Host name on which VIPS will be running. This mib object will be available only on V-series sensors.ro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.2.10
ivSysVmMgmtAdditionalInfoA textual string containing additional information about the management interface. This mib object will be available only on v-series sensors.ro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.2.11
systemFailoverGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.3
ivSysFailoverStatusIndicates if IDS peer is in peer-down or peer-up mode. Default: peer-down (2).ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.3.1
ivSysFailoverActionThis object is used to indicate if the sensor is in failover configuration or not. If the sensors are in failover configuration, then both sensors have to be set to on(1). Default: off(2)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.3.2
ivSysFailoverModeAdded for the I-3000/I-4010 sensors. This object is used to specify to the sensor if it is primary or secondary when failover is enabled. This value ( 1 or 2) must be set on the sensor prior to enabling failover. When failover is disabled, the sensor will automatically update this object to standalone (0). The manager can opt to explicitly set this after disabling failover on the sensor, however it is not necessary. Default: standalone(0), since failover is disabledrw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.3.3
ivSysFailopenActionThis object is used to indicate if the sensor should fail-open when in failover mode. Default: disable(2)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.3.4
ivSysSTPForwardConfigThis object is used to indicate if the sensor should forward the STP traffic through peer in failover mode. Default: disable(2)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.3.5
emsGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.4
emsTableThis table comprises of exactly two possible EMS entries each defined by <emsEntry>.
SEQUENCE OF EmsEntry
.1.3.6.1.4.1.8962.2.1.2.1.4.1
emsEntryEach entry specified is indexed by <emsIndex>. Additonaly it contains the <emsIPAddress> and <emsPriority>
EmsEntry
.1.3.6.1.4.1.8962.2.1.2.1.4.1.1
emsIndexFixed index for the two EMS entries. Valid values are [1,2] only.
Integer32
.1.3.6.1.4.1.8962.2.1.2.1.4.1.1.1
emsPriorityIdentifies whether the EMS identifed by the IPAddress is the Primary or Secondary. This value is only informational from sensor point of view and is set by the EMS when we have established connection to it. Note that transition at EMS from Primary to Secondary or vice versa will have no effect on the sensor. The only thing sensor needs to worry about while in MDR mode is the active/standby status.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.4.1.1.2
emsIPAddressIP Address of a EMS (in this entry).ro
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.4.1.1.3
emsHAModeIdentifies the MDR mode of the EMS. Initially when the system comes up this would be set to unknown till we contact the EMS and get its MDR status. This field also gets updated when a MDR-to-Standalone or Standalone-to-MDR action is triggered.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.4.1.1.4
emsHAStatusThis object specifies if the EMS is an active or a standby when operating in failover modero
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.4.1.1.5
emsAlertChannelStatusReturns the status of the alert channel connection with EMS identifed by the emsIPAddress of this entry.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.4.1.1.6
emsPacketLogChannelStatusReturns the status of the packet log channel connection with EMS identified by the emsIPAddress of this entry.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.4.1.1.7
emsIPv6AddressIPv6 Address of a EMS (in this entry).ro
Ipv6Address (IPV6-TC)
.1.3.6.1.4.1.8962.2.1.2.1.4.1.1.8
emsIPAddressTypeIdentifies the type of EMS IPAddress. If set to ip-v4, then the emsIPAddress object would be set else if this object is set to ip-v6, then the empIPv6Address object would be set.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.4.1.1.9
emsAuthChannelStatusReturns the status of the authentication channel connection with EMS identified by the emsIPAddress of this entry.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.4.1.1.10
emsChangeActionThis object is used to indicate to the sensor, changes in the EMS MDR operation mode.rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.4.2
emsParamIpAddressThis object is one of the parameters that need to be set before emsChangeAction is triggered. If the action is Switchover this specifies the IP address of the Manager that the sensor should switch to. If the action is Standalone-to-MDR this specifies the Peer EMS IP address and this will result in using a free entry in the emsTable. If the action is MDR-to-Standalone this specifies the future Standalone EMS IP address which should be one of the two EMSs specified in the emsTable. The acutal swithover or change in MDR opearation mode will be done when indicated by the Manager through the emsChangeAction object. Setting this object would reset the emsParamIpv6Address and emsParamAddIpv6Address objects.rw
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.4.3
emsParamPriorityThis object specifies the priority of the EMS setting the standalone-to-MDR change action.rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.4.4
emsParamAddIpAddressThis object specifies the secondary IP address of the EMS while in MDR mode. If the emsChangeAction is standalone-to-MDR, this specifies the secondary IP address of the new peer Manager. If the emsChangeAction is secondary NIC address, this specifies the secondary IP address of the EMS identified by emsParamIpAddress. Setting this object would reset the emsParamIpv6Address and emsParamAddIpv6Address objects.rw
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.4.5
emsParamIpv6AddressThis object is one of the parameters that need to be set before emsChangeAction is triggered. If the action is Switchover this specifies the IPv6 address of the Manager that the sensor should switch to. If the action is Standalone-to-MDR this specifies the Peer EMS IPv6 address and this will result in using a free entry in the emsTable. If the action is MDR-to-Standalone this specifies the future Standalone EMS IPv6 address which should be one of the two EMSs specified in the emsTable. The acutal swithover or change in MDR opearation mode will be done when indicated by the Manager through the emsChangeAction object. Setting this object would reset the emsParamIpAddress and emsParamAddIpAddress objects.rw
Ipv6Address (IPV6-TC)
.1.3.6.1.4.1.8962.2.1.2.1.4.6
emsParamAddIpv6AddressThis object specifies the secondary IPv6 address of the EMS while in MDR mode. If the emsChangeAction is standalone-to-MDR, this specifies the secondary IPV6 address of the new peer Manager. If the emsChangeAction is secondary NIC address, this specifies the secondary IPv6 address of the EMS identified by emsParamIpAddress. Setting this object would reset the emsParamIpAddress and emsParamAddIpAddress objects.rw
Ipv6Address (IPV6-TC)
.1.3.6.1.4.1.8962.2.1.2.1.4.7
emsTenantIdThis object specifies the TenantId. which identifies unique customer in Trellix eco systemrw
OCTET STRING
.1.3.6.1.4.1.8962.2.1.2.1.4.8
emsPrimaryNSMGUIDThis object specifies the Primary NSM Server GUID. which identifies unique NSM in Trellix eco systemrw
OCTET STRING
.1.3.6.1.4.1.8962.2.1.2.1.4.9
emsSecondaryNSMGUIDThis object specifies the Secondary NSM Server GUID. which identifies unique NSM in Trellix eco systemrw
OCTET STRING
.1.3.6.1.4.1.8962.2.1.2.1.4.10
tftpGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.5
tftpKeyThis specifies the tftp shared secret key between the IntruShield Sensor and EMS. Default: All 128 octets filled with '0'.rw
OCTET STRING
.1.3.6.1.4.1.8962.2.1.2.1.5.1
tftpFileSizeThe size of the file in bytes. Default: 0rw
Integer32
.1.3.6.1.4.1.8962.2.1.2.1.5.2
tftpFileNameThis specifies the name of the file to TFTP (with the source path)rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.5.3
tftpServerAddressTFTP server IP address. Is the EMS address when downloading from EMS to management card. Setting this object would reset the tftpServerIpv6Address objects.rw
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.5.4
tftpActionInvokes TFTP service using other (required) parameters defined in <tftpGrp>. Valid values are : (0)-other, (1)-downloadimage, (2)-downloadsigfile, (3)-uploaddos, (4)-uploadtrace, (5)-downloaddos, (6)-aborttransfer, (7)-downloadcertfile, (8)-downloadimageandsigfile, (9)-downloadmperootcertfile, (10)-download_sgap_ssl_cert, (11)-upload_sgap_ssl_csr, (12)-upload_ibac_ad_file, (13)-download_ibac_ad_file, (14)-upload_swh_learned_file, (15)-downloadPacketCaptureFilterFile ,(16)-uploadPacketCaptureFilterFile, (17)-downloadGeoLocationDatabase, (18)-uploadPacketCapturePCAPFile, (19)-download_usrid_acl_file, (20)-download-bot-dat-file, (21)-download-ntba-ssl-cert-file,(22)-upload-dev-prof-file, (25)-download_matd_ssl_cert, (28)-download-ffp-bulk-file, (33)-download_zcenter_ssl_cert, (34)-download-gti-private-cloud-cert-file, (35)-upload_suricata_failed_rules, (36)-upload_ca_sensor_csr, (37)-download_ca_sensor_cert, (38)-download_syslog_ssl_cert, (39)-download_ca_cert_storerw
TrellixTFTPAction (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.5.5
tftpActionStatusThe status of the current TFTP actionro
TrellixTFTPStatus (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.5.6
tftpActionInProgressResultSpecifies TFTP service completion percentage.ro
TrellixTFTPInProgressResult (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.5.7
tftpActionFailedResultSee TrellixTFTPFailedResultro
TrellixTFTPFailedResult (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.5.8
tftpActionTransactionIdUsed to ensure single file transfer at a time. Default: 0.rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.5.9
tftpServerIpv6AddressTFTP server IPv6 address. Is the EMS IPv6 address when downloading from EMS to management card. Either one of the Ipv4 or Ipv6 address should be set by the ISM. Setting this object would reset the tftpServerIpAddress objects.rw
Ipv6Address (IPV6-TC)
.1.3.6.1.4.1.8962.2.1.2.1.5.10
tftpIVKeyThis specifies the tftp Initialization Vector that is used for AES Decryption between the IntruShield Sensor and EMS. Default: All 128 octets filled with '0'.rw
OCTET STRING
.1.3.6.1.4.1.8962.2.1.2.1.5.11
chassisGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.7
temperatureStatusro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.7.1
fanStatusro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.7.2
primaryPowerSupplyStatusThis powerSupply MIB object gives the primary powerSupply status. (0) - Primary PowerSupply Module is not present. (1) - Primary PowerSupply Module is present and operational. (2) - Primary PowerSupply Module is present and its not operational. (3) - Error while retrieving the powerSupply status, please re-try after some time.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.7.3
secondaryPowerSupplyStatusThis powerSupply MIB object gives the secondary powerSupply status. (0) - Secondary PowerSupply Module is not present. (1) - Secondary PowerSupply Module is present and operational. (2) - Secondary PowerSupply Module is present and its not operational. (3) - Error while retrieving the powerSupply status, please re-try after some time.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.7.4
pciLegacyErrorStatusBMC PCI Legacy Error (parity error (PERR) and system error (SERR))ro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.7.5
pciFatalError1StatusBMC PCI Fatal Error1 Statusro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.7.6
pciFatalError2StatusBMC PCI Fatal Error2 Status (Continuation of Fatat Error 1)ro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.7.7
systemEventLogStatusBMC System Event Log (SEL buffer) Statusro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.7.8
bmcWatchdogStatusBMC Watchdog Statusro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.7.9
processorStatusTableThis table contain list of processors
SEQUENCE OF ProcessorStatusEntry
.1.3.6.1.4.1.8962.2.1.2.1.7.10
processorStatusEntryThe table entries denotes various processor details for each index (processor)
ProcessorStatusEntry
.1.3.6.1.4.1.8962.2.1.2.1.7.10.1
processorStatusProcessor Presence Statusro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.7.10.1.1
memoryECCStatusMemory ECC Statusro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.7.11
postSysEventStatusPOST Sys Event Statusro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.7.12
postErrorStatusPOST Error Statusro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.7.13
managementCardGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.8
mgmtCardTableThis table contains entries, one per management card, indexed by the appropriate slotIndex.
SEQUENCE OF MgmtCardEntry
.1.3.6.1.4.1.8962.2.1.2.1.8.1
mgmtCardEntryThis MIB object contains all the columnar objects, that describe the contents of each management card within the IntruShield node. This entry is indexed by a fixed value slotIndex of 1 (one) for all models.
MgmtCardEntry
.1.3.6.1.4.1.8962.2.1.2.1.8.1.1
mcActionActions applicable on this card, uses TC TrellixIDSAction. Default: other Only 'reset' and 'swupdate' action are supported.rw
TrellixIDSAction (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.8.1.1.1
mcActionStatusOutcome of a SNMP set on the mcAction object. Uses TC TrellixIDSActionStatus Default: otherro
TrellixIDSActionStatus (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.8.1.1.2
mcActionResultDetail information when <mcAction> is set to 'reset', based on <mcActionStatus> Default: 0, details not defined.ro
TrellixIDSActionResult (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.8.1.1.3
mcHwVersionThe manufacturer specified hardware version information. Typically indicated major, minor, patch information for version.ro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.8.1.1.4
mcCurrentSwVersionThe manufacturer specified software version information that is currently running. Typically indicated major, minor, patch information for version.ro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.8.1.1.5
mcFutureSwFileNameThe new software (image) file residing on flash.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.8.1.1.6
mcDateAndTimeSystem date and time set by EMS.rw
DateAndTime (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.8.1.1.7
slave-ChassisGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.9
slaveTemperatureStatusro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.9.1
slaveFanStatusro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.9.2
slavePrimaryPowerSupplyStatusThis powerSupply MIB object gives the primary powerSupply status. (0) - Slave Primary PowerSupply Module is not present. (1) - Slave Primary PowerSupply Module is present and operational. (2) - Slave Primary PowerSupply Module is present and its not operational. (3) - Error while retrieving the powerSupply status, please re-try after some time.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.9.3
slaveSecondaryPowerSupplyStatusThis powerSupply MIB object gives the secondary powerSupply status. (0) - Slave Secondary PowerSupply Module is not present. (1) - Slave Secondary PowerSupply Module is present and operational. (2) - Slave Secondary PowerSupply Module is present and its not operational. (3) - Error while retrieving the powerSupply status, please re-try after some time.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.9.4
sensorCardGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.10
sensorCardTableThis table contains entries, one per sensor card and indexed by the slotIndex.
SEQUENCE OF SensorCardEntry
.1.3.6.1.4.1.8962.2.1.2.1.10.1
sensorCardEntryThis MIB object contains all the columnar objects, that describe the contents of each sensor card within the Trellix IDS. This entry is indexed by a fixed value chassis slotIndex of 2 (two) for all models.
SensorCardEntry
.1.3.6.1.4.1.8962.2.1.2.1.10.1.1
scActionActions on this card. See TrellixIDSAction Default: other Only reset and sigupdate are supported.rw
TrellixIDSAction (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.10.1.1.1
scSigUpdateResultIndicates detail results of scAction object. Default: 0ro
TrellixIDSActionResult (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.10.1.1.2
scHwVersionThe manufacturer specified hardware version information. Typically indicated major, minor, patch information for version.ro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.10.1.1.3
scCurrentSwVersionThe manufacturer specified software version information that is currently running. Typically indicated major, minor, patch information for version.ro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.10.1.1.4
scFutureSwFileNameThe new software (image) file residing on flash.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.10.1.1.5
scCurrentSigVersionThe manufacturer specified signature file version information that is currently running. Typically indicated major, minor, patch information for version.ro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.10.1.1.6
scFutureSigFileNameThe new signature file residing on flash.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.10.1.1.7
scMACAddressReadOnly parameter, to allow SNMP manager to view the MAC address of this card.ro
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.10.1.1.8
scCurrentBotDATVersionThe manufacturer specified BotDAT file version information that is currently running.ro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.10.1.1.9
ipTableThis table contains entries that define the IP configuration objects per sensor card.
SEQUENCE OF IpEntry
.1.3.6.1.4.1.8962.2.1.2.1.10.6
ipEntryThis table entry contains the sensor card specific ( <slotIndex> based) IP configuration objects. This entry is indexed by a fixed value chassis slotIndex of 2 (two) for all models.
IpEntry
.1.3.6.1.4.1.8962.2.1.2.1.10.6.1
ipFragmentTimerIP fragment reassembly timer Default: 30 secondsrw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.10.6.1.1
ipOverlapOptionIf set to oldData(1), ip reassembly module takes old data. Otherwise it takes new data. Default: oldData (1)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.10.6.1.2
ipTTLConfigModeIf set to noTTLChecking(1), the TTL in the packet is not checked. If set to checkThreshold(2), then TTL is checked against the value in ipTTLThreshold object. If set to resetTTL(3), the TTL value is reset to the value set by ipTTLResetValue object. Default: noTTLChecking (1)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.10.6.1.3
ipTTLThresholdSpecifies the minimum threshold for the TTL value. The TTL in the packet is checked against the value configured here. If TTL is less than the value configured here, an alert is raised. Default: 32rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.10.6.1.4
ipTTLResetValueSpecifies the value that TTL should be reset to. Default: 32rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.10.6.1.5
ipSmallestFragmentSizeSpecifies the smallest fragment size that is acceptable. Any fragments smaller than the size specified here (other than the last one) will be counted and an alert raised if exceeds the threshold configured. The size should be multiple of 8. Default: 256rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.10.6.1.6
ipSmallFragmentThresholdCount of acceptable small fragments as specified by ipSmallestFragmentSize in 1 minute. Default: 10000rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.10.6.1.7
ipFragmentReassemblyOptionFlag to indicate if sensor should reassemble IP Framgments. Default: enablerw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.10.6.1.8
ipv6OverlapOptionIf set to oldData(1), ipv6 reassembly module takes old data. Otherwise it takes new data. Default: oldData (1)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.10.6.1.9
ipv6SmallestFragmentSizeSpecifies the smallest ipv6 fragment size that is acceptable. Any fragments smaller than the size specified here (other than the last one) will be counted and an alert raised if exceeds the threshold configured. The size should be multiple of 8. Default: 48rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.10.6.1.10
ipv6SmallFragmentThresholdCount of acceptable small fragments as specified by ipSmallestFragmentSize in 1 minute. Default: 10000rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.10.6.1.11
tcpTableThis table contains entries that define the TCP configuration objects per sensor card.
SEQUENCE OF TcpEntry
.1.3.6.1.4.1.8962.2.1.2.1.10.7
tcpEntryThis table entry contains the sensor card specific ( <slotIndex> based) TCP configuration objects. This entry is indexed by a fixed value chassis slotIndex of 2 (two) for all models.
TcpEntry
.1.3.6.1.4.1.8962.2.1.2.1.10.7.1
supportedUDPFlowsNumber of UDP flows supported. Deafult: 1 million, UDP and TCP combined. Default: 100000 for I4000, 25000 for I2600, 5000 for I1200, 10000 for I1400rw
Integer32
.1.3.6.1.4.1.8962.2.1.2.1.10.7.1.1
tcbInactivityTimerTCB inactivity timeout Default: 10 minutesrw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.10.7.1.2
tcpSegmentTimerTCP segment reassembly timer. Default: 60 secondsrw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.10.7.1.3
tcp2MSLTimerTCP 2MSL timer Default: 10 secondsrw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.10.7.1.4
inactiveFlowsRSTEnabledOption to RST incative flows enabled (TRUE) or not (FALSE). Default: FALSErw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.10.7.1.5
dropReTxTCPEnabledIntruShield may get TCP segments which have already been processed by it apriori (due to the segments being dropped in between it and the destination). By default, forward it without any processing, but provide the user with an option to drop such selectively retransmitted segments. This object enables the dropping of retransmitted TCP packets. Default: FALSErw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.10.7.1.6
coldStartTimeWhen sensor powers up, it will treat the packets for flows that did not exist without valid TCB as valid packets. After the time configured with this object, packets without valid flows are considered invalid packets. Default: 60minrw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.10.7.1.7
coldStartDropActionWhen this object is set to dropFlows(1), in inline mode sensor will drop the packets without valid TCB. When this object is set to forwardFlows(2), in inline mode sensor will forward the packets until coldStartTime. After that it will drop the packets without valid TCB. Default: forwardFlows(2)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.10.7.1.8
normalizationOnOffOptionEnable or Disable normalization Default: off(2)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.10.7.1.9
tcpOverlapOptionIf this object is set to oldData(1), tcp reassembly module will use the old data. Otherwise it will use the newer data. Default: newData(2)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.10.7.1.10
sAckPermittedOptionIf set to on, removes in SYN and clears in further packets. This applies only in inline mode.rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.10.7.1.11
tTCPOptionThresholdGenerate alert if too many. TBDrw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.10.7.1.12
dropOnPAWSFailIf set to enable, drop if fails PAWS test. If set to disable always forward the packet.rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.10.7.1.13
timestampEchoMatchFailIf set to enable, drop if TS-echo was one not sent earlier. If set to disable always forward the packet.rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.10.7.1.14
dropMD5OptionIf set to enable, drop packet if SYN=0 and it contains no MD5 but MD5 was used at setup. If set to disable always forward the packet.rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.10.7.1.15
unsolicitedUDPPacketsTimeoutIf a UDP response packet is received without a request packet, the packet will be dropped. This object configures the acceptable request to response time. Default: 60rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.10.7.1.16
synProxyEnableIf set to enable, sensor will do SYN proxy for every SYN request. SYN proxy is done only when TCP SYN flood is detected.rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.10.7.1.17
ackScanDiscardTimeThe time in which ACK scan messages should be discarded. Default 15 minutesrw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.10.7.1.18
halfOpenConnectionResetEnableResets either all or only DOS packets whose 3 Way Handshake has not finished. Default: Disable(1).rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.10.7.1.19
outOfContextTcpPktEnableUsed to en/dis able processing of out of context TCP packets. Enable aka PERMIT, Disable aka DENY, PERMIT_OUT_OF_ORDER(3), DENY-NO-TCB (4) aka PERMIT-ACL-MODE, STATELESS_INSPECTION (5). Default: PERMIT(1)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.10.7.1.20
synCookieConfigThis object specifies the directions in which to enable syn cookie when there is a SYN flood. This option is valid only for monitoring ports operating in inline mode. Default: 0rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.10.7.1.21
synCookieInboundThresholdThis object specifies the threshold value for the number of incomplete SYNs from outside network beyond which SYN cookie mechanism has to be enabled. Default: 4096rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.10.7.1.22
synCookieOutboundThresholdThis object specifies the threshold value for the number of incomplete SYNs from inside network beyond which SYN cookie mechanism has to be enabled. Default: 4096rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.10.7.1.23
synCookieMssThis object specifies the maximum segment size to be sent in SYN Ack, with SYN cookie mechanism enabled. Default: 536rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.10.7.1.24
sinkHoleTimeToLiveThis object specifies the TTL duration for sinkhole. TTL duration can range from 6 hours to 18 hours, Default: 12 hoursrw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.10.7.1.25
sinkHoleIpAddressThis object is used to configure IPv4 address of sinkhole. It can be any valid ip address apart from broadcast and multicast address. Default: 127.0.0.1rw
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.10.7.1.26
sessionTableSession table is used by user to configure TCP and UDP flows in the sensor.
SEQUENCE OF SessionEntry
.1.3.6.1.4.1.8962.2.1.2.1.10.8
sessionEntryIndexed with 5-tuple flow parameters and VIDS identifier. This table is used only to send sets to the sensor. Doing GET on this table will not return any information.
SessionEntry
.1.3.6.1.4.1.8962.2.1.2.1.10.8.1
sessionSrcIpAddressSource ip address.
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.10.8.1.1
sessionDestIpAddressDestination ip address.
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.10.8.1.2
sessionSrcPortNoSource port number.
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.10.8.1.3
sessionDestPortNoDestination port number.
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.10.8.1.4
sessionProtocolProtocol type.
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.10.8.1.5
sessionVIDSIdentifierVIDS identifier that owns this flow. If VIDS is not enabled, this oject will be ignored.
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.10.8.1.6
sessionConfigActionSetting this object to resetSession(1) causes the flow to be reset. Setting this object to logSession(2) causes the flow to be logged for the time specified with sessionLogTime object.rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.10.8.1.7
sessionLogTimeThe time for which the packet needs to be logged.rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.10.8.1.8
sessionIntfPortNoThe sensor linear interface port index on which the attack has been detected. This is mandatory when the sessionConfigAction is resetSession.rw
TrellixPortLinearIndex (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.10.8.1.9
sessionV6TableSession table v6 is used by user to configure TCP and UDP flows over Ipv6 in the sensor.
SEQUENCE OF SessionV6Entry
.1.3.6.1.4.1.8962.2.1.2.1.10.9
sessionV6EntryIndexed with 5-tuple flow parameters and VIDS identifier. This table is used only to send sets to the sensor. Doing GET on this table will not return any information.
SessionV6Entry
.1.3.6.1.4.1.8962.2.1.2.1.10.9.1
sessionSrcIpv6AddressSource ipv6 address.
Ipv6Address (IPV6-TC)
.1.3.6.1.4.1.8962.2.1.2.1.10.9.1.1
sessionDestIpv6AddressDestination ipv6 address.
Ipv6Address (IPV6-TC)
.1.3.6.1.4.1.8962.2.1.2.1.10.9.1.2
sessionv6SrcPortNoSource port number.
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.10.9.1.3
sessionv6DestPortNoDestination port number.
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.10.9.1.4
sessionv6ProtocolProtocol type.
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.10.9.1.5
sessionv6VIDSIdentifierVIDS identifier that owns this flow. If VIDS is not enabled, this oject will be ignored.
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.10.9.1.6
sessionv6ConfigActionSetting this object to resetSession(1) causes the flow to be reset. Setting this object to logSession(2) causes the flow to be logged for the time specified with sessionLogTime object.rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.10.9.1.7
sessionv6LogTimeThe time for which the packet needs to be logged.rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.10.9.1.8
sessionv6IntfPortNoThe sensor linear interface port index on which the attack has been detected. This is mandatory when the sessionConfigAction is resetSessionrw
TrellixPortLinearIndex (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.10.9.1.9
pluggableModuleStateIndicates the state of the pluggable modules in the system. Applicable for Rubicon models only. 32 bit starting from LSB, 4 bits for each slot starting from 2, will contain the moduleSysType enum => 0000 0000 0000 0000 0000 <slot4> <slot3> 0000.ro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.10.10
interfacePortGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.11
intfPortTableTable containing entries for each interface port (indexed via intfPortIndex) on each sensor card (indexed via appropriate slotIndex). This table contains Trellix specific configuration objects. Tables that contain MIB objects borrowed from MIB-II are in the TRELLIX-SENSOR-PERF-MIB.
SEQUENCE OF IntfPortEntry
.1.3.6.1.4.1.8962.2.1.2.1.11.1
intfPortEntryThis MIB object contains all the columnar objects, that describe the contents of each interface port on each IntruShield sensor card. Indexed by slotIndex/intfPortIndex
IntfPortEntry
.1.3.6.1.4.1.8962.2.1.2.1.11.1.1
intfPortIfDescrA textual string containing information about the interface. Returns the string that is printed on the box.ro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.11.1.1.1
intfPortIfTypeThe type of interface, distinguished according to the physical/link protocol(s) immediately 'below' the network layer in the protocol stack. For brevity, Trellix options are as specified by the TC, TrellixIDSPortType. However, the SNMP MIB-II - Interfaces MIB specifies many more valid options. See comments section for details.ro
TrellixIDSPortType (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.11.1.1.2
intfPortIfAdminStatusThe desired state of the interface. The testing(3) state indicates that no operational packets can be passed. Default: downrw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.11.1.1.3
intfPortIfOperStatusThe current operational state of the interface. The testing(3) state indicates that no operational packets can be passed. Default: downro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.11.1.1.4
intfPortOperatingModeReadWrite parameter specifies the operating mode for the Trellix IDS sensor to be used. Different modes supported are inline-fo-passive(1), non-inline or tap(2), span(3) and inlne-fc(4), inline-fo-active kit(5 - available on M-series only). Default: non-inlinerw
TrellixIDSOperatingMode (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.11.1.1.5
intfPortEnableFullDuplexTrue: Sets interface port to work as a full-duplex one. Otherwise as half-duplex. Default: Truerw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.11.1.1.6
intfPortFullDuplexPeerThis MIB object returns the intfPortIndex value of the interface port that is a peer. Used only when operating mode is inline(1) or monitor-dual-intf(2).ro
Integer32
.1.3.6.1.4.1.8962.2.1.2.1.11.1.1.7
intfPortSpeedGet current speed/negotiation on the interface.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.11.1.1.8
intfPortSpeedConfigSet desired speed/negotiation on the interface. Default values are as follows: I-Series - fixed-hundred-Mbps (infinity/hichborn/2x00(1a-3b) auto-gig-Mbps on 3000/4010/4000/2x00(4a,4b) M-Series - auto-ten-gig-Mbps on palomar/pyramid(1a-4b),auto-gig-Mbps(5a-8b) Default: see aboverw
TrellixPortSpeed -- was TrellixFEType, now deprecated
.1.3.6.1.4.1.8962.2.1.2.1.11.1.1.9
intfPortEnableInternalTapSet to TRUE to enable feature. Applies to Fast Ethernet (FE) ports only (see TrellixIDSPortType). For non FE ports, set to 'FALSE' . Setting this to 'TRUE' requires that <intfPortCurrentOperatingMode> is already set to 'monitor-dual-intf' Default: Truerw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.11.1.1.10
intfPortInOutTypeThis MIB object reflects the Input or Output labeling of this interface port. Used only when operating mode is inline(1) or monitor-dual-intf(2). Default: not-specified(3)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.11.1.1.11
intfGEPortSpeedConfigOnly applicable to gigabit-ethernet ports, to specify whether auto or 1 Gbps See TrellixGEType Default: 'auto-negotiate'rw
TrellixGEType (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.11.1.1.12
intfFailOpenSwitchStatusReturns the status of the external optical bypass switch status. For FE ports, this object will return not-applicable(1). For GE ports, if external optical bypass switch is connected to sensor ports, this will return present(2). Otherwise, it will return not-present(3).ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.11.1.1.13
intfFailOpenPortStatusReturns the packet forwarding status of the sensor ports connected to the optical bypass switch. If status is inline-fail-open(2), sensor is doing the forwarding. If status is bypass(3), the bypass switch is doing the forwarding and sensor will not process any traffic in this mode. Tap(4), absent(5) , unknown (6) and layer2-bypass(7) are available only in M-series for non RJ45(captive) ports when connected to active FO kit and sensor operating mode is inline-fail-open-active-kit. tap - operational status(up), kit(present), heart-beat(tap) absent - operational status(up), kit(absent), hear-beat(none) unknown - operational status(down), kit(absent), heart-beat(not available).ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.11.1.1.14
intfPortEnableAntiSpoofingspoofed packet detect rcvd on the both sides . Default: 'disable-bothsides-spoof-detect' (0)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.11.1.1.15
intfPortHostQRActionStatusThis object depicts the sensor level host quarantine and remediation action status for the specific interface port. The value 'quarantine' indicates just quarantine the host and the value 'remediate' indicates both quarantining and remediating the host. Default: disabledrwobsolete
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.11.1.1.18
intfPortMpeQRActionStatusThis object depicts the MPE respone based host quarantine and remediation action status for the specific interface port. The value 'mpeNotify' indicates just informing the MPE server about the problem host; the value 'mpeQuarantine' indicates first informing the MPE server about the problem host and then quarantine the host based on the response from the MPE-server and the MPE based Quarantine and Remediation scope mib object value; and the value 'mpeRemediate' indicates first informing the MPE server about the problem host and then remediating the host based on the response from the MPE-server and the MPE based Quarantine and Remediation scope mib object value. Default: disabledrwobsolete
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.11.1.1.19
intfPortAllowlistACLLookupStatusThis object indicates the status of allowlist ACL lookup for this interface port. Default: disabledrwobsolete
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.11.1.1.20
intfPortPeerDeviceAdvtStatusApplicable if sensor port is set to auto-negotiate, else other(0). Specifies the advertised speed-duplex of the peer appliance port connected to this sensor port.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.11.1.1.21
intfPortIsMcafeeConnectorTrue: connector is not inserted. True: connector is inserted in port and McAfee certified. False: connector is inserted and not McAfee certified.ro
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.11.1.1.22
intfPortAllowAnyConnectorTrue: Permit usage of any connector for port. False: Restrict usage to McAfee certified connector only. Default: Falserw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.11.1.1.23
intfPortCageTypePhysical connector cage type on sensor chassis panel.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.11.1.1.24
intfPortGetMediaTypeGets the media of the connector present in the port cage. None (0) if cage is empty.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.11.1.1.25
intfPortSetMediaTypeSets the media of the connector the user desired for the port. Default: opticalrw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.11.1.1.26
intfPortAdditionalInfoA textual string containing information about the interface. Typically returns connector specific information. For V-series sensors(vmips) this object will return monitoring ports label.ro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.11.1.1.27
intfPortMonPortIpAddressThis object is used to configure / retrieve the IPv4 address of the monitoring port. Default: 0.0.0.0rw
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.11.1.1.28
intfPortMonPortNetMaskThis object is used to configure / retrieve netmask for the IPv4 address of the monitoring port. Default: 0.0.0.0rw
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.11.1.1.29
intfPortGatewayIpAddressThis object is used to configure / retrieve the IPv4 address of the gateway. Default: 0.0.0.0rw
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.11.1.1.30
intfPortNbadConfigStatusThis object value if set to TRUE indicates that flow record generation to be sent to the NBAD server, is enabled over this monitoring port. Default: Falserw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.11.1.1.31
intfPortVlanIdThis MIB object indicates the Vlan ID of the VLAN to which the monitoring port is connected.rw
Integer32
.1.3.6.1.4.1.8962.2.1.2.1.11.1.1.32
intfPortAppIdStatsConfigStatusThis object value if set to TRUE indicates that the appId stats collection is enabled over this monitoring port. Default: Truerw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.11.1.1.33
intfPortConnectorTypePhysical connector type plugged into the port cage.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.11.1.1.34
intfPortLinearIndexThis MIB object indicates the Linear Index of the monitoring port. This index is generated by the sensor appliance using the pair of slot index and the port index values. The other MIB tables would directly use this linear index, whereever applicable.ro
TrellixPortLinearIndex (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.11.1.1.35
intfPortFecConfigThis object is used to configure FECrw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.11.1.1.36
intfPortTranceiverSerialNumberA textual string containing information about the interface. Typically returns transceiver's serial number.ro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.11.1.1.37
intfPortGBICHotSwapTimeIndicates time when the front end GBIC for any port was hot swapped last.ro
DateAndTime (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.11.2
responsePortGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.12
respPortTableTable containing entries for each response port (indexed via respPortIndex) on each sensor card (indexed via valid slotIndex). This table contains Trellix specific MIB objects.
SEQUENCE OF RespPortEntry
.1.3.6.1.4.1.8962.2.1.2.1.12.1
respPortEntryThis MIB object contains all the columnar objects, that describe the contents of each response port within the Trellix IDS sensor card. Indexed by slotIndex/respPortIndex
RespPortEntry
.1.3.6.1.4.1.8962.2.1.2.1.12.1.1
respPortDescrA textual string containing information about the interface. Returns the string that is printed on the box.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.12.1.1.1
respPortTypeThe type of interface, distinguished according to the physical/link protocol(s) immediately 'below' the network layer in the protocol stack. See TrellixIDSPortType.ro
TrellixIDSPortType (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.12.1.1.2
respPortAdminStatusThe desired state of the interface. Default: Uprw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.12.1.1.3
respPortOperStatusThe current operational state of the interface. The testing(3) state indicates that no operational packets can be passed.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.12.1.1.4
respPortEnableFullDuplexTrue: Sets response port to work as a full-duplex one. otherwise as half-duplex. If True, respPortFullDuplexPeer must be specified. Default: Falserw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.12.1.1.5
respPortSpeedSee TrellixPortSpeed Default: fixed-hundred-Mbps (2)rw
TrellixPortSpeed (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.12.1.1.6
respPortPktDestinationThis object is used when response ports are chosen for sending response packets. When router mode is chosen, packets will be sent to router with destination MAC as defined in intfRespMacAddress. Default value is switch (1).rw
SEQUENCE OF IntfRespEntry
.1.3.6.1.4.1.8962.2.1.2.1.12.1.1.7
respPortMacAddressSpecifies the macaddress of the router to which the response packets have to be sent to.rw
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.12.1.1.8
respCUGEPortSpeedOnly applicable to copper-gigabit-ethernet ports, to specify whether 10mbps or 100mbps or 1-gbps or auto-neg. See TrellixCUGEType Default: auto-negotiaterw
TrellixCUGEType (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.12.1.1.9
respAdditionalInfoA textual string containing additional information about the response interface. This mib object will be available only on V-series sensors.ro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.12.1.1.11
intfRespTableTable containing entries for each interface port. The table describes how responses have to be sent in monitoring mode.
Unknown
.1.3.6.1.4.1.8962.2.1.2.1.12.2
intfRespEntryIndexed by slotIndex/intfPortIndex
IntfRespEntry
.1.3.6.1.4.1.8962.2.1.2.1.12.2.1
intfRespTypeSetting this object to responsePort (2) causes responses to be sent via the response port. The response port no that needs to be used is specified with intfRespPortNo object. Setting this object to inline (3) causes responses to be sent inline. Note that in monitoring mode, responses can only be sent inline when the monitoring port is in half-duplex mode. Default action will be responsePort (1).rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.12.2.1.1
intfRespPortNoSpecifies the response port number that needs to be used for this monitoring port. The response ports are configured by respPortTable.rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.12.2.1.2
dosConfigGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.14
dosLearningModeActionThis object can be used to switch the mode to DOS learning or force detection mode . The saved profile can be reloaded by setting the object to reloadProfile(3). When set to forceDetection (1), user must be warned as follows, Warning: You are about to force the sensor into Detection Mode before the required 48-hour learning period. The traffic profile learned by the sensor may not be adequate for DOS attack detection and prevention. It is desirable to place the sensor in learning mode while receiving normal traffic for at least 48 hours.rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.14.1
dosProfileTableTable defines profile data for each DOS VPT entry.
SEQUENCE OF DosProfileEntry
.1.3.6.1.4.1.8962.2.1.2.1.14.2
dosProfileEntryIndexed by VIDS ID and Profile ID.
DosProfileEntry
.1.3.6.1.4.1.8962.2.1.2.1.14.2.1
dosProfileVidsIdThe virtual admin domain identifier.
Unsigned32
.1.3.6.1.4.1.8962.2.1.2.1.14.2.1.1
dosProfileIdThe identifier of the profile.
Unsigned32
.1.3.6.1.4.1.8962.2.1.2.1.14.2.1.2
dosProfileStatusThe status of the profile entry.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.14.2.1.3
dosProfileLearningTimeThe time (in hundredths of a second) since learning was started for the profile.ro
Unsigned32
.1.3.6.1.4.1.8962.2.1.2.1.14.2.1.4
dosProfileBulkTableTable defines profile data for each DOS VPT entry. This table is primarily used to get the GETNEXT and GETBULK.
SEQUENCE OF DosProfileBulkEntry
.1.3.6.1.4.1.8962.2.1.2.1.14.3
dosProfileBulkEntryIndexed by profile index.
DosProfileBulkEntry
.1.3.6.1.4.1.8962.2.1.2.1.14.3.1
dosProfileBulkIndexThe index of the profile table.
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.14.3.1.1
dosProfileBulkVidsIdThe virtual admin domain identifier.ro
Unsigned32
.1.3.6.1.4.1.8962.2.1.2.1.14.3.1.2
dosProfileBulkIdThe identifier of the profile.ro
Unsigned32
.1.3.6.1.4.1.8962.2.1.2.1.14.3.1.3
dosProfileBulkStatusThe status of the profile entry.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.14.3.1.4
dosProfileBulkLearningTimeThe time (in hundredths of a second) since learning was started for the profile.ro
Unsigned32
.1.3.6.1.4.1.8962.2.1.2.1.14.3.1.5
dosProfileShortAndLongTermTableTable defines short term and long term profile data per DOS measure per VPT. Each VPT is indexed by the global VIDSID, global NIId.
SEQUENCE OF DosProfileShortAndLongTermEntry
.1.3.6.1.4.1.8962.2.1.2.1.14.4
dosProfileShortAndLongTermEntryIndexed by global VIDSIndex, global NIIndex & measureId.
DosProfileShortAndLongTermEntry
.1.3.6.1.4.1.8962.2.1.2.1.14.4.1
dosProfileShortAndLongTermVIDSIndexThe VIDS id index.
Unsigned32
.1.3.6.1.4.1.8962.2.1.2.1.14.4.1.1
dosProfileShortAndLongTermNIIndexThe NI id index.
Unsigned32
.1.3.6.1.4.1.8962.2.1.2.1.14.4.1.2
dosProfileShortAndLongTermMeasureIndexThe measure id index.
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.14.4.1.3
dosProfileShortAndLongTermBinCountThe count indicates the number of short or long term values to be interpreted in their respective content objects. Max value is 32. If the value is set to 10, then only the first 80 bytes in each of the strings have valid data. Note: that 256 octet strings can accomodate a max of 32 values (3 octects each)ro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.14.4.1.4
dosProfileShortTermContentThis specifies the short term profile data. Default: All 256 octets filled with '0'.ro
OCTET STRING
.1.3.6.1.4.1.8962.2.1.2.1.14.4.1.5
dosProfileLongTermContentThis specifies the long term profile data. Default: All 256 octets filled with '0'.ro
OCTET STRING
.1.3.6.1.4.1.8962.2.1.2.1.14.4.1.6
enableDosPktLoggingThis object can be used to turn on/off the logging od DOS packets. Default: disable (2).rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.14.6
timedDosPktDropTableTable defines action and duration to enable/disable/extend the duration for which DOS pkts are to be drpped. Also provides the absolute time remaining till when it the sensor will drop these packets.
SEQUENCE OF TimedDosPktDropEntry
.1.3.6.1.4.1.8962.2.1.2.1.14.7
timedDosPktDropEntryIndexed by VIDS ID NI ID and MeasureId.
TimedDosPktDropEntry
.1.3.6.1.4.1.8962.2.1.2.1.14.7.1
timedDosPktDropVidsIdIndexThe Vids identifier.
Unsigned32
.1.3.6.1.4.1.8962.2.1.2.1.14.7.1.1
timedDosPktDropNiIdIndexThe NI identifier.
Unsigned32
.1.3.6.1.4.1.8962.2.1.2.1.14.7.1.2
timedDosPktDropMsrIdIndexThe MeasureId identifier.
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.14.7.1.3
timedDosPktDropActionThe action tells the bulkTimedDosPktDropTable to add(enable the duration for), delete(disable), modify(extend the duration for) an entry.rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.14.7.1.4
timedDosPktDropDurationThe duration for which the DOS pkt drop has been enabled or extended.rw
Unsigned32
.1.3.6.1.4.1.8962.2.1.2.1.14.7.1.5
timedDosPktDropEndTimeThe absolute end time when the duration for intended action expires.ro
Unsigned32
.1.3.6.1.4.1.8962.2.1.2.1.14.7.1.6
bulkTimedDosPktDropTableTable lists entries indexed by the bulkTimedDosPktDropIndex, each returns the corresponding VidsId, NiId, MeasureId and the EndTime value.
SEQUENCE OF BulkTimedDosPktDropEntry
.1.3.6.1.4.1.8962.2.1.2.1.14.8
bulkTimedDosPktDropEntryIndexed by bulk index.
BulkTimedDosPktDropEntry
.1.3.6.1.4.1.8962.2.1.2.1.14.8.1
bulkTimedDosPktDropIndexThe bulk index .
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.14.8.1.1
bulkTimedDosPktDropVidsIdThe Vids identifier.ro
Unsigned32
.1.3.6.1.4.1.8962.2.1.2.1.14.8.1.2
bulkTimedDosPktDropNiIdThe NI identifier.ro
Unsigned32
.1.3.6.1.4.1.8962.2.1.2.1.14.8.1.3
bulkTimedDosPktDropMsrIdThe MeasureId identifier.ro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.14.8.1.4
bulkTimedDosPktDropEndTimeThe absolute end time when the duration for intended action expires.ro
Unsigned32
.1.3.6.1.4.1.8962.2.1.2.1.14.8.1.5
internalVLANIdThis object identifies the VLAN ID to be used by the sensor to tag any untagged pkts on Rx, and untag them on Tx. It must not match any other VLAN ID assigned for the customer network. Default: 4095rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.14.9
pktLogGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.15
pktLogServerIPAddressIP Addressrw
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.15.1
pktLogServerPortTCP Port on which the pkt log server can receive packet logs from the IntruShield IDS.rw
Integer32
.1.3.6.1.4.1.8962.2.1.2.1.15.2
pktLogMaxPacketsPerFlowNumber of packets per flow which need to be logged, 0 means log entire flow. Default: 1000rw
Integer32
.1.3.6.1.4.1.8962.2.1.2.1.15.3
pktLogEncryptionEnableThis object can be used to enable encryption of packet log channel. RC4 will be used for encryption. Default: enable (1)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.15.4
pktLogServerIPv6AddressIPv6 Address of the ISM to which the logs need to be delivered. ISM should set either the Ipv4 or the Ipv6 address.rw
Ipv6Address (IPV6-TC)
.1.3.6.1.4.1.8962.2.1.2.1.15.5
pktAlertThrottleGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.16
pktAlertThrottleGlobalThresholdOnce this threshold is exceeded, sensor will only send one summary alert for all addresses (srcip's and destip's) that match the attackid/vidsid. Default: 10rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.16.1
pktAlertThrottleIntervalIf the number of alerts exceeds the amount configured in pktAlertThrottleThreshold or pktAlertThrottleGlobalThreshold in pktAlertThrottleInterval seconds, alerts will be throttled. Units are in seconds. Default: 120 secondsrw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.16.2
pktAlertThrottleActionThis object can be used to enable and disable alert throttling. Default: enable(1)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.16.3
pktAlertThrottleThresholdThis object is used to configure the number of alerts that need to be sent before sensor starts to throttle the alerts. For example if this value is 10, it will send the first 10 alerts with the following key: attackid/vidsid/srcip/destip. This parameters will use the pktAlertThrottleInterval as the interval. Default: 5rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.16.4
pktAlertCorrelationTimeThis object is used to configure the time that the sensor will correlate multiple signatures for a single attack and only send the signature with the lowest benign trigger probability. Default: 5 secsrw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.16.5
sslConfigGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.17
sslSessionCacheLifetimeDuration in minutes for which the SSL Session is kept alive, inspite of no SSL data transfer between the client/server . Default: 5rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.17.1
sslSupportActionThis object can be used to enable support for specific ssl flow count (non 0) and disable SSL (0) on sensor. Sensor reboot is typically required to activate support of requested flow count. EMS must check for max requested ssl flows based on product type: I4000: 100K, I2600: 25K , I1200: not supported. Default: not supported (0)rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.17.2
sslSupportStatusThis object can be used to get SSL support status on sensor. It will show 0 if disabled, or a non 0 value indicating the ssl flow count currently supported. User must reboot sensor to ensure that requested flow count is actually supported by sensor. EMS must check for max supported ssl flows based on product type: I4000: 100K, I2600: 25K , I1200: not supported. Default: not supported (0)ro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.17.3
sslSessionRemoveCertsDelete all ssl certs, thereby terminating decryption of related ssl traffic, but leave ssl support enabled within sensor.rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.17.4
sslPktLoggingEnableSpecifies if sensor should log decrypted SSL packets or not. Default: 2, disabledrw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.17.5
sslModesofOperationDetermines the SSL decryption direction and method. disable(0) - No SSL decryption performed for traffic. inbound known key only(1) - Only Inbound SSL decryption using RSA key exchange. outbound proxy only(2) - Only Outbound SSL using MITM proxy inbound proxy only(3) - Only Inbound SSL using MITM Proxy inbound and outbound proxy(4) - Inbound and Outbound proxy using MITM Proxy inbound known key and outbound proxy(5) - Inbound using RSA key exchange and Outbound using MITM Proxy Default: disable (0)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.17.6
sslSessionCacheLifetimeOutboundDuration in minutes for which the SSL Session is kept alive, inspite of no SSL data transfer between the client/server. This setting will be applied for SSL traffic in Outbound direction. This is not applicable on I-series and M-series Default: 5rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.17.7
sslPktLoggingOutboundEnableSpecifies if sensor should log decrypted SSL packets or not on the Outbound direction. This is not applicable on I-series and M-series Default: 2, disabledrw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.17.8
sslProxyOutboundUnknownServerCertificateThis object will be used to configure the action that the sensor will need to take when the sensor is unable to verify the validaity of the certificate. This is not applicable on I-series and M-series Default: decrypt(3)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.17.9
sslProxyOutboundUntrustedServerCertficateThis object will be used to configure the action that the sensor will need to take when the sensor receives an untrusted certificate from the external server. This could be either due to certificate not being trusted by any root CA, expired, revoked etc. This is not applicable on I-series and M-series Default: decrypt (3)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.17.10
sslProxyOutboundUnsupportedCipherSuiteThis object will be used to configure the action that the sensor will need to take when an internal client sends a list of ciphers and the sensor does not support any of the cipher suite This is not applicable on I-series and M-series Default: ignore (1)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.17.11
sslProxyInboundUnsupportedCipherSuiteThis is reserved for future used. This object is not currently implemented. This object will be used to configure the action that the sensor will need to take when an external client sends a list of ciphers and the sensor does not support any of the cipher suite This is not applicable on I-series and M-series Default: ignore (1)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.17.12
sslProxyOutboundUnsupportedServerCertificateThis object will be used to configure the action that the sensor will need to take when the sensor encounters an unsupported server certificate in an outbound direction. This is not applicable on I-series and M-series Default: ignore (1)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.17.13
sslProxyInboundUnsupportedServerCertificateThis is reserved for future used. This object is not currently implemented. This object will be used to configure the action that the sensor will need to take when the sensor encounters an unsupported server certificate in an inbound direction. This is not applicable on I-series and M-series Default: ignore (1)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.17.14
maxSslFlowSupportedInSslDisableModeThis object specifies the max number of SSL flows supported when SSL is disabled on the sensor.ro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.17.15
maxFlowSupportedInSslDisableModeThis object specifies the max number of flows supported by sensor when SSL is disabled on the sensor.ro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.17.16
maxSslFlowSupportedInSslInboundLegacyModeThis object specifies the max number of SSL flows supported when SSL is enabled in inbound legacy mode.ro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.17.17
maxFlowSupportedInSslInboundLegacyModeThis object specifies the max number of flows supported by sensor when SSL is enabled in inbound legacy modero
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.17.18
maxSslFlowSupportedInSslOutboundModeThis object specifies the max number of SSL flows supported when SSL is enabled in outbound mode.ro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.17.19
maxFlowSupportedInSslOutboundModeThis object specifies the max number of flows supported by sensor when SSL is enabled in outbound modero
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.17.20
sslModesofOperationStatusProvides current SSL decryption method used in Sensor for inbound traffic. disable(0) - No SSL decryption performed for traffic. inbound known key only(1) - Only Inbound SSL decryption using RSA key exchange. outbound proxy only(2) - Only Outbound SSL using MITM proxy inbound proxy only(3) - Only Inbound SSL using MITM Proxy inbound and outbound proxy(4) - Inbound and Outbound proxy using MITM Proxy inbound known key and outbound proxy(5) - Inbound using RSA key exchange and Outbound using MITM Proxy Default: disable (0)ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.17.21
sslProxyOutboundUnknownURLCategoryThis object will be used to configure the action that the sensor will need to take when the sensor identifies an unknown url category in the ssl packet. This configuration is only supported in case of outbound ssl. This is not applicable on I-series and M-series Default: ignore (1)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.17.22
sslShKeyDecryptEnableSpecifies if sensor should decrypt using shared keys from SSL probes. Default: 2, disabledrw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.17.23
l2ConfigGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.18
l2ModeEnableThis specifies if sensor is configured to detect failure and go into L2 mode on exceeding cfg threshold within cfg duration. Default: 2, disabledrw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.18.1
l2ModeStatusThis object identifies the mode the sensor is currently in.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.18.2
l2ModeCfgDurationThis object specifies the time duration input criteria for enabling the sensor in layer2 mode. Default: 10 minsrw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.18.3
l2ModeCfgThresholdThis object specifies the event frequency input criteria for enabling the sensor in layer2 mode. Default: 1rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.18.4
l2ModeOccCountThis object identifies the frequency of event occurence when ensor was last enabled in layer2 mode.ro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.18.5
l2ModeReasonThis object contains reason for sensor to enter into Layer-2 mode.ro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.18.6
aclLogAlertGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.19
aclAlertLoggingThis object specifies various ways to enable ACL Alert logging or disable it altogether. This is applicable on a sensor wide basis for all ports in inline mode. Default: disable (5)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.19.1
aclAlertThrottleMaxIpPairOnce this threshold is exceeded, sensor will only send one summary acl alert for all addresses (srcip's and destip's) that match the aclid/vidsid. Default: 10rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.19.2
aclAlertThrottleIntervalIf the number of acl alerts exceeds the amount configured in aclAlertThrottleThreshold in aclAlertThrottleInterval seconds, alerts will be throttled. Units are in seconds. Default: 120 secondsrw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.19.3
aclAlertThrottleActionThis object can be used to enable and disable acl alert throttling. Default: enable(1)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.19.4
aclAlertThrottleThresholdThis object is used to configure the number of alerts that need to be sent before sensor starts to throttle the alerts. For example if this value is 10, it will send the first 10 alerts with the following key: aclid/vidsid/srcip/destip. This parameters will use the aclAlertThrottleInterval as the interval. Default: 5rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.19.5
aclAlertDirectToSyslogThis object can be used to enable sending acl logs directly to syslog viewer instead of sending it via NSM. Default: sendViaNSM (1)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.19.6
tacacsPlusAuthGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.20
enableTacacsPlusAuthThis object can be used to enable or disable user authentication & accounting using TACACS+. Default: disable (2)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.20.1
enableTacacsPlusTrafficEncrThis object can be used to enable or disable encryption of TACACS+ traffic. Default: disable (2)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.20.2
tacacsPlusEncrSecretThis object specifies the secret to be used in generating the encrypted TACACS+ trafficrw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.20.3
tacacsPlusServerIPTableThis table contains entries that specifiy the IP addresses of the TACACS+ servers
SEQUENCE OF TacacsPlusServerIPEntry
.1.3.6.1.4.1.8962.2.1.2.1.20.4
tacacsPlusServerIPEntryThis table entry specifies the IP address of the TACACS+ server
TacacsPlusServerIPEntry
.1.3.6.1.4.1.8962.2.1.2.1.20.4.1
tacIndexFixed index for the four TACACS+ Server entries. Valid values are [1,2,3,4] only.
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.20.4.1.1
tacacsPlusServerIPAddrThis object specifies the IP Address of the TACACS+ serverrw
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.20.4.1.2
enableTacacsPlusAuthorizationTo enable TACACS Plus authorizationrw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.20.5
ipV6ConfigGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.21
ipV6TrafficHandlingThis object can be used to specify how the IPv6 traffic is handled on all ports of a sensor. dont-parse-block-inline - Traffic will not be subjected to IPS/IDS. On Inline ports, traffic will be blocked. dont-parse-allow-inline - Traffic will not be subjected to IPS/IDS. On Inline ports , traffic wll be allowed to go through the sensor. parse-and-detect-attacks - Parse and detect attacks in IPv6 traffic and pass the traffic on inline ports Default: dont-parse-allow-inline(2)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.21.2
hostQGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.22
hostQConfigGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.22.1
hostQFilterTimeOutThe number of minutes for which this entry should be in affect. Default: 5 minutesrwobsolete
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.22.1.1
hostQDeleteAllFiltersIf set to not-applicable(0), applied filters are not deleted. If set to true (1) all filters are deleted. Default: not-applicable (0)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.22.1.2
hostQBulkFilterV4TableTable containing entries for filters that are applied on the \ sensor in Inline mode. This table supports only GET-NEXT operations
SEQUENCE OF HostQBulkFilterV4Entry
.1.3.6.1.4.1.8962.2.1.2.1.22.2
hostQBulkFilterV4EntryIndexed by sequence number.
HostQBulkFilterV4Entry
.1.3.6.1.4.1.8962.2.1.2.1.22.2.1
hostQBulkFilterIndexV4Index which uniquely identifies the V4 filter rulero
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.22.2.1.1
hostQBulkFilterSrcIPAddrV4Source IPV4 Address.ro
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.22.2.1.2
hostQBulkFilterVidsIdV4This objects returns the vids id for which this filter was applied.ro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.22.2.1.3
hostQBulkFilterAttackIdV4This objects returns the attack id for which this filter was applied.ro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.22.2.1.4
hostQBulkFilterEndTimeV4This objects returns the filter expiry time in UTC formatro
Unsigned32
.1.3.6.1.4.1.8962.2.1.2.1.22.2.1.5
hostQBulkFilterQRStatusV4This objects returns the host quarantine and remediation action status.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.22.2.1.6
hostQBulkFilterMPEReplyMsgV4This objects returns the message returned by the MPE server.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.22.2.1.7
hostQBulkFilterMonPortIdV4This objects returns the monitoring linear port index on which the attack was detected for the quarantined host.ro
TrellixPortLinearIndex (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.22.2.1.8
hostQBulkFilterEZIdV4This objects returns the applied NAZ Id for the quarantined host.ro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.22.2.1.9
hostQBulkFilterV6TableTable containing entries for IPv6 filters that are applied on the sensor in Inline mode.
SEQUENCE OF HostQBulkFilterV6Entry
.1.3.6.1.4.1.8962.2.1.2.1.22.3
hostQBulkFilterV6EntryIndexed by sequence number.
HostQBulkFilterV6Entry
.1.3.6.1.4.1.8962.2.1.2.1.22.3.1
hostQBulkFilterIndexV6Index which uniquely identifies the IPv6 filter rule.ro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.22.3.1.1
hostQBulkFilterSrcIPAddrV6Source IPV6 Address.ro
Ipv6Address (IPV6-TC)
.1.3.6.1.4.1.8962.2.1.2.1.22.3.1.2
hostQBulkFilterVidsIdV6This objects returns the vids id for which this filter was applied.ro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.22.3.1.3
hostQBulkFilterAttackIdV6This objects returns the attack id for which this filter was applied.ro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.22.3.1.4
hostQBulkFilterEndTimeV6This objects returns the filter expiry time in UTC format.ro
Unsigned32
.1.3.6.1.4.1.8962.2.1.2.1.22.3.1.5
hostQBulkFilterQRStatusV6This objects returns the host quarantine and remediation action status.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.22.3.1.6
hostQBulkFilterMPEReplyMsgV6This objects returns the message returned by the MPE server.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.22.3.1.7
hostQBulkFilterMonPortIdV6This objects returns the monitoring linear port index on which the attack was detected for the quarantined Ipv6 host.ro
TrellixPortLinearIndex (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.22.3.1.8
hostQNeverDenyV4TableTable defines ipaddresses from which traffic is never blocked. Typically user will add all the critical network elements like routers, servers, etc.obsolete
SEQUENCE OF HostQNeverDenyV4Entry
.1.3.6.1.4.1.8962.2.1.2.1.22.4
hostQNeverDenyV4EntryIndexed by hostQNeverDenyIpAddress. Supports up to 100 entries.obsolete
HostQNeverDenyV4Entry
.1.3.6.1.4.1.8962.2.1.2.1.22.4.1
hostQNeverDenyIpAddressV4The ipV4 address from which traffic will never be blocked.obsolete
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.22.4.1.1
hostQNeverDenyActionV4This object is to user to add and delete rows in to the table.rwobsolete
RowStatus (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.22.4.1.2
hostQNeverDenyV6TableTable defines ipaddresses from which traffic is never blocked. Typically user will add all the critical network elements like routers, servers, etc.obsolete
SEQUENCE OF HostQNeverDenyV6Entry
.1.3.6.1.4.1.8962.2.1.2.1.22.5
hostQNeverDenyV6EntryIndexed by hostQNeverDenyIpAddress. Supports up to 100 entries.obsolete
HostQNeverDenyV6Entry
.1.3.6.1.4.1.8962.2.1.2.1.22.5.1
hostQNeverDenyIpAddressV6The ipV6 address from which traffic will never be blocked.obsolete
Ipv6Address (IPV6-TC)
.1.3.6.1.4.1.8962.2.1.2.1.22.5.1.1
hostQNeverDenyActionV6This object is to user to add and delete rows in to the table.rwobsolete
RowStatus (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.22.5.1.2
hostQUserDefFilterV4TableTable is used to add/delete/extend IPv4 filters on the sensor
SEQUENCE OF HostQUserDefFilterV4Entry
.1.3.6.1.4.1.8962.2.1.2.1.22.6
hostQUserDefFilterV4Entry
HostQUserDefFilterV4Entry
.1.3.6.1.4.1.8962.2.1.2.1.22.6.1
hostQUserDefFilterSrcIpV4Source IPV4 address.
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.22.6.1.1
hostQUserDefFilterVidsIdV4Vids ID.
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.22.6.1.2
hostQUserDefFilterAttackIdV4Attack ID.
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.22.6.1.3
hostQUserDefFilterDurationV4Filter durationrw
Unsigned32
.1.3.6.1.4.1.8962.2.1.2.1.22.6.1.4
hostQUserDefFilterActionV4Setting this object to add(1) will add the entry.rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.22.6.1.5
hostQUserDefFilterRemediationV4Setting this object to TRUE, will enable host rememdiation for the user defined quarantine rule. Default : FALSErw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.22.6.1.6
hostQUserDefFilterV6TableTable is used to add/delete/extend IPv6 filters on the sensor
SEQUENCE OF HostQUserDefFilterV6Entry
.1.3.6.1.4.1.8962.2.1.2.1.22.7
hostQUserDefFilterV6Entry
HostQUserDefFilterV6Entry
.1.3.6.1.4.1.8962.2.1.2.1.22.7.1
hostQUserDefFilterSrcIpV6Source IPV6 address.
Ipv6Address (IPV6-TC)
.1.3.6.1.4.1.8962.2.1.2.1.22.7.1.1
hostQUserDefFilterVidsIdV6Vids ID.
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.22.7.1.2
hostQUserDefFilterAttackIdV6Attack ID.
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.22.7.1.3
hostQUserDefFilterDurationV6Filter durationrw
Unsigned32
.1.3.6.1.4.1.8962.2.1.2.1.22.7.1.4
hostQUserDefFilterActionV6Setting this object to add(1) will add the entry.rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.22.7.1.5
nmsGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.23
nmsUserGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.23.1
nmsUserTable
SEQUENCE OF NMSUserEntry
.1.3.6.1.4.1.8962.2.1.2.1.23.1.1
nmsUserEntryEach entry specified is indexed by <nmsUserIndex>. Additonaly it contains the
NMSUserEntry
.1.3.6.1.4.1.8962.2.1.2.1.23.1.1.1
nmsUserNameUserName nms (in this entry).
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.23.1.1.1.1
nmsAuthKeyNMS Auth Keyrw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.23.1.1.1.2
nmsEncrKeyNMS Encryption Key.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.23.1.1.1.3
nmsUserChangeActionThis object used for user to add and delete rows in to the tablerw
RowStatus (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.23.1.1.1.4
nmsDeleteAllUsersThis action object deletes all user entries in the nmsUserTable.rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.23.1.2
nmsCommitUserEntryChangesThis action object commits all the changes made to the user entries in the nmsUserTable.rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.23.1.3
nmsIpGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.23.2
nmsIpTable
SEQUENCE OF NMSIpEntry
.1.3.6.1.4.1.8962.2.1.2.1.23.2.1
nmsIpEntryEach entry specified is indexed by <nmsIpIndex>. Additonaly it contains the
NMSIpEntry
.1.3.6.1.4.1.8962.2.1.2.1.23.2.1.1
nmsIpAddressUserName nms (in this entry).
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.23.2.1.1.1
nmsIpChangeActionThis object used for user to add and delete rows in to the table.rw
RowStatus (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.23.2.1.1.2
nmsIpv6Table
SEQUENCE OF NMSIpv6Entry
.1.3.6.1.4.1.8962.2.1.2.1.23.2.2
nmsIpv6EntryEach entry specified is indexed by <nmsIpv6Index>.
NMSIpv6Entry
.1.3.6.1.4.1.8962.2.1.2.1.23.2.2.1
nmsIpv6AddressIPv6 address of the system having SNMP access to the sensor
Ipv6Address (IPV6-TC)
.1.3.6.1.4.1.8962.2.1.2.1.23.2.2.1.1
nmsIpv6ChangeActionThis object used for user to add and delete rows in to the table.rw
RowStatus (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.23.2.2.1.2
mpeGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.24
mpeConfigGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.24.1
mpeQRScopeThis object describes about the MPE Quarantine and Remediation scope. The value 'unmanaged-hosts', indicates that the MPE interface port based quarantine and remediation action is applicable only to the MPE server's unmanaged host and the value 'all-hosts' indicate that the MPE interface port based qarantine and remediation action is applicable to all the hosts, independent of MPE server. Default: unmanaged-hosts(1)rwobsolete
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.24.1.1
mpeThrottleTimeoutThis depicts the MPE throttling timeout in seconds. Default: 120rwobsolete
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.24.1.2
mpeInstallConfigGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.24.1.3
mpeIpAddressThe ipaddress of the MPE serverrw
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.24.1.3.1
mpeAnonymousPortThe Anonymous SSL port on MPE server Default: 8443rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.24.1.3.2
mpeTrustedSSLPortThe Trusted SSL port on MPE server Default: 8444rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.24.1.3.3
mpeePOCredePO credentials in the form of username:passwordrw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.24.1.3.4
mpeAnonymousURIURI of the MPE server which listens on Anonymous SSL portrw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.24.1.3.5
mpeTrustedURIURI of the MPE server which listens on Trusted SSL portrw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.24.1.3.6
mpeInstallConfigActionThis object describes about the possible MPE Install configuration actions.rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.24.1.3.7
mpeInstallConfigStatusThis describes the possible MPE install configuration states. Default : deinstalled (4)ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.24.1.3.8
mpeRootCertStatusThis object informs whether the MPE Root Certificate file is present on the sensor.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.24.1.4
mpeDeleteRootCertThis object is used to remove the MPE Root Certificate from the sensor. Deletion of the MPE root certificate succeeds only when the MPE is not yet installed.rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.24.1.5
mnacHealthLevelListenPortThis object is used to configure/retrieve the trusted health level message listen port on the sensor, on which MNAC communication happens asynchronously. Default: 8445rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.24.1.6
mnacConnectivityFailureTimeoutThis object is used to configure/retrieve the MNAC connectivity failure in seconds. Default: 32rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.24.1.7
mnacAgentGUIDPortThis object is used to configure/retrieve the agent GUID request listen port on the MNAC Agent, to which the intrushield sensor would send the agent GUID request. Default: 8444rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.24.1.8
mpeExcludedMacTableobsolete
SEQUENCE OF MPEExcludedMacEntry
.1.3.6.1.4.1.8962.2.1.2.1.24.2
mpeExcludedMacEntryEach entry specified is indexed by MAC Adress.obsolete
MPEExcludedMacEntry
.1.3.6.1.4.1.8962.2.1.2.1.24.2.1
mpeMacAddressMac address to be excluded from Mpe processing (Floater Mac)obsolete
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.24.2.1.1
mpeMacChangeActionThis object used for user to add and delete rows in to the table.rwobsolete
RowStatus (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.24.2.1.2
remediationGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.25
remediationConfigGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.25.1
remediationTimeoutTime in minutes for which the hosts needs to be quarantined so that it can be remediated. Default: 30rwobsolete
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.25.1.2
ezLogAlertGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.26
ezAlertLoggingThis object specifies various ways to enable EZ(enforcement zone) alert logging or disable it altogether. This is applicable on a sensor wide basis for all ports in inline mode. Default: disable (5)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.26.1
ezAlertThrottleMaxIpPairOnce this threshold is exceeded, sensor will only send one summary ez alert for all addresses (srcip's and destip's) that match the aclid/vidsid. Default: 10rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.26.2
ezAlertThrottleIntervalThis object specifies the enforcement zone alert throttle interval. Default: 120 secondsrw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.26.3
ezAlertThrottleActionThis object can be used to enable and disable ez alert throttling. Default: enable(1)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.26.4
ezAlertThrottleThresholdThis object is used to configure the number of alerts that need to be sent before sensor starts to throttle the ez alerts. For example if this value is 10, it will send the first 10 ez alerts with the following key: aclid/vidsid/srcip/destip. This parameters will use the ezAlertThrottleInterval as the interval. Default: 5rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.26.5
ezAlertDirectToSyslogThis object can be used to enable sending EZ logs directly to syslog viewer instead of sending it via NSM. Default: sendViaNSM (1)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.26.6
nbadGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.27
nbadConfigGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.27.1
nbadSensorIpAddressThe ipaddress of the NBAD server to which all the collected flowrecords would be sent.rw
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.27.1.1
nbadSensorPortThe port on which the NBAD server is listening for flow records.rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.27.1.2
nbadIPSPriMonPortIdThis object contains the primary IPS monitoring linear port index to be used to send flow records to the NBAD sensor.rw
TrellixPortLinearIndex (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.27.1.3
nbadIPSSecMonPortIdThis object contains the secondary IPS monitoring linear port index to be used to send flow records to the NBAD sensor. This monitoring port would be used only when the configured primary monitoring port cannot be utilised to send the flow records to the NBAD sensor.rw
TrellixPortLinearIndex (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.27.1.4
nbadAppFingerPrintingEnabledThis object value if set to TRUE indicates that application finger printing is enabled. Default: Falserw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.27.1.5
nbadOSFingerPrintingEnabledThis object value if set to TRUE indicates that OS finger printing is enabled. Default: Falserw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.27.1.6
nbadSslFlowDataCaptureEnabledThis object value if set to TRUE indicates that ssl flow data capture is enabled. Default: Falserw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.27.1.7
nbadFlowProtocolIdThis object value set indicates the protocol type of the exported flow records. Default: netflow (1)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.27.1.8
nbadFlowProtocolVersionThis object value set indicates the protocol version of the exported flow records. Default: netFlowVersion9 (1)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.27.1.9
nbadCaptureTCPThis object value set indicates whether netflow capture for TCP flows is enabled or not. Default: enable (1)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.27.1.10
nbadCaptureUDPThis object value set indicates whether netflow capture for UDP flows is enabled or not. Default: enable (1)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.27.1.11
nbadCaptureICMPThis object value set indicates whether netflow capture for ICMP flows is enabled or not. Default: disable (2)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.27.1.12
hostDataGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.28
hostDataTableTable containing entries for each discovered host. (indexed via hostDataIndex) This table contains Trellix specific MIB objects.
SEQUENCE OF HostDataEntry
.1.3.6.1.4.1.8962.2.1.2.1.28.1
hostDataEntryThis MIB object contains all the columnar objects, that describe the contents of each discovered host. Indexed by hostDataIndex
HostDataEntry
.1.3.6.1.4.1.8962.2.1.2.1.28.1.1
hostDataIndexThe index of the Host Data Entryro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.28.1.1.1
hostIPAddressThe ipaddress of the detected host.ro
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.28.1.1.2
hostMacAddressThe MAC address of the detected host.ro
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.28.1.1.3
hostDetectedDHCPMonPortIdThe monitoring interface linear port index over which the host was detected in DHCP mode.ro
TrellixPortLinearIndex (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.28.1.1.4
hostNameThe name of the detected host.ro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.28.1.1.5
hostUpdatedTimeStampThe time of the host getting updated last. This would be zero intilially at the time of host getting detected.ro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.28.1.1.6
hostAgentGuidThe agent GUID of the detected host.ro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.28.1.1.7
hostNACStatusThe detected host NAC status.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.28.1.1.8
hostStateThe state of the detected host entry.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.28.1.1.9
hostDeploymentModeThe deployment mode of the detected host.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.28.1.1.10
hostHealthLevelThe health level of the detected host.ro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.28.1.1.11
hostEZIdThe applied enforcement zone id for the detected host.ro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.28.1.1.12
hostUserNameThe IBAC username of the detected host.ro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.28.1.1.13
hostPolicyIdThe IBAC policy id of the detected host.ro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.28.1.1.14
hostDetectedTimeStampThe time of the host getting detected.ro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.28.1.1.15
hostOSInfoThe Operation system information of the detected host.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.28.1.1.16
hostMNACAgentOSInfoThe OS information of the detected host provided by the MNAC agent.ro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.28.1.1.17
hostActiveIndicates whether the host is Active or not. If set to true, it indicates the host is activero
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.28.1.1.18
hostDetectedStdMonPortIdThe monitoring interface linear port index over which the host was detected in Standard mode.ro
TrellixPortLinearIndex (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.28.1.1.19
hostDetectionTypeThe detection type of the detected host. For OOB cases, this includes the discovery mechanism as well.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.28.1.1.20
hostUserAuthProtocolAuthentication type of the logged in IBAC user.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.28.1.1.21
hostSwitchIdSwitch instance ID on which host was detected in OOB mode.ro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.28.1.1.22
hostSwitchPortIdSwitch port ID on which host was detected in OOB modero
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.28.1.1.23
hostSwitchPortGroupIdSwitch port group ID on which host was detected in OOB modero
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.28.1.1.24
hostQuarantineVlanIdQuarantine VLAN Id corresponding to the host which was detected in OOB mode.ro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.28.1.1.25
hostProductionVlanIdProduction VLAN Id corresponding to the host which was detected in OOB mode.ro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.28.1.1.26
nasIpAddressThe Network Server Access Ipaddress of the switch where the host is connecting to.ro
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.28.1.1.27
nasGroupObjectIdFlexible policy Network Server Access Group Object Id for the host.ro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.28.1.1.28
userGroupObjectIdFlexible policy User Group Object Id for the host.ro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.28.1.1.29
deviceProfileStringThe device profile string provided by the third party device profiling ldap server for the host.ro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.28.1.1.30
hostOperationalModeThis object indicates the operational mode for the host.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.28.1.1.31
hostEnforcementActionThis object indicates the kind of enforcement done for the host.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.28.1.1.32
flexiblePolicyRuleIdThis indicates the flexible policy rule for the host.ro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.28.1.1.33
hostConfigGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.28.2
hostEntryAttributeHost entry attribute to be considered for config action.rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.28.2.1
hostEntryIpAddressHost entry Ip address to be considered for config action.rw
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.28.2.2
hostEntryMacHost entry Mac address to be considered for config action.rw
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.28.2.3
hostEntryConfigHost entry config action.rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.28.2.4
hostEntryEZIdEZ-ID to be considered for modifying the NAZ of the given host entry.rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.28.2.5
hostDataAvailabilityStatusThis object indicates the availability of the hostData through SNMP. This information is useful immediately after the sensor reboot, as the Host Data even if present on the sensor would be available through SNMP only after the system health becomes GOOD, as the host data would be initialised only during the initial sigfile processing. True: Host Data available after the sensor initialisation or no persisted hostdata. False: In other scenarios.ro
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.28.3
sgapGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.29
sgapConfigGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.29.1
sgapAuthTimeoutAuthentication channel timeout in seconds. Default: 30rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.29.1.1
sgapCSRConfigGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.29.1.2
sgapCSRCountryNameCountry name for generating the CSR. Use the two-letter code without punctuation for country like US or CA.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.29.1.2.1
sgapCSRStateProvinceState or Province name for generating the CSR. Spell out the state completely.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.29.1.2.2
sgapCSRLocalityCity or town name for generating the CSR.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.29.1.2.3
sgapCSRCompanyCompany name for generating the CSR. If the company name has symbols, spell out the symbol or omit it to enroll.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.29.1.2.4
sgapCSROrganizationalUnitThe organizational unit is the name of the department or organization unit making the request. This is an optional fieldrw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.29.1.2.5
sgapCSRCommonNameThe common name is the host plus domain name. It looks like www.company.com or company.com.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.29.1.2.6
sgapCSRGenerateActionThis action is used to generate the CSR/self signed certificate. Default : other (0)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.29.1.2.7
sgapCSRGenerateStatusThis object describes the possible CSR generation states. Default : other (0)ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.29.1.2.8
sgapCertStatusThis object indicates the sgap cert status on the sensor. Default: 0ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.29.1.3
alarmAndTrendsGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.30
sensorPerfAlertGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.30.1
sensorPerfAlertEnableThis object is used to enable/disable generation of sensor performance alerts, for the purpose of historical trends. Default: false(2)rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.30.1.1
sensorPerfAlertDurationThis object is used to configure the duration of sensor performance alerts in minutes, for the purpose of historical trends. Default: 5rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.30.1.2
sensorPerfAlertParametersThis object is used to configure the parameters of sensor performance alerts, for the purpose of historical trends. The parameter bit positions are as given below. msb-bit(1) : cpu-utilization, msb-bit(2) : tcpudp-flows, msb-bit(3) : sensor-throughput, msb-bit(4) : mon-port-data-rate, msb-bit(5) : reserved msb-bit(6) : reserved msb-bit(7) : system-memory, msb-bit(8) : packet-buffers, msb-bit(9) : decrypted-ssl-flowsrw
OCTET STRING
.1.3.6.1.4.1.8962.2.1.2.1.30.1.3
alarmConfigGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.30.2
alarmStatusThis object is used to enable/disable generation of threshold based alarms. Default: false(2)rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.30.2.1
alarmDeleteAllEntriesThis object is used to delete all alarm entries in a single operation.rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.30.2.2
alarmDurationThis object indicates the duration in minutes, at which the sensor needs to perform threshold checks and if required generate the specific alarm. Default : 1rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.30.2.3
alarmTableTable containing entries for configured threshold based alarms. (indexed via alarmIndex) This table contains Trellix specific MIB objects.
SEQUENCE OF AlarmEntry
.1.3.6.1.4.1.8962.2.1.2.1.30.2.4
alarmEntryThis MIB object contains all the columnar objects, that describe the contents of each threshold based alarm. Indexed by alarmIndex
AlarmEntry
.1.3.6.1.4.1.8962.2.1.2.1.30.2.4.1
alarmIndexThe index of the threshold based alarm entry
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.30.2.4.1.1
alarmSampleTypeThis object indicates the alarm sample type for which the sensor needs to generate alarms based on alarm threshold settings. The threshold value range vary based on the sample types : cpu-utilization-abs : 0 - 100, tcpudp-flows : 0 - 100, sensor-throughput-delta : 0 - 100, mon-port-throughput-delta : 0 - 100, l2-error-drop-delta : 0 - 4294967295, l3-l4-error-drop-delta : 0 - 4294967295, system-memory : 0 - 100, packet-buffers : 0 - 100, decrypted-ssl-flows : 0 - 100rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.30.2.4.1.2
alarmSampleTypeIndexBitmapThis object provides the index bit map for the alarm sample type id. The bit setting would be similar to the BITS type and in network order. The bitmap would be as given below : cpu-utilization-abs - 0, sensor-throughput-delta - 0, mon-port-throughput-delta - Bit position indicates the <linear portIndex> sensor-l2-error-drop-delta - 0, sensor-l3-l4-error-drop-delta - 0rw
OCTET STRING
.1.3.6.1.4.1.8962.2.1.2.1.30.2.4.1.3
alarmSampleTypeDescThis object provides the alarm sample type description such as 'lower-band', 'higher-band', etc.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.30.2.4.1.4
alarmRaisingThresholdThis object indicates the raising threshold value. The sensor would generate raising threshold alarm when the sample type counter exceeds this value.rw
Unsigned32
.1.3.6.1.4.1.8962.2.1.2.1.30.2.4.1.5
alarmFallingThresholdThis object indicates the falling threshold value. The sensor would generate falling threshold alarm when the sample type counter reduces below this value.rw
Unsigned32
.1.3.6.1.4.1.8962.2.1.2.1.30.2.4.1.6
alarmStartupTypeThis object indicates the first alarm type that the sensor must generate before generating the other threshold based alarm. For eg; if the value is set to 'raising (1)', then the sensor has to first raise an alarm based on raising threshold value and only then based on falling threshold value. Default : raising (1)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.30.2.4.1.7
alarmEntryStatusThis object is used to create a new threshold based alarm.rw
RowStatus (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.30.2.4.1.8
bwSavingStatusThis object is used to enable/disable bandwidth saving. Default: false(2)rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.30.2.5
oobnacGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.31
oobnacSwDiscoveryGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.31.1
swInstanceTableTable containing entries for each switch instance(indexed via switch id).
SEQUENCE OF SwInstanceEntry
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1
swInstanceEntryThis MIB object contains all the attributes that are specific to the switch instance. Indexed by swIdIndex
SwInstanceEntry
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1
swIdIndexThe index
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.1
swDetDescDescription returned by the switch.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.2
swProfileIdswitch profile id returned by the switch.rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.3
swIPAddressIP address of the switch instance sent down from ISM when a new switch is being added.rw
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.4
swIPV6AddressIPV6 address of the switch instance sent down from ISM when a new switch is being added.rw
Ipv6Address (IPV6-TC)
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.5
swNameSwitch name returned by the switch.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.6
swDescSwitch name returned by the switch. This can be modified by ISM.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.7
swEnableOption to enable/disable the specific switch upon discovery. The default value is enable(1).rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.8
swSNMPsupportSupport for snmp communication between sensor and the switch.Currently the value always remains true.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.9
swSnmpVerSupportsnmp version supported by the switch. The default will be version 2.rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.10
swREADCommunityStrString used for all read-only snmp data communication between sensor and the switch. The default string is public.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.11
swWRITECommunityStrString used for all read-write snmp data communication between sensor and the switch.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.12
swTRAPCommunityStrcommunity string used for the all the traps received from the switch.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.13
swSNMPPortsnmp port for snmp communication with the switch(161).rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.14
swV3UserNameUser name for snmp v3 communication.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.15
swV3SecurityLevelLevel of security supported by the switch. The default value is authPriv(3).rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.16
swV3AuthProtocolprotocol for authentication of the user. The default value is Md5(1).rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.17
swV3AuthKeyKey for authentication of the user.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.18
swV3EncrProtocolprotocol for encryption of snmp communication messages. The default value is DES(1).rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.19
swV3EncrKeykey for encryting messages.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.20
swCLIsupportSupport for CLI communication between sensor and the switch.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.21
swCLINwProtocolsupport for a command line interfaces network protocol such as TELNET or ssh. Default value is telnet(1).rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.22
swCLIUserNameuser name for CLI communication.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.23
swCLIPwdpassword to authenticate CLI user.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.24
swCLIEnablePwdEnable password to authenticate CLI user.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.25
swCLIAutoSaveConfigIf this option is enabled then auto save CLI configuration changes to flash.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.26
swRadiusSupportSupport for radius communication between sensor and the switch. The default value is enable(1).rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.27
swRadiusSharedSecretA case-sensitive text string used to validate communications between two radius devices.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.28
swPlaceHolderVlanspecial vlan value used for assigning qvlan value to an empty port.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.29
swUseDefaultQVlanPoolOption to use globally set qvlan pool range.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.30
swQVlanPoolRangeQvlan pool range assigned for the switch instance.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.31
swDiscoverActionThis action data will add a switch entry in the table. Default action is createAndGo(4).rw
RowStatus (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.32
swCLILoginTypeDifferent login types supported for CLI.rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.33
swAuthMacAddRadSrvOptionSupport for option to authenticate MAC addresses against radius server.Default option is to disabled(0).rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.34
swActionStatusVariable to poll the status of the switch(in case sw goes down).ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.35
swPortDefaultVlanVariable used for updating port default vlan for universal control point (UCP)switches. For non-ucp switches the value will default to zero.rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.36
swActionStatusTimeTime when swActionStatus variable was updated.ro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.31.1.1.1.37
swIpAddressIP address of the switch instance sent down from ISM when a new switch is being added.rw
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.31.1.2
swIpV6AddressIPV6 address of the switch instance sent down from ISM when a new switch is being added.rw
Ipv6Address (IPV6-TC)
.1.3.6.1.4.1.8962.2.1.2.1.31.1.3
readCommunityStringThis string is used for all read-only snmp data communication between sensor and the switch. The default string is public.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.31.1.4
snmpPortThe default port on which snmp runs(161).rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.31.1.5
snmpVerSupportsnmp version supported by the switch. The default will be version 2.rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.31.1.6
writeCommunityStrString used for all read-write snmp data communication between sensor and the switch.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.31.1.7
trapCommunityStrcommunity string used for the all the traps received from the switch.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.31.1.8
v3UserNameUser name for snmp v3 communication.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.31.1.9
v3SecurityLevelLevel of security supported by the switch. The default value is authPriv(3).rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.31.1.10
v3AuthProtocolprotocol for authentication of the user. The default value is Md5(1).rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.31.1.11
v3AuthKeyKey for authentication of the user.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.31.1.12
v3EncrProtocolprotocol for encryption of snmp communication messages. The default value is DES(1).rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.31.1.13
v3EncrKeykey for encryting messages.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.31.1.14
cliNwProtocolsupport for a command line interfaces network protocol such as TELNET or ssh. Default value is telnet(1).rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.31.1.15
cliUserNameuser name for CLI communication.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.31.1.16
cliPwdpassword to authenticate CLI user.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.31.1.17
cliEnablePwdEnable password to authenticate CLI user.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.31.1.18
swQueryActionaction to get preliminary data (like sys uptime, sys description etc) from the switch. also to test cli and snmp.rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.31.1.19
cliLoginTypeDifferent login types supported for CLI.rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.31.1.20
profileIdswitch profile id returned by the switch.rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.31.1.21
switchIdThe sw global id used to re-learn the switch.rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.31.1.22
oobnacAllSwitchesGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.31.2
oobnDefaultQvlanPooldefault qvlan pool range assigned for the all switches using default qvlan pool.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.31.2.1
oobnacRadNumRetriesThe default number of retries(3) allowed for radius users.rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.31.2.2
oobnacRadRespTimeOutThe default timeout value(3 seconds) for radius response timeout.rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.31.2.3
oobnacFailoverGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.31.3
oobnacFloatingIpAddressFloating Management Port IP Address.rw
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.31.3.1
oobnacFloatingIpv6AddressFloating Management Port IPv6 Address.rw
Ipv6Address (IPV6-TC)
.1.3.6.1.4.1.8962.2.1.2.1.31.3.2
oobnacFloatingNetMaskFloating Management Port Network mask as a IPAddress prefix.rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.31.3.3
oobnacFloatingv6NetMaskFloating Management Port IPv6 Network mask as a IPAddress prefix.rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.31.3.4
oobnacFloatingGatewayIpAddressFloating Management Port Gateway IP Address.rw
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.31.3.5
oobnacFloatingGatewayIpv6AddressFloating Management Port Gateway IP Address.rw
Ipv6Address (IPV6-TC)
.1.3.6.1.4.1.8962.2.1.2.1.31.3.6
oobnacPeerIpAddressFailover Peer Management Port IP Address.rw
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.31.3.7
oobnacPeerIpv6AddressFailover Peer Management Port IPv6 Address.rw
Ipv6Address (IPV6-TC)
.1.3.6.1.4.1.8962.2.1.2.1.31.3.8
oobnacFailoverSensorStatusStatus of the sensor in OOBNac failover.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.31.3.9
malwareGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.32
malwarePriDNSServerIpIP address of the primary DNS server.rwobsolete
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.32.1
malwareSecDNSServerIpIP address of the secondary DNS server.rwobsolete
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.32.2
malwarePriDNSServerIpV6IPV6 address of the primary DNS server.rwobsolete
Ipv6Address (IPV6-TC)
.1.3.6.1.4.1.8962.2.1.2.1.32.3
malwareSecDNSServerIpV6IPV6 address of the secondary DNS server.rwobsolete
Ipv6Address (IPV6-TC)
.1.3.6.1.4.1.8962.2.1.2.1.32.4
malwareRiskLevelMalware risk level threshold value set by the user. The default level is Very Low.rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.32.5
malwareArtemisDetectionModeartemis configuration to do either of the settings Alert only, Alert and Block or Alert, Block and TCP-Reset.rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.32.6
malwareUDFDetectionModeuser-defined configuration to do either of the settings Alert only, Alert and Block or Alert, Block and TCP-Reset.rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.32.7
gamEngSensorCfgGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.32.8
gamEngSensorAutoUpdateConfigEnable / disable the Sensor auto update config. Default : True (Enable)rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.32.8.1
gamEngSensorAutoUpdateIntervalSets the Sensor auto update Interval in minutes. Default : 90rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.32.8.2
gamEngVerProvides the current gam engine version available on sensor.ro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.32.8.3
gamDatVerProvides the current gam dat version available on sensor.ro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.32.8.4
avEngVerProvides the current AV engine version available on sensor.ro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.32.8.5
avDatVerProvides the current AV dat version available on sensor.ro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.32.8.6
gamEngUpdatedTimeProvides the time in UTC format when sensor had updated GAM engine successfully.ro
Unsigned32
.1.3.6.1.4.1.8962.2.1.2.1.32.8.7
gamManualFullUpdateFileUploadStatusProvides the current file upload status.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.32.8.8
miscCfgGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.33
jumboframeParsingConfigConfiguration option to enable/disable jumboframe parsing. The new setting would be effective only after a sensor reboot. Default: disablerw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.33.1
currentJumboframeParsingStatusThe current running jumboframe parsing status.ro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.33.2
appIdStatsConfigStatusThis object value if set to TRUE indicates that the appId stats collection is enabled for the sensor. Default: Falserw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.33.3
hitlessRebootStatusStatus option to read whether hitless reboot is possible or not at this time.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.33.4
existingGeoDBFilenameThis specifies the name of geo database file present in sensor. NULL would be returned when there is no geo DB file on the sensor.ro
OCTET STRING
.1.3.6.1.4.1.8962.2.1.2.1.33.5
nsmTrackUserLoggingStatusConfiguration option to enable/disable NSM audit logging. Default: disablerw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.33.6
accelerateFTPInboundConfigConfiguration option to enable/disable accelerate ftp in inbound direction Default: false (2)rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.33.7
accelerateFTPOutboundConfigConfiguration option to enable/disable accelerate ftp in outbound direction. Default: false (2)rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.33.8
parseTunnellingConfigConfiguration option to enable/disable parsing of tunnelled packet. Default: false (2)rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.33.9
prev256ByteLoggingConfigConfiguration option to enable/disable prev 256 byte logging. Default: false (2)rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.33.10
cliAuditLoggingConfigConfiguration option to enable/disable cli audit logging through SNMP. Default: false (2)rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.33.11
snortRuleEngineConfigConfiguration option to switch snort rule engine between traditional and next generation. The new setting would be effective only after a sensor reboot. Default: traditionalrw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.33.12
currentSnortRuleEngineStatusThe current running snort rule engine on sensor.ro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.33.13
insightsTelemetryConfigConfiguration option to enable/disable usage of configured telemetry data for Insightsrw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.33.14
layer2FwdGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.34
layer2FwdCfgGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.34.1
layer2FwdTypeDifferent modes for using layer2 forward feature.rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.34.1.1
layer2IntfPortThe intf linear port index of the sensor for the mode chosen.rw
TrellixPortLinearIndex (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.34.1.2
layer2FwdActionAction to take for the specified port(s).rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.34.1.3
layer2FwdBeginIdStart port id(range 1-65535) for the mode selected(tcp/udp/vlan).rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.34.1.4
layer2FwdEndIdEnd port id(range 1-65535) for the mode selected(tcp/udp/vlan).rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.34.1.5
layer2FwdConfigLayer2 forward configuration to enable or disable this feature. Each bit represents the layer2 forward type. From the LSB the 1st bit for TCP, 2nd bit for UDP, 3rd bit for VLAN. Default will be 7, indicating this feature is enablerw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.34.1.6
layer2FwdTCPTableTable containing TCP port ranges configured for L2 forwarding.(indexed via intf port number and entry number).
SEQUENCE OF Layer2FwdTCPEntry
.1.3.6.1.4.1.8962.2.1.2.1.34.2
layer2FwdTCPEntryThis MIB object contains all the attributes that are specific to the L2 fwd entry for TCP table. Indexed by intfPortLinearIndex and entry number.
Layer2FwdTCPEntry
.1.3.6.1.4.1.8962.2.1.2.1.34.2.1
tcpIntfPortIndexThe intfPort linear index
TrellixPortLinearIndex (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.34.2.1.1
tcpEntryIndexThe index
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.34.2.1.2
tcpPortRangerange for which L2 forwarding feature is enabled.ro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.34.2.1.3
layer2FwdUDPTableTable containing UDP port ranges configured for L2 forwarding.(indexed via intfPortIndex and entry number).
SEQUENCE OF Layer2FwdUDPEntry
.1.3.6.1.4.1.8962.2.1.2.1.34.3
layer2FwdUDPEntryThis MIB object contains all the attributes that are specific to the L2 fwd entry for UDP table. Indexed by intfPortLinearIndex and entry number.
Layer2FwdUDPEntry
.1.3.6.1.4.1.8962.2.1.2.1.34.3.1
udpIntfPortIndexThe intfPort linear index
TrellixPortLinearIndex (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.34.3.1.1
udpEntryIndexThe index
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.34.3.1.2
udpPortRangerange for which L2 forwarding feature is enabled.ro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.34.3.1.3
layer2FwdVLANTableTable containing VLAN port ranges configured for L2 forwarding.(indexed via interface number and entry number).
SEQUENCE OF Layer2FwdVLANEntry
.1.3.6.1.4.1.8962.2.1.2.1.34.4
layer2FwdVLANEntryThis MIB object contains all the attributes that are specific to the L2 fwd entry for VLAN table(indexed via intfPortLinearIndex and entry number).
Layer2FwdVLANEntry
.1.3.6.1.4.1.8962.2.1.2.1.34.4.1
vlanIntfPortIndexThe intfPort linear index
TrellixPortLinearIndex (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.34.4.1.1
vlanEntryIndexThe entry index
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.34.4.1.2
vlanPortRangerange for which L2 forwarding feature is enabled. Maximum vlan range supported on each interface is 4k.ro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.34.4.1.3
layer2FwdIPTableTable containing IP protocol ranges configured for L2 forwarding.(indexed via intfPortIndex and entry number).
SEQUENCE OF Layer2FwdIPEntry
.1.3.6.1.4.1.8962.2.1.2.1.34.5
layer2FwdIPEntryThis MIB object contains all the attributes that are specific to the L2 fwd. entry for IP table. Indexed by intfPortLinearIndex and entry number.
Layer2FwdIPEntry
.1.3.6.1.4.1.8962.2.1.2.1.34.5.1
ipIntfPortIndexThe intfPort linear index
TrellixPortLinearIndex (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.34.5.1.1
ipEntryIndexThe index
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.34.5.1.2
ipPortRangerange for which L2 forwarding feature is enabled.ro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.34.5.1.3
pktCapCfgGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.35
pktCapModeOption to select packet capture Mode. File mode is not supported in 6.x release. Default: disablerw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.35.1
pktCapDurationThe duration for which capture will be enabled.. Units are in seconds. Default: 120 seconds duration value 0 indicate indefinite capture till the capture is stopped. Default: 120rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.35.2
pktCapPmSpanPortForCaptureSpan linear port index for the capture: ISM also needs to verify that port should be configured as Span port. Applicable only for port mode capture. Zero indicates no port assigned. Default: 0rw
TrellixPortLinearIndex (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.35.3
pktCapFmLocationThis will determine whether capture file is to be uploaded to manager, tftpServer or ScpServer. Note :Applicable only for file mode capture Default: managerrw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.35.4
pktCapFmMaxSizeThe size of the maximum capture file. It will be configurable but to the maximum value of sensor define limit. Default: 100 MB for M8000, M6050, M4050, M3050 58 MB for N450, Wilson 40 MB for Eagle, Diablo Note :Applicable only for file mode capturerw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.35.5
pktCapFmFUServerAddressFile Upload server IPv4 / IPv6 address. Note :Applicable only for file mode capturerw
OCTET STRING
.1.3.6.1.4.1.8962.2.1.2.1.35.6
pktCapFmFUFileNameThis specifies the name of the file with the source path on the file upload server. This is optional. If not set, the filename used will be of the format '%DEVICE_NAME%-PacketCapture-%TimeStamp%. Note :Applicable only for file mode capturerw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.35.7
pktCapFmFUSettingThis option will determine whether user needs to initiate the file upload or it will be done automatically. Default: automatic Note :Applicable only for file mode capturerw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.35.8
pktCapFilterFileNamePacket Capture Filter File Name send by NSM using secure TFTP channelro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.35.9
pktCapFilterFileTimeStampPacket Capture FilterFile creationTimeStampro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.35.10
pktCapCommandGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.35.11
pktCapCmdOption to start/stop packet capture feature and also to delete filter file. Default: stoprw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.35.11.1
pktCapStatusOption to access packet capture Status. Default: idlero
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.35.11.2
packetCaptureFmFUControlOption to control manual upload of the file. Note :Applicable only for file mode capture Default: stoprw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.35.11.3
packetCaptureFmFileStatusPacket Capture File status. Note :Applicable only for file mode capture Default : fileUploadNotStartedro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.35.11.4
packetCaptureFmTestOption to test packet capture file upload function. Note :Applicable only for file mode capture Default: stoprw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.35.11.5
packetCaptureFmTestStatusPacket Capture File upload test status. Note :Applicable only for file mode capture Default : resultNotValidro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.35.11.6
pktCapFmSCPUserNameSCP Server Username. Note :Applicable only for file mode capture and upload method is SCPrw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.35.12
pktCapFmSCPPasswordSCP Server Password. Note :Applicable only for file mode capture and upload method is SCPrw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.35.13
dnsCfgGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.36
priDNSServerIpIP address of the primary DNS server.rw
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.36.1
secDNSServerIpIP address of the secondary DNS server.rw
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.36.2
priDNSServerIpV6IPV6 address of the primary DNS server.rw
Ipv6Address (IPV6-TC)
.1.3.6.1.4.1.8962.2.1.2.1.36.3
secDNSServerIpV6IPV6 address of the secondary DNS server.rw
Ipv6Address (IPV6-TC)
.1.3.6.1.4.1.8962.2.1.2.1.36.4
dnsSearchListThis specifies the space separated list of search suffix for DNS lookuprw
OCTET STRING
.1.3.6.1.4.1.8962.2.1.2.1.36.5
layer7DCapConfigGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.37
layer7DCapPercentageOfFlowsThis object specifies percentage of flows allocated for L7 Dcap when layer7 DCap feature is enabled.rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.37.1
layer7DCapBuffSizeThis object specifies the size of the buffer to be captured when L7 Dap feature is enabled . . Default: 1500rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.37.2
layer7DCapMaxSupportedFlowsThis object specifies maximum number of flows supported for L7 Dcap when L7 Dap feature is enabled .ro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.37.3
interfacePhysicalPortGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.38
intfPhysicalPortTableTable containing entries for each interface physical port (indexed via intfPhysicalPortIndex) on each sensor card (indexed via appropriate slotIndex). This table contains Trellix specific configuration objects. Tables that contain MIB objects borrowed from MIB-II are in the TRELLIX-SENSOR-PERF-MIB.
SEQUENCE OF IntfPhysicalPortEntry
.1.3.6.1.4.1.8962.2.1.2.1.38.1
intfPhysicalPortEntryThis MIB object contains all the columnar objects, that describe the contents of each interface physical port on each IntruShield sensor card. Indexed by slotIndex/intfPhysicalPortIndex
IntfPhysicalPortEntry
.1.3.6.1.4.1.8962.2.1.2.1.38.1.1
intfPhysicalPortIfDescrA textual string containing information about the interface. Returns the string that is printed on the box.ro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.38.1.1.1
intfPhysicalPortIfTypeThe type of interface, distinguished according to the physical/link protocol(s) immediately 'below' the network layer in the protocol stack. For brevity, Trellix options are as specified by the TC, TrellixIDSPortType. However, the SNMP MIB-II - Interfaces MIB specifies many more valid options. See comments section for details.ro
TrellixIDSPortType (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.38.1.1.2
intfPhysicalPortIfAdminStatusThe desired state of the interface. The testing(3) state indicates that no operational packets can be passed. Default: downrw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.38.1.1.3
intfPhysicalPortIfOperStatusThe current operational state of the interface. The testing(3) state indicates that no operational packets can be passed. Default: downro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.38.1.1.4
intfPhysicalPortEnableFullDuplexTrue: Sets interface port to work as a full-duplex one. Otherwise as half-duplex. Default: Truerw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.38.1.1.5
intfPhysicalPortSpeedGet current speed/negotiation on the interface.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.38.1.1.6
intfPhysicalPortSpeedConfigSet desired speed/negotiation on the interface. Default values are as follows: I-Series - fixed-hundred-Mbps (infinity/hichborn/2x00(1a-3b) auto-gig-Mbps on 3000/4010/4000/2x00(4a,4b) M-Series - auto-ten-gig-Mbps on palomar/pyramid(1a-4b),auto-gig-Mbps(5a-8b) Default: see aboverw
TrellixPortSpeed -- was TrellixFEType, now deprecated
.1.3.6.1.4.1.8962.2.1.2.1.38.1.1.7
intfPhysicalPortIsMcafeeConnectorTrue: connector is not inserted. True: connector is inserted in port and McAfee certified. False: connector is inserted and not McAfee certified.ro
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.38.1.1.8
intfPhysicalPortAllowAnyConnectorTrue: Permit usage of any connector for port. False: Restrict usage to McAfee certified connector only. Default: Falserw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.38.1.1.9
intfPhysicalPortCageTypePhysical connector cage type on sensor chassis panel.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.38.1.1.10
intfPhysicalPortGetMediaTypeGets the media of the connector present in the port cage. None (0) if cage is empty.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.38.1.1.11
intfPhysicalPortSetMediaTypeSets the media of the connector the user desired for the port. Default: opticalrw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.38.1.1.12
intfPhysicalPortMonPortIpAddressThis object is used to configure / retrieve the IPv4 address of the monitoring port. Default: 0.0.0.0rw
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.38.1.1.13
intfPhysicalPortMonPortNetMaskThis object is used to configure / retrieve netmask for the IPv4 address of the monitoring port. Default: 0.0.0.0rw
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.38.1.1.14
intfPhysicalPortGatewayIpAddressThis object is used to configure / retrieve the IPv4 address of the gateway. Default: 0.0.0.0rw
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.38.1.1.15
intfPhysicalPortNbadConfigStatusThis object value if set to TRUE indicates that flow record generation to be sent to the NBAD server, is enabled over this monitoring port. Default: Falserw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.38.1.1.16
intfPhysicalPortVlanIdThis MIB object indicates the Vlan ID of the VLAN to which the monitoring port is connected.rw
Integer32
.1.3.6.1.4.1.8962.2.1.2.1.38.1.1.17
intfPhysicalPortLBSerialNumberThis MIB object indicates the manufacturer provided serial number of the Load Balancer switch to which the sensor port is connected.ro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.38.1.1.18
intfPhysicalPortLBPortNumberThis MIB object returns the port number on the Load Balancer switch to which the sensor port is connected.ro
Integer32
.1.3.6.1.4.1.8962.2.1.2.1.38.1.1.19
intfPhysicalPortConnectorTypePhysical connector type plugged into the port cage.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.38.1.1.20
intfPhysicalPortLinearIndexThis MIB object indicates the Linear Index of the monitoring port. This index is generated by the sensor appliance using the pair of slot index and the port index values. The other MIB tables would directly use this linear index, whereever applicable.ro
TrellixPortLinearIndex (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.38.1.1.21
gtiConfigGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.39
gtiProxyServerNameThe proxy server name is the domain name of the HTTP proxy server in front of the sensor. It looks like www.company.com. It can also be the IP address of the HTTP proxy server. 0.0.0.0 is the default valuerw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.39.1
gtiProxyPortTCP Port on which the HTTP proxy server is listening. 0 is the default valuerw
Integer32
.1.3.6.1.4.1.8962.2.1.2.1.39.2
gtiProxyUsernameThe username to be used to connect to the HTTP proxy server.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.39.3
gtiProxyPasswordThe password to be used to connect to the HTTP proxy server.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.39.4
gtiConfigPrivateCloudGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.39.5
gtiPrivateCloudServerIPAddressTypeIdentifies the type of GTI Private Cloud Server IP Address. If set to ip-v4, then the gtiPrivateCloudServerIPv4Address object would be set else if this object is set to ip-v6, then the gtiPrivateCloudServerIPv6Address object would be set.rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.39.5.1
gtiPrivateCloudServerIPv4AddressThis object is used to configure the IPv4 address of the GTI Private Cloud server. The gtiPrivateCloudServerIPv6Address would be zero if the current object is initialized.rw
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.39.5.2
gtiPrivateCloudServerIPv6AddressThis object is used to configure the IPv6 address of the GTI Private Cloud server. The gtiPrivateCloudServerIPv4Address would be zero if the current object is initialized.rw
Ipv6Address (IPV6-TC)
.1.3.6.1.4.1.8962.2.1.2.1.39.5.3
gtiPrivateCloudServerConnectionConfigThis object is used to enable or disable or reconnect the Connection with the GTI Private Cloud Server. Default: 2, disablerw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.39.5.4
gtiPrivateCloudServerDeleteCertificateThis object is used to delete the GTI Private Cloud Server Certificate at the sensor. For deleting this certificate, the gtiPrivateCloudServerConnectionConfig should be disabled. DEFAULT: 2, dont-deleterw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.39.5.5
gtiPrivateCloudServerCertificateStatusThis object is used to indicate the GTI Private Cloud server certificate status at the sensorro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.39.5.6
gtiPrivateCloudChannelStatusThis object is used to indicate the gtiPrivateCloud channel status at the sensorro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.39.5.7
gtiUnifiedConfigGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.39.6
gtiFileRESTGTITypeThis object is used to send type of GTI server to use for file reputation feature. DEFAULT: 2, public-gti-serverrw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.39.6.1
gtiFileRESTPublicGTIFQDNThis object is used to send Name Server or FQDN of File Rep GTI server. Default value is NULLrw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.39.6.2
gtiFileRESTUsernameThis object is used to send username for configured GTI server. It should be sent in both cases, public server and private server. Default value is NULLrw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.39.6.3
gtiFileRESTPasswordThis object is used to send password for configured GTI server. It should be sent in both cases, public server and private server. Default value is NULLrw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.39.6.4
gtiFileRESTConnectionConfigThis object is used to send action to take with the recieved config. Value 1 will be sent when config is changed to private GTI server first time. Value 2 will be sent when config is changed to public GTI server. Value 3 will be sent when private GTI server config is changed, given that private GTI server is enabled already. Default value: 2rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.39.6.5
gtiFileRESTPvtGTIIPTypeThis object is used to send address type of configured GTI server. Default value: 4, IPv4rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.39.6.6
gtiFileRESTPvtGTIIPv4AddressThis object is used to configure the IPv4 address of the GTI File-Rep REST Cloud server. The gtiFileRESTPvtGTIIPV6Address would be zero if the current object is initialized. Default Value: NULLrw
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.39.6.7
gtiFileRESTPvtGTIIPV6AddressThis object is used to configure the IPv6 address of the GTI File-Rep REST Cloud server. The gtiFileRESTPvtGTIIPv4Address would be zero if the current object is initialized. Default Value: NULLrw
Ipv6Address (IPV6-TC)
.1.3.6.1.4.1.8962.2.1.2.1.39.6.8
ntpConfigGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.40
ntpConfigTableTable containing entries for each NTP(Network Time Protocol) server that is specified (indexed via ntpServerIndex). A maximum of two entries will be supported. Valid ntpServerIndex values are 1 and 2.
SEQUENCE OF NtpConfigEntry
.1.3.6.1.4.1.8962.2.1.2.1.40.1
ntpConfigEntryEach entry comprises the ntp client side configuration for each of the ntp servers specified.
NtpConfigEntry
.1.3.6.1.4.1.8962.2.1.2.1.40.1.1
ntpConfigServerIPv4This object is used to specify the IPv4 address of the remote NTP server. Default: 0.0.0.0rw
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.40.1.1.1
ntpConfigServerIPv6This object is used to specify the IPv6 address of the remote NTP server.rw
Ipv6Address (IPV6-TC)
.1.3.6.1.4.1.8962.2.1.2.1.40.1.1.2
ntpConfigPollIntervalThis object specifies the minimum poll interval. The value which is received represents the exponent of 2. If the received value is x then NTPD daemon process will calculate the min poll as 2^x seconds. Default: 6rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.40.1.1.3
ntpConfigAuthenticationEnableThis object specifies if ntp server authentication is enabled or not for the specified ntp server. False : Authentication Disable True : Authentication Enable Default: Falserw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.40.1.1.4
ntpConfigKeyIdThis MIB object specifies the key id for the corresponding association between an ntp server and ntp client. This object is used only if ntp server authentication is enabled. Default: 1rw
Integer32
.1.3.6.1.4.1.8962.2.1.2.1.40.1.1.5
ntpConfigKeyTypeThis object specifies the key type for the corresponding key id. This object is used only if ntp server authentication is enabled. Default: MD5(1)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.40.1.1.6
ntpConfigKeyValueThis object specifies the symmetric key value for the corresponding key id. This object is used only if ntp server authentication is enabled.rw
OCTET STRING
.1.3.6.1.4.1.8962.2.1.2.1.40.1.1.7
ntpConfigFileCreateThis object is used to (create ntp.conf file and start)/(stop) ntpd process. Default: stop-ntpd (0)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.40.2
pluggableModuleGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.41
pluggableModuleTableTable containing entries for each pluggable Module (indexed via slotIndex).
SEQUENCE OF PluggableModuleEntry
.1.3.6.1.4.1.8962.2.1.2.1.41.1
pluggableModuleEntryThis MIB object contains all the columnar objects, that describe the contents of each pluggable module on each IntruShield sensor card. Indexed by slotIndex
PluggableModuleEntry
.1.3.6.1.4.1.8962.2.1.2.1.41.1.1
moduleSerialNumberThis object describes the Manufacturer-provided serial number of the pluggable module.ro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.41.1.1.1
moduleSysTypeThis object describes the type of the module plugged in.ro
TrellixPluggableModuleType (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.41.1.1.2
modulePresentTrue: Indicates the module is present. Otherwise not present. Default: Falsero
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.41.1.1.3
moduleNumPortsThis MIB object returns the number of ports in this module.ro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.41.1.1.4
moduleRebootRequiredThis MIB object returns whether a reboot is needed to apply the module. Default: Falsero
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.41.1.1.5
insightixNetworkGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.42
insightixCfgGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.42.1
ldapServerIPAddressTypeIdentifies the type of Insightix LDAP server IPAddress. If set to ip-v4, then the ldapServerIpv4Address object would be set else if this object is set to ip-v6, then the ldapServerIpv6Address object would be set.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.42.1.1
ldapServerIPv4AddressThe IPv4 address of the Insightix LDAP serverrw
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.42.1.2
ldapServerIPv6AddressIPv6 Address of the Insightix LDAP server.rw
Ipv6Address (IPV6-TC)
.1.3.6.1.4.1.8962.2.1.2.1.42.1.3
ldapServerPortThe ldap server listener port on the insightix server. If SSL is enabled, the standard portnum is 636, else if ssl is disabled, the standard portnum is 389. Default: 636rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.42.1.4
ldapServerSSLConfigSpecifies if SSL is enabled for insightix ldap server. Default: 1, enablerw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.42.1.5
ldapServerBaseDNBase Distinguished Name to be used for retrieving device profile information from the Insightix ldap server. Default : dc=insightixrw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.42.1.6
ldapServerUserNameUserName to be used for authenticating to the Insightix ldap server.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.42.1.7
ldapServerPasswordPassword to be used for authenticating to the Insightix ldap server.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.42.1.8
ldapServerConfigActionThis object describes about the sensor's possible configuration actions with the insightix ldap server. Default: 2, disablerw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.42.1.9
ldapServerConfigStatusThis describes the sensor's possible insightix ldap server configuration states. Default : deinstalled (4)ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.42.1.10
ntbaChannelCfgGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.43
ntbaServerIPAddressTypeThis object is used to configure the IP address type of the mgmt port at the NTBA endrw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.43.1
ntbaServerIPv4AddressThis object is used to configure the IPv4 address of the NTBA server. The ntbaServerIPv6Address would be zero if the current object is initializedrw
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.43.2
ntbaServerIPv6AddressThis object is used to configure the IPv6 address of the NTBA server. The ntbaServerIPv4Address would be zero if the current object is initializedrw
Ipv6Address (IPV6-TC)
.1.3.6.1.4.1.8962.2.1.2.1.43.3
ntbaServerPortThis object is used to configure the NTBA Server Listening TCP port Default: 8505rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.43.4
ntbaServerConnectionConfigThis object is used to enable or disable the TCP Connection with the NTBA server Default: 2, disablerw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.43.5
ntbaServerDeleteCertificateThis object is used to delete the ntba Server Certificate at the sensor. For deleting this certificate, the ntbaServerConnectionConfig should be disabled. DEFAULT: 2, dont-deleterw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.43.6
ntbaServerCertificateStatusThis object is used to indicate the NTBA server certificate status at the sensorro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.43.7
ntbaShdKeySHAValueThis object contains the SHA1 hashed value of sensor name and sensormodel from NSMrw
OCTET STRING
.1.3.6.1.4.1.8962.2.1.2.1.43.8
ntbaChannelStatusThis object is used to indicate the NTBA SSL channel status at the sensorro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.43.9
validEdgeChannelCfgGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.44
validEdgeServerIPAddressTypeThis object is used to configure the IP address type of the mgmt port at the validEdge endrw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.44.1
validEdgeServerIPv4AddressThis object is used to configure the IPv4 address of the validEdge server. The validEdgeServerIPv6Address would be zero if the current object is initializedrw
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.44.2
validEdgeServerIPv6AddressThis object is used to configure the IPv6 address of the validEdge server. The validEdgeServerIPv4Address would be zero if the current object is initializedrw
Ipv6Address (IPV6-TC)
.1.3.6.1.4.1.8962.2.1.2.1.44.3
validEdgeServerPortThis object is used to configure the validEdge Server Listening TCP port Default: 8505rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.44.4
validEdgeServerConnectionConfigThis object is used to enable or disable the TCP Connection with the validEdge server Default: 2, disablerw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.44.5
validEdgeServerDeleteCertificateThis object is used to delete the validEdge Server Certificate at the sensor. For deleting this certificate, the validEdgeServerConnectionConfig should be disabled. DEFAULT: 2, dont-deleterw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.44.6
validEdgeServerCertificateStatusThis object is used to indicate the validEdge server certificate status at the sensorro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.44.7
validEdgeShdKeySHAValueThis object contains the SHA1 hashed value of sensor name and sensormodel from NSMrw
OCTET STRING
.1.3.6.1.4.1.8962.2.1.2.1.44.8
validEdgeChannelStatusThis object is used to indicate the validEdge SSL channel status at the sensorro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.44.9
validEdgeChannelGlobalUserIdThis object is used to configure global matd user id/profile id assigned to a sensor.rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.44.10
validEdgeChannelGlobalUserNameThis object is used to configure global matd user name/profile name assigned to a sensor.rw
OCTET STRING
.1.3.6.1.4.1.8962.2.1.2.1.44.11
dxlCfgGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.45
dxlConfigOption to enable(1) or dissable(2) the DXL on Sensor.rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.45.1
epoCfgGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.46
epoIPAddressTypeIdentifies the type of EPO IPAddress. If set to ip-v4, then the epoIPAddress object would be set else if this object is set to ip-v6, then the epoIPv6Address object would be set.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.46.1
epoIpAddressThe IPv4 Address of the EPO Serverrw
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.46.2
epoIPv6AddressIPv6 Address of a EPO Serverro
Ipv6Address (IPV6-TC)
.1.3.6.1.4.1.8962.2.1.2.1.46.3
epoPortThe EPO port through which MA connects to EPO Server Default: 8443rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.46.4
epoCredUsernameEPO server :usernamerw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.46.5
epoCredPasswdEPO server :Passwordrw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.46.6
epoActionThis config object indicates the epo action (1-Connect, 2-Disconnect, 3-Reconnect) to be taken by all the dependent modules in the sensor.rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.46.7
radiusAuthGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.47
radiusAuthConfigThis action object can be used to enable/re-init or disable user authentication using RADIUS. The value of 'True/Enable' would be interpreted as 're-init', when the configuration is already set to True/Enable. Default: False (2)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.47.1
radiusPrimaryServerIPAddrTypeIdentifies the type of IPAddress of the Primary Radius Server. If set to ip-v4, then the radiusPrimaryServerIPAddr object would be set else if this object is set to ip-v6, then the radiusPrimaryServerIPv6Addr object would be set.rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.47.2
radiusPrimaryServerIPAddrThis object specifies the IPv4 Address of the Primary RADIUS serverrw
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.47.3
radiusPrimaryServerIPv6AddrThis object specifies the IPv6 Address of the Primary RADIUS Serverrw
Ipv6Address (IPV6-TC)
.1.3.6.1.4.1.8962.2.1.2.1.47.4
radiusPrimaryServerEncrSecretThis object specifies the secret to be used in generating the encrypted RADIUS traffic between the client and Primary Radius Serverrw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.47.5
radiusPriServerAuthPortThis object specifies the port on which Primary RADIUS Server is listening for authentication requests. Default: 1812rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.47.6
radiusPriServerAccConfigThis object specifies whether accounting has to be enabled on the Primary Radius Server or not. Default: True (1)rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.47.7
radiusPriServerAccPortThis object specifies the port on which Primary RADIUS Server is listening for accounting requests. Default: 1813rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.47.8
radiusPriServerConnTimeOutThis object specifies the time in seconds the client has to wait before it can contact the Backup RADIUS Server in case the Primary RADIUS Server fails. Default: 6rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.47.9
radiusBackupServerIPAddrTypeThis object specifies the IP Address Type of the Backup RADIUS serverrw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.47.10
radiusBackupServerIPAddrThis object specifies the IPv4 Address of the Backup RADIUS serverrw
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.47.11
radiusBackupServerIPv6AddrThis object specifies the IPv6 Address of the Backup RADIUS Serverrw
Ipv6Address (IPV6-TC)
.1.3.6.1.4.1.8962.2.1.2.1.47.12
radiusBackupServerEncrSecretThis object specifies the secret to be used in generating the encrypted RADIUS traffic between the client and Backup Radius Serverrw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.47.13
radiusBackupServerAuthPortThis object specifies the port on which Backup RADIUS Server is listening for authentication requests. Default: 1812rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.47.14
radiusBackupServerAccConfigThis object specifies whether accounting has to be enabled on the Backup Radius Server or not. Default: True (1)rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.47.15
radiusBackupServerAccPortThis object specifies the port on which Backup RADIUS Server is listening for accounting requests. Default: 1813rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.47.16
radiusBackupServerConnTimeOutThis object specifies the time in seconds before which the the sensor decides that the Backup server is not responding. Default: 6rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.47.17
sshAccessGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.48
sshAccessCfgGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.48.1
sshAccessControlStatusConfiguration option to enable/disable ssh access control list for ipv4. Default: false (2)rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.48.1.1
sshAccessControlResetIpv4Configuration option to to delete/reset the ssh access ipv4 contol list. Default: false (2)rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.48.1.2
sshAccessLogSupportConfiguration option to enable/disable ssh access messages logging support. Default: false (2)rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.48.1.3
sshAccessControlResetIpv6Configuration option to delete/reset ssh access control list for ipv6. Default: false (2)rw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.48.1.4
sshAccessNumIpv4EntriesThis object ranges from 1 to 100, as only a maximum of 100 entries are supported.ro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.48.2
sshAccessIpTable
SEQUENCE OF SSHAccessIpEntry
.1.3.6.1.4.1.8962.2.1.2.1.48.3
sshAccessIpEntryEach entry specified is indexed by <sshIpv4Index>.
SSHAccessIpEntry
.1.3.6.1.4.1.8962.2.1.2.1.48.3.1
sshIpv4IndexThis object sshIpv4Index ranges from 1 to 100, It support only 100 entries.
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.48.3.1.1
sshIpAddressIP Address of a SSH Access Control(ipv4).rw
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.48.3.1.2
sshMaskIpv4Mask of a SSH Access Control(ipv4).rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.48.3.1.3
sshAccessIpConfigThis object used for user to add and delete rows in to the table.rw
RowStatus (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.48.3.1.4
sshAccessNumIpv6EntriesThis object ranges from 1 to 100, as only a maximum of 100 entries are supported.ro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.48.4
sshAccessIpv6Table
SEQUENCE OF SSHAccessIpv6Entry
.1.3.6.1.4.1.8962.2.1.2.1.48.5
sshAccessIpv6EntryEach entry specified is indexed by <sshIpv6Index>.
SSHAccessIpv6Entry
.1.3.6.1.4.1.8962.2.1.2.1.48.5.1
sshIpv6IndexThis object sshIpv6Index range from 1 to 100, It support max 100 entries
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.48.5.1.1
sshAccessIpv6AddressIPv6 address for the ssh access control listrw
Ipv6Address (IPV6-TC)
.1.3.6.1.4.1.8962.2.1.2.1.48.5.1.2
sshAccessIpv6MaskIPv6 Mask for the ssh access control listrw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.48.5.1.3
sshAccessIpv6ConfigThis object used for user to add and delete rows in to the table.rw
RowStatus (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.48.5.1.4
virtualPluggableModuleGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.49
moduleOneNumPortsThis MIB object returns the number of ports in the first module of VSS Box. To be used in conjunction with interfacePortGrp of { ivSensorConfigurationMIB 11 } to represent attributes of VSS switch virtual ports. Default: 0 (If the module is not inserted)rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.49.1
moduleTwoNumPortsThis MIB object returns the number of ports in the first module of VSS Box. To be used in conjunction with interfacePortGrp of { ivSensorConfigurationMIB 11 } to represent attributes of VSS switch virtual ports. Default: 0 (If the module is not inserted)rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.49.2
sslProbeAccessGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.51
sslProbeAccessCfgGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.51.1
sslProbeAccessMaxAgentConnConfiguration option to restrict the total number of connections that the sensor can handle from the SSL Probes. Default: 1024rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.51.1.1
sslProbeAccessNumIpv4EntriesThis object ranges from 1 to 64, as only a maximum of 64 entries are supported.ro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.51.2
sslProbeAccessIpTable
SEQUENCE OF SSLProbeAccessIpEntry
.1.3.6.1.4.1.8962.2.1.2.1.51.3
sslProbeAccessIpEntryEach entry specified is indexed by <sslProbeIpv4Index>.
SSLProbeAccessIpEntry
.1.3.6.1.4.1.8962.2.1.2.1.51.3.1
sslProbeIpAddressIP Address of a SSL Probe Access Control(ipv4).rw
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.51.3.1.1
sslProbeMaskIpv4Mask of a SSL Probe Access Control(ipv4).rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.51.3.1.2
sslProbeAccessIpConfigThis object used for user to add and delete rows in to the table.rw
RowStatus (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.51.3.1.3
sslProbeAccessNumIpv6EntriesThis object ranges from 1 to 64, as only a maximum of 64 entries are supported.ro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.51.4
sslProbeAccessIpv6Table
SEQUENCE OF SSLProbeAccessIpv6Entry
.1.3.6.1.4.1.8962.2.1.2.1.51.5
sslProbeAccessIpv6EntryEach entry specified is indexed by <sslProbeIpv6Index>.
SSLProbeAccessIpv6Entry
.1.3.6.1.4.1.8962.2.1.2.1.51.5.1
sslProbeAccessIpv6AddressIPv6 address for the sslProbe access control listrw
Ipv6Address (IPV6-TC)
.1.3.6.1.4.1.8962.2.1.2.1.51.5.1.1
sslProbeAccessIpv6MaskIPv6 Mask for the sslProbe access control listrw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.51.5.1.2
sslProbeAccessIpv6ConfigThis object used for user to add and delete rows in to the table.rw
RowStatus (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.51.5.1.3
sensorCertificateGroup
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.52
sensorCertificateConfigGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.52.1
sensorCertificateCSRConfigGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.52.1.1
sensorCertificateCSRCountryNameCountry name for generating the CSR. Use the two-letter code without punctuation for country like US or CA.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.52.1.1.1
sensorCertificateCSRStateProvinceState or Province name for generating the CSR. Spell out the state completely.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.52.1.1.2
sensorCertificateCSRLocalityCity or town name for generating the CSR.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.52.1.1.3
sensorCertificateCSRCompanyCompany name for generating the CSR. If the company name has symbols, spell out the symbol or omit it to enroll.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.52.1.1.4
sensorCertificateCSROrganizationalUnitThe organizational unit is the name of the department or organization unit making the request. This is an optional fieldrw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.52.1.1.5
sensorCertificateCSRCommonNameThe common name is the host plus domain name. It looks like www.company.com or company.com.rw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.52.1.1.6
sensorCertificateCSRGenerateActionThis action is used to generate the CSR/self signed certificate. Default : other (0)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.52.1.1.7
sensorCertificateCSRGenerateStatusThis object describes the possible CSR generation states. Default : other (0)ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.52.1.1.8
sensorCertSubAltNameTo push sensorCert subject alternative namerw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.52.1.1.9
sensorCertificateStatusThis object indicates the cert status on the sensor. Default: 0ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.52.1.2
sensorCertMigrateActionTo push request for sensor cert migrationrw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.52.1.3
sensorStackGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.53
stackNameStack Namero
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.53.1
stackNodeIdID of stackNode.ro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.53.2
stackNodeLeftNeighbourNode id of Left Neighbour, configured in stackro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.53.3
stackNodeRightNeighbourNode id of Right Neighbour, configured in stackro
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.53.4
interfaceVirtualPortGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.54
intfVirtualPortTableTable containing entries for each interface port (indexed via intfPortIndex) on each sensor card (indexed via appropriate slotIndex). This table contains Trellix specific configuration objects. Tables that contain MIB objects borrowed from MIB-II are in the TRELLIX-SENSOR-PERF-MIB.
SEQUENCE OF IntfVirtualPortEntry
.1.3.6.1.4.1.8962.2.1.2.1.54.1
intfVirtualPortEntryThis MIB object contains all the columnar objects, that describe the contents of each interface port on each IntruShield sensor card. Indexed by slotIndex/intfPortIndex
IntfVirtualPortEntry
.1.3.6.1.4.1.8962.2.1.2.1.54.1.1
intfVirtualPortIfDescrA textual string containing information about the interface. Returns the string that is printed on the box.ro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.54.1.1.1
intfVirtualPortIfTypeThe type of interface, distinguished according to the physical/link protocol(s) immediately 'below' the network layer in the protocol stack. For brevity, Trellix options are as specified by the TC, TrellixIDSPortType. However, the SNMP MIB-II - Interfaces MIB specifies many more valid options. See comments section for details.rw
TrellixIDSPortType (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.54.1.1.2
intfVirtualPortIfAdminStatusThe desired state of the interface. The testing(3) state indicates that no operational packets can be passed. Default: downrw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.54.1.1.3
intfVirtualPortOperatingModeReadWrite parameter specifies the operating mode for the Trellix IDS sensor to be used. Different modes supported are inline-fo-passive(1), non-inline or tap(2), span(3) and inlne-fc(4), inline-fo-active kit(5 - available on M-series only). Default: non-inlinerw
TrellixIDSOperatingMode (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.54.1.1.4
intfVirtualPortEnableFullDuplexTrue: Sets interface port to work as a full-duplex one. Otherwise as half-duplex. Default: Truerw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.54.1.1.5
intfVirtualPortSpeedConfigSet desired speed/negotiation on the interface.rw
TrellixPortSpeed -- was TrellixFEType, now deprecated
.1.3.6.1.4.1.8962.2.1.2.1.54.1.1.6
intfVirtualPortEnableInternalTapSet to TRUE to enable feature. Applies to Fast Ethernet (FE) ports only (see TrellixIDSPortType). For non FE ports, set to 'FALSE' . Setting this to 'TRUE' requires that <intfPortCurrentOperatingMode> is already set to 'monitor-dual-intf' Default: Truerw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.54.1.1.7
intfVirtualPortInOutTypeThis MIB object reflects the Input or Output labeling of this interface port. Used only when operating mode is inline(1) or monitor-dual-intf(2). Default: not-specified(3)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.54.1.1.8
intfVirtualFailOpenSwitchStatusReturns the status of the external optical bypass switch status. For FE ports, this object will return not-applicable(1). For GE ports, if external optical bypass switch is connected to sensor ports, this will return present(2). Otherwise, it will return not-present(3).rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.54.1.1.9
intfVirtualFailOpenPortStatusReturns the packet forwarding status of the sensor ports connected to the optical bypass switch. If status is inline-fail-open(2), sensor is doing the forwarding. If status is bypass(3), the bypass switch is doing the forwarding and sensor will not process any traffic in this mode. Tap(4), absent(5) , unknown (6) and layer2-bypass(7) are available only in M-series for non RJ45(captive) ports when connected to active FO kit and sensor operating mode is inline-fail-open-active-kit. tap - operational status(up), kit(present), heart-beat(tap) absent - operational status(up), kit(absent), hear-beat(none) unknown - operational status(down), kit(absent), heart-beat(not available).rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.54.1.1.10
intfVirtualPortEnableAntiSpoofingspoofed packet detect rcvd on the both sides . Default: 'disable-bothsides-spoof-detect' (0)rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.54.1.1.11
intfVirtualPortAllowAnyConnectorTrue: Permit usage of any connector for port. False: Restrict usage to McAfee certified connector only. Default: Falserw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.54.1.1.12
intfVirtualPortCageTypePhysical connector cage type on sensor chassis panel.rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.54.1.1.13
intfVirtualPortSetMediaTypeSets the media of the connector the user desired for the port. Default: opticalrw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.54.1.1.14
intfVirtualPortMonPortIpAddressThis object is used to configure / retrieve the IPv4 address of the monitoring port. Default: 0.0.0.0rw
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.54.1.1.15
intfVirtualPortMonPortNetMaskThis object is used to configure / retrieve netmask for the IPv4 address of the monitoring port. Default: 0.0.0.0rw
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.54.1.1.16
intfVirtualPortGatewayIpAddressThis object is used to configure / retrieve the IPv4 address of the gateway. Default: 0.0.0.0rw
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.54.1.1.17
intfVirtualPortNbadConfigStatusThis object value if set to TRUE indicates that flow record generation to be sent to the NBAD server, is enabled over this monitoring port. Default: Falserw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.54.1.1.18
intfVirtualPortVlanIdThis MIB object indicates the Vlan ID of the VLAN to which the monitoring port is connected.rw
Integer32
.1.3.6.1.4.1.8962.2.1.2.1.54.1.1.19
intfVirtualPortAppIdStatsConfigStatusThis object value if set to TRUE indicates that the appId stats collection is enabled over this monitoring port. Default: Truerw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.54.1.1.20
intfVirtualPortLinearIndexThis MIB object indicates the Linear Index of the monitoring port. This index is generated by the sensor appliance using the pair of slot index and the port index values. The other MIB tables would directly use this linear index, whereever applicable.ro
TrellixPortLinearIndex (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.54.1.1.21
intfVirtualPortFECConfigThis object value if set to TRUE indicates that FEC is enabled, FALSE for FEC disbaled Default: Falserw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.54.1.1.22
responseVirtualPortGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.55
respVirtualPortTableTable containing entries for each response port (indexed via respPortIndex) on each sensor card (indexed via valid slotIndex). This table contains Trellix specific MIB objects.
SEQUENCE OF RespVirtualPortEntry
.1.3.6.1.4.1.8962.2.1.2.1.55.1
respVirtualPortEntryThis MIB object contains all the columnar objects, that describe the contents of each response port within the Trellix IDS sensor card. Indexed by slotIndex/respPortIndex
RespVirtualPortEntry
.1.3.6.1.4.1.8962.2.1.2.1.55.1.1
respVirtualPortDescrA textual string containing information about the interface. Returns the string that is printed on the box.ro
DisplayString (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.55.1.1.1
respVirtualPortTypeThe type of interface, distinguished according to the physical/link protocol(s) immediately 'below' the network layer in the protocol stack. See TrellixIDSPortType.ro
TrellixIDSPortType (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.55.1.1.2
respVirtualPortAdminStatusThe desired state of the interface. Default: Uprw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.55.1.1.3
respVirtualPortOperStatusThe current operational state of the interface. The testing(3) state indicates that no operational packets can be passed.ro
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.55.1.1.4
respVirtualPortEnableFullDuplexTrue: Sets response port to work as a full-duplex one. otherwise as half-duplex. If True, respPortFullDuplexPeer must be specified. Default: Falserw
TruthValue (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.55.1.1.5
respVirtualPortSpeedSee TrellixPortSpeed Default: fixed-hundred-Mbps (2)rw
TrellixPortSpeed (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.55.1.1.6
respVirtualPortPktDestinationThis object is used when response ports are chosen for sending response packets. When router mode is chosen, packets will be sent to router with destination MAC as defined in intfRespMacAddress. Default value is switch (1).rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.55.1.1.7
respVirtualPortMacAddressSpecifies the macaddress of the router to which the response packets have to be sent to.rw
MacAddress (SNMPv2-TC)
.1.3.6.1.4.1.8962.2.1.2.1.55.1.1.8
respVirtualCUGEPortSpeedOnly applicable to copper-gigabit-ethernet ports, to specify whether 10mbps or 100mbps or 1-gbps or auto-neg. See TrellixCUGEType Default: auto-negotiaterw
TrellixCUGEType (TRELLIX-INTRUVERT-TC)
.1.3.6.1.4.1.8962.2.1.2.1.55.1.1.9
respVirtualAdditionalInfoA textual string containing additional information about the response interface. This mib object will be available only on V-series sensors.ro
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.55.1.1.11
intfVirtualRespTableTable containing entries for each interface port. The table describes how responses have to be sent in monitoring mode.
SEQUENCE OF IntfVirtualRespEntry
.1.3.6.1.4.1.8962.2.1.2.1.55.2
intfVirtualRespEntryIndexed by slotIndex/intfPortIndex
IntfVirtualRespEntry
.1.3.6.1.4.1.8962.2.1.2.1.55.2.1
intfVirtualRespTypeSetting this object to responsePort (2) causes responses to be sent via the response port. The response port no that needs to be used is specified with intfRespPortNo object. Setting this object to inline (3) causes responses to be sent inline. Note that in monitoring mode, responses can only be sent inline when the monitoring port is in half-duplex mode. Default action will be responsePort (1).rw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.55.2.1.1
intfVirtualRespPortNoSpecifies the response port number that needs to be used for this monitoring port. The response ports are configured by respPortTable.rw
INTEGER
.1.3.6.1.4.1.8962.2.1.2.1.55.2.1.2
mvxCfgGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.56
mvxConnectionConfigThis object is used to enable or disable the MVX integration Default: 2, disablerw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.56.1
mvxIPAddressTypeThis object is used to configure the IP address type of the mgmt port at the MVX engine endrw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.56.2
mvxBrokerIPv4AddressThis object is used to configure the IPv4 address of the MVX engine. The mvxBrokerIPv4Address would be zero if the current object is initializedrw
IpAddress
.1.3.6.1.4.1.8962.2.1.2.1.56.3
mvxBrokerIPv6AddressThis object is used to configure the IPv6 address of the MVX engine. The mvxBrokerIPv6Address would be zero if the current object is initializedrw
Ipv6Address (IPV6-TC)
.1.3.6.1.4.1.8962.2.1.2.1.56.4
mvxUserNameThis object is used to send username for configured MVX engine. Default value is NULLrw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.56.5
mvxPasswordThis object is used to send password for configured MVX engine. Default value is NULLrw
DisplayString
.1.3.6.1.4.1.8962.2.1.2.1.56.6
mvxCertificateValidationThis object is used to indicate the MVX server certificate flag at the sensorrw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.56.7
mvxAuthStatusThis object is used to indicate the authentication status between sensor and MVX enginero
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.56.8
mvxUseProxyThis object is used to indicate the configured proxy is used by the MVX engine or notrw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.56.9
arpCfgGrp
OBJECT IDENTIFIER
.1.3.6.1.4.1.8962.2.1.2.1.103
arpSDEnableOption to enable/disable ARP Spoof Detection. Default: enablerw
Enumeration
.1.3.6.1.4.1.8962.2.1.2.1.103.1